Communication method and apparatus

Through the interaction between the network functional network elements and the ACME server, and the use of trust information and key verification information, the problem of the ACME protocol and the 5G service architecture is solved, and the security certificate issuance and interactive adaptation between the network functional network elements is realized.

WO2025180293A1PCT designated stage Publication Date: 2025-09-04HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/078336
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-26
Filing Date
2025-02-20
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

The existing automated certificate management environment (ACME) protocol is not suitable for the service architecture of the 5G network, resulting in the interactive authentication process between network elements of the network function.

Method used

It provides a communication method to verify and issue the identification of network functional network elements and the ACME server through the interaction between the network functional network elements, including order requests, challenge responses and certificate requests, and uses trust information, key verification information and token challenges, which is adapted to the 5G service architecture.

Benefits of technology

It realizes network function network element identification verification and certificate issuance based on ACME process in 5G network, improving the secure interactive adaptability between network function network elements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025078336_04092025_PF_FP_ABST
    Figure CN2025078336_04092025_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and apparatus, used for supporting and adapting to verification of an identifier of a network function network element in an ACME process. The method may comprise the following steps: a network function network element sends an order request, wherein the order request comprises an identifier of the network function network element, and the order request is used for requesting to create an order for issuing a first certificate for the identifier of the network function network element; the network function network element may also receive a challenge message, wherein the challenge message comprises verification mode information which is used for indicating a mode of verifying the identifier of the network function network element in the order; the network function network element may also send a challenge response message on the basis of the verification mode information, wherein the challenge response message comprises the identifier of the network function network element and / or first information obtained on the basis of the identifier of the network function network element, and the identifier of the network function network element and / or the first information is used for verifying the identifier of the network function network element in the order; and the network function network element may also send a certificate request message to obtain the first certificate.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on February 26, 2024, with application number 202410211398.7 and invention name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of mobile communication technologies, and in particular to a communication method and device. Background Art

[0004] The core network of the fifth generation (5G) mobile communication network utilizes network function virtualization (NFV) technology. This technology breaks down the functions of network elements into distinct network functions (NFs) and deploys them in a virtualized form on the network platform, enabling rapid deployment of network functions. To simplify communication and access control between network elements, 5G networks employ a service-based architecture (SBA), through which virtualized network elements interact.

[0005] For network security reasons, interactions between different NFs are based on their authentication certificates. However, the current Automatic Certificate Management Environment (ACME) protocol authentication process is not compatible with the service-oriented architecture of 5G networks and needs improvement. Summary of the Invention

[0006] The present application provides a communication method and apparatus for providing an ACME authentication and certificate issuance mechanism adapted to the 5G service-oriented architecture.

[0007] In a first aspect, a communication method is provided. The method may be implemented by a first communication device. The first communication device may be a network function element (NFE) or a component within the NFE. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The NFE may act as an ACME client to request an ACME server to issue a certificate. The ACME server may be a first authentication device.

[0008] Taking the execution subject as a network function network element as an example, the method can be implemented through the following steps: the network function network element sends an order request, the order request includes the identifier of the network function network element, and the order request is used to request the creation of an order for issuing a first certificate for the identifier of the network function network element; the network function network element can also receive a challenge message, the challenge message includes verification method information, and the verification method information is used to indicate the method for verifying the identifier of the network function network element in the order; the network function network element can also send a challenge response message based on the verification method information, the challenge response message includes the identifier of the network function network element and / or the first information obtained based on the identifier of the network function network element, the identifier of the network function network element and / or the first information are used to verify the identifier of the network function network element in the order; the network function network element can also obtain the first certificate by sending a certificate request message (or certificate request), and the certificate request message is used to complete the order.

[0009] Based on the first aspect, the communication method provided in this application can support and adapt to verifying the identity of the network function element during the order and challenge phases of the ACME process. In addition, the network function element can also obtain a first certificate issued for the identity of the network function element through a certificate request, thereby implementing certificate issuance based on the ACME process.

[0010] In one possible implementation, the network function element may send an order request to the first authentication device and receive a challenge response message sent by the first authentication device. In addition, the network function element may send a certificate request to the first authentication device and obtain a first indication issued by the first authentication device based on the certificate request.

[0011] In one possible implementation, the verification method is to perform the verification based on the trust information of the network function network element, or the verification method is a trust challenge, an initial trust challenge, a pre-configured trust challenge, or a challenge based on initial trust. In this case, the first information may include the trust information; wherein the trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; first signature information obtained by signing the identifier of the network function network element; a first message authentication code obtained based on a symmetric key and the identifier of the network function network element. In other words, when the verification method information indicates that the verification is to be performed based on the trust information of the network function network element, the first information may include the trust information.

[0012] The trust information may be determined, generated, or produced by a second authentication device, and the network function element may obtain the trust information from the second authentication device. The second authentication device may be an operations, administration, and maintenance element / function (OAM) or a network repository function (NRF), without specific limitation. Alternatively, the trust information may be preconfigured in the network function element, and the network function element may obtain the trust information based on the preconfigured information. Accordingly, the first authentication device may perform verification based on the trust information.

[0013] Based on this implementation, the ACME authentication and certificate issuance can be based on the initial trust of the network function element's identity. For example, the trust information can be different from the authentication period of ACME authentication, or it can be understood that obtaining the trust information for the network function element's identity can serve as a prerequisite or guarantee for its successful authentication in the ACME process.

[0014] In one possible implementation, the challenge response message includes the identifier of the network function network element, and the verification method is to perform the verification based on the first key verification information stored in the network repository function network element, or NRF registration challenge, etc., or in other words, the verification method information indication is used to indicate that the verification is performed based on the first key verification information stored in the network repository function network element.

