Communication method and communication apparatus
Through the authentication process of security protection of user identification in the communication system, the network security issues of terminal devices are solved, the legality and authenticity of users are ensured, and the security and user experience of network sessions are improved.
Patent Information
- Application Number
- PCT/CN2025/075431
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-26
- Filing Date
- 2025-01-27
- Publication Date
- 2025-08-14
AI Technical Summary
In existing communication systems, the network security of terminal devices cannot be effectively protected, and there are potential security risks caused by illegal users.
The authentication process of security protection of the first user identifier of the user equipment on the network side includes receiving and verifying messages carrying the security protection user identifier, activating the NAS security context, and providing services after the authentication is successful, ensuring the legitimacy and authenticity of the user.
Improves the security of network sessions, reduces potential security risks, and improves user experience.
Smart Images

Figure CN2025075431_14082025_PF_FP_ABST
Abstract
Description
Communication method and communication device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on February 8, 2024, with application number 202410179989.0, and invention name “A communication method and communication device”, and the Chinese patent application filed with the State Intellectual Property Office of China on February 26, 2024, with application number 202410210954.9, and invention name “A communication method and communication device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art
[0003] In communication systems, such as the fifth generation (5G), network security requires a primary authentication process for terminal devices accessing the network. This involves authenticating and authorizing the terminal devices. Only after successful authentication can the terminal device access the network and further request a protocol data unit (PDU) session to access various services on the data network (DN). However, current network communications may contain illegal users, making security unreliable. Therefore, additional measures are urgently needed to mitigate potential security risks. Summary of the Invention
[0004] The present application provides a communication method and a communication device, which can ensure network security.
[0005] In a first aspect, a communication method is provided. The method may be executed by a first network element, or may be executed by a chip or circuit of the first network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by the first network element.
[0006] The method includes: a first network element receives a first message from a user device, the first message including a first user identifier of a first user using the user device with security protection; the first network element initiates an authentication process for the first user based on the first message; the first network element sends a second message to the user device, the second message being used to indicate an authentication result for the first user.
[0007] The first user using the user device can be understood as a user who logs in to the user device, or a user who logs in to an external device that establishes a communication connection with the user device.
[0008] It should be understood that the first user identification has security protection, for example, integrity security protection and / or confidentiality security protection.
[0009] Optionally, the first message may have security protection. In other words, this application does not limit the security protection method of the first user identifier, for example, it may be security protection for the first user identifier alone, or it may be security protection for the first message carrying the first user identifier.
[0010] Optionally, the second message may have the same security protection as the first message, which will not be described in detail.
[0011] According to the above solution, after receiving the first message carrying the securely protected first user identifier, the first network element can trigger an authentication process for the first user and send a second message to the user device, so that the user device can determine the authentication result for the first user based on the second message. By authenticating the first user and indicating the authentication result for the first user to the user device, the network side enables the first network element and the user device to determine the legitimacy and authenticity of the first user. If the first user authentication is successful, the first user can obtain services, ensuring the security of the network session and reducing potential security risks.
[0012] In some implementations, before the first network element receives the first message from the user equipment, the method also includes: the first network element receives a registration request message from the user equipment, the registration request message including an identifier of the user equipment; the first network element determines to initiate a primary authentication process for the user equipment based on the registration request message; after the primary authentication process for the user equipment, the first network element sends a non-access stratum security mode command (NASSMC) message to the user equipment, the NAS SMC message is used to activate a NAS security context; the first network element receives a non-access stratum security mode command complete (NASSMP) message from the user equipment.
[0013] Based on the above solution, the network side can complete the registration of the user device based on the registration request message of the user device, and trigger the NAS SMC process to activate the NAS security context, that is, the network side can ensure the authenticity and legitimacy of the user device, and the subsequent information interaction between the user device and the network side is securely protected. In other words, the first message sent by the user device to the first network element to trigger the authentication of the first user can be securely protected using the NAS security context, which can prevent other attackers from maliciously tampering with the parameters carried in the first message, such as the first user identifier, and reduce potential security risks. In addition, after the primary authentication of the user device is successful, the network side can initiate an authentication process for the first user, while ensuring the legitimacy and authenticity of the user device and the first user using the user device, ensuring network session security, and improving user experience.
[0014] It should be noted that in this implementation, the network side's authentication of the first user occurs on the basis of the successful authentication of the user device, and the authentication result of the first user is independent of the authentication result of the user device. In other words, the authentication result of the first user has no effect on the authentication result of the user device. Even if the authentication of the first user fails, resulting in the first user being unable to access the network through the user device, it will not affect other users' access to the network through the user device (that is, the failure of authentication of the first user will not change the result of the previous successful authentication of the user device).
[0015] In some implementations, the first message is a NASSMP message; before the first network element receives the first message from the user equipment, the method also includes: the first network element receives a registration request message from the user equipment, the registration request message including an identifier of the user equipment; the first network element determines to initiate a primary authentication process for the user equipment based on the registration request message; after the primary authentication process for the user equipment, the first network element sends a NASSMC message to the user equipment, and the NAS SMC message is used to activate the NAS security context.
[0016] Based on the above solution, the network side completes the registration of the user device based on the registration request message of the user device, and triggers the NAS SMC process to activate the NAS security context, that is, the network side can ensure the authenticity and legitimacy of the user device, and the subsequent information interaction between the user device and the network side is securely protected. In other words, carrying the first user identifier in the NAS SMP message with security protection can not only prevent other attackers from maliciously tampering with the first user identifier, reduce potential security risks, but also reduce signaling overhead. In addition, after the primary authentication of the user device is successful, the network side can initiate an authentication process for the first user, while ensuring the legitimacy and authenticity of the user device and the first user using the user device, ensuring network session security, and improving user experience.
[0017] In some implementations, before the first network element receives the first message from the user device, the method also includes: the first network element receives a registration request message from the user device, the registration request message including an identifier of the user device and a second user identifier of the second user; the first network element determines to initiate a primary authentication process for the user device based on the registration request message; after the primary authentication for the user device is successful, the first network element initiates an authentication process for the second user.
[0018] Based on the above scheme, when the second user is the first user of the user device, the second user triggers the user device to register with the network. At this time, the registration request message sent by the user device carries both the identifier of the user device and the second user identifier of the second user. The network side completes the registration of the user device based on the registration request message of the user device, and triggers the NAS SMC process during the registration process to activate the NAS security context, thereby completing the primary authentication for the user device. After the primary authentication of the user device is successful, the authentication process for the second user is initiated. Subsequently, when other users (such as the first user) want to access the network through the user device again. The first message sent by the user device to the first network element can be protected by security, thereby ensuring the security of other users using the user device to access the network in the future.
[0019] In some implementations, the first network element initiates an authentication process for the first user based on the first message, including: the first network element initiates authentication for the first user based on the first indication information associated with the first message; wherein the first indication information is represented by one or more of the name of the first message, the first user identifier, or the designated information elements carried in the first message.
[0020] Based on the above scheme, the first network element can determine and initiate authentication for the first user based on the first indication information. For example, the name of the first message can be a user authentication request message, the designated information element can be a registration type (indicating that the first message can be a registration request message for the first user), a specific field in the first message (used to identify the first user using the user device), etc.
[0021] In some implementations, initiating an authentication process for a first user includes: the first network element determines a first authentication function; the first network element sends a user authentication request message to the first authentication function, the user authentication request message includes a first user identifier, and the user authentication request message can be used to request authentication of the first user; the first network element receives a user authentication response message from the first authentication function, and the user authentication response message is used to indicate an authentication result for the first user.
[0022] In some implementations, the first network element determines the first authentication function, including: the first network element determines the first authentication function according to local configuration information; and / or the first network element determines the first authentication function according to the first user identifier.
[0023] It should be understood that the first authentication function supports authentication of the first user corresponding to the first user identifier.
[0024] Optionally, the authentication function for authenticating the user and the authentication function for primary authentication of the user equipment may be the same. In some implementations, the first network element determining the first authentication function includes: obtaining the first authentication function for primary authentication of the user equipment.
[0025] In some implementations, the user authentication request message further includes second indication information, where the second indication information indicates to authenticate the first user.
[0026] Based on the above scheme, by carrying the second indication information in the user authentication request message, the first authentication function determines to authenticate the first user according to the second indication information, and when it is determined that the authentication of the first user is successful, the authenticity and legitimacy of the first user are known, thereby providing network services to the first user and ensuring user experience.
[0027] In some implementations, the user authentication response message includes the first user's authentication result and / or first user authentication result indication information, the first user authentication result indication information indicates the first user's authentication result, and the first user's authentication result indicates whether the first user authentication is successful or failed.
[0028] Based on the above scheme, by carrying the authentication result of the first user and / or the first user authentication result indication information in the user authentication response message, the first network element can determine the authentication result of the first user, and thus know the authenticity and legitimacy of the first user, so that when the authentication of the first user is successful, network services can be provided to the first user to ensure user experience.
[0029] In some implementations, the second message includes the first user's authentication result and / or second user authentication result indication information, the second user authentication result indication information indicates the first user's authentication result, and the first user's authentication result indicates whether the first user authentication is successful or failed.
[0030] Based on the above scheme, the first network element can directly or indirectly notify the user device of the authentication result of the first user through the second message, so that the user device knows the authenticity and legitimacy of the first user, and thus can perform subsequent operations based on the authentication result of the first user, such as providing services to the first user if the authentication of the first user is successful, or refusing to provide services to the first user if the authentication of the first user fails.
[0031] In some implementations, the method further includes: when the authentication result of the first user indicates that the first user authentication is successful, the first network element stores the association relationship between at least one of the authentication result of the first user, the identifier of the user device, and the authentication success time and the first user identifier.
[0032] Based on the above scheme, when the authentication result of the first user indicates that the first user authentication is successful, the first network element can associate at least one of the authentication result of the first user, the authentication success time, and the identifier of the user device with the first user identifier, and store them together, so that the first network element can subsequently receive the first message from the user device. The first network element can determine not to initiate the authentication process for the first user based on the locally stored authentication result of the first user associated with the first user identifier (for example, the first user authentication is successful), and then provide services to the first user, thereby reducing signaling overhead and improving user service experience.
[0033] In some implementations, the first user identifier includes a first information portion and a second information portion, the first information portion is used to identify the first user, the second information portion is used to determine routing information of a first storage function, the first storage function is used to store the credentials of the first user, and the credentials are used to identify and verify the first user.
[0034] In some implementations, when the first network element is a mobility management network element, the first message is a first NAS message, and the second message is a second NAS message; or, when the first network element is a session management network element, the first message is a first session management (SM) message, and the second message is a second SM message.
[0035] In some implementations, the first NAS message is a registration request message, or the first NAS message is a user authentication request message, or the first NAS message is a NAS SMP message.
[0036] In some implementations, when the first NAS message is a registration request message, the method further includes: the first network element sending a registration completion message to the user equipment after the authentication process for the first user; or, the first network element sending a registration completion message to the user equipment before the authentication process for the first user.
[0037] That is to say, this application does not limit the order of the registration process and the user authentication process, that is, the first network element may send the registration completion message to the user equipment before or after the user authentication process.
[0038] In some implementations, the first SM message is a protocol data unit (PDU) session establishment request message, or the first SM message is a user authentication request message, or the first SM message is an extensible authentication protocol response (EAP-Response) message.
[0039] In a second aspect, a communication method is provided, which can be executed by a user device, or by a chip or circuit of the user device, which is not limited in this application. For ease of description, the following description is based on an example of execution by a user device.
[0040] The method includes: a user device sends a first message to a first network element, the first message including a first user identifier of a first user using the user device with security protection; the user device receives a second message from the first network element, the second message is used to indicate an authentication result for the first user; the user device sends the authentication result of the first user to the first user.
[0041] Optionally, the first message and / or the second message may have security protection, for example, integrity security protection and / or confidentiality security protection.
[0042] According to the above solution, the user device sends a first message carrying a securely protected first user identifier to the first network element, so that the first network element can trigger an authentication process for the first user based on the first message. The user device can then receive a second message from the first network element, so that the user device can determine the authentication result for the first user based on the second message and notify the first user of the authentication result. By requesting the network side to authenticate the first user and obtaining the authentication result of the first user from the first network element, the first network element and the user device can determine the legitimacy and authenticity of the first user. If the first user authentication is successful, the first user can ensure the security of the network session and reduce potential security risks.
[0043] In some implementations, the method further includes: when the authentication result of the first user indicates that the first user is successfully authenticated, the user device stores an association between at least one of the authentication result of the first user and the authentication success time and the first user identifier.
[0044] Based on the above scheme, when the authentication result of the first user indicates that the first user authentication is successful, the user equipment can associate at least one of the authentication result of the first user and the authentication success time with the first user identifier and store them together, so that when the subsequent user equipment determines that the first user has logged in, it can determine not to send the first message to the first network element to request authentication of the first user based on the locally stored authentication result of the first user associated with the first user identifier (for example, the first user authentication is successful), and then provide services for the first user, thereby reducing signaling overhead and improving user service experience.
[0045] In some implementations, before the user device sends the first message to the first network element, the method also includes: when the first user uses the first user identifier to log in to the user device and / or the external device, the user device determines that the authentication result for the first user is not stored locally, wherein the external device is communicatively connected to the user device.
[0046] Based on the above solution, when the user device determines that the first user has logged in, it can send a first message to the first network element to request authentication of the first user based on the fact that the authentication result for the first user is not stored locally, and then provide services to the first user. While reducing signaling overhead, the user service experience can be improved.
[0047] In some implementations, the user equipment sends the first message to the first network element, including: when the first user uses the first user identifier to log in to the user equipment and / or the external device, the user equipment sends the first message with security protection to the first network element.
[0048] In some implementations, before the user device sends a first message with security protection to the first network element, the method also includes: the user device sends a registration request message to the first network element, the registration request message includes an identifier of the user device; after the main authentication process for the user device, the user device receives a NASSMC message from the first network element, the NAS SMC message is used to activate a NAS security context; the user device sends a NASSMP message to the first network element.
[0049] In some implementations, the first message is a NASSMP message; before the user device sends the first message with security protection to the first network element, the method also includes: the user device sends a registration request message to the first network element, and the registration request message includes an identifier of the user device; after the main authentication process for the user device, the user device receives a NASSMC message from the first network element, and the NAS SMC message is used to activate the NAS security context.
[0050] In some implementations, before the user equipment sends the first message to the first network element, the method further includes: the user equipment sends a registration request message to the first network element, where the registration request message includes an identifier of the user equipment and a second user identifier of the second user.
[0051] In some implementations, the first user identifier includes a first information portion and a second information portion, the first information portion is used to identify the first user, the second information portion is used to determine routing information of a first storage function, the first storage function is used to store the credentials of the first user, and the credentials are used to identify and verify the first user.
[0052] In some implementations, before the user device sends a first message with security protection to the first network element, the method also includes: the user device obtains a first user identifier, specifically including: the user device receives the first user identifier from an external device; and / or the user device logs in to the user device using the first user identifier according to the first user, and obtains the first user identifier.
[0053] In some implementations, the second message includes the first user's authentication result and / or second user authentication result indication information, the second user authentication result indication information indicates the first user's authentication result, and the first user's authentication result indicates whether the first user authentication is successful or failed.
[0054] In some implementations, the user device sends the first user's authentication result to the first user, including: the user device sends third user authentication result indication information to the first user, the third user authentication result indication information indicates the authentication result of the first user, and the first user's authentication result indicates whether the first user authentication is successful or failed.
[0055] In some implementations, the method further includes: when the authentication result of the first user indicates that the first user authentication is successful, the user device provides services to the first user; or, when the authentication result of the first user indicates that the first user authentication fails, the user device refuses to provide services to the first user.
[0056] In some implementations, when the first network element is a mobility management network element, the first message is a first NAS message and the second message is a second NAS message; or, when the first network element is a session management network element, the first message is a first SM message and the second message is a second SM message.
[0057] In some implementations, the first NAS message is a registration request message, or the first NAS message is a user authentication request message, or the first NAS message is a NAS SMP message.
[0058] In some implementations, the first SM message is a PDU session establishment request message, or the first SM message is a user authentication request message, or the first SM message is an Extensible Authentication Protocol response EAP-Response message.
[0059] The beneficial effects of the above-mentioned second aspect and some implementation methods can be referred to the description of the first aspect and some implementation methods, and will not be repeated here.
[0060] In a third aspect, a communication method is provided. The method may be executed by a first network element, or may be executed by a chip or circuit of the first network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by the first network element.
[0061] The method includes: receiving a first message from a user device, the first message including a user identifier, the first message being used to trigger a network to authenticate the user identifier; determining to authenticate the user identifier and obtaining a user authentication result; and sending a second message to the user device, the second message being used to indicate the user authentication result.
[0062] In some implementations, determining to authenticate the user identifier includes: determining to authenticate the user identifier based on a name of the first message.
[0063] In some implementations, determining to authenticate the user identifier includes: determining to authenticate the user identifier based on the user identifier carried in the first message.
[0064] In some implementations, determining to authenticate the user identifier includes: determining to authenticate the user identifier based on a registration type carried in the first message.
[0065] In some implementations, determining to authenticate the user identifier includes: determining to authenticate the user identifier based on local configuration information.
[0066] In some implementations, the user identity has integrity security protection and / or confidentiality security protection.
[0067] In some implementations, the method further includes: storing an association between the user authentication result and the user identifier.