[0015] In one possible implementation, the network function network element may further send a registration request message to the network repository function network element. The registration request message includes an identifier of the network function network element and first key verification information, where the first key verification information is determined based on a public key of an account of the network function network element. The registration request message may be sent before or after the network function network element sends the account request, without specific limitation.

[0016] Based on this implementation, the first authentication device may obtain first key verification information from the network repository function network element according to the identifier of the network function network element, and verify the identifier of the network function network element according to the first key verification information.

[0017] In one possible implementation, the account request further includes information about the network repository function element. Therefore, the network function element can indicate to the first authentication device the network repository function element storing the first key verification information through this information, so that the first authentication device can determine to obtain the first key verification information from this network function element.

[0018] In one possible implementation, the verification method is to perform the verification based on a first token issued by the network repository function network element, or in other words, the challenge method includes a token challenge, and the first information includes the first token. Accordingly, the first authentication device can verify the identity of the network function network element based on the first token carried in the challenge response message.

[0019] In one possible implementation, the first token is obtained based on the private key of the network repository function element. Accordingly, the first authentication device can verify the first token based on the public key of the network repository function element to verify the identity of the network function element.

[0020] In a possible implementation manner, the network function network element may also obtain the first token from the network repository function network element.

[0021] In one possible implementation, the network function network element may send a token request to the network repository function network element, where the token request is used to request the first token and the token request includes an identifier of the network function network element. The network function network element may also receive the first token from the network repository function network element. Therefore, the network function network element may obtain the first token by sending the token request.

[0022] In one possible implementation, the token request also includes information indicating that the token of the network function network element is used for verification of the identity of the network function network element by the first authentication device; and / or, the token request also includes information indicating the public key of the account of the network function network element or the account public key. The information indicating that the token of the network function network element is used for verification of the identity of the network function network element by the first authentication device can also be described as: information indicating that the token of the network function network element is used for token verification or token challenge. The network repository function network element can generate a first token for token challenge based on this information.

[0023] In one possible implementation, the first token may further include information indicating that the token of the network function network element is used by the first authentication device to verify the identity of the network function network element. Accordingly, the first authentication device may perform a token challenge based on the token. And / or, the first token may further include information indicating the public key of the account of the network function network element or the public key of the account. The network repository function sends a token response message to the network function network element, where the token response message includes the first token.

[0024] In one possible implementation, the network function network element may further send at least one of the following information: information indicating that the token of the network function network element is used for the verification; information indicating the public key of the account of the network function network element or the public key of the account. The network repository function network element may determine, based on the information indicating that the token of the network function network element is used for the verification, that the token used for the request of the network function network element's identity is a token used for verification of the network function network element's identity in the ACME process.

[0025] In a possible implementation, the first token further includes: information indicating that the first token is used for the verification; and / or information indicating the public key of the account of the network function network element or the account public key. The information in the first token indicating that the token of the network function network element is used for the verification can be used to determine that the first token is used for the verification of the identity of the network function network element in the ACME process. The information indicating the public key of the account of the network function network element in the first token can be used to prove the account of the public key of the network function network element. The account public key of the network function network element in the first token can be used to prove the account public key of the network function network element.

[0026] In one possible implementation, the challenge response message also includes second signature information obtained based on the private key of the network function element's account. Accordingly, the first authentication device can verify the second signature information based on the public key of the network function element's account, further improving security.

[0027] In one possible implementation, the challenge response message includes the identifier of the network function network element. Accordingly, the first authentication device can issue a first certificate based on the identifier of the network function network element. For example, the first authentication device can determine whether the identifier of the network function network element has been verified. If so, the first certificate can be issued. In addition, the challenge response message can also be a message signed by the account of the network function network element. The first authentication device can also determine the public key of the account corresponding to the identifier of the network function network element based on the identifier of the network function network element in the challenge response message, verify the signature of the challenge response message, and if the verification is successful, the first certificate can be issued.

[0028] In one possible implementation, the challenge response message further includes information indicating the public key of the network function element. The information indicating the public key may be used by the first authentication device to determine the public key of the account of the network function element. For example, the information indicating the public key may include an account public key identifier or an account public key identifier.

[0029] In a second aspect, a communication method is provided. The method may be implemented by a second communication device. The second communication device may be an ACME server or a component within the ACME server. The component herein may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The ACME server may be a first authentication device.

[0030] Taking the execution subject as the first authentication device as an example, the method can be implemented by the following steps:

[0031] The first authentication device receives an order request, which includes an identifier of a network function network element, and the order request is used to request the creation of an order for issuing a first certificate for the identifier of the network function network element; the first authentication device determines a verification method for verifying the identifier of the network function network element based on the identifier of the network function network element; the first authentication device can also send a challenge message, and the challenge message includes verification method information, and the verification method information is used to indicate the verification method; the first authentication device receives a challenge response message corresponding to the verification method information, and the challenge response message includes the identifier of the network function network element and / or first information obtained based on the identifier of the network function network element; the first authentication device can also perform the verification based on the identifier of the network function network element and / or the first information; the first authentication device can also receive a certificate request message, and the certificate request message is used to complete the order, and issue the first certificate if the verification passes.

[0032] In one possible implementation, the verification method is to perform the verification based on the trust information of the network function network element, and the first information includes the trust information; wherein the trust information includes at least one of the following: the second certificate of the network function network element, the second certificate includes the identification of the network function network element; the first signature information obtained by signing the identification of the network function network element; the first message verification code obtained based on the symmetric key and the identification of the network function network element.

[0033] In a possible implementation, the trust information includes the second certificate, and the verification based on the first information includes: obtaining a root certificate of the second certificate; and verifying the second certificate based on the root certificate.