[0068] In some implementations, the first message is a non-access stratum (NAS) message or a session management (SM) message.
[0069] The beneficial effects of the third aspect and some of its implementations can be referred to the description of the first aspect and some of its implementations, and will not be repeated here.
[0070] In a fourth aspect, a communication method is provided, which can be executed by a user device, or by a chip or circuit of the user device, which is not limited in this application. For ease of description, the following description is based on an example of execution by a user device.
[0071] The method comprises: sending a first message to a first network element, the first message comprising a user identifier and used to trigger a network to authenticate the user identifier; and receiving a second message from the first network element, the second message being used to indicate a user authentication result.
[0072] In some implementations, sending the first message to the first network element includes: when it is determined that the user uses the user identifier to log in to the user equipment, sending the first message to the first network element.
[0073] In some implementations, determining that the user uses the user identifier to log in to the user device includes: determining that the user uses the user identifier to log in to an external device, and the external device establishes a connection with the user device.
[0074] In some implementations, the user identity has integrity security protection and / or confidentiality security protection.
[0075] In some implementations, the method further includes: storing an association between the user authentication result and the user identifier.
[0076] In some implementations, the first message is a non-access stratum (NAS) message or a session management (SM) message.
[0077] The beneficial effects of the fourth aspect and some of its implementations can be referred to the description of the third aspect and some of its implementations, and will not be repeated here.
[0078] In the fifth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the first aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0079] A transceiver unit is used to receive a first message from a user device, the first message including a first user identifier of a first user using the user device; a processing unit is used to initiate an authentication process for the first user based on the first message; the transceiver unit is also used to send a second message with security protection to the user device, the second message being used to indicate an authentication result for the first user.
[0080] The transceiver unit can perform the receiving and sending processing in the aforementioned first aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned first aspect and its possible implementations.
[0081] In the sixth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the second aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0082] Exemplarily, the transceiver unit is used to send a first message with security protection to a first network element, the first message including a first user identifier of a first user using a user device; the transceiver unit is also used to receive a second message with security protection from the first network element, the second message being used to indicate an authentication result for the first user; the transceiver unit is also used for the user device to send the authentication result of the first user to the first user.
[0083] The transceiver unit can perform the receiving and sending processing in the aforementioned second aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned second aspect and its possible implementations.
[0084] In the seventh aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the third aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0085] A transceiver unit is configured to receive a first message from a user device, the first message including a user identifier, and the first message is configured to trigger a network to authenticate the user identifier; a processing unit is configured to determine whether to authenticate the user identifier and obtain a user authentication result; and a transceiver unit is configured to send a second message to the user device, the second message being configured to indicate the user authentication result.
[0086] The transceiver unit can perform the receiving and sending processing in the aforementioned third aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned third aspect and its possible implementations.
[0087] In the eighth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the fourth aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0088] Exemplarily, the transceiver unit is used to send a first message to a first network element, the first message includes a user identifier, and the first message is used to trigger the network to authenticate the user identifier; the transceiver unit is used to receive a second message from the first network element, and the second message is used to indicate a user authentication result.
[0089] The transceiver unit can perform the receiving and sending processing in the aforementioned fourth aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned fourth aspect and its possible implementations.
[0090] In the ninth aspect, a communication system is provided, including a first network element and a user device, the first network element is used to execute the method in the above-mentioned first aspect or third aspect and any possible implementation thereof, and the user device is used to execute the method in the above-mentioned second aspect or fourth aspect and any possible implementation thereof.
[0091] Optionally, the communication system further includes a first authentication function, a second storage function or an external device.
[0092] In the tenth aspect, a computer-readable storage medium is provided, which stores a computer program or code. When the computer program or code is run on a computer, the computer executes the method in the above-mentioned first to fourth aspects and any possible implementation thereof.
[0093] In the eleventh aspect, a chip or chip system is provided, comprising at least one processor, wherein the at least one processor is coupled to a memory, the memory being used to store a computer program, and the processor being used to call and run the computer program from the memory, so that a device equipped with the chip system executes the methods in the above-mentioned first to fourth aspects and any possible implementation thereof.
[0094] The chip may include an input circuit or interface for sending information or data, and an output circuit or interface for receiving information or data.
[0095] In the twelfth aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method in the above-mentioned first to fourth aspects and any possible implementation thereof.
[0096] In a thirteenth aspect, a computer program is provided, which, when executed, implements the method in any possible implementation manner of the first to fourth aspects.
[0097] It should be understood that the beneficial effects of the fifth to thirteenth aspects mentioned above can be referred to the first to fourth aspects and any possible implementation methods thereof, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0098] FIG1 is a schematic diagram of a network architecture;
[0099] FIG2 is a schematic diagram of a user equipment (UE) registering with a network;
[0100] FIG3 is a schematic diagram of a unified data management (UDM) function initiating a home network-triggered master authentication process;
[0101] FIG4 is a flow chart of a communication method provided in an embodiment of the present application;
[0102] FIG5 is a flow chart of another communication method provided in an embodiment of the present application;
[0103] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;
[0104] FIG7 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0105] FIG8 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0106] FIG9 is a schematic structural diagram of a chip system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0107] The technical solution in this application will be described below with reference to the accompanying drawings.
[0108] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0109] In a communication system, the part operated by an operator may be referred to as a public land mobile network (PLMN), or an operator network, etc. PLMN is a network established and operated by the government or an operator approved by it for the purpose of providing land mobile communication services to the public. It is mainly a public network in which mobile network operators (MNOs) provide mobile broadband access services to users. The PLMN described in the embodiments of the present application may specifically be a network that complies with the standards of the 3rd Generation Partnership Project (3GPP), referred to as a 3GPP network. 3GPP networks generally include but are not limited to fifth-generation mobile communication (5th-generation, 5G) networks, fourth-generation mobile communication (4th-generation, 4G) networks, and other future communication systems.
[0110] For ease of description, the embodiments of the present application will be described using PLMN or 5G network as an example.
[0111] Figure 1 is a schematic diagram of a network architecture 100, using the 5G network architecture based on a service-based architecture (SBA) in a non-roaming scenario as defined in the 3GPP standardization process as an example. As shown in Figure 1 , the network architecture may include a terminal device component, a data network (DN) component, and a carrier network (PLMN) component. The carrier network PLMN component may include, but is not limited to, a (radio) access network (R)AN) 120 and a core network (CN) component.
[0112] The following is a brief description of the functions of the network elements in each part.
[0113] The terminal device portion may include a terminal device 110, which is a device that provides voice and / or data connectivity to the user. The terminal device 110 may also be referred to as a user equipment UE. The terminal device 110 in this application is a device with wireless transceiver functions, which can communicate with one or more core network (CN) devices via an access network device (or also referred to as an access device) in a (radio) access network (R)AN 120. The terminal device 110 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent or user device, etc. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on water (such as a ship, etc.); it may also be deployed in the air (such as an airplane, balloon and satellite, etc.). The terminal device 110 may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a smartphone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), or the like. Alternatively, the terminal device 110 may be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, an unmanned aerial vehicle (UAV), or a terminal in the Internet of Things (IoT), the Internet of Vehicles (IoV), any terminal in a 5G network or future networks, a relay user device, or a terminal in a future evolving 6G network. The relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home. The terminal device here refers to a 3GPP terminal. The embodiments of the present application do not limit the type or category of terminal devices. For ease of explanation, the present application will use UE to represent terminal devices as an example for explanation.
[0114] (R)AN 120 may include one or more access network elements or access network devices, and the interface between the access network device and the terminal device may be a Uu interface (or air interface, i.e., the messages exchanged between the access network device and the terminal device may be called air interface messages). Of course, in future communications, the interface name may remain unchanged or may be replaced by other names, and this application does not limit this. (R)AN 120 is a device that provides wireless communication functions for the terminal device 110, which can connect the terminal device to a node or device of a wireless network, and may also be called a network device. (R)AN 120 can be regarded as a subnet of the operator network, and is an implementation system between a service node in the operator network and the terminal device 110. For example, the terminal device 110 can connect to a service node of the operator network through (R)AN 120, thereby obtaining the services provided by the service node. For the convenience of description, in all embodiments of this application, the above-mentioned device that provides wireless communication functions for the terminal device 110 is collectively referred to as an access network device or simply referred to as RAN. It should be understood that this document does not limit the specific type of access network device.
[0115] The CN part may include but is not limited to the following network functions (NF): user plane function (UPF) 130, network exposure function (NEF) 131, network function repository function (NRF) 132, policy control function (PCF) 133, unified data management function (UDM) 134, unified data repository function (UDR) 135, application function (AF) 136, authentication server function (AUSF) 137, access and mobility management function (AMF) 138, and session management function (SMF) 139.
[0116] The data network DN 140, also called a packet data network (PDN), is typically a network outside the operator's network, such as a third-party network.
[0117] The following is a brief description of the NF functions included in CN.
[0118] 1. UPF 130 is a gateway provided by the operator, serving as the gateway for communication between the operator network and DN 140. UPF 130 network functions include packet routing and transmission, packet inspection, service usage reporting, Quality of Service (QoS) processing, legal monitoring, uplink packet inspection, downlink packet storage, and other user-plane-related functions.
[0119] 2. NEF 131 is a control plane function provided by the operator. It mainly enables third parties to use the services provided by the network, supports the network to open its capabilities, event and data analysis, provide PLMN security configuration information from external applications, and convert interactive information within and outside the PLMN.
[0120] 3. NRF 132 is a control plane function provided by the operator, which can be used to maintain real-time information of network functions and services in the network.
[0121] 4. PCF 133 is the control plane function provided by the operator. It mainly supports providing a unified policy framework to control network behavior, provides policy rules to the control layer network function, and is responsible for obtaining user subscription information related to policy decisions.
[0122] 5. UDM 134 is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network.
[0123] 6. UDR 135 is a control plane function provided by the operator. It provides the UDM with the function of saving and retrieving subscription data, the PCF with the function of saving and retrieving policy data, and the user's NF group ID information.
[0124] 7. AF 136 is a control plane function provided by the operator. It mainly provides corresponding services by interacting with other NFs in the PLMN, such as providing roaming UE with visitor network selection information, guiding the routing of data flows, and accessing NEF 131.
[0125] 8. AUSF 137 is a control plane function provided by the operator, and is usually used for level 1 authentication, i.e., authentication between the terminal device 110 (subscriber) and the operator's network.
[0126] 9. AMF 138 is a control plane network function provided by the operator network, responsible for access control and mobility management of the terminal device 110 accessing the operator network, such as mobility status management, allocation of user temporary identity, authentication and authorization of users, etc.
[0127] 10. SMF 139 is a control plane network function provided by the operator network. It is responsible for managing the protocol data unit (PDU) sessions of the terminal device 110 (including session establishment, modification, and release). This function is used for the selection and reselection of user plane function network elements, the allocation of Internet Protocol (IP) addresses for the terminal device, and quality of service (QoS) control. A PDU session is a channel for transmitting PDUs. The terminal device exchanges PDUs with the DN 140 through a PDU session. The SMF network function 139 is responsible for establishing, maintaining, and deleting PDU sessions. The SMF network function 139 includes session management (such as session establishment, modification, and release, including tunnel maintenance between the user plane function (UPF) 130 and the (R)AN 120), selection and control of the UPF network function 130, service and session continuity (SSC) mode selection, roaming, and other session-related functions.
[0128] It is understood that the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or software.
[0129] In Figure 1, Nnef, Nnrf, Npcf, Nudm, Nudr, Naf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. For example, the meaning of the above interface serial numbers can be found in the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface serial numbers. It should be noted that the interface name between the various network functions in Figure 1 is only an example. In a specific implementation, the interface name of the system architecture may also be other names, which is not limited by this application. In addition, the name of the message (or signaling) transmitted between the above-mentioned network elements is only an example and does not constitute any limitation on the function of the message itself.
[0130] It should be noted that in the architecture shown in Figure 1, the interface between the (R)AN and CN can also be called the NG interface (not shown in the figure), and the (R)AN and CN are connected via the NG interface. The NG interface can include the NG-C interface and the NG-U interface. The NG-C interface is a control plane interface, connecting the (R)AN and AMF, and is used to transmit control plane data; the NG-U interface is a user plane interface, connecting the (R)AN and UPF, and is used to transmit user plane data.
[0131] It should be understood that the above network architecture 100 is only described from the perspective of a service-based architecture. In this service-based architecture, the PLMN can combine some or all network functions in an orderly manner according to specific scenario requirements, realizing customized network capabilities and services, thereby deploying dedicated networks for different services, that is, realizing 5G network slicing. Network slicing technology enables operators to respond to customer needs more flexibly and quickly, and supports flexible allocation of network resources.
[0132] For ease of explanation, in the embodiments of the present application, network functions (such as NEF 131...SMF 139) are collectively referred to as NFs. That is, the NFs described later in the embodiments of the present application can be replaced by any network function. In addition, in the embodiments of the present application, the session management function SMF 139 is referred to as SMF, and the terminal device 110 is referred to as UE. That is, the SMFs described later in the embodiments of the present application can be replaced by session management functions, and the UE can be replaced by a terminal device. Figure 1 only schematically illustrates some network functions, and the NFs described later are not limited to the network functions shown in Figure 1.
[0133] It should be understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in Figure 1 can be understood as network elements used to implement different functions in the core network, for example, they can be combined into network slices as needed. These core network network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements.
[0134] It should also be understood that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may continue to use the terminology used in 5G, or may adopt other names.
[0135] Currently, to ensure network security, a primary authentication process is required for terminal devices (such as UE) that access the network. This involves identity authentication and authorization of the terminal devices. Only after passing the authentication can the terminal devices access the network.
[0136] Figure 2 is a schematic diagram of a process for a UE to register with a network. As shown in Figure 2, the method 200 includes the following steps. For parts not fully described, please refer to the relevant description of the existing protocol.
[0137] S210, the UE registers with the network.
[0138] Exemplarily, the UE sends an N1message to the Security Anchor Function (SEAF) to request registration with the network. Optionally, the N1message may be a registration request message, which carries the UE's Subscription Concealed Identifier (SUCI) or the 5G Globally Unique Temporary Identifier (5G-GUTI). SEAF and AMF are jointly established, and it can be understood that SEAF is part of AMF, that is, the UE can request registration with the network by sending a registration request message to the AMF.
[0139] Correspondingly, after receiving the N1message from the UE, SEAF can initiate identity authentication to the UE according to local policies during any process of establishing a signaling connection with the UE.
[0140] Exemplarily, when SEAF wants to start authentication of UE, SEAF sends a Nausf_UEAuthentication_Authenticate Request message to AUSF to invoke the Nausf_UEAuthentication service. The message carries the serving network name (SN Name) and SUCI or SUPI. The SN Name is used to bind the anchor key to the serving network through the serving network identifier to ensure that the anchor key is used for secure communication between the UE and the 5G core network. It should be understood that if SEAF receives SUCI from the UE, the message carries SUCI; if SEAF receives 5G-GUTI from the UE, SEAF determines SUPI based on the 5G-GUTI and carries SUPI in the message.
[0141] It should be understood that SUPI consists of a SUPI type and a value. There are four SUPI types: IMSI, NSI (network specific identifier), a Global Line Identifier (GLI), or a Global Cable Identifier (GCI). There are two SUPI value formats: IMSI and NAI. To prevent the user's SUPI from being exposed over the air interface, the SUPI component excluding the SUPI type is typically calculated to produce a result that becomes part of the SUCI.
[0142] Correspondingly, after AUSF receives the Nausf_UEAuthentication_Authenticate Request message from SEAF, AUSF can check whether the SEAF in the service network that makes the authentication request has the right to use the SN Name in the Nausf_UEAuthentication_Authenticate Request by comparing the SN Name carried in the message with the expected SN Name. AUSF can temporarily store the received service network name. If the service network does not have the right to use the SN Name, AUSF sends a Nausf_UEAuthentication_Authenticate Response message to SEAF, which is used to indicate that "the service network is not authorized", that is, SEAF can reject the UE's registration process. If the service network has the right to use the SN Name, AUSF sends a Nudm_UEAuthentication_Get Request message to UDM to request primary authentication of the UE. The message carries SUCI or SUPI, and SN Name.
[0143] Correspondingly, after receiving the Nudm_UEAuthentication_Get Request message from AUSF, if the message carries SUCI, UDM first needs to parse the message to obtain SUPI, and then select an authentication method based on the SUPI, such as the 5G Authentication and Key Agreement (5G-AKA) authentication method or the Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication method.
[0144] It should be understood that current 5G networks support two authentication methods: 5G-AKA and EAP-AKA'. This application does not limit how the UDM selects an authentication method based on the SUPI. For example, implementations of the UDM selecting an authentication method based on the SUPI include: the operator can configure the authentication method in the subscription data, so that the UDM can specify the authentication method after obtaining the UE's SUPI; or the UDM can select the authentication method based on the SUPI type in the SUPI. For example, if the SUPI type is IMSI, 5G-AKA is selected. If the SUPI type is NAI, EAP-AKA' is selected.
[0145] S220, UDM executes the main authentication process.
[0146] Exemplarily, UDM sends an authentication vector to AUSF, such as the authentication vector of 5G-AKA or the authentication vector of EAP-AKA', in response to the authentication request message of AUSF, and then performs the main authentication with the UE. The specific authentication implementation method can refer to the relevant description in Chapter 6 of the existing protocol TS 33.501.