[0034] In a possible implementation, the first authentication device obtains the root certificate of the second certificate in, for example: the root certificate of the second certificate may come from the second authentication device, or may be pre-configured in the first authentication device.

[0035] In one possible implementation, the trust information includes the first signature information, which is obtained by signing the identification of the network function network element based on the private key of the second authentication device. The verification based on the first information includes: obtaining the public key of the second authentication device; and verifying the first signature information based on the public key of the second authentication device.

[0036] In a possible implementation, the first authentication device obtains the public key of the second authentication device in, for example: the public key of the second authentication device may come from the second authentication device, or may be pre-configured in the first authentication device.

[0037] In one possible implementation, the trust information includes the first message verification code, and the verification based on the first information includes: obtaining the symmetric key based on the identifier of the network function network element; obtaining the second message verification code based on the symmetric key and the identifier of the network function network element; and comparing the first message verification code with the second message verification code.

[0038] In a possible implementation, the first authentication device obtains the symmetric key in, for example: the symmetric key may come from the second authentication device, or may be pre-configured in the first authentication device.

[0039] In a possible implementation manner, the challenge response message includes an identifier of the network function network element, and the verification manner is to perform the verification according to first key verification information stored in the network repository function network element.

[0040] In one possible implementation, the first key verification information is determined based on the public key of the account of the network function network element; the verification based on the identifier of the network function network element includes: obtaining the first key verification information from the network repository function network element based on the identifier of the network function network element; and verifying the first key verification information based on the public key of the account of the network function network element.

[0041] In a possible implementation manner, the challenge response message further includes information of the network repository function network element, and the method further includes: determining the network repository function network element according to the information of the network repository function network element.

[0042] In one possible implementation, the verifying the first key verification information based on the public key of the account of the network function network element includes: determining the second key verification information based on the public key of the account of the network function network element; and comparing the second key verification information and the first key verification information.

[0043] In one possible implementation, the network repository function network element is determined based on the identifier of the network function network element or the information of the network repository function network element; and a request message is sent to the determined network repository function network element to request the first key verification information. The request message includes the identifier of the network function network element or indication information, and the indication information is used to instruct the acquisition of the first key verification information. The identifier of the network function network element or the information of the network repository function network element may be carried in a challenge response message.

[0044] In a possible implementation, the first information includes the first token. The verification method at this time may be to verify the network function network element according to the first token issued by the network repository function network element.

[0045] In a possible implementation, the first token is obtained based on a private key of the network repository function network element, and the verification based on the first information includes: verifying the first token based on a public key of the network repository function network element.

[0046] In one possible implementation, the first token may also include one or more of the following information: information indicating that the first token (or the token of the network function network element) is used for the verification; and / or, indication information of the public key of the account of the network function network element or the account public key.

[0047] In a possible implementation, the first token may also be pushed by the network repository function network element to the first authentication device after the first token is generated. Optionally, the network repository function network element may also push the identifier of the network function network element. Accordingly, after receiving the challenge response message, the first authentication device may query the first token corresponding to the identifier of the network function diagram pushed by the network repository function network element based on the identifier of the network function network element carried in the challenge response message, thereby obtaining the first token. The first authentication device may also perform verification based on the first token, and the verification method may refer to the description in this application. In this implementation, the challenge response message may not carry the first token but may carry the identifier of the network function network element, which is used by the first authentication device to determine the first token.

[0048] In addition, the first authentication device may also request the first token from the network repository function network element according to the identifier of the network function network element carried in the challenge response message.

[0049] In one possible implementation, the challenge response message also includes second signature information obtained based on the private key of the account of the network function network element, and the method also includes: obtaining the public key of the network function network element; and verifying the second signature information based on the public key of the account of the network function network element.

[0050] In a possible implementation, after the second signature information is verified and the verification is passed, the method further includes: determining an association relationship between the identifier of the network function network element and the account.

[0051] In a possible implementation manner, the challenge response message further includes indication information of the public key of the network function network element.

[0052] In a possible implementation manner, the certificate request message includes an identifier of the network function network element.

[0053] The beneficial effects of the method shown in the above second aspect and its various possible implementations can refer to the description of the beneficial effects of the method shown in the first aspect and its corresponding implementations, and will not be repeated here.

[0054] In a third aspect, a communication method is provided. The method may be implemented by a first communication device. The first communication device may be a network function element (NFE) or a component within the NFE. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The NFE may act as an ACME client to request an ACME server to issue a certificate. The ACME server may be a first authentication device.

[0055] Taking the execution subject as a network function element as an example, the method can be implemented by the following steps:

[0056] The network function network element sends an account request, where the account request is used to request the creation or update of an account of the network function network element. The account request includes the identifier of the network function network element and / or first information obtained based on the identifier of the network function network element. The identifier of the network function network element and / or the first information are used to verify the identifier of the network function network element; the network function network element receives an account response message, where the account response message is used to indicate that the account creation is complete; the network function network element obtains a first certificate issued for the identifier of the network function network element by sending a certificate request message.

[0057] Based on the third aspect, the communication method provided in this application can support and adapt to verifying the identity of the network function element during the account phase of the ACME process. In addition, the network function element can also obtain a first certificate issued for the identity of the network function element through a certificate request, thereby implementing certificate issuance based on the ACME process.

[0058] In one possible implementation, the network function element may send an account request to the first authentication device and receive an account response message sent by the first authentication device. In addition, the network function element may send a certificate request to the first authentication device and obtain a first indication issued by the first authentication device based on the certificate request.

[0059] In one possible implementation, the first information may include trust information; wherein, the trust information includes at least one of the following: a second certificate of the network function network element, the second certificate including an identification of the network function network element; first signature information obtained by signing the identification of the network function network element; a first message verification code obtained based on a symmetric key and the identification of the network function network element.

[0060] Referring to the description of the first aspect, the network function element may obtain trust information from the second authentication device. The verification method at this time may be to perform the verification based on the trust information of the network function element, or the verification method may be a trust challenge, an initial trust challenge, a pre-configured trust challenge, or a challenge based on initial trust.

[0061] Based on this implementation, the ACME authentication and certificate issuance can be based on the initial trust of the network function element's identity. For example, the trust information can be different from the authentication period of ACME authentication, or it can be understood that obtaining the trust information for the network function element's identity can serve as a prerequisite or guarantee for its successful authentication in the ACME process.

[0062] In a possible implementation, the account request includes the identifier of the network function element. In this case, the verification method is to perform the verification based on the first key verification information stored in the network repository function element, or perform an NRF registration challenge.

[0063] In one possible implementation, the network function network element may further send a registration request message to the network repository function network element. The registration request message includes an identifier of the network function network element and first key verification information, where the first key verification information is determined based on a public key of an account of the network function network element. The registration request message may be sent before or after the network function network element sends the account request, without specific limitation.

[0064] Based on this implementation, the first authentication device may obtain first key verification information from the network repository function network element according to the identifier of the network function network element, and verify the identifier of the network function network element according to the first key verification information.

[0065] In one possible implementation, the account request further includes information about the network repository function element. Therefore, the network function element can indicate to the first authentication device the network repository function element storing the first key verification information through this information, so that the first authentication device can determine to obtain the first key verification information from this network function element.

[0066] In a possible implementation, the first information includes the first token. Accordingly, the first authentication device may verify the identity of the network function network element based on the first token carried in the account request.

[0067] In one possible implementation, the first token is obtained based on the private key of the network repository function element. Accordingly, the first authentication device can verify the first token based on the public key of the network repository function element to verify the identity of the network function element.

[0068] In a possible implementation manner, the network function network element may also obtain the first token from the network repository function network element.

[0069] In one possible implementation, the network function network element may send a token request to the network repository function network element, where the token request is used to request the first token and the token request includes an identifier of the network function network element. The network function network element may also receive the first token from the network repository function network element. Therefore, the network function network element may obtain the first token by sending the token request.

[0070] In one possible implementation, the token request further includes information indicating that the token of the network function network element is used for verification of the identity of the network function network element by the first authentication device; and / or the token request further includes information indicating a public key of an account of the network function network element or an account public key. The network repository function sends a token response message to the network function network element, where the token response message includes the first token.

[0071] In one possible implementation, the network function network element may further send at least one of the following information: information indicating that the token of the network function network element is used for the verification; information indicating the public key of the account of the network function network element or the public key of the account. The network repository function network element may determine, based on the information indicating that the token of the network function network element is used for the verification, that the token used for the request of the network function network element's identity is a token used for verification of the network function network element's identity in the ACME process.

[0072] In a possible implementation, the first token further includes: information indicating that the first token is used for the verification; and / or information indicating the public key of the account of the network function network element or the account public key. The information in the first token indicating that the token of the network function network element is used for the verification can be used to determine that the first token is used for the verification of the identity of the network function network element in the ACME process. The information indicating the public key of the account of the network function network element in the first token can be used to prove the account of the public key of the network function network element. The account public key of the network function network element in the first token can be used to prove the account public key of the network function network element.

[0073] In one possible implementation, the identifier of the network function network element in the account request is carried in an external account binding (EAB) identifier field. The EAB identifier field can be used to carry an identifier or information related to the account requested to be established by the account request. Through the account registration process, the first authentication device can determine, based on the EAB identifier field, that the content carried by the field is associated with the account. Based on this implementation, after account registration, the first authentication device can determine that the identifier of the NF carried in the EAB field is associated with the account.

[0074] In one possible implementation, the account request also includes second signature information obtained based on the private key of the network function element's account. Accordingly, the first authentication device can verify the second signature information based on the public key of the network function element's account, further improving security.

[0075] In one possible implementation, the certificate request includes the identifier of the network function network element. Accordingly, the first authentication device can issue the first certificate based on the identifier of the network function network element. For example, the first authentication device can determine whether the identifier of the network function network element has been verified. If so, the first certificate can be issued. In addition, the certificate request can also be a message signed by the account of the network function network element. The first authentication device can also determine the public key of the account corresponding to the identifier of the network function network element based on the identifier of the network function network element in the certificate request, verify the signature of the certificate request, and if the verification is successful, the first certificate can be issued.

[0076] In one possible implementation, the account request and / or certificate request message also includes information indicating the public key of the network function element. The public key indication information can be used by the first authentication device to determine the public key of the account of the network function element. For example, the public key indication information may include an account public key identifier or an account public key identifier.

[0077] In a fourth aspect, a communication method is provided. The method may be implemented by a second communication device. The second communication device may be an ACME server or a component within the ACME server. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The ACME server may be a first authentication device.

[0078] Taking the execution subject as the first authentication device as an example, the method can be implemented by the following steps:

[0079] The first authentication device receives an account request, wherein the account request is used to request the creation or update of an account for a network function network element, and the account request includes the identifier of the network function network element and / or first information obtained based on the identifier of the network function network element; the first authentication device verifies the identifier of the network function network element based on the identifier of the network function network element and / or the first information. After determining that the verification is successful, the first authentication device sends an account response message to the network function network element, wherein the account response message is used to indicate that the account creation is complete; the first authentication device may also receive a certificate request message, and if the verification is successful, issue a first certificate for the identifier of the network function network element.