[0147] S230, main authentication result confirmation process.
[0148] Exemplarily, an authentication result can be obtained based on the above-mentioned primary authentication of the UE, and then the AUSF and UDM perform the primary authentication result confirmation process.
[0149] In one example, if the above-mentioned UDM selects the EAP-AKA' authentication method to authenticate the UE, after AUSF receives the EAP-Response / AKA'-Challenge message from the UE or SEAF and completes the authentication of the UE, AUSF sends a Nudm_UEAuthentication_ResultConfirmation Request message to the UDM.
[0150] In another example, if the UDM selects the 5G-AKA authentication method to authenticate the UE, after the AUSF receives the Nausf_UEAuthentication_Authenticate Request message from the SEAF and the AUSF successfully authenticates the UE, the AUSF sends a Nudm_UEAuthentication_ResultConfirmation Request message to the UDM.
[0151] The Nudm_UEAuthentication_ResultConfirmation Request message carries the UE's authentication status, including the UE's SUPI, authentication timestamp, authentication result (e.g., authentication success or failure), authentication method (or authentication type (e.g., EAP-AKA' authentication method or 5G-AKA authentication method)), and serving network name (SN Name). Optionally, to prevent fraud, the AUSF may only carry information about successful authentication in the message based on operator policy.
[0152] Correspondingly, the UDM stores the UE's authentication status, including SUPI, authentication timestamp, authentication result, and serving network name (SN Name).
[0153] It should be noted that a UE can register with different AMFs, such as AMF1 and AMF2, using 3GPP and non-3GPP access technologies. This means that AMF1 and AMF2 can provide services to the same UE. Based on the above registration and authentication process, the UDM stores the two authentication results, the identity verification timestamp, and the information of SN Name#1 and SN Name#2. This application does not limit the number of AMFs.
[0154] Furthermore, UDM sends a Nudm_UEAuthentication_ResultConfirmation Response message to AUSF.
[0155] It should be understood that UDM may detect and accept certain types of spoofing attacks based on operator policies. For example, UDM stores the ID and time of the visited network. Optionally, the operator can classify the visited networks: for example, in the first category, AMF needs to send the Nudm_UECM_Registration Request message immediately; in the second category, it only needs to check whether the Nudm_UECM_Registration Request message is received within a short time after the authentication process is completed; in the third category, no check is required. If UDM receives a new Nudm_UECM_Registration Request message, UDM checks whether the new visited network is the same as the previously stored one. If they are the same, the registration request is accepted; if they are different, a rejection request message is sent with a reason value to notify AMF that it needs to send a Nausf_UEAuthentication_Authenticate Request message to AUSF to trigger the main authentication process.
[0156] S240: Optionally, execute a NAS security mode command (SMC) process.
[0157] It should be understood that the NAS SMC procedure is intended to protect the UE registration request from a man-in-the-middle attack, preventing an attacker from modifying the information element IE containing the UE security capabilities provided by the UE in the registration request.
[0158] Exemplarily, the AMF activates NAS integrity protection and sends a NAS security mode command message to the UE. Correspondingly, after receiving the NAS security mode command message from the AMF, the UE needs to verify the NAS security mode command message, including checking whether the UE security functions sent by the AMF match the security functions stored in the UE to ensure that attackers do not modify these functions, and verify the integrity protection using the indicated NAS integrity algorithm and the NAS integrity key of the KAMF indicated by the ngKSI. In addition, after sending the NAS security mode command message, the AMF activates NAS uplink decryption. If the integrity verification of the NAS security mode command message is successful, the UE should start NAS integrity protection and encryption / decryption using the security context indicated by the ngKSI. Further, the UE sends the NAS security mode completion message to the AMF for encryption and integrity protection, and the AMF activates NAS downlink encryption.
[0159] S250, the remaining registration process.
[0160] During the remaining registration process, the AMF may register with the UDM. This process registers the AMF currently serving the UE with the UDM. After receiving the AMF registration information, the UDM stores AMF-related information, such as the AMF ID. It should be noted that a UE can register with different AMFs, such as AMF1 and AMF2, using both 3GPP and non-3GPP access technologies. This means that AMF1 and AMF2 can serve the same UE. The UDM can store information related to multiple AMFs, such as AMF1ID and AMF2ID.
[0161] Exemplarily, SEAF sends a registration response message to the UE to indicate that the UE has successfully registered, and the UE can then request to establish a session to access various services on the data network.
[0162] Figure 3 is a schematic diagram of a home network (eg, a UDM in a home network) triggering a master authentication process. As shown in Figure 3, the method 300 includes the following steps. For parts not fully described, please refer to the relevant description of the existing protocol.
[0163] S310, optionally, the UDM pre-configures an operator authentication policy to determine the initiating network to trigger a primary authentication process for the UE.
[0164] S320: When the UDM determines that the home network is initiated to trigger the primary authentication process, it determines the AMF1 that provides services for the UE.
[0165] Exemplarily, the UDM decides to trigger and execute the home network authentication process for the UE based on an event (e.g., SoR / UPU or AAnF request) or authentication policy. For example, the AAnF sends a Nudm_UECM_AuthTrigger request to the UDM, instructing the UDM to perform primary authentication. Correspondingly, the UDM determines to initiate the home network trigger primary authentication process for the UE based on the received event and the pre-configured operator authentication policy, and then the UDM determines the serving AMF / SEAF for the UE.
[0166] Based on the above method 200, it can be known that the UE can register with AMF1 and AMF2 through 3GPP access technology or non-3GPP access technology, indicating that the current UE is served by the AMF1 and AMF2. In other words, the current UE is on AMF1 and AMF2, or in other words, the UE can be found through AMF1 and AMF2. Correspondingly, after the main authentication, the UDM stores the information of AMF1 and AMF2, such as AMF1ID and AMF2ID. That is, the UDM knows that the AMF1 and AMF2 are providing services for the UE, and subsequently when the UDM determines to trigger re-authentication of the UE, it can find the AMF1 and AMF2 serving the UE. For example, the UDM selects AMF1 to re-authenticate the UE according to the operator's authentication policy.
[0167] S330, UDM sends an authentication notification message to AMF1, and correspondingly, AMF1 receives the authentication notification message from UDM.
[0168] The authentication notification message is used to request AMF1 to trigger authentication of the UE, and the authentication notification message includes the UE's SUPI.
[0169] Correspondingly, after receiving the authentication response message from the UDM, AMF1 determines whether to trigger primary authentication of the UE based on the local authentication policy and UE status. If it can be initiated, AMF1 determines to perform primary authentication of the UE.
[0170] S340, AMF1 executes the main authentication process.
[0171] Among them, the specific implementation method of AMF1 performing primary authentication can refer to the relevant description of the above method 200.
[0172] It should be noted that in this application, "authentication" and "authentication" can be replaced. For example, "primary authentication" can be replaced by "primary authentication", and "authentication suspension flag" can be replaced by "authentication suspension flag". For ease of description, the following uniformly uses "authentication, primary authentication, suspension flag, authentication suspension flag", etc.
[0173] Furthermore, AMF1 may send an authentication response message to UDM.
[0174] S350, AMF1 sends an authentication response message to UDM, and correspondingly, UDM receives the authentication response message from AMF1.
[0175] In response to the Authentication Notification message, AMF1 sends an Authentication Response message to the UDM. This message notifies the UDM of the success or failure of the request. If the Authentication Response message does not carry a Failure Cause value, this means that the AMF can perform primary authentication of the UE. This is the process of step S340. If AMF1 is unable to perform the primary authentication process according to step S340, for example, if the UE is unreachable or AMF1 cannot find the UE, the Authentication Response message carries a Failure Cause value, indicating that AMF1 cannot initiate primary authentication of the UE.
[0176] It should be noted that the execution order of step S340, step S350 and the steps is not limited.
[0177] Considering that the existing solution only authenticates SUPI and the single network slice selection assistance information (S-NSSAI) used by user devices, there may be unreal or illegal users or external devices accessing the network or using network services, which increases network security risks.
[0178] In view of this, the present application provides a communication method and communication device that ensure network security by triggering authentication of a user identifier (e.g., user ID). For example, a user device can send a first message carrying a securely protected first user identifier to a first network element, so that the first network element initiates authentication for the first user based on the first message and feeds back the first user's authentication result to the user device. This allows the user device and the first network element to determine the authenticity and legitimacy of the first user, thereby providing services to the first user, ensuring network session security while improving user experience.
[0179] Specifically, the following ideas may be included but are not limited to:
[0180] (1) Authentication of the user ID is triggered by an authentication request sent by the user equipment UE;
[0181] When the terminal (for example, user equipment UE) senses that a user (for example, a first user) has logged in (the terminal may sense it at the first moment or the second moment, the first moment is the UE registration state; the second moment is the UE deregistration state) (if it is the second moment, the terminal needs to first send a message to the network side to request that the terminal be registered with the network side), the signaling unit in the terminal sends a first message to the first network element. The first network element is the network element responsible for authentication in the network. The first message requests the network side to authenticate the user. The first message carries a first identifier, which is the identifier of the logged-in user. After receiving the first message, the first network element initiates an authentication process for the first identifier, and then sends a second message to the terminal. The second message indicates the authentication result for the first user. If the authentication is successful, the user is allowed to log in. Otherwise, if the authentication fails, the user is prohibited from logging in.
[0182] Optionally, in the embodiment of the present application, the first identifier can be replaced by: a first user identifier.
[0183] (2) Complete the authentication of the user ID through the user ID registration process;
[0184] Solution 1: When the user logs into the terminal at the first moment;
[0185] Exemplarily, the terminal sends a third message to the first network element. The third message includes a first identifier and / or first indication information. The third message requests the network side to register the user. The first indication information indicates the registration type, which is to register the user. In other words, the registration type indicated by the first indication information indicates that the third message is sent for the user's registration. After receiving the third message, the first network element authenticates the first identifier. In other words, the first network element authenticates the user corresponding to the first identifier based on the third message.
[0186] Optionally, the third message is a registration request message (ie, an example of the first message), which is used to request the network side to register the user.
[0187] Solution 2: When the user logs into the terminal at the second moment;
[0188] Exemplarily, the terminal sends a third message to the first network element. After receiving the third message, the first network element authenticates the terminal UE and the user user, and sends a fourth message to the terminal at a third time, where the fourth message indicates that the terminal can successfully register with the network. The third time may be after the UE is authenticated, or after both the UE and the user are authenticated.
[0189] Optionally, the third message is a registration request message (ie, an example of the first message), which is used to request the network side to register the user and the UE. Optionally, the fourth message is a registration completion message.
[0190] Specifically, for the user equipment (UE), the following logic is added to trigger the sending of an authentication request: when a user logs in to the UE, a message (i.e., an example of a first message) is sent to the AMF (i.e., an example of a first network element) requesting the core network to authenticate the user corresponding to the user ID; a user-granular registration is initiated with the network, with the user ID and registration type included in the registration message; or, alternatively, only the user ID is included in the registration message. It should be understood that the registration type indicates that the registration message is sent for the user's registration.
[0191] For the first network element side, it includes: adding the logic of triggering the main authentication process: receiving the UE authentication request; searching the UDM for the binding relationship based on the authentication request, and performing the main authentication after the binding relationship is legal; receiving the user granularity registration request sent by the UE; recording the user allowed to log in on the UE into the UE context, and adding the linked user in the UE context.
[0192] The communication method provided by the embodiment of the present application will be described in detail below with reference to the accompanying drawings. The embodiment provided by the present application can be applied to any communication scenario in which a transmitting device and a receiving device communicate, for example, it can be applied to the communication system shown in FIG1 above.
[0193] Figure 4 is a flow chart of a communication method 400 provided in an embodiment of the present application. As shown in Figure 4, the method flow can be described by an external device, a user device (such as a UE), a first network element (such as an AMF or SMF), a first authentication function (such as an AUSF) or a first storage function or a credential storage function (such as an UDM) as the execution subject. The method includes the following steps. For parts not fully described, please refer to the relevant description of the existing protocol.
[0194] S401, the user holds a certificate of trust.
[0195] In this application, a credential is configuration information that enables a user to be uniquely identified and verified, and can be in the form of a set of strings or a certificate. This embodiment does not limit the specific format of the credential.
[0196] The user holds the credentials, which can be understood as: the credentials can be stored on the user device (for example, in the memory of the user device) or not stored on the user device (for example, in the USIM card, or the user's personal notebook, user memory, etc.).
[0197] It should be understood that the user's credentials can be used on an external device or a user device. The external device may be a terminal device (e.g., a mobile phone without a SIM card inserted) or a user device that can establish a connection with the user device UE (e.g., a tablet without 3GPP wireless capabilities).
[0198] In the embodiment of the present application, the user credentials can be used in the subsequent user authentication process, for example, the user device generates an authentication vector based on the user credentials. The specific implementation method can refer to the relevant description of the following step S407, which is not explained here.
[0199] S402: The first storage function stores the user's credentials.
[0200] Exemplarily, the user's credentials are stored in a credentials storage function (i.e., an example of the first storage function). The user's credentials are stored in the credentials storage function, which means that the credentials are stored based on the user dimension. If a user is represented by a user ID (or user ID), the credentials of a user ID are unique. On the terminal side, the user can use the credentials to log in to different external devices or different user devices.
[0201] S403: The user equipment successfully registers with the first network element.
[0202] In other words, the user equipment successfully registers with the first network element, which can be understood as the user equipment registering with the network. For example, the user equipment sends a registration request message to the first network element to request registration with the network, and the user equipment receives a registration completion message from the network. The registration request message carries the user equipment identifier UE ID (e.g., SUCI or 5G-GUTI). Optionally, for the specific implementation of the user equipment successfully registering with the first network element, reference may be made to the relevant description of method 200 above.
[0203] It should be noted that this step is optional and can be understood as: the user equipment UE can register with the AMF (ie, an example of the first network element) in advance (for example, if the UE has been used, it means that the user equipment has registered with the first network element); or, the user equipment can also be triggered to initiate registration (for example, the user equipment has been used before, but as the user goes offline, the user equipment also presents a deregistered state. At this time, the condition for the user equipment to be triggered is: the user equipment is logged in by the user, or the UE receives a message from an external device).
[0204] For example, the user device may request to register with the network to the first network element in advance (for example, the user device has been used by the user before executing step S403, which means that the user device has previously requested to register with the first network element and the registration is successful, and it can be understood that the user device has always been in a registered state); or, the user device may also initiate registration with the first network element after being triggered by the user to log in (for example, the user device has been used before executing step S403, but as the user goes offline, the user device also becomes deregistered, or the user device enters a deregistered state due to not being used for a long time, or the user device is in factory settings and has never been used by the user. At this time, the triggering condition for the user device to initiate registration with the first network element may be: the user device is logged in by a user (for example, the first user), or the user device receives a message (or pop-up window) from an external device, and the message (or pop-up window) indicates that the first user triggered the login to the external device).
[0205] S404: An external device or user triggers login.
[0206] For example, a user (i.e., an example of a first user) logs in to an external device or a user device using a user ID (or user ID) (i.e., an example of a first user identifier). For example, if the user logs in to the external device, the external device establishes a connection with the user device. Accordingly, the user device determines that the user is logged in.
[0207] That is, the user device can determine that the user is logged into the external device based on the establishment of a communication connection between the external device and the user device, or the user device receiving a message (or pop-up window) from the external device. For another example, if the user is logged into the user device, the user may have logged in a username on the user device. Accordingly, the user device can determine that the user is logged in based on the username.
[0208] In other words, there are one or more methods for the user device to determine that the user is logged in, for example, the user device determines it by establishing a connection between the user device and the external device, or the user device is determined by the user logging in, or the user device determines that the user is logged in based on a message (or pop-up window) received from the external device, and the message (or pop-up window) indicates that the first user is logged in to the external device.
[0209] It should be noted that there are one or more methods for establishing a connection between the external device and the user device, such as establishing a connection through Bluetooth technology or WiFi technology, and this embodiment does not impose any specific restrictions.
[0210] S405: The user equipment sends a first message to the first network element.
[0211] Correspondingly, the first network element receives the first message from the user equipment.
[0212] Exemplarily, after determining that a user (ie, an example of the first user) is logged in, the user equipment generates a first message and sends the first message to the first network element.
[0213] The first message includes a first user identifier of a first user using a user device, such as a user ID (userID), which is protected by security. It should be understood that the first user identifier has security protection, including integrity protection and / or confidentiality protection. For example, the user ID (userID) in the first message is confidentiality protected.
[0214] It should be noted that the first user using the user device can be understood as: a user who logs in to the user device, or a user who logs in to an external device that establishes a communication connection with the user device.
[0215] Optionally, the first message has security protection, including: integrity security protection and / or confidentiality security protection. It should be noted that this application does not limit the protection method for the first user identifier to have security protection. For example, it can be security protection for the first user identifier alone, or it can be security protection for the first message carrying the first user identifier.
[0216] Exemplarily, the first network element may be a network element within the operator's core network that processes user authentication. For example, the first network element may be a mobility management network element or a session management network element. In this case, the first message is a message that carries a user ID and is ultimately received by the first network element. For example, when the first network element is a mobility management network element, the first message may be a NAS message (i.e., an example of a first NAS message), such as a registration request message, a user authentication request message, or a NAS SMP message. For example, when the first network element is a session management network element, the first message may be a message carried in a session management container (i.e., an example of a first SM message), such as a PDU session establishment request message, a user authentication request message, or an EAP-Response / Identity message. This embodiment does not limit the type of the first network element, nor does it limit the specific implementation of the first message.
[0217] The following is an example of how the first message or the first user identifier carried in the first message, such as a user ID (userID), has security protection.
[0218] In one implementation, the first message carries a security-protected user ID (userID). For example, the user equipment uses a 5G NAS security context to perform security protection on the first NAS message (i.e., an instance of the first message) or the first user ID, where the security protection includes confidentiality protection and / or integrity protection.
[0219] In the first example, before the user equipment sends the first message to the first network element, the user equipment has already registered with the network (at this point, step S403 has already been executed), and primary authentication has been completed between the network and the user equipment based on the user equipment identifier (e.g., SUPI), and a NAS security context has been activated through a NAS SMC procedure. Therefore, the information or parameters exchanged between the user equipment and the first network element are security-protected, and the first message or the first user identifier may be security-protected.
[0220] For example, before the first network element receives a first message carrying a security-protected first user identifier from a user device, the method further includes: the first network element receiving a registration request message from the user device, the registration request message including the identifier of the user device; the first network element determining, based on the registration request message, to initiate a primary authentication process for the user device; after the primary authentication process for the user device, the first network element sending a NASSMC message to the user device, the NAS SMC message being used to activate a NAS security context; and the first network element receiving a NASSMP message from the user device. For specific implementation methods, reference may be made to the relevant description of the aforementioned method 200.
[0221] In the second example, before the user equipment sends the first message to the first network element, the user equipment has been registered with the network (at this time, the above step S403 has been executed), and the network side and the user equipment have completed the primary authentication based on the identifier of the user equipment (for example, SUPI), and the network side triggers the NAS SMC process to activate the NAS security context.
[0222] For example, the first message is a NASSMP message, and therefore, the first message or the first user identifier may be security-protected. For example, before the first network element receives the first message carrying the security-protected first user identifier from the user equipment, the method further includes: the first network element receiving a registration request message from the user equipment, the registration request message including the identifier of the user equipment; the first network element determining, based on the registration request message, to initiate a primary authentication process for the user equipment; and after the primary authentication process for the user equipment, the first network element sending a NASSMC message to the user equipment.
[0223] In the third example, before the user equipment sends the first message to the first network element, the user equipment has already registered with the network (at this time, the above step S403 has been executed), and the network side and the user equipment have completed the primary authentication based on the user equipment identifier (e.g., SUPI), and the NAS security context is activated through the NAS SMC process. Therefore, the first message or the first user identifier can be security-protected. In addition, in this implementation, since the user equipment carries both the user equipment identifier and the user ID (userID) in the registration request message, the network side can first perform primary authentication on the user equipment, and after the primary authentication of the user equipment is successful, initiate the authentication process for the user.
[0224] For example, before the first network element receives a first message carrying a security-protected first user identifier from a user device, the method further includes: the first network element receives a registration request message from the user device, the registration request message including the identifier of the user device and the second user identifier of the second user; the first network element determines to initiate a primary authentication process for the user device based on the registration request message; after the primary authentication for the user device is successful, the first network element initiates an authentication process for the second user.
[0225] In another implementation, the first message carries fourth indication information, where the fourth indication information indicates that authentication is to be performed for a user ID (userID) (i.e., an example of the first user). This application does not limit the form of the fourth indication information. For example, the fourth indication information may be: user ID-based capability information, or user ID (userID). The user ID-based capability information indicates that the user device supports authentication of the user corresponding to the user ID (userID).
[0226] It should be understood that the above two implementations can be implemented independently or in combination, for example, the first message carries both the protected user ID (userID) and the fourth indication information, which is not limited in this embodiment.
[0227] Below, an example is given of the first user identifier carried in the first message, such as the form of the user ID (userID).
[0228] Exemplarily, the userID includes at least an information portion that uniquely identifies the user (i.e., an example of the first information portion) and a routing information portion (i.e., an example of the second information portion) used to determine the credential storage function (i.e., an example of the first storage function). At least one of the first network element and the network element containing the first authentication function (i.e., an example of the first authentication function) can determine the credential storage function network element based on the routing information of the credential storage function. The credential storage function can determine the credential corresponding to the user based on the information portion that uniquely identifies the user.
[0229] Furthermore, the first network element and / or the first authentication function sends a user authentication vector request message to the credential storage function. After receiving the user authentication vector request message, the credential storage function generates a user authentication vector according to the credential corresponding to the user and feeds back the user authentication vector.
[0230] The following is an example of the userID in the embodiment of the present application. It should be noted that the present application does not limit the userID.
[0231] In one implementation, the userID can be represented in the NAI format, such as username@realm. The username portion carries information that uniquely identifies the user, such as a 64-bit string that is easy for the user to remember. The realm portion carries routing information that determines the credential storage function.
[0232] In another implementation, the userID may be expressed in a fully qualified domain name (FQDN) format.
[0233] In the embodiment of the present application, before the user equipment sends the first message to the first network element, the method further includes: the user equipment obtains a first user identifier, such as a user ID (userID).
[0234] Exemplarily, the specific implementation manner in which the user equipment obtains the userID may be one or more of the following.
[0235] In a first implementation manner, the user equipment may be obtained through a connection with a user equipment.
[0236] For example, the message (or pop-up window) sent by the external device to the user device carries the userID. It should be understood that in this implementation, a communication connection is established between the external device and the user device.
[0237] In a second implementation manner, the user device may be obtained through user input.
[0238] For example, when a user logs in to a user device using a username (eg, the user's mobile phone number or WeChat ID), the user device may determine the username as the user's userID.
[0239] In a third implementation, the user device may obtain partial information of the userID according to a message sent by an external device or through user input, and then determine the userID.
[0240] For example, the user device first obtains the information portion of the userID that uniquely identifies the user (i.e., an example of the first information portion), and then determines the userID. In one example, after the user enters an account with the username 123456, the user device obtains 123456 and determines it as the information portion that uniquely identifies the user. The user device then determines the user device's home public land mobile network (HPLMNID) and / or router-identity (RID) as routing information for determining the credential storage function, such as 5gc.RID.HPLMNID, and then combines them to obtain a userID that conforms to the NAI format of 123456@5gc.RID.HPLMNID.
[0241] In a fourth implementation, the information portion for uniquely identifying the user in the userID (ie, an example of the first information portion) contains confidentiality-protected information for uniquely identifying the user.
[0242] That is, the information portion of the userID in this implementation that uniquely identifies the user can be regarded as the information that uniquely identifies the user after confidentiality protection (obtained by establishing a communication connection with an external device or obtained by user input), namely, the userID.
[0243] S406: The first network element determines to execute a user authentication process.
[0244] Exemplarily, the first network element determines to initiate an authentication process for the first user based on the first message. For example, the first network element determines to initiate a user authentication process for the first user based on first indication information associated with the first message. Optionally, the first indication information may be carried in the first message or may not be carried in the first message, and this application does not limit this.
[0245] The first indication information may be represented by one or more of the following: for example, the name of the first message, the first user identifier, or a designated information element in the first message.
[0246] For example, the method in which the first network element determines to perform the user authentication process includes at least one of the following:
[0247] (1) The first network element may determine to execute the user authentication process according to the name of the first message. For example, the name of the first message may be a user authentication request message (for example, Namf_UserAuthentication_Authenticate Request); or,
[0248] (2) The first network element may determine to perform a user authentication process based on a specific information element (IE) in the first message, for example, the IE may be a registration type (indicating that the first message may be a registration request message for a user), a specific field in the first message (used to identify the first user using the user equipment), for example, a value of "1" in the field indicates that the first message is a request for authentication of the user; or
[0249] (3) The first network element determines to execute the user authentication process based on local configuration information, for example, the configuration information indicates that when the first network element receives a first user identifier with security protection, or when the configuration information indicates that when the first network element receives a first message carrying security protection from the user equipment, or when the configuration information indicates that when the first network element receives a first message carrying security protection from the user equipment, the authentication process for the user user is triggered.
[0250] S407: Execute the user authentication process.
[0251] Illustratively, the user authentication process occurs between the first authentication function, the credential storage function (ie, an example of the first storage function), the user device, and the first user.
[0252] In one implementation, performing an authentication process for a first user includes: a first network element determining (or discovering) a first authentication function; the first network element sending a user authentication request message to the first authentication function, the user authentication request message including a first user identifier, the user authentication request message being used to request authentication of the first user; the first authentication function sending a user authentication vector request message to a first storage function, the user authentication vector request message including the first user identifier; the first storage function generating a user authentication vector based on the first user identifier; the first storage function sending the user authentication vector to the first authentication function; the first authentication function completing user authentication between the user device and the first user based on the user authentication vector. Finally, the first authentication function sending a user authentication response message to the first network element, the user authentication response message being used to indicate an authentication result for the first user, indicating whether the authentication of the first user succeeded or failed.
[0253] Optionally, the authentication function for authenticating the user and the authentication function for primary authentication of the user equipment may be the same. In some implementations, the first network element determining the first authentication function includes: obtaining the first authentication function for primary authentication of the user equipment.
[0254] Optionally, the user authentication response message includes the authentication result of the first user and / or first user authentication result indication information, the first user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the authentication of the first user is successful or failed.
[0255] It should be noted that the user authentication process is a bidirectional authentication process, that is, it includes both the network's authentication of the first user and the first user's authentication of the network. The specific implementation of the first network element determining (discovering) the first authentication function and executing the user authentication process can be found in the description of method 500 below and will not be described in detail here.
[0256] In this application, the first storage function may have one or more possible implementations. In one implementation, the first storage function is used only to store the credentials corresponding to the user ID (i.e., an example of the first user identifier), such as a UDM. In another implementation, the first storage function is used to store the credentials corresponding to the user ID and also to perform user authentication to ultimately determine that the user is authentic and legitimate, such as by an authentication, authorization, and accounting (AAA) server.
[0257] In the present application, the first authentication function has one or more implementation methods. For example, the first authentication function can be a proxy service function, which is used to forward user authentication-related messages to the network element that performs the user authentication function, such as the first authentication function is an authentication, authorization, and accounting proxy (authentication, authorization, accounting proxy, AAA-P) or a network slice-specific authentication and authorization function (NSSAAF), and the network element that performs the user authentication function can be AAA, or AMF, or AUSF, or UDM. For another example, the first authentication function is a network element that performs the user authentication function, such as AAA, or AMF, or AUSF, or UDM.
[0258] S408: The first network element sends a second message to the user equipment.
[0259] Correspondingly, the user equipment receives the second message from the first network element.
[0260] The second message may be a response message to the first message, or may be a message unrelated to the first message.
[0261] It should be understood that the second message is used to indicate the authentication result for the first user.
[0262] Optionally, the second message may have the same security protection as the first message, which will not be described in detail.
[0263] In the first example, the second message carries a user authentication result (i.e., an example of the first user's authentication result), where the user authentication result includes a successful user authentication or a failed user authentication. Optionally, if the user authentication fails, the first network element may send a cause value to the user equipment, indicating that the user authentication failed.
[0264] In the second example, the second message carries second user authentication result indication information, the second user authentication result indication information indicates the authentication result of the first user, and the authentication result of the first user indicates that the first user authentication is successful or the user authentication fails.
[0265] Optionally, the second user authentication result indication information may be the same as or different from the first user authentication result indication information. For example, the information formats of the first user authentication result indication information and the second user authentication result indication information may be changed.
[0266] Optionally, the second message may also carry the first user identifier. Optionally, the first user identifier may be security-protected. In one example, the second message may not be security-protected, but the second message may carry the security-protected first user identifier. In another example, if the second message is security-protected, it indicates that the first user identifier carried in the second message is security-protected.
[0267] In this application, the second message may be implemented in one or more ways, which are not specifically limited in this embodiment. For example, after determining the user authentication result (ie, an example of the authentication result of the first user), the first network element sends the second message to the user equipment.
[0268] Optionally, when the user authentication result indicates that the user authentication is successful, the first network element can associate at least one of the authentication result of the first user (for example, user authentication is successful), the authentication success time, and the identifier of the user device (such as SUPI) with the identifier of the first user (for example, userID), and store them together, so that after the first network element subsequently receives the first message from the user device, the first network element can determine not to initiate the authentication process for the first user based on the locally stored authentication result of the first user associated with the userID (for example, user authentication is successful), and then provide services to the first user, reduce signaling overhead, and ensure user service experience.
[0269] Optionally, the authentication success time may be understood as: the time when the network side completes authentication of the first user, or the time when the first network element receives the authentication result of the first user.
[0270] Optionally, the first network element can also obtain an effective time period from the first authentication function, which is used to indicate the effective time period during which the first user can access the network, or to indicate the effective time period during which the network side recognizes or confirms the authenticity and legality of the first user. In other words, the first network element can provide services to the first user during the effective time period and refuse to provide services to the first user during the non-effective time period.
[0271] S409: The user equipment determines to execute the first action according to the second message.
[0272] Furthermore, the user equipment may send an authentication result for the first user to the first user or the external device.
[0273] Exemplarily, when the second message is used to indicate that the user authentication is successful, the user device may execute subsequent processes for the external device or user. For example, continue to execute the PDU session establishment process or registration process. When the second message is used to indicate that the user authentication fails, the user device refuses to execute subsequent processes for the external device or user. For example, when the user device is connected to the external device, the user device may release the connection with the external device, or send a user authentication failure message to the external device through the connection, or the user device may trigger the network side to perform user authentication on the first user again, for example, the user device re-executes the above step S405, or the user device may force the user to log off from the user device, etc.
[0274] In other words, when the second message indicates that the first user's authentication result is successful, it indicates that the first user is authentic and legitimate, and the user device can continue to execute subsequent processes for the external device or the first user. Conversely, when the second message indicates that the first user's authentication result is unauthentic and illegitimate, it indicates that the first user is not authentic and legitimate, and the user device can refuse to execute subsequent processes for the external device or user.
[0275] It should be noted that the first action here can be replaced by other descriptions such as the first service, the first business, or the first operation.
[0276] Optionally, when the second message indicates that the user authentication is successful, the user device may associate at least one of the authentication success and the authentication success time with the userID and store them together. That is, when the second message indicates that the first user authentication is successful, the user device may associate at least one of the first user's authentication result (e.g., user authentication success) and the authentication success time with the first user's identifier (e.g., userID) and store them, so that when the first user subsequently logs in to the user device or external device again, the user device can determine not to trigger a request for the network side to authenticate the first user based on the locally stored authentication result of the first user associated with the userID (e.g., user authentication success), and then directly provide services to the first user, reducing signaling overhead and improving user service experience.
[0277] Optionally, if the above-mentioned first network element obtains the effective time period from the first authentication function, the user equipment can also obtain the effective time period from the first network element, which is used to indicate the effective time period during which the first user can access the network, or to indicate the effective time period during which the network side recognizes or confirms the authenticity and legality of the first user. In other words, the first user can obtain services within the effective time period, and may not be able to obtain services during the non-valid time period.
[0278] Based on the above solution, a user ID authentication process is proposed. Based on the user device's registration with the network, the user sends an authentication request to the network after logging in, or the network authenticates the user ID through user device registration. This solves the problem of the network being unable to determine the validity of a user ID when accessing the network. This ensures the security of network sessions and the proper functioning of user-related QoS, traffic control, billing, and other functions.
[0279] Specifically, the above scheme provides a process for user authentication for a first user identifier (e.g., user ID). On the basis of the user device being registered with the network, after determining that the first user has logged into the user device or an external device, it triggers the sending of a first message carrying a security-protected first user identifier of the first user using the user device to the network side to request authentication of the first user. Alternatively, by carrying a security-protected first user identifier in a registration request message for the user device (i.e., an example of the first message), two-way authentication between the network side and the first user is achieved. While ensuring that the user device and the first user are both legal or authentic, services are provided to the first user, thereby ensuring network session security and reducing potential security risks.
[0280] It should be understood that the trigger of the first message on the user device side comes from the user login or the connection between the user device and the external device. This is different from the initiation timing of the existing main authentication and slice authentication, as described above. The first network element determines that user authentication is required based on the first message. Compared with the main authentication and slice authentication, the judgment conditions have changed, as described above. The user authentication coverage network element is different from the network elements covered by the existing main authentication and slice authentication for user devices, as described above. The user device needs to know the user authentication result. Because user authentication does not occur on the user device, it may be transparently transmitted to the device, so it needs to be modified so that the user device knows the user authentication result. The first network element and the user device store the user authentication result for subsequent processing. For example, the first network element or the user device can determine whether to authenticate the first user based on whether the authentication result of the first user is stored, or determine whether to authenticate the first user and whether to provide services to the first user based on whether the stored authentication result of the first user is successful or failed.
[0281] Figure 5 is a flow chart of a communication method 500 provided in an embodiment of the present application. As shown in Figure 5, the method flow can be described by an external device, user equipment UE, AMF, AUSF or UDM as the execution subject, mainly to solve the problem that after the user uses the user ID to log in to the UE, the network side does not authenticate the legitimacy of the user ID (that is, the network side cannot determine whether the user corresponding to the user ID can access the network). The method includes the following multiple steps. For the parts not described in detail, please refer to the relevant description of the existing protocol.
[0282] S501, the user holds a certificate of trust.