[0080] In one possible implementation, the first information may include trust information, and the trust information includes at least one of the following: a second certificate of the network function network element, the second certificate including an identification of the network function network element; first signature information obtained by signing the identification of the network function network element; a first message verification code obtained based on a symmetric key and the identification of the network function network element.

[0081] In a possible implementation, the trust information includes the second certificate, and the verification based on the first information includes: obtaining a root certificate of the second certificate; and verifying the second certificate based on the root certificate.

[0082] In a possible implementation, the first authentication device obtains the root certificate of the second certificate in, for example: the root certificate of the second certificate may come from the second authentication device, or may be pre-configured in the first authentication device.

[0083] In one possible implementation, the trust information includes the first signature information, which is obtained by signing the identification of the network function network element based on the private key of the second authentication device. The verification based on the first information includes: obtaining the public key of the second authentication device; and verifying the first signature information based on the public key of the second authentication device.

[0084] In a possible implementation, the first authentication device obtains the public key of the second authentication device in, for example: the public key of the second authentication device may come from the second authentication device, or may be pre-configured in the first authentication device.

[0085] In one possible implementation, the trust information includes the first message verification code, and the verification based on the first information includes: obtaining the symmetric key based on the identifier of the network function network element; obtaining the second message verification code based on the symmetric key and the identifier of the network function network element; and comparing the first message verification code with the second message verification code.

[0086] In a possible implementation, the first authentication device obtains the symmetric key in, for example: the symmetric key may come from the second authentication device, or may be pre-configured in the first authentication device.

[0087] In a possible implementation, the account request includes the identifier of the network function network element. In this case, the network function network element identifier is verified by performing the verification based on the first key verification information stored in the network repository function network element.

[0088] In one possible implementation, the first key verification information is determined based on the public key of the account of the network function network element; the verification based on the identifier of the network function network element includes: obtaining the first key verification information from the network repository function network element based on the identifier of the network function network element; and verifying the first key verification information based on the public key of the account of the network function network element.

[0089] In a possible implementation manner, the account request further includes information of the network repository function network element, and the method further includes: determining the network repository function network element according to the information of the network repository function network element.

[0090] In one possible implementation, the verifying the first key verification information based on the public key of the account of the network function network element includes: determining the second key verification information based on the public key of the account of the network function network element; and comparing the second key verification information and the first key verification information.

[0091] In one possible implementation, the network repository function network element is determined based on the identifier of the network function network element or the information of the network repository function network element; and a request message is sent to the determined network repository function network element to request the first key verification information. The request message includes the identifier of the network function network element or indication information, and the indication information is used to instruct the acquisition of the first key verification information. The identifier of the network function network element or the information of the network repository function network element may be carried in an account request.

[0092] In a possible implementation manner, the first information includes the first token.

[0093] In a possible implementation, the first token is obtained based on a private key of the network repository function network element, and the verification based on the first information includes: verifying the first token based on a public key of the network repository function network element.

[0094] In one possible implementation, the first token may also include one or more of the following information: information indicating that the first token is used for the verification; and / or, indication information of the public key of the account of the network function network element or the account public key.

[0095] In a possible implementation, the first token may also be pushed by the network repository function network element to the first authentication device after the first token is generated. Optionally, the network repository function network element may also push the identifier of the network function network element. Accordingly, after receiving the challenge response message, the first authentication device may query the first token corresponding to the identifier of the network function diagram pushed by the network repository function network element based on the identifier of the network function network element carried in the certificate request, thereby obtaining the first token. The first authentication device may also perform verification based on the first token, and the verification method may refer to the description in this application. In this implementation, the certificate request may not carry the first token but may carry the identifier of the network function network element, which is used by the first authentication device to determine the first token.

[0096] In addition, the first authentication device may also request the first token from the network repository function network element according to the identifier of the network function network element carried in the certificate request.

[0097] In a possible implementation manner, the identifier of the network function network element in the account request is carried in an external account binding identifier field.

[0098] In a possible implementation, the account request further includes second signature information obtained according to a private key of the account of the network function network element. The first authentication device may verify the second signature information according to a public key of the account of the network function network element.

[0099] In a possible implementation, after the second signature information is verified and the verification is passed, the method further includes: determining an association relationship between the identifier of the network function network element and the account.

[0100] In a possible implementation manner, the certificate request message includes an identifier of the network function network element.

[0101] In a possible implementation manner, the account request and / or certificate request message further includes indication information of the public key of the network function network element.

[0102] The beneficial effects of the fourth aspect and its various possible implementations can be found in the description of the beneficial effects in the third aspect and its corresponding implementations, and will not be repeated here.

[0103] In a fifth aspect, a communication method is provided. The method may be implemented by a first communication device. The first communication device may be a network function element or a component within the network function element. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The network function element may act as an ACME client to request an ACME server to issue a certificate. The ACME server may be a first authentication device.

[0104] Taking the execution subject as a network function element as an example, the method can be implemented by the following steps:

[0105] The network function network element receives an account response message, wherein the account response message is used to indicate that the account creation or update is completed, and the account response message includes indication information of the account; the network function network element sends a pre-authorization request, wherein the pre-authorization request includes indication information of the account of the network function network element, and the pre-authorization request also includes an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, and the pre-authorization request is used to request pre-authorization of the account and to request verification of the identifier of the network function network element; the network function network element receives a pre-authorization response message, wherein the pre-authorization response message is used to indicate that the pre-authorization of the account is completed and that the verification is passed; the network function network element obtains a first certificate issued for the identifier of the network function network element by sending a certificate request.

[0106] Based on the fifth aspect, the communication method provided in this application can support and adapt to verifying the identity of the network function network element during the pre-authorization phase of the ACME process. In addition, the network function network element can also obtain a first certificate issued for the identity of the network function network element through a certificate request, thereby implementing certificate issuance based on the ACME process.