[0283] In this application, a credential is configuration information that enables a user to be uniquely identified and verified, and can be in the form of a set of strings or a certificate. This embodiment does not limit the specific format of the credential.
[0284] The user holds the credentials, which can be understood as: the credentials can be stored on the user device (for example, in the memory of the user device) or not stored on the user device (for example, in the USIM card, or the user's personal notebook, user memory, etc.).
[0285] It should be understood that the user's credentials can be used on an external device or UE. The external device may be a terminal device (e.g., a mobile phone without a SIM card inserted) or a user device that can establish a connection with the UE (e.g., a tablet without 3GPP wireless capabilities).
[0286] S502: The UDM stores user credentials.
[0287] For example, the user's credentials are stored in the credentials storage function. The user's credentials are stored in the credentials storage function, which means that the credentials are stored based on the user dimension. If the user is represented by a user ID (or user ID), the credentials of a user ID are unique. On the terminal side, the user can use the credentials to log in to different external devices or different UEs.
[0288] S503: The UE registers with the network.
[0289] Optionally, the UE successfully registers with the AMF. For specific implementation methods, please refer to the relevant description above. This step is optional. The UE can register with the AMF in advance (for example, if the UE has been used, it means that the UE has been registered with the AMF); the UE can also initiate registration after being triggered (for example, the UE has been used before, but as the user goes offline, the UE also becomes unregistered. At this time, the condition for the UE to be triggered is: the UE is logged in by the user, or the UE receives a message from an external device).
[0290] S504: An external device or user triggers login.
[0291] Exemplarily, the user uses a user ID (or user ID) to log in to the external device or log in to the user device. If the user logs in to the external device, the external device establishes a connection with the user device. Accordingly, the user device determines that the user is logged in. There are one or more methods for the user device to determine that the user is logged in, for example, the user device determines by establishing a connection with the external device, or the user device is determined by the user logging in. It should be noted that there are one or more methods for the external device to establish a connection with the user device, such as through Bluetooth technology or WiFi technology, and this embodiment does not impose specific limitations.
[0292] For the specific implementation of the above steps S501-S504, reference may be made to the relevant description of steps S401-S404 of the above method 400.
[0293] S505. The UE sends a first NAS message (i.e., an example of the first message) to the AMF (i.e., an example of the first network element).
[0294] Accordingly, the AMF receives the first NAS message from the UE.
[0295] Exemplarily, the first NAS message carries at least one of the following: UE identity information (ie, an example of an identifier of a user equipment), userID (ie, an example of a first user identifier), or first indication information.
[0296] The userID has security protection, including integrity security protection and / or confidentiality security protection. For example, the userID is protected by confidentiality.
[0297] Optionally, the first NAS message has security protection, including integrity security protection and / or confidentiality security protection. It should be noted that this application does not limit the protection method for the userID to have security protection. For example, it can be security protection for the userID alone or for the first NAS message carrying the userID.
[0298] In one implementation, the first NAS message is a registration request message, which carries at least two of UE identity information, a userID, and the first indication information. Optionally, the registration request message may only carry the userID.
[0299] (1)UE identity information;
[0300] Exemplarily, the UE identity information may also be described as a UE identifier (such as a UE ID), which may be, for example, a SUCI or a 5G-GUTI;
[0301] (2)userID;
[0302] For example, the userID may include an information portion that uniquely identifies the user and a routing information portion used to determine the credential storage function, wherein the credential storage function may determine the credential corresponding to the user based on the information portion that uniquely identifies the user.
[0303] In one example, the userID is represented in the NAI format: username@realm. The username portion carries information that uniquely identifies the user, such as a 64-bit string that is easy for the user to remember. The realm portion carries routing information that determines the credential storage function.
[0304] In another example, the userID is represented in FQDN format. This application does not limit the representation of the userID.
[0305] (3) first instruction information;
[0306] The first indication information instructs the user to log in, for example, instructs the user to log in to the user equipment, or indicates that the UE receives a message (or pop-up window) sent by an external device, and the message (or pop-up window) instructs the user to log in to the external device.
[0307] Optionally, the first indication information may be a registration type, for example, the registration type indicates that the registration request message is used to request registration for the user; or, the first indication information may also be a userID; or, the first indication information may also be a bit indication information, for example, when the bit indication information is set to 1, it indicates that the registration request message is not used for UE registration, or it indicates that the registration request message is sent because the user logs in or receives a message from an external device; or, the first indication information may also be the user ID authentication capability information of the UE (for example, capability of User-Id based authentication), for example, when the UE has user authentication capability, it indicates that the registration request message is used to request registration for the user or for an external device, and the network can perform user authentication at this time.
[0308] It should be noted that when the UE identity information is 5G-GUTI, the userID is confidentiality protected; when the UE identity information is 5G-SUCI, the userID can be placed in the confidentiality protection part.
[0309] Specifically, when the UE identity information is carried in the first NAS message and the UE identity information is 5G-GUTI, the userID is protected by confidentiality and / or integrity security; when the UE identity information is carried in the first NAS message and the UE identity information is SUCI, the userID can be placed in the confidentiality protection part.
[0310] It should be understood that if the first NAS message carries both UE identity information and userID, the network side can first perform primary authentication on the UE, and then the network side triggers the NAS SMC process to activate the NAS security context, for example, the AMF sends a NASSMC message to the UE, and the AMF receives a NASSMP message from the UE. Furthermore, after the primary authentication of the UE is successful, the authentication process for the user is initiated.
[0311] In another implementation, the first NAS message is a user authentication request message, which can be regarded as a new type of NAS message. The user authentication request message carries UE identity information, userID, and at least one of the first indication information.
[0312] (1) UE identity information is SUCI or 5G-GUTI;
[0313] (2) userID, please refer to the above description for details;
[0314] (3) first instruction information;
[0315] Among them, the first indication information indicates the user to log in, for example, indicates to log in to the user equipment, or indicates that the UE receives a message (or pop-up window) sent by an external device. It should be understood that the message (or pop-up window) indicates that the user logs in to the external device.
[0316] Optionally, the first indication information may be a NAS message type, for example, the NAS message type indicates that the user authentication request message is used to request user authentication; or, the first indication information may also be a userID; or, the first indication information may also be user ID authentication capability information of the UE, for example, when the UE has user authentication capability, it represents that the user authentication request message is sent for the user to log in to the user device or the user device receives a message from an external device, and the network can perform user authentication at this time.
[0317] It should be noted that when the UE identity information is carried in the first NAS message, and when the UE identity information is 5G-GUTI, the userID is confidentiality protected, or when the UE identity information is 5G-SUCI, the userID can be placed in the confidentiality protection part; when the UE identity is not carried in the first NAS message, the userID can be protected confidentially through the NAS confidentiality protection key.
[0318] In another implementation, the first NAS message is a NAS security mode complete (SMP) message, and the NAS SMP message carries the userID. For a specific implementation, refer to the above description.
[0319] Exemplarily, before executing step S505, the method further includes: the AMF receives a registration request message from the UE, the registration request message including UE identity information (e.g., 5G-SUCI or 5G-GUTI); the AMF determines to initiate a primary authentication process for the UE based on the registration request message; after the primary authentication process for the user equipment, the AMF sends a NASSMC message to the UE, where the NAS SMC message is used to activate the NAS security context. That is, in this implementation, when executing the NAS SMC process, the UE can reduce signaling overhead while ensuring network session security by carrying a security-protected userID in the NAS SMP message.
[0320] S506: AMF determines to execute the user authentication process.
[0321] Specifically, the AMF determines to execute the user authentication process based on the information carried by the first NAS message or the information associated with the first NAS message.
[0322] In one possible implementation, the AMF determines to execute the user authentication procedure based on the userID in the first NAS message.
[0323] In another possible implementation, the AMF determines to execute the user authentication process according to the first indication information in the first NAS message.
[0324] For example, the first indication information may be a registration type (indicating that the first NAS message may be a registration request message for the user), a specific field or user ID (userID) associated with the user, or user ID authentication capability information of the UE.
[0325] In another possible implementation, the AMF determines to execute the user authentication process according to the name of the first message, such as the user authentication request message (e.g., Namf_UserAuthentication_Authenticate Request).
[0326] Optionally, the AMF may determine to execute a user authentication process based on local configuration information. For specific implementation methods, please refer to the relevant description of method 400.
[0327] It should be noted that this application does not limit the timing when AMF confirms the need to perform user authentication.
[0328] Optionally, after receiving the first NAS message, the AMF may confirm that there are one or more times when user authentication needs to be performed. For example, after receiving the first NAS message, the AMF determines that user authentication should be performed after a specific process is completed. Here, the specific process may be a main authentication process for the UE, or a registration process for the UE, that is, user authentication is performed after the UE is successfully registered. For the description of the main authentication process, refer to the relevant description above. This means that the AMF must first authenticate the UE, and only after the UE is successfully authenticated can the user be authenticated. For example, when the first NAS message carries UE identity information, if the UE identity information is SUCI, the AMF first executes the main authentication process and then confirms the execution of the user authentication process.
[0329] Optionally, the timing when the AMF confirms that user authentication needs to be performed may be a NASSMC process, for example, the AMF triggers authentication of the user after receiving the NASSMP message sent by the UE; or, the timing when the AMF confirms that user authentication needs to be performed may also be: the AMF may perform the action of determining user authentication after obtaining the UE's subscription data. For example, if the AMF determines that the UE can be used for user login or can perform the user authentication process on behalf of an external device, then the action of determining user authentication is performed. For example, if the UE's subscription data indicates that the user ID can be bound to the UE, then the user authentication is determined to be performed.
[0330] Optionally, the AMF may confirm that user authentication is required after obtaining the subscription data of the user ID currently logged in on the UE. For example, if the AMF determines that the UE's user ID can log in to the UE or an external device, the AMF may then perform the action of confirming user authentication.
[0331] S507, AMF executes the AUSF discovery process.
[0332] Exemplarily, when the AMF determines to perform user authentication, the AMF performs the AUSF discovery process.
[0333] In one implementation, the AMF discovers an AUSF that can perform user authentication based on local configuration.
[0334] In another implementation, the AMF determines the AUSF that can perform user authentication based on the Userid.
[0335] It should be noted that if the first NAS message is a Registration Request message, this step can occur before or after the Registration Accept message. That is, before step S506 is executed, the AMF can send a third NAS message to the UE, where the third NAS message is a Registration Accept message. Alternatively, after step S515 is executed, the AMF can send a third NAS message to the UE, where the third NAS message is a Registration Accept message. In other words, this application does not limit the order of the registration process and the user authentication process. That is, the AMF can send a Registration Complete message to the UE before or after the user authentication process is completed.
[0336] Below, the specific implementation method of AMF discovering (or determining) AUSF is explained.
[0337] For example, when selecting AUSF, AMF may discover AUSF based on the UE's userID, specifically including:
[0338] The AUSF is discovered based on the home network identifier in the user ID, routing indicator, and local configuration.
[0339] Based on the AUSF Group ID in the context of the user ID in the AMF, the AUSF is discovered through the NRF. When the AMF discovers the AUSF through the NRF, the NRF may send the AUSF Group ID to the AMF. The AMF may send the Group ID to other AMFs to enable them to select the AUSF based on the AUSF Group ID.
[0340] Discover AUSF through NRF based on user ID: When AMF discovers AUSF through NRF, AMF can send the UE's user ID to NRF, and then NRF performs AUSF discovery based on the UE's user ID.
[0341] For non-roaming scenarios, NRF searches for the corresponding AUSF based on the user ID in the Nnrf_NFDiscovery_Request message sent by AMF, or sends all AUSFs in the group based on the AUSF group to which it belongs. NRF will include the AUSF identifier, FQDN or IP address of the AUSF in the Nnrf_NFDiscovery_Request Response.
[0342] For roaming scenarios, the NRF in the serving network passes the Nnrf_NFDiscovery_Request message sent by the AMF to the NRF in the home network to look up the user ID to find the corresponding AUSF, or to provide all AUSF instance information in the group based on the AUSF group ID. The NRF in the home network will include the AUSF ID, FQDN or IP address of the AUSF in the Nnrf_NFDiscovery_Request Response and send it to the AMF through the NRF in the serving network.
[0343] S508, AMF sends a user authentication request message to AUSF.
[0344] Accordingly, AUSF receives the user authentication request message from AMF.
[0345] Exemplarily, the user authentication request message carries a userID, that is, the user authentication request message is used to request authentication of the user user.
[0346] Optionally, the user authentication request message may further carry second indication information for indicating authentication of the user user. The second indication information is used to indicate the user authentication request message, or the second indication information may be a user authentication request message, or is used to indicate that the current user authentication process is in progress. Specifically, the second indication information is used to indicate that the user authentication request message is sent for a user authentication process.
[0347] Optionally, there are one or more ways to implement the second indication information, for example, the second indication information is the message itself, that is, the user authentication request message. For another example, the second indication information is a new service-based operation. For example, the second indication information can be a user authentication type. For example, when the authentication type is user authentication, it means that the user authentication request message is an authentication request for the user, not for the UE. For another example, the second indication information can also be bit indication information used to characterize the authentication type. For example, when the bit indication information is set to 1, it means that the user authentication request message is not for the UE authentication, or it means that the user authentication request message is for the user authentication requested by the user or an external device. This embodiment does not limit the implementation method of the second indication information.
[0348] Optionally, the user authentication request message may also carry an SNName. The SNName may be the PLMNID of the AMF or a fixed string, such as "userauthentication." This embodiment does not specifically limit the SNName.
[0349] S509, AUSF executes the UDM discovery process.
[0350] Exemplarily, before AUSF executes the UDM discovery process, AUSF determines to execute the user authentication process based on the user authentication request message in step S508. For example, AUSF determines to execute the user authentication process based on the second indication information, thereby triggering the UDM discovery process. For example, AUSF determines to execute the user authentication process based on the user ID carried in the user authentication request message, thereby triggering the UDM discovery process. For example, AUSF determines to execute the user authentication process based on the user ID and the second indication information carried in the user authentication request message, thereby triggering the UDM discovery process. For example, AUSF may:
[0351] Discover the UDM based on the home network identifier and routing instructions in the user ID;
[0352] Discover the UDM through NRF based on the UDM Group ID in the context of the user ID in the AMF;
[0353] The UDM is discovered through the NRF based on the user ID. Optionally, the AUSF can determine that the user authentication process is to be executed by the fact that the user authentication request message in step S508 does not carry the SNName. This is because the SN name is the service network name associated with the UE. If the user authentication request message does not carry the SNName, the AUSF can understand that the user authentication request message is not for the authentication of the UE, but for the authentication of the user.
[0354] S510, the AUSF sends a user authentication vector request message (eg, Nudm_UEAuthentication_Request) to the UDM.
[0355] Correspondingly, the UDM receives a user authentication vector request message for requesting to obtain an authentication vector.
[0356] Illustratively, the user authentication vector request message carries a userID.
[0357] Optionally, the user authentication vector request message further carries third indication information, where the third indication information is used to indicate that it is a user authentication vector request message, or to indicate that the current process is a user authentication process, specifically, to indicate that the current user authentication vector request message is sent for a user authentication process.
[0358] Optionally, there are one or more implementation methods of the third indication information, for example, the third indication information is the message itself. For another example, the third indication information is a new service-based operation. For example, the third indication information can be a user authentication type. For example, when the authentication type is user authentication, it represents that the user authentication vector request message is a request for an authentication vector for the user, rather than for requesting an authentication vector for the UE, or represents that the user authentication vector request message is sent for user authentication requested by the user or an external device. For another example, the third indication information can also be bit indication information used to characterize the authentication type. For example, when the bit indication information is set to 1, it represents that the user authentication vector request message is not a request for an authentication vector for the UE, or represents that the authentication vector request message is an authentication vector requested for the user or an external device. This embodiment does not limit the implementation method of the third indication information.
[0359] Optionally, if the AUSF in step S508 receives the SNName in the user authentication request message, the following step S510 also carries the SNName.
[0360] S511, UDM generates an authentication vector based on the credentials corresponding to the user ID.
[0361] Exemplarily, the UDM selects an authentication method (EAP-AKA) according to the user's contract information and generates a corresponding authentication vector AV.
[0362] S512, UDM sends a user authentication vector acquisition response message to AUSF.
[0363] Accordingly, the AUSF receives a User Authentication Vector Response message.
[0364] The user authentication vector response message carries the user authentication vector.
[0365] Exemplarily, the UDM sends the authentication vector to the AUSF via a user authentication vector response message (e.g., Nudm_UEAuthentication_Response). Optionally, the message may also carry the user ID (if the user authentication vector request message sent by the AUSF to the UDM carries the user ID, the user authentication vector response message carries the user ID).
[0366] S513, executing the user authentication process.
[0367] Exemplarily, the AUSF performs a user authentication process with an external device or a user logged in on the UE. There are one or more implementation methods for the user authentication process, such as an EAP-AKA authentication process or a 5G-AKA authentication process. This embodiment does not specifically limit the implementation method of the user authentication process.
[0368] S514, AUSF sends a user authentication response message to AMF.
[0369] Correspondingly, AMF receives the user authentication response message from AUSF.
[0370] Exemplarily, the user authentication response message carries first user authentication result indication information and userID.
[0371] (1) The first user authentication result indication information is used to indicate whether the user authentication is successful or failed, that is, the first user authentication result indication information is used to indicate the authentication result of the first user.