[0107] In one possible implementation, the first information may include trust information; wherein, the trust information includes at least one of the following: a second certificate of the network function network element, the second certificate including an identification of the network function network element; first signature information obtained by signing the identification of the network function network element; a first message verification code obtained based on a symmetric key and the identification of the network function network element.

[0108] Referring to the description of the first aspect, the network function element may obtain trust information from the second authentication device. The verification method at this time may be to perform the verification based on the trust information of the network function element, or the verification method may be a trust challenge, an initial trust challenge, a pre-configured trust challenge, or a challenge based on initial trust.

[0109] Based on this implementation, the ACME authentication and certificate issuance can be based on the initial trust of the network function element's identity. For example, the trust information can be different from the authentication period of ACME authentication, or it can be understood that obtaining the trust information for the network function element's identity can serve as a prerequisite or guarantee for its successful authentication in the ACME process.

[0110] In a possible implementation, the pre-authorization request includes an identifier of the network function element. In this case, the verification method is to perform the verification based on the first key verification information stored in the network repository function element, or perform an NRF registration challenge.

[0111] In one possible implementation, the network function network element may further send a registration request message to the network repository function network element, where the registration request message includes an identifier of the network function network element and first key verification information, where the first key verification information is determined based on a public key of an account of the network function network element. The registration request message may be sent before or after the network function network element sends the pre-authorization request, without specific limitation.

[0112] Based on this implementation, the first authentication device may obtain first key verification information from the network repository function network element according to the identifier of the network function network element, and verify the identifier of the network function network element according to the first key verification information.

[0113] In one possible implementation, the pre-authorization request further includes information about the network repository function element. Therefore, the network function element can indicate to the first authentication device the network repository function element storing the first key verification information through this information, so that the first authentication device can determine to obtain the first key verification information from this network function element.

[0114] In a possible implementation, the first information includes the first token. Accordingly, the first authentication device may verify the identifier of the network function network element based on the first token carried in the pre-authorization request.

[0115] In one possible implementation, the first token is obtained based on the private key of the network repository function element. Accordingly, the first authentication device can verify the first token based on the public key of the network repository function element to verify the identity of the network function element.

[0116] In a possible implementation manner, the network function network element may also obtain the first token from the network repository function network element.

[0117] In one possible implementation, the network function network element may send a token request to the network repository function network element, where the token request is used to request the first token and the token request includes an identifier of the network function network element. The network function network element may also receive the first token from the network repository function network element. Therefore, the network function network element may obtain the first token by sending the token request.

[0118] In one possible implementation, the token request further includes information indicating that the token of the network function network element is used for verification of the identity of the network function network element by the first authentication device; and / or the token request further includes information indicating the public key of the account of the network function network element. The network repository function sends a token response message to the network function network element, where the token response message includes the first token.

[0119] In one possible implementation, the network function network element may further send at least one of the following information: information indicating that the token of the network function network element is used for the verification; and information indicating the public key of the account of the network function network element. The network repository function network element may determine, based on the information indicating that the token of the network function network element is used for the verification, that the token used for the request of the network function network element's identity is a token used for verification of the network function network element's identity in the ACME process.

[0120] In one possible implementation, the first token further includes: information indicating that the first token is used for the verification; and / or information indicating the public key of the account of the network function network element. The information in the first token indicating that the token of the network function network element is used for the verification can be used to determine that the first token is used for verification of the identity of the network function network element in the ACME process. The information indicating the public key of the account of the network function network element in the first token can be used to prove the account of the public key of the network function network element.

[0121] In one possible implementation, the pre-authorization request also includes second signature information obtained based on the private key of the network function network element's account. Accordingly, the first authentication device can verify the second signature information based on the public key of the network function network element's account, further improving security.

[0122] In one possible implementation, the certificate request includes the identifier of the network function network element. Accordingly, the first authentication device can issue the first certificate based on the identifier of the network function network element. For example, the first authentication device can determine whether the identifier of the network function network element has been verified. If so, the first certificate can be issued. In addition, the certificate request can also be a message signed by the account of the network function network element. The first authentication device can also determine the public key of the account corresponding to the identifier of the network function network element based on the identifier of the network function network element in the certificate request, verify the signature of the certificate request, and if the verification is successful, the first certificate can be issued.

[0123] In one possible implementation, the certificate request also includes information indicating the public key of the network function element. The public key indication information can be used by the first authentication device to determine the public key of the account of the network function element. For example, the public key indication information may include an account public key identifier or an account public key identifier.

[0124] In a sixth aspect, a communication method is provided. The method may be implemented by a second communication device. The second communication device may be an ACME server or a component within the ACME server. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The ACME server may be a first authentication device.

[0125] Taking the execution subject as the first authentication device as an example, the method can be implemented by the following steps:

[0126] The first authentication device sends an account response message, the account response message indicating that the account creation or update is complete, the account response message including indication information of the account; the first authentication device receives a pre-authorization request, the pre-authorization request including indication information of the account of the network function network element, the pre-authorization request also including an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, the pre-authorization request requesting pre-authorization of the account and requesting verification of the identifier of the network function network element; the first authentication device verifies the identifier of the network function network element based on the identifier of the network function network element and / or the first information; if the verification is successful, the first authentication device sends a pre-authorization response message indicating that pre-authorization of the account is complete; and / or the first authentication device may further receive a certificate request message and, if the verification is successful, issue a first certificate for the identifier of the network function network element. The first authentication device may send the pre-authorization response message without requiring that the network function network element's identifier be verified successfully.