[0372] (2) The first user authentication indication information may be bit indication information, or enumeration type indication information, or a message. For example, when the first user authentication indication information is bit indication information, bit 0 indicates authentication failure, and bit 1 indicates authentication success; for another example, when the first user authentication indication information is enumeration type indication information, the character string "Failure" indicates authentication failure, and the character string "success" indicates authentication success. For another example, when the first user authentication indication information is a message, EAP-Failure indicates authentication failure, and EAP-Success indicates authentication success; after the AUSF determines the user authentication result, it sends a user authentication response message to the AMF.
[0373] Optionally, if the first user authentication result indication information indicates that the user authentication is successful, the AMF locally creates context information for the userID. Optionally, the AMF stores at least one of the correspondence between the userID and the SUPI and the authentication success time. Alternatively, the AMF stores the correspondence between the userID and the SUPI and / or the authentication success time.
[0374] S514a: AMF saves the authentication result of the user.
[0375] S515: The AMF sends a second NAS message to the UE.
[0376] Accordingly, the UE receives a second NAS message from the AMF.
[0377] The second NAS message carries second user authentication result indication information, and the second user authentication result indication information is used to indicate the user authentication result, such as user authentication success or user authentication failure.
[0378] In one implementation, the second user authentication result indication information is the same as the first user authentication result indication information.
[0379] Exemplarily, when the second user authentication result indication information indicates that the user authentication is successful, the UE allows the user or external device to continue to use the UE and provide services to the UE. When the second user authentication result indication information indicates that the user authentication fails, the UE allows the user or external device to continue to try authentication again, or disconnects the user from the UE and releases the connection between the UE and the external device. If the UE allows the user or external device to continue to try authentication again, the UE resends the first NAS message to the AMF. Optionally, when the second user authentication result indication information indicates that the user authentication is successful, the UE locally creates context information of the userID. Optionally, the UE saves the time when the userID authentication is successful.
[0380] S515a, the UE saves the authentication result of the user.
[0381] Optionally, when the user authentication result indicated by the second NAS message indicates that the user authentication is successful, the UE can associate at least one of the authentication success and the authentication success time with the userID and store them together, so that when the user logs in to the UE or external device again later, the UE can determine not to trigger the network authentication of the first user based on the locally stored user authentication result associated with the userID (that is, the user authentication is successful), and then provide services to the first user, reduce signaling overhead, and ensure user service experience.
[0382] S516: The UE sends third user authentication result indication information to the user or external device.
[0383] Correspondingly, the external device receives the third user authentication result indication information from the UE.
[0384] The third user authentication result indication information is used to indicate the user authentication result, such as user authentication success or user authentication failure.
[0385] In one implementation, the third user authentication result indication information, the second user authentication result indication information, and the first user authentication result indication information are the same.
[0386] Exemplarily, when the UE sends third-user authentication result indication information to the external device, one or more implementations are included. For example, the UE may display a notification message indicating "Login successful." When the UE sends the third-user authentication result indication information to the external device, the third-user authentication result indication information is transmitted in a manner adapted to the protocol between the UE and the external device.
[0387] It should be noted that, in this embodiment, the above-mentioned execution entity AUSF can be replaced by NSSAAF, or AAA-Proxy, or NSSAAF and AAA-Proxy, and UDM can be replaced by an AAA server. When UDM is replaced by an AAA server and AUSF is replaced by AAA-P, AAA-P is an optional network element. When AAA-P is not required, the relevant adjustments of this embodiment are: Step S508 and Step S509 are not required. Step S510 is sent by AMF, and Step S513 is sent to AMF. The endpoint of Step S513 is the AAA server. The sender of Step S514 is the AAA server.
[0388] It should be noted that the authentication of the user ID involved in this embodiment can be understood as: authenticating the user corresponding to the userID, that is, the authentication of the user ID in this application can be replaced by: authenticating the user.
[0389] In summary, the embodiment of FIG5 mainly makes the following improvements:
[0390] UE side: When the user ID logs in to the UE, an authentication request is initiated to trigger the network side to authenticate the user ID. The request includes the user ID:
[0391] Case 1: The UE enters the registered state through the registration process (authenticating the SUCI in the registration process). At this time, the user logs in to the UE and the UE initiates an authentication request to authenticate the user ID.
[0392] Case 2: The UE is in the unregistered state. At this time, the user logs in to the UE. After the UE initiates the registration process and enters the registered state, the UE initiates an authentication request to authenticate the user ID.
[0393] In addition, after the UE obtains the user authentication result for the user ID from the AMF, it can save the correspondence between the user authentication result and the user ID. For example, if the user authentication result indicates that the user authentication is successful, the UE can store the association between the user authentication success and the user ID. This facilitates the subsequent login of the user to the UE or an external device. The UE can determine that the user is authentic and legitimate based on the locally stored user authentication result associated with the user ID (i.e., user authentication is successful). The UE does not need to request authentication of the user from the network side, and can then provide services to the user, reducing signaling overhead and ensuring user service experience.
[0394] AMF side:
[0395] Trigger user authentication based on the received NAS message containing the authentication request
[0396] Based on the user ID, determine whether the authentication server is internal or external, that is, authentication is performed through AMF / AUSF or through an external AAA server.
[0397] Based on the user ID, AUSF (option a: AUSF performs authentication) / UDM (generates authentication vector, option b: AMF performs authentication) / AAAServer (option c: AAA server performs authentication) is discovered.
[0398] The authentication result is returned to the UE. If the authentication result is successful, the network can subsequently provide the requested paid service for the user ID. If the authentication result fails, the user cannot access the network, but it does not affect the SUCI authentication result that identifies the UE, that is, the UE can access the network.
[0399] Based on the above solution, after the user equipment UE senses the user login or the connection between the user equipment and the external device, it actively sends a first message to the first network element AMF to inform the user information (for example, userID), and then requests to trigger the user authentication process to ensure network security. This implementation method enables two-way authentication between the UE and the service network, ensuring that the core network side can know that the user ID is a valid ID and provide network services on this basis. In the existing technology, the network side and the UE can only implement two-way authentication for SUCI and can only determine the legitimacy of SUPI. Therefore, for the user ID scenario, the legitimacy of the user ID logged into the UE cannot be guaranteed. After the user ID logs in to the user equipment or external device, the user is authenticated through a new NAS message (i.e., an example of the first message), i.e., an authentication request for the user ID.
[0400] Optionally, in the embodiment of the present application, authentication of the user ID must occur on the basis of successful SUPI authentication, and the authentication result of the user ID is independent of the authentication result of the SUPI. In other words, the authentication result of the user ID has no effect on the authentication result of the SUPI, that is, the authentication result of the first user has no effect on the authentication result of the user equipment, that is, it has no effect on the use of the UE corresponding to the SUPI in the 5GC. Specifically, even if the authentication of the user fails, resulting in the user being unable to access the network through the user equipment, it does not affect other users accessing the network through the user equipment (that is, the failure of the authentication of the first user does not change the previous successful authentication result of the user equipment).
[0401] Figure 6 is a flow chart illustrating a communication method 600 according to an embodiment of the present application. As shown in Figure 6 , this method flow can be executed by an external device, user equipment (UE), AMF, SMF, AUSF, or UDM, to address the issue of a session modification / establishment request sent by the UE not containing an EAP ID (i.e., a DN-specific identity). The method includes the following steps. For portions not fully described, reference can be made to the relevant descriptions of existing protocols.
[0402] S601, the user holds a certificate of trust.
[0403] S602: The UDM stores user credentials.
[0404] S603: The UE successfully registers with the network.
[0405] S604: An external device or user triggers login.
[0406] For the specific implementation of the above steps S601-S604, reference may be made to the relevant description of steps S501-S504 of the above method 500.
[0407] S605, the UE sends a first SM message (ie, an example of a first message) to the SMF (ie, an example of a first network element).
[0408] Accordingly, the SMF receives the first SM message from the UE.
[0409] Exemplarily, the first SM message carries at least one of the following: userID (ie, an example of the first user identifier), or first indication information.
[0410] The userID has security protection, including integrity security protection and / or confidentiality security protection. For example, the userID is protected by confidentiality.
[0411] Optionally, the first SM message has security protection, including: integrity security protection and / or confidentiality security protection. It should be noted that this application does not limit the protection method for userID to have security protection. For example, it can be security protection for userID alone, or it can be security protection for the first SM message carrying userID.
[0412] In one implementation, the first SM message is a PDU session establishment message, and the PDU session establishment message carries at least one of a userID and the first indication information.
[0413] (1) The definition and representation of userID can refer to the relevant description of the above method 400 or 500.
[0414] (2) The first indication information is used for user login, for example, instructing the user to log in to the user device, or receiving a message (or pop-up window) sent by an external device, which instructs the user to log in to the external device.
[0415] Optionally, the first indication information may be a PDU session type. For example, the PDU session type indicates that the PDU session establishment message is used to request to establish a session for the user; or, the first indication information may also be a userID; or, the first indication information may also be bit indication information. For example, when the bit indication information is set to 1, it indicates that the PDU session establishment is not used for the UE to establish a PDU session itself, or it indicates that the PDU session establishment is sent because the user logs in to the user device or the user device receives a message sent by an external device; or, the first indication information may also be the UE's user ID authentication capability information (for example, capability of User-Id based authentication). For example, when the UE has user authentication capability, it indicates that the PDU session establishment message is used to request to establish a PDU session for the user or for an external device. At this time, the network can perform user authentication.
[0416] In another implementation, the first SM message is a user authentication request message, which can be regarded as a new type of SM message. The user authentication request message carries UE identity information, userID and at least one of the first indication information.
[0417] (1) userID, please refer to the above description for details;
[0418] (2) The first indication information is used to instruct the user to log in, for example, to instruct the user to log in to the user equipment, or to indicate that the UE has received a message (or pop-up window) sent by an external device, and the message (or pop-up window) instructs the user to log in to the external device.
[0419] Optionally, the first indication information may be an SM message type, such as an SM message type indicating that a user authentication request message is used to request authentication of the user; or, the first indication information may also be a userID; or, the first indication information may also be the user ID authentication capability information of the UE, such as when the UE has user authentication capability, the user authentication request message is sent when the user logs in to the user device or the user device receives a message from an external device, and the network can perform user authentication at this time.
[0420] It should be noted that when the UE identity information is carried in the first SM message, and when the UE identity information is 5G-GUTI, the userID is confidentiality protected, or when the UE identity information is 5G-SUCI, the userID can be placed in the confidentiality protection part; when the UE identity information is not carried in the first SM message, the userID can be protected confidentially through the SM confidentiality protection key.
[0421] In another implementation, the first SM message is an EAP-Response / Identity message, and the EAP-Response / Identity message carries the userID. For a specific implementation, refer to the above description.
[0422] Illustratively, before executing step S605, the method further includes: the SMF receiving a registration request message from the UE, the registration request message including UE identity information; and the AMF determining, based on the registration request message, to initiate a primary authentication procedure for the UE; for example, the SMF sending an EAP-request / Identity message to the UE. That is, in this implementation, during the EAP-AKA authentication procedure for the UE, the UE carries a securely protected userID in the EAP-request / Identity message, thereby ensuring network session security while reducing signaling overhead.
[0423] S606, SMF determines to execute the user authentication process.
[0424] Specifically, the SMF determines to execute the user authentication process based on the information carried by the first SM message or the information associated with the first SM message.
[0425] In one implementation, the SMF determines to execute the user authentication process based on the user ID in the first SM message.
[0426] In another implementation, the SMF determines to execute the user authentication process based on the first indication information in the first SM message.
[0427] For example, the first indication information may be a session type (indicating that the first SM message may be a session establishment request message for the user), a specific field or user ID (userID) associated with the user, or user ID authentication capability information of the UE.
[0428] In another possible implementation, the SMF determines to execute the user authentication process according to the name of the first message, such as the user authentication request message (eg, Namf_UserAuthentication_Authenticate Request).
[0429] Optionally, the SMF may determine to execute a user authentication process based on local configuration information. For specific implementation, please refer to the relevant description of method 400.
[0430] It should be noted that this application does not limit the timing when SMF confirms the need to perform user authentication.
[0431] Illustratively, after receiving the first SM message, the SMF may determine that there are one or more timings for performing user authentication. For example, after obtaining the UE's subscription data, the SMF may perform an action to determine user authentication. For example, if the SMF determines that the UE can be used for user login or can replace an external device to perform a user authentication process, then the action to determine user authentication is performed. For another example, if the SMF determines that it can support the execution of the user authentication process, then the action to determine user authentication is performed. For example, if the UE's subscription data indicates that the user ID can be bound to the UE, then the user authentication is determined to be performed.
[0432] Optionally, the timing when the SMF confirms that user authentication needs to be performed may also be: the SMF performs the determination action after obtaining the subscription data of the user ID currently logged in on the UE. For example, if the SMF determines that the user ID of the UE can log in to the UE or an external device, the SMF then performs the action of determining user authentication.
[0433] It should be noted that, when the first SM message is an EAP-Response / Identity message, the SMF first executes step S606 and then executes step S605.
[0434] S607, SMF executes the AUSF discovery process.
[0435] Exemplarily, when the SMF determines to perform user authentication, the SMF executes the AUSF discovery process.
[0436] In one implementation, the SMF discovers an AUSF that can perform user authentication based on local configuration.
[0437] In another implementation, the SMF determines the AUSF that can perform user authentication based on the Userid.
[0438] It should be noted that if the first SM message is a PDU session establishment message, step S607 can occur before the PDU session establishment message or after the PDU session establishment message. That is to say, before step S607 is executed, the SMF can send a third SM message to the UE, and the third SM message is a PDU session establishment acceptance message. Alternatively, after executing step S615, the SMF can send a third SM message to the UE, and the third SM message is a PDU session establishment acceptance message. In other words, this application does not limit the order of the session establishment process and the user authentication process, that is, the SMF sends the session establishment acceptance message to the UE before the user authentication process is completed or after the user authentication process is completed.
[0439] For the specific implementation method of SMF discovering (or determining) AUSF, please refer to the relevant description of the above method 500 and will not be explained here.
[0440] S608, SMF sends a user authentication request message to AUSF.
[0441] Accordingly, AUSF receives the user authentication request message from SMF.
[0442] Exemplarily, the user authentication request message carries a userID, that is, the user authentication request message is used to request authentication of the user.
[0443] Optionally, the user authentication request message may further carry second indication information, where the second indication information indicates that the user is to be authenticated. The second indication information is used to indicate the user authentication request message, or the second indication information may be a user authentication request message, or is used to indicate that the current user authentication process is in progress. Specifically, the second indication information is used to indicate that the current user authentication request message is sent for a user authentication process.
[0444] Optionally, there are one or more ways to implement the second indication information, for example, the second indication information is the message itself, that is, the user authentication request message. For another example, the second indication information is a new service-based operation. For example, the second indication information can be a user authentication type. For example, when the authentication type is user authentication, it means that the user authentication request message is an authentication request for the user, not for the UE. For another example, the second indication information can also be bit indication information used to characterize the authentication type. For example, when the bit indication information is set to 1, it means that the user authentication request message is not for the UE authentication, or it means that the user authentication request message is for the user authentication requested by the user or an external device. This embodiment does not limit the implementation method of the second indication information.
[0445] Optionally, the user authentication request message may also carry an SNName. The SNName may be the PLMNID of the SMF or a fixed string, such as "userauthentication." This embodiment does not specifically limit the SNName.
[0446] S609, AUSF executes the UDM discovery process.
[0447] Exemplarily, before AUSF executes the UDM discovery process, AUSF determines to execute the user authentication process based on the user authentication request message in step S508. For example, AUSF determines to execute the user authentication process based on the second indication information, thereby triggering the UDM discovery process. For another example, AUSF determines to execute the user authentication process based on the user ID carried in the user authentication request message, thereby triggering the UDM discovery process. For another example, AUSF determines to execute the user authentication process based on the user ID and the second indication information carried in the user authentication request message, thereby triggering the UDM discovery process.
[0448] Optionally, AUSF can determine to execute the user authentication process by not carrying SNName in the user authentication request message in step S608. This is because SN name is the service network name associated with the UE. If the user authentication request message does not carry SNName, AUSF can understand that the user authentication request message is not for authentication of the UE, but for authentication of the user.
[0449] S610, the AUSF sends a user authentication vector request message (eg, Nudm_UEAuthentication_Request) to the UDM.
[0450] Correspondingly, the UDM receives a user authentication vector request message for requesting to obtain an authentication vector.
[0451] Illustratively, the user authentication vector request message carries a userID.
[0452] Optionally, the user authentication vector request message further carries third indication information. The third indication information is used to indicate that it is a user authentication vector acquisition request message, or to indicate that the current process is a user authentication process. Specifically, the third indication information is used to indicate that the current user authentication vector request message is sent for a user authentication process.
[0453] Optionally, there are one or more implementation methods of the third indication information, for example, the third indication information is the message itself. For another example, the third indication information is a new service-based operation. For example, the third indication information can be a user authentication type. For example, when the authentication type is user authentication, it represents that the user authentication vector request message is a request for an authentication vector for the user, rather than for requesting an authentication vector for the UE, or represents that the user authentication vector request message is sent for user authentication requested by the user or an external device. For another example, the third indication information can also be bit indication information used to characterize the authentication type. For example, when the bit indication information is set to 1, it represents that the user authentication vector request message is not a request for an authentication vector for the UE, or represents that the authentication vector request message is an authentication vector requested for the user or an external device. This embodiment does not limit the implementation method of the third indication information.
[0454] Optionally, if the AUSF in step S608 receives the SNName in the user authentication request message, the following step S610 also carries the SNName.
[0455] S611, UDM generates an authentication vector based on the credentials corresponding to the user ID.
[0456] S612, UDM sends a user authentication vector acquisition response message to AUSF.
[0457] Accordingly, the AUSF receives a User Authentication Vector Response message.
[0458] The user authentication vector response message carries the user authentication vector.
[0459] S613: Execute the user authentication process.
[0460] Exemplarily, the AUSF performs a user authentication process with an external device or a user logged in on the UE. There are one or more ways to implement the user authentication process, such as EAP or 5G-AKA authentication process. This embodiment does not specifically limit the user authentication process method.
[0461] For the specific implementation of the above steps S611-S613, reference may be made to the relevant description of steps S511-513 of the above method 500.
[0462] S614, AUSF sends a user authentication response message to SMF.
[0463] Correspondingly, SMF receives the user authentication response message from AUSF.
[0464] Exemplarily, the user authentication response message carries first user authentication result indication information and userID.
[0465] (1) The first user authentication result indication information is used to indicate whether the user authentication is successful or failed, that is, the first user authentication result indication information is used to indicate the authentication result of the first user.
[0466] (2) The first user authentication indication information may be bit indication information, or enumeration type indication information, or a message. For example, when the first user authentication indication information is bit indication information, bit 0 indicates authentication failure, and bit 1 indicates authentication success; for another example, when the first user authentication indication information is enumeration type indication information, the character string "Failure" indicates authentication failure, and the character string "success" indicates authentication success. For another example, when the first user authentication indication information is a message, EAP-Failure indicates authentication failure, and EAP-Success indicates authentication success; after the AUSF determines the user authentication result, it sends a user authentication response message to the SMF.
[0467] Optionally, if the first user authentication result indication information indicates that the user authentication is successful, the SMF locally creates context information for the userID. Optionally, the SMF stores at least one of a correspondence between the userID and the SUPI and a time of successful authentication. In other words, the SMF stores a correspondence between the userID and the SUPI and / or a time of successful authentication.
[0468] S614a, SMF saves the authentication result of the user.
[0469] S615: The SMF sends a second SM message to the UE.
[0470] Accordingly, the UE receives a second SM message from the SMF.
[0471] The second SM message carries second user authentication result indication information, and the second user authentication result indication information is used to indicate the user authentication result, such as user authentication success or user authentication failure.
[0472] In one implementation, the second user authentication result indication information is the same as the first user authentication result indication information.
[0473] Exemplarily, when the second user authentication result indication information indicates that the user authentication is successful, the UE allows the user or the external device to continue to use the UE and provide services for the UE. When the second user authentication result indication information indicates that the user authentication fails, the UE allows the user or the external device to continue to try authentication again, or logs the user off the UE and releases the connection between the UE and the external device. When the UE allows the user or the external device to continue to try authentication again, the UE resends the first SM message to the SMF. Optionally, when the second user authentication result indication information indicates that the user authentication is successful, the UE locally creates context information of the userID. Optionally, the UE saves the time when the userID authentication is successful.
[0474] S615a, the UE saves the authentication result of the user.
[0475] Optionally, when the authentication result of the user indicated by the second SM message indicates that the user authentication is successful, the UE can associate at least one of the authentication success and the authentication success time with the userID and store them together, so that when the user logs in to the UE or external device again in the future, the UE can determine not to trigger the network authentication of the first user based on the locally stored authentication result of the user associated with the userID (that is, the user authentication is successful), and then provide services to the first user, reduce signaling overhead, and ensure user service experience.
[0476] S616: The UE sends third user authentication result indication information to the user or external device.
[0477] Correspondingly, the external device receives the third user authentication result indication information from the UE.
[0478] The third user authentication result indication information is used to indicate the user authentication result, such as user authentication success or user authentication failure.
[0479] In one implementation, the third user authentication result indication information, the second user authentication result indication information, and the first user authentication result indication information are the same.
[0480] Exemplarily, when the UE sends third-user authentication result indication information to the external device, one or more implementations are included. For example, the UE may display a notification message indicating "Login successful." When the UE sends the third-user authentication result indication information to the external device, the third-user authentication result indication information is transmitted in a manner adapted to the protocol between the UE and the external device.
[0481] It should be noted that, in this embodiment, the above-mentioned execution entity AUSF can be replaced by NSSAAF, or AAA-Proxy, or NSSAAF and AAA-Proxy, and UDM can be replaced by an AAA server. When UDM is replaced by an AAA server and AUSF is replaced by AAA-P, AAA-P is an optional network element. When AAA-P is not required, the relevant adjustments of this embodiment are: Step S608 and Step S609 are not required. Step S610 is sent by SMF, and Step S613 is sent to SMF. The endpoint of Step S613 is the AAA server. The sender of Step S614 is the AAA server.
[0482] Based on the above solution, after the user equipment UE detects a user login or a connection between the user equipment and an external device, it proactively sends a first message to the first network element SMF to inform the user information (e.g., user ID), and then requests to trigger the user authentication process to ensure network security. This implementation method enables bidirectional authentication between the UE and the serving network, ensuring that the core network side can know that the user ID is a valid ID and provide network services on this basis. In the existing technology, the network side and the UE can only implement bidirectional authentication for SUCI and can only determine the legitimacy of SUPI. Therefore, in the user ID scenario, the legitimacy of the user ID logged into the UE cannot be guaranteed. After the user ID logs in to the user equipment or external device, the user is authenticated by sending a new SM message (i.e., an example of the first message).
[0483] Optionally, in the embodiment of the present application, authentication of the user ID must occur on the basis of successful SUPI authentication, and the authentication result of the user ID is independent of the authentication result of the SUPI. In other words, the authentication result of the user ID has no effect on the authentication result of the SUPI, that is, the authentication result of the first user has no effect on the authentication result of the user equipment, that is, it has no effect on the use of the UE corresponding to the SUPI in the 5GC. Specifically, even if the authentication of the user fails, resulting in the user being unable to access the network through the user equipment, it does not affect other users accessing the network through the user equipment (that is, the failure of the authentication of the first user does not change the previous successful authentication result of the user equipment).
[0484] The above description, in conjunction with Figures 1 to 6 , details the communication method embodiment of the present application. The following description, in conjunction with Figures 7 to 9 , details the communication device embodiment of the present application. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for portions not described in detail, reference can be made to the preceding method embodiment.
[0485] Figure 7 is a schematic diagram of the structure of a communication device 1000 provided in an embodiment of the present application. As shown in Figure 7, the device 1000 may include a transceiver unit 1010 and a processing unit 1020. The transceiver unit 1010 can communicate with the outside world, and the processing unit 1020 is used to process data. The transceiver unit 1010 may also be referred to as a communication interface or a transceiver unit.
[0486] In one possible design, the device 1000 can implement steps or processes corresponding to those performed by the first network element in the above method embodiment, wherein the processing unit 1020 is used to perform processing-related operations of the first network element in the above method embodiment, and the transceiver unit 1010 is used to perform transceiver-related operations of the first network element in the above method embodiment.
[0487] Exemplarily, the transceiver unit 1010 is used to receive a first message from a user device, the first message including a first user identifier of a first user using the user device with security protection; the processing unit 1020 is used to initiate an authentication process for the first user based on the first message; the transceiver unit 1010 is also used to send a second message to the user device, the second message being used to indicate an authentication result for the first user.
[0488] Exemplarily, before receiving the first message from the user equipment, the method also includes: the transceiver unit 1010 is also used to receive a registration request message from the user equipment, the registration request message including the identifier of the user equipment; the processing unit 1020 is also used to determine to initiate a main authentication process for the user equipment based on the registration request message; after the main authentication process for the user equipment, the transceiver unit 1010 is also used to send a non-access stratum security mode command NASSMC message to the user equipment, the NAS SMC message is used to activate the NAS security context; the transceiver unit 1010 is also used to receive a NAS security mode command completion NASSMP message from the user equipment.
[0489] Exemplarily, the first message is a NASSMP message; before receiving the first message from the user equipment, the method also includes: the transceiver unit 1010 is also used to receive a registration request message from the user equipment, and the registration request message includes an identifier of the user equipment; the processing unit 1020 is also used to determine to initiate a main authentication process for the user equipment based on the registration request message; after the main authentication process for the user equipment, the transceiver unit 1010 is also used to send a NASSMC message to the user equipment, and the NAS SMC message is used to activate the NAS security context.
[0490] Exemplarily, before receiving the first message from the user device, the method also includes: the transceiver unit 1010 is also used to receive a registration request message from the user device, the registration request message including the identifier of the user device and the second user identifier of the second user; the processing unit 1020 is also used to determine to initiate a main authentication process for the user device based on the registration request message; after the main authentication for the user device is successful, the processing unit 1020 is also used to initiate an authentication process for the second user.
[0491] Exemplarily, the processing unit 1020 is used to initiate an authentication process for the first user based on the first message, including: the processing unit 1020 is also used to initiate authentication for the first user based on the first indication information associated with the first message; wherein the first indication information is represented by the name of the first message, the first user identifier, or one or more of the specified information elements in the first message.
[0492] Exemplarily, the processing unit 1020 is used to initiate an authentication process for the first user, including: the processing unit 1020 is also used to determine the first authentication function; the transceiver unit 1010 is also used to send a user authentication request message to the first authentication function, the user authentication request message includes the first user identifier, and the user authentication request message is used to request authentication of the first user; the transceiver unit 1010 is also used to receive a user authentication response message from the first authentication function, and the user authentication response message is used to indicate the authentication result for the first user.
[0493] Exemplarily, the processing unit 1020 is further used to determine the first authentication function, including: the processing unit 1020 is further used to determine the first authentication function according to local configuration information; and / or, the processing unit 1020 is further used to determine the first authentication function according to the first user identifier.
[0494] Exemplarily, the user authentication request message further includes second indication information, where the second indication information indicates to authenticate the first user.
[0495] Exemplarily, the user authentication response message includes the authentication result of the first user and / or first user authentication result indication information, the first user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
[0496] Exemplarily, the second message includes the authentication result of the first user and / or second user authentication result indication information, the second user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
[0497] Exemplarily, when the authentication result of the first user indicates that the first user authentication is successful, the processing unit 1020 is further configured to store an association between at least one of the authentication result of the first user, the identifier of the user device, and the authentication success time and the first user identifier.
[0498] Exemplarily, the first user identifier includes a first information part and a second information part, the first information part is used to identify the first user, the second information part is used to determine the routing information of the first storage function, the first storage function is used to store the credentials of the first user, and the credentials are used to identify and verify the first user.
[0499] Exemplarily, when the first network element is a mobility management network element, the first message is a first NAS message, and the second message is a second NAS message; or, when the first network element is a session management network element, the first message is a first session management SM message, and the second message is a second SM message.
[0500] Exemplarily, the first NAS message is a registration request message, or the first NAS message is a user authentication request message, or the first NAS message is a NAS SMP message.
[0501] Exemplarily, when the first NAS message is a registration request message, the method further includes: after the authentication process for the first user, the transceiver unit 1010 is also used to send a registration completion message to the user equipment; or, before the authentication process for the first user, the transceiver unit 1010 is also used to send a registration completion message to the user equipment.
[0502] Exemplarily, the first SM message is a protocol data unit (PDU) session establishment request message, or the first SM message is a user authentication request message, or the first SM message is an extensible authentication protocol response (EAP-Response) message.
[0503] In another possible design, the device 1000 can implement steps or processes corresponding to the execution of the first authentication function in the above method embodiment, wherein the transceiver unit 1010 is used to perform operations related to the transmission and reception of the first authentication function in the above method embodiment, and the processing unit 1020 is used to perform operations related to the processing of the first authentication function in the above method embodiment.
[0504] In another possible design, the device 1000 can implement steps or processes corresponding to those performed by the user equipment in the above method embodiments, wherein the processing unit 1020 is used to perform processing-related operations of the user equipment in the above method embodiments, and the transceiver unit 1010 is used to perform transceiver-related operations of the user equipment in the above method embodiments.
[0505] Exemplarily, the transceiver unit 1010 is used to send a first message to a first network element, the first message including a first user identifier of a first user using a user device with security protection; the transceiver unit 1010 is also used to receive a second message from the first network element, the second message is used to indicate an authentication result for the first user; the transceiver unit 1010 is also used to send the authentication result of the first user to the first user.
[0506] Exemplarily, the method further includes: when the authentication result of the first user indicates that the first user authentication is successful, the processing unit 1020 is configured to store an association relationship between at least one of the authentication result of the first user and the authentication success time and the first user identifier.
[0507] Exemplarily, before the transceiver unit 1010 is also used to send the first message to the first network element, the method also includes: when the first user uses the first user identifier to log in to the user device and / or the external device, the processing unit 1020 is also used to determine that the authentication result for the first user is not stored locally, wherein the external device is communicatively connected to the user device.
[0508] Exemplarily, the transceiver unit 1010 is used to send a first message to a first network element, including: when a first user uses a first user identifier to log in to a user device and / or an external device, the transceiver unit 1010 is also used to send a first message to the first network element.
[0509] Exemplarily, before the transceiver unit 1010 is used to send a first message to the first network element, the method also includes: the transceiver unit 1010 is also used to send a registration request message to the first network element, the registration request message includes an identifier of the user equipment; after the main authentication process for the user equipment, the transceiver unit 1010 is also used to receive a non-access stratum security mode command NASSMC message from the first network element, the NAS SMC message is used to activate the NAS security context; the transceiver unit 1010 is also used to send a NAS security mode command completion NASSMP message to the first network element.
[0510] Exemplarily, the first message is a NASSMP message; before the transceiver unit 1010 is used to send the first message to the first network element, the method also includes: the transceiver unit 1010 is also used to send a registration request message to the first network element, and the registration request message includes an identifier of the user equipment; after the main authentication process for the user equipment, the transceiver unit 1010 is also used to receive a NASSMC message from the first network element, and the NAS SMC message is used to activate the NAS security context.
[0511] Exemplarily, before the transceiver unit 1010 is used to send the first message to the first network element, the method further includes: the transceiver unit 1010 is also used to send a registration request message to the first network element, the registration request message including the identifier of the user equipment and the second user identifier of the second user.
[0512] Exemplarily, the first user identifier includes a first information part and a second information part, the first information part is used to identify the first user, the second information part is used to determine the routing information of the first storage function, the first storage function is used to store the credentials of the first user, and the credentials are used to identify and verify the first user.
[0513] Exemplarily, before the transceiver unit 1010 is used to send the first message to the first network element, the method also includes: the processing unit 1020 is also used to obtain the first user identifier, specifically including: the transceiver unit 1010 is also used to receive the first user identifier from an external device; and / or, the processing unit 1020 is also used to obtain the user identifier based on the first user using the first user identifier to log in to the user device.
[0514] Exemplarily, the second message includes the authentication result of the first user and / or second user authentication result indication information, the second user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
[0515] Exemplarily, the transceiver unit 1010 is also used to send the authentication result of the first user to the first user, including: the transceiver unit 1010 is also used to send third user authentication result indication information to the first user, the third user authentication result indication information indicates the authentication result of the first user, and the authentication result of the first user indicates whether the authentication of the first user is successful or failed.
[0516] Exemplarily, the method also includes: when the authentication result of the first user indicates that the first user authentication is successful, the processing unit 1020 is also used to provide services to the first user; or, when the authentication result of the first user indicates that the first user authentication fails, the processing unit 1020 is also used to refuse to provide services to the first user.
[0517] Exemplarily, when the first network element is a mobility management network element, the first message is a first NAS message, and the second message is a second NAS message; or, when the first network element is a session management network element, the first message is a first session management SM message, and the second message is a second SM message.
[0518] Exemplarily, the first NAS message is a registration request message, or the first NAS message is a user authentication request message, or the first NAS message is a NAS SMP message.
[0519] Exemplarily, when the first NAS message is a registration request message, the method also includes: after the authentication process for the first user, the transceiver unit 1010 is also used to receive a registration completion message from the first network element; or, before the authentication process for the first user, the transceiver unit 1010 is also used to receive a registration completion message from the first network element.
[0520] Exemplarily, the first SM message is a protocol data unit (PDU) session establishment request message, or the first SM message is a user authentication request message, or the first SM message is an extensible authentication protocol response (EAP-Response) message.
[0521] It should be understood that the device 1000 here is embodied in the form of a functional unit. The term "unit" here can refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor or a group processor, etc.) and a memory for executing one or more software or firmware programs, a merging logic circuit and / or other suitable components that support the described functions. In an optional example, those skilled in the art can understand that the device 1000 can be specifically the transmitting end in the above embodiment, and can be used to execute the various processes and / or steps corresponding to the transmitting end in the above method embodiment, or the device 2000 can be specifically the receiving end in the above embodiment, and can be used to execute the various processes and / or steps corresponding to the receiving end in the above method embodiment. To avoid repetition, it will not be repeated here.
[0522] The apparatus 1000 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the transmitting end in the above-mentioned method, or the apparatus 1000 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the receiving end in the above-mentioned method. The functions can be implemented by hardware, or can be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions; for example, the transceiver unit can be replaced by a transceiver (for example, the transmitting unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as the processing unit, can be replaced by a processor to respectively perform the transceiver operations and related processing operations in each method embodiment.