[0127] In one possible implementation, the first information may include trust information, and the trust information includes at least one of the following: a second certificate of the network function network element, the second certificate including an identification of the network function network element; first signature information obtained by signing the identification of the network function network element; a first message verification code obtained based on a symmetric key and the identification of the network function network element.

[0128] In a possible implementation, the trust information includes the second certificate, and the verification based on the first information includes: obtaining a root certificate of the second certificate; and verifying the second certificate based on the root certificate.

[0129] In a possible implementation, the first authentication device obtains the root certificate of the second certificate in, for example: the root certificate of the second certificate may come from the second authentication device, or may be pre-configured in the first authentication device.

[0130] In one possible implementation, the trust information includes the first signature information, which is obtained by signing the identification of the network function network element based on the private key of the second authentication device. The verification based on the first information includes: obtaining the public key of the second authentication device; and verifying the first signature information based on the public key of the second authentication device.

[0131] In a possible implementation, the first authentication device obtains the public key of the second authentication device in, for example: the public key of the second authentication device may come from the second authentication device, or may be pre-configured in the first authentication device.

[0132] In one possible implementation, the trust information includes the first message verification code, and the verification based on the first information includes: obtaining the symmetric key based on the identifier of the network function network element; obtaining the second message verification code based on the symmetric key and the identifier of the network function network element; and comparing the first message verification code with the second message verification code.

[0133] In a possible implementation, the first authentication device obtains the symmetric key in, for example: the symmetric key may come from the second authentication device, or may be pre-configured in the first authentication device.

[0134] In a possible implementation, the pre-authorization request includes the identifier of the network function network element. In this case, the network function network element identifier is verified by performing the verification based on the first key verification information stored in the network repository function network element.

[0135] In one possible implementation, the first key verification information is determined based on the public key of the account of the network function network element; the verification based on the identifier of the network function network element includes: obtaining the first key verification information from the network repository function network element based on the identifier of the network function network element; and verifying the first key verification information based on the public key of the account of the network function network element.

[0136] In a possible implementation manner, the pre-authorization request further includes information of the network repository function network element, and the method further includes: determining the network repository function network element according to the information of the network repository function network element.

[0137] In one possible implementation, the verifying the first key verification information based on the public key of the account of the network function network element includes: determining the second key verification information based on the public key of the account of the network function network element; and comparing the second key verification information and the first key verification information.

[0138] In one possible implementation, the network repository function network element is determined based on the identifier of the network function network element or the information of the network repository function network element; and a request message is sent to the determined network repository function network element to request the first key verification information. The request message includes the identifier of the network function network element or indication information, and the indication information is used to instruct the acquisition of the first key verification information. The identifier of the network function network element or the information of the network repository function network element may be carried in a pre-authorization request.

[0139] In a possible implementation manner, the first information includes the first token.

[0140] In a possible implementation, the first token is obtained based on a private key of the network repository function network element, and the verification based on the first information includes: verifying the first token based on a public key of the network repository function network element.

[0141] In a possible implementation, the first token may also include one or more of the following information: information indicating that the first token is used for the verification; and / or information indicating the public key of the account of the network function network element.

[0142] In a possible implementation, the first token may also be pushed by the network repository function network element to the first authentication device after the first token is generated. Optionally, the network repository function network element may also push the identifier of the network function network element. Accordingly, after receiving the challenge response message, the first authentication device may query the first token corresponding to the identifier of the network function diagram pushed by the network repository function network element based on the identifier of the network function network element carried in the certificate request, thereby obtaining the first token. The first authentication device may also perform verification based on the first token, and the verification method may refer to the description in this application. In this implementation, the certificate request may not carry the first token but may carry the identifier of the network function network element, which is used by the first authentication device to determine the first token.

[0143] In addition, the first authentication device may also request the first token from the network repository function network element according to the identifier of the network function network element carried in the certificate request.

[0144] In a possible implementation, the pre-authorization request further includes second signature information obtained based on a private key of the account of the network function network element. The first authentication device may verify the second signature information based on a public key of the account of the network function network element.

[0145] In a possible implementation, after the second signature information is verified and the verification is passed, the method further includes: determining an association relationship between the identifier of the network function network element and the account.

[0146] In a possible implementation manner, the certificate request includes an identifier of the network function network element.

[0147] In a possible implementation manner, the certificate request further includes indication information of the public key of the network function network element.

[0148] The beneficial effects of the sixth aspect and its various possible implementations can be found in the description of the beneficial effects in the third aspect and its corresponding implementations, and will not be repeated here.

[0149] In a seventh aspect, a communication method is provided. The method may be implemented by a first communication device. The first communication device may be a network function element or a component within the network function element. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The network function element may act as an ACME client to request an ACME server to issue a certificate. The ACME server may be a first authentication device.

[0150] Taking the execution subject as a network function element as an example, the method can be implemented by the following steps:

[0151] The network function network element sends a challenge response message, and the challenge response message is used to instruct the first authentication device to perform a first verification on the domain name or IP address of the network function network element; the network function network element sends a certificate request, and the certificate request includes the identifier of the network function network element and / or the first information obtained based on the identifier of the network function network element, and the certificate request is used to request the first certificate corresponding to the identifier of the network function network element; the identifier of the network function network element and / or the first information are used by the first authentication device to perform a second verification on the identifier of the network function network element; the network function network element obtains the first certificate, and the first certificate is issued by the first authentication device after determining that the second verification is passed.

[0152] Among them, the first verification can be a verification based on the domain name or IP address of the network function network element. The second verification can be a verification based on the identifier of the network function network element and / or the first information. Based on the method shown in the seventh aspect, a first certificate can be issued after the first verification and the second verification to support and adapt to the verification of the identifier of the network function network element in the certificate issuance phase in the ACME process. In addition, the network function network element can also obtain the first certificate issued for the identifier of the network function network element through a certificate request, thereby realizing the certificate issuance based on the ACME process.