[0523] In addition, the above-mentioned transceiver unit can also be a transceiver circuit (for example, it can include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit. In an embodiment of the present application, the device in Figure 7 can be the receiving end or the transmitting end in the aforementioned embodiment, or it can be a chip or a chip system, such as a system on chip (SoC). Among them, the transceiver unit can be an input and output circuit or a communication interface. The processing unit is a processor or microprocessor or integrated circuit integrated on the chip. This is not limited here.
[0524] Figure 8 is a schematic diagram of the structure of a communication device 2000 provided in an embodiment of the present application. As shown in Figure 8, the device 2000 includes a processor 2010 and a transceiver 2020. The processor 2010 and the transceiver 2020 communicate with each other via an internal connection path. The processor 2010 is used to execute instructions to control the transceiver 2020 to send and / or receive signals.
[0525] Optionally, the apparatus 2000 may further include a memory 2030, which communicates with the processor 2010 and the transceiver 2020 via an internal connection path. The memory 2030 is used to store instructions, and the processor 2010 may execute the instructions stored in the memory 2030.
[0526] In a possible implementation, the device 2000 is used to implement various processes and steps corresponding to the first network element in the above method embodiment.
[0527] In another possible implementation, the apparatus 2000 is used to implement various processes and steps corresponding to the user equipment in the above method embodiment.
[0528] In another possible implementation, the device 2000 is used to implement various processes and steps corresponding to the first authentication function in the above method embodiment.
[0529] It should be understood that the device 2000 can be specifically the transmitting end or receiving end in the above-mentioned embodiments, or can also be a chip or chip system. Correspondingly, the transceiver 2020 can be the transceiver circuit of the chip, which is not limited here. Specifically, the device 2000 can be used to perform the various steps and / or processes corresponding to the transmitting end or receiving end in the above-mentioned method embodiments.
[0530] Optionally, the memory 2030 may include a read-only memory and a random access memory, and provide instructions and data to the processor. A portion of the memory may also include non-volatile random access memory. For example, the memory may also store device type information. The processor 2010 may be configured to execute instructions stored in the memory. When the processor 2010 executes the instructions stored in the memory, the processor 2010 is configured to perform the various steps and / or processes of the above-described method embodiments corresponding to the transmitting end or the receiving end.
[0531] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor or an instruction in the form of software. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here.
[0532] It should be noted that the processor in the embodiments of the present application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above-mentioned method embodiment can be completed by hardware integrated logic circuits in the processor or by software instructions. The above-mentioned processor can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor in the embodiments of the present application can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above-mentioned method.
[0533] It will be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory, dynamic random access memory, synchronous dynamic random access memory, double data rate synchronous dynamic random access memory, enhanced synchronous dynamic random access memory, synchronous linked dynamic random access memory, and direct memory bus random access memory. It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0534] FIG9 is a schematic diagram of the structure of a chip system 3000 provided in an embodiment of the present application. As shown in FIG9 , the chip system 3000 (or also referred to as a processing system) includes a logic circuit 3010 and an input / output interface 3020 .
[0535] The logic circuit 3010 may be a processing circuit in the chip system 3000. The logic circuit 3010 may be coupled to a storage unit and call instructions in the storage unit so that the chip system 3000 can implement the methods and functions of the various embodiments of the present application. The input / output interface 3020 may be an input / output circuit in the chip system 3000, outputting information processed by the chip system 3000 or inputting data or signaling information to be processed into the chip system 3000 for processing.
[0536] As a solution, the chip system 3000 is used to implement the operations performed by the user equipment in the above various method embodiments.
[0537] As a solution, the chip system 3000 is used to implement the operations performed by the first network element in the above method embodiments.
[0538] As a solution, the chip system 3000 is used to implement the operations performed by the first authentication function in the above method embodiments.
[0539] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions are stored for implementing the method executed by at least one of the user equipment, the first network element or the first authentication function in the above-mentioned method embodiments.
[0540] An embodiment of the present application also provides a computer program product, comprising computer program code or instructions, which, when executed on a computer, enables the computer to implement the method executed by at least one of the user equipment, the first network element, and the first authentication function in the above-mentioned method embodiments.
[0541] An embodiment of the present application also provides a communication system, including the aforementioned first network element and / or first authentication function.
[0542] Optionally, the communication system further includes the aforementioned user equipment.
[0543] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.
[0544] To facilitate understanding of the above embodiments provided in this application, the following points are explained:
[0545] 1) In this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0546] 2) In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Where a, b and c can be single or multiple, respectively.
[0547] 3) Throughout this application, the terms "first," "second," and various numerical references (e.g., #1, #2, etc.) are used to distinguish between different messages for ease of description and are not intended to limit the scope of the embodiments of this application. For example, they are used to distinguish between different messages, rather than to describe a specific order or precedence. It should be understood that such references are interchangeable, where appropriate, to allow for the description of scenarios beyond the embodiments of this application.
[0548] 4) In this application, descriptions such as "when...", "in the case of...", and "if" all mean that the device will perform corresponding processing under certain objective circumstances. They do not limit the time, nor do they require the device to perform judgment actions when implementing them, nor do they mean that there are other limitations.
[0549] 5) In this application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and it does not mean that the indication information must carry A.
[0550] The indication methods involved in the embodiments of this application should be understood to encompass various methods that enable the party to be indicated to obtain information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or timing of these sub-information can be the same or different. This application does not limit the specific transmission method.
[0551] In the embodiments of the present application, the "indication information" may be an explicit indication, i.e., a direct indication via signaling, or may be obtained based on parameters indicated by the signaling, in combination with other rules, other parameters, or by deduction. It may also be an implicit indication, i.e., based on a rule or relationship, or based on other parameters, or by deduction. This application does not impose specific limitations on this.
[0552] 6) In this application, "protocol" may refer to a standard protocol in the field of communications, such as 5G protocol, NR protocol, and related protocols used in future communication systems, which are not limited in this application. "Predefined" may include pre-definition. For example, protocol definition. "Preconfiguration" can be implemented by pre-saving corresponding codes, tables, or other methods that can be used to indicate relevant information in the device. This application does not limit its specific implementation method.
[0553] 7) In this application, "communication" may also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving".
[0554] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0555] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0556] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the explicit or discussed mutual coupling or direct coupling or communication connection can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0557] The units described as separate components may or may not be physically separate, and the components explicitly described as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of the solution of this embodiment according to actual needs.
[0558] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0559] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk, or an optical disk.
[0560] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: include: receiving a first message from a user device, where the first message includes a first user identifier of a first user using the user device with security protection; Initiating an authentication process for the first user according to the first message; A second message is sent to the user equipment, where the second message is used to indicate an authentication result for the first user.
2. The method according to claim 1, characterized in that Before receiving the first message from the user equipment, the method further includes: receiving a registration request message from the user equipment, where the registration request message includes an identifier of the user equipment; Determining, according to the registration request message, to initiate a primary authentication process for the user equipment; After the main authentication process for the user equipment, send a non-access stratum security mode command (NAS SMC) message to the user equipment, where the NAS SMC message is used to activate a NAS security context; Receiving a NAS security mode command completion NASSMP message from the user equipment.
3. The method according to claim 1, characterized in that The first message is a NASSMP message; Before receiving the first message from the user equipment, the method further includes: receiving a registration request message from the user equipment, where the registration request message includes an identifier of the user equipment; Determining, according to the registration request message, to initiate a primary authentication process for the user equipment; After the main authentication process for the user equipment, a NASSMC message is sent to the user equipment, where the NAS SMC message is used to activate a NAS security context.
4. The method according to claim 1, wherein Before receiving the first message from the user equipment, the method further includes: receiving a registration request message from the user equipment, the registration request message including an identifier of the user equipment and a second user identifier of a second user; Determining, according to the registration request message, to initiate a primary authentication process for the user equipment; After the primary authentication for the user equipment is successful, an authentication process for the second user is initiated.
5. The method according to any one of claims 1 to 4, characterized in that The initiating an authentication process for the first user according to the first message includes: Initiate authentication for the first user according to the first indication information associated with the first message; The first indication information is represented by one or more of the name of the first message, the first user identifier, or a designated information element in the first message.
6. The method according to any one of claims 1 to 5, characterized in that The initiating an authentication process for the first user includes: determining a first authentication function; Sending a user authentication request message to the first authentication function, where the user authentication request message includes the first user identifier and is used to request authentication of the first user; A user authentication response message is received from the first authentication function, where the user authentication response message is used to indicate an authentication result for the first user.
7. The method according to claim 6, characterized in that The determining of the first authentication function includes: Determining the first authentication function according to local configuration information; and / or, The first authentication function is determined according to the first user identifier.
8. The method according to claim 6 or 7, characterized in that The user authentication request message further includes second indication information, where the second indication information indicates to authenticate the first user.
9. The method according to any one of claims 6 to 8, characterized in that The user authentication response message includes the authentication result of the first user and / or first user authentication result indication information, the first user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
10. The method according to any one of claims 1 to 9, characterized in that The second message includes the authentication result of the first user and / or second user authentication result indication information, the second user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: When the authentication result of the first user indicates that the first user authentication is successful, an association relationship between the authentication result of the first user, at least one of the identifier of the user equipment and the authentication success time, and the first user identifier is stored.
12. The method according to any one of claims 1 to 11, characterized in that The first user identifier includes a first information part and a second information part, the first information part is used to identify the first user, the second information part is used to determine routing information of a first storage function, the first storage function is used to store the credentials of the first user, and the credentials are used to identify and verify the first user.
13. The method according to any one of claims 1 to 12, characterized in that The method is applied to a first network element; When the first network element is a mobility management network element, the first message is a first NAS message, and the second message is a second NAS message; or, When the first network element is a session management network element, the first message is a first session management (SM) message, and the second message is a second SM message.
14. The method according to claim 13, characterized in that The first NAS message is a registration request message, or the first NAS message is a user authentication request message, or the first NAS message is a NAS SMP message.
15. The method according to claim 14, characterized in that When the first NAS message is a registration request message, the method further includes: After the authentication process for the first user, sending a registration completion message to the user equipment; or, Before the authentication process for the first user, a registration completion message is sent to the user equipment.
16. The method according to any one of claims 13 to 15, characterized in that The first SM message is a protocol data unit (PDU) session establishment request message, or the first SM message is a user authentication request message, or the first SM message is an extensible authentication protocol response (EAP-Response) message.
17. A communication method, characterized in that: include: Sending a first message to a first network element, where the first message includes a first user identifier of a first user using a user equipment with security protection; receiving a second message from the first network element, where the second message is used to indicate an authentication result for the first user; Sending the first user an authentication result.
18. The method according to claim 17, characterized in that The method further comprises: When the authentication result of the first user indicates that the first user is successfully authenticated, an association relationship between at least one of the authentication result of the first user and the authentication success time and the first user identifier is stored.
19. The method according to claim 17 or 18, characterized in that Before sending the first message to the first network element, the method further includes: When the first user logs in to the user device and / or the external device using the first user identifier, it is determined that no authentication result for the first user is stored locally, wherein the external device is communicatively connected to the user device.
20. The method according to claim 17, wherein The sending the first message to the first network element includes: When the first user uses the first user identifier to log in to the user equipment and / or external device, the first message is sent to the first network element.
21. The method according to any one of claims 17 to 20, characterized in that Before sending the first message to the first network element, the method further includes: Sending a registration request message to the first network element, where the registration request message includes an identifier of the user equipment; After the primary authentication process for the user equipment, receiving a non-access stratum security mode command (NAS SMC) message from the first network element, where the NAS SMC message is used to activate a NAS security context; Send a NAS security mode command to the first network element to complete the NASSMP message.
22. The method according to any one of claims 17 to 20, characterized in that The first message is a NASSMP message; Before sending the first message to the first network element, the method further includes: Sending a registration request message to the first network element, where the registration request message includes an identifier of the user equipment; After the main authentication process for the user equipment, a NASSMC message is received from the first network element, where the NAS SMC message is used to activate a NAS security context.
23. The method according to any one of claims 17 to 20, characterized in that Before sending the first message to the first network element, the method further includes: A registration request message is sent to the first network element, where the registration request message includes an identifier of the user equipment and a second user identifier of a second user.
24. The method according to any one of claims 17 to 23, characterized in that The first user identifier includes a first information part and a second information part, the first information part is used to identify the first user, the second information part is used to determine routing information of a first storage function, the first storage function is used to store the credentials of the first user, and the credentials are used to identify and verify the first user.
25. The method according to any one of claims 17 to 24, characterized in that Before sending the first message to the first network element, the method further includes: Obtaining the first user identifier specifically includes: receiving the first user identifier from an external device; and / or, The first user identifier is obtained according to the first user logging into the user device using the first user identifier.
26. The method according to any one of claims 17 to 25, characterized in that The second message includes the authentication result of the first user and / or second user authentication result indication information, the second user authentication result indication information indicates the authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
27. The method according to any one of claims 17 to 24, characterized in that The sending the authentication result of the first user to the first user includes: Sending third user authentication result indication information to the first user, where the third user authentication result indication information indicates an authentication result of the first user, and the first user authentication result indicates whether the first user authentication is successful or failed.
28. The method according to any one of claims 17 to 27, characterized in that The method further comprises: If the authentication result of the first user indicates that the first user is successfully authenticated, providing services to the first user; or If the authentication result of the first user indicates that the authentication of the first user fails, refusing to provide services to the first user.
29. A communication method, characterized in that: include: receiving a first message from a user equipment, where the first message includes a user identifier, and the first message is used to trigger a network to authenticate the user identifier; Determining to authenticate the user identification and obtaining a user authentication result; A second message is sent to the user equipment, where the second message is used to indicate the user authentication result.
30. The method according to claim 29, wherein Determining to authenticate the user identifier includes: According to the name of the first message, it is determined to authenticate the user identifier.
31. The method according to claim 29 or 30, characterized in that Determining to authenticate the user identifier includes: According to the user identifier carried in the first message, it is determined to authenticate the user identifier.
32. The method according to any one of claims 29 to 31, characterized in that Determining to authenticate the user identifier includes: According to the registration type carried in the first message, it is determined to authenticate the user identifier.
33. The method according to any one of claims 29 to 32, characterized in that Determining to authenticate the user identifier includes: Authenticate the user identifier according to the local configuration information.
34. The method according to any one of claims 29 to 33, characterized in that The user identification has integrity security protection and / or confidentiality security protection.
35. The method according to any one of claims 29 to 34, characterized in that The method further comprises: The association relationship between the user authentication result and the user identifier is stored.
36. The method according to any one of claims 29 to 35, characterized in that The first message is a non-access stratum (NAS) message or a session management (SM) message.
37. A communication method, characterized in that: include: Sending a first message to a first network element, where the first message includes a user identifier, and the first message is used to trigger a network to authenticate the user identifier; A second message is received from the first network element, where the second message is used to indicate a user authentication result.
38. The method according to claim 37, wherein Sending a first message to a first network element includes: If it is determined that the user logs in to the user equipment using the user identifier, the first message is sent to the first network element.
39. The method according to claim 38, characterized in that The determining that the user uses the user identifier to log in to the user device includes: It is determined that the user uses the user identifier to log in to the external device, and the external device establishes a connection with the user device.
40. The method according to any one of claims 37 to 39, characterized in that The user identification has integrity security protection and / or confidentiality security protection.
41. The method according to any one of claims 37 to 40, characterized in that The method further comprises: The association relationship between the user authentication result and the user identifier is stored.
42. The method according to any one of claims 37 to 41, characterized in that The first message is a non-access stratum (NAS) message or a session management (SM) message.
43. A communication device, characterized in that include: One or more functional modules, wherein the one or more functional modules are used to execute the method according to any one of claims 1 to 16 and 29 to 36, or the one or more functional modules are used to execute the method according to any one of claims 17 to 28 and 37 to 42.
44. A communication device, characterized in that include: At least one processor configured to execute a computer program or instructions such that the method of any one of claims 1 to 16, 29 to 36, or any one of claims 17 to 28, 37 to 42 is performed.
45. The communication device according to claim 44, characterized in that The communication device further comprises a memory for storing the computer program or instructions; and / or, The communication device further includes a communication interface coupled to the at least one processor, wherein the communication interface is configured to input and / or output information.
46. The communication device according to claim 44 or 45, characterized in that The communication device is a chip or a chip system.
47. A computer-readable storage medium, characterized in that include: The computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the method according to any one of claims 1 to 16 and 29 to 36, or enables the computer to execute the method according to any one of claims 17 to 28 and 37 to 42.
48. A computer program product, characterized in that The invention comprises instructions, which, when executed on a computer, enable the method according to any one of claims 1 to 16, 29 to 36 to be implemented, or enable the method according to any one of claims 17 to 28, 37 to 42 to be implemented.
49. A communication system, characterized in that include: A first network element, wherein the first network element is configured to execute the method according to any one of claims 1 to 16 and 29 to 36.
50. The communication system according to claim 49, wherein: The communication system further comprises a user equipment, wherein the user equipment is configured to execute the method according to any one of claims 17 to 28 and 37 to 42.
Citation Information
Patent Citations
Communication method and communication device
CN120456019A
Method and system for accessing network to public device
CN102131197A
Authentication method and device and equipment
CN111818516A
Secondary authentication method and device
CN115835218A
Communication method and related devices
WO2021026927A1