[0153] In one possible implementation, the first information may include the trust information; wherein, the trust information includes at least one of the following: a second certificate of the network function network element, the second certificate including the identification of the network function network element; first signature information obtained by signing the identification of the network function network element; a first message verification code obtained based on a symmetric key and the identification of the network function network element.

[0154] Referring to the description of the first aspect, the network function element may obtain trust information from the second authentication device. In this case, the second verification may be performed based on the trust information of the network function element, or the verification method may be a trust challenge, an initial trust challenge, a pre-configured trust challenge, or a challenge based on initial trust.

[0155] Based on this implementation, the second verification can be performed based on the initial trust of the network function element's identity. For example, the trust information can be different from the authentication period of ACME authentication, or it can be understood that obtaining the trust information for the network function element's identity can serve as a prerequisite or guarantee for its authentication in the ACME process.

[0156] In a possible implementation, the certificate request includes an identifier of the network function network element. In this case, the verification method is to perform the verification based on the first key verification information stored in the network repository function network element, or perform an NRF registration challenge.

[0157] In one possible implementation, the network function network element may further send a registration request message to the network repository function network element, where the registration request message includes an identifier of the network function network element and first key verification information, where the first key verification information is determined based on the public key of the account of the network function network element. The registration request message may be sent before or after the network function network element sends the certificate request, without specific limitation.

[0158] Based on this implementation, the first authentication device may obtain first key verification information from the network repository function network element according to the identifier of the network function network element, and verify the identifier of the network function network element according to the first key verification information.

[0159] In one possible implementation, the certificate request further includes information about the network repository function element. Therefore, the network function element can indicate to the first authentication device the network repository function element storing the first key verification information through this information, so that the first authentication device can determine to obtain the first key verification information from this network function element.

[0160] In a possible implementation, the first information includes the first token. Accordingly, the first authentication device may verify the identity of the network function network element based on the first token carried in the certificate request.

[0161] In one possible implementation, the first token is obtained based on the private key of the network repository function element. Accordingly, the first authentication device can verify the first token based on the public key of the network repository function element to verify the identity of the network function element.

[0162] In a possible implementation manner, the network function network element may also obtain the first token from the network repository function network element.

[0163] In one possible implementation, the network function network element may send a token request to the network repository function network element, where the token request is used to request the first token and the token request includes an identifier of the network function network element. The network function network element may also receive the first token from the network repository function network element. Therefore, the network function network element may obtain the first token by sending the token request.

[0164] In one possible implementation, the token request also includes information indicating that the token of the network function network element is used for verification of the identity of the network function network element by the first authentication device; and / or, the token request also includes indication information of the public key of the account of the network function network element or the account public key. The first token also includes information indicating that the token of the network function network element is used for verification of the identity of the network function network element by the first authentication device, and / or, indication information of the public key of the account of the network function network element or the account public key. The network repository function sends a token response message to the network function network element, and the token response message includes the first token.

[0165] In one possible implementation, the network function network element may further send at least one of the following information: information indicating that the token of the network function network element is used for the verification; information indicating the public key of the account of the network function network element or the public key of the account. The network repository function network element may determine, based on the information indicating that the token of the network function network element is used for the verification, that the token used for the request of the network function network element's identity is a token used for verification of the network function network element's identity in the ACME process.

[0166] In a possible implementation, the first token further includes: information indicating that the first token is used for the verification; and / or information indicating the public key of the account of the network function network element or the account public key. The information in the first token indicating that the token of the network function network element is used for the verification can be used to determine that the first token is used for the verification of the identity of the network function network element in the ACME process. The information indicating the public key of the account of the network function network element in the first token can be used to prove the account of the public key of the network function network element. The account public key of the network function network element in the first token can be used to prove the account public key of the network function network element.

[0167] In one possible implementation, the certificate request also includes second signature information obtained based on the private key of the network function network element's account. Accordingly, the first authentication device can verify the second signature information based on the public key of the network function network element's account, further improving security.

[0168] In one possible implementation, the certificate request also includes the domain name or IP address of the network function network element, and the domain name or IP address of the network function network element is used to perform a third verification on the identifier of the network function network element. If the third verification passes, the first certificate can be issued, thereby further improving the authentication security. Among them, the first authentication device can store the first association relationship after determining that the first verification passes. The first association relationship may include the association relationship between the account information of the NF and the domain name (or IP address) of the NF. In addition, the first authentication device can store the second association relationship after determining that the second verification passes, and the second association relationship may include the association relationship between the identifier of the NF and the account that sent the certificate request.

[0169] As an example of the third verification, the first authentication device can determine the account associated with the NF's identifier based on the second association relationship (referred to as the first account), which can be the account that sends the certificate request. In addition, the first authentication device determines the account associated with the NF's domain name or IP address (referred to as the second account) based on the NF's domain name or IP address in the certificate request message and the first association relationship. If the first account is the same as the second account (i.e., the public key of the account or the public key identifier of the account is the same), it can be determined that the NF's identifier and the NF's domain name or IP address associated with the same account have an association relationship, i.e., a third association relationship. The third association relationship can be an association relationship between the NF's domain name or IP address and the NF's identifier. The first authentication device can perform a third verification based on the third association relationship, i.e., compare the NF's domain name or IP address and the NF's identifier in the third association relationship with the NF's domain name or IP address and the NF's identifier in the certificate request message. If they are the same, it can be determined that the third verification is passed; otherwise, if they are not the same, it can be determined that the third verification is failed.

[0170] In an eighth aspect, a communication method is provided. The method may be implemented by a second communication device. The second communication device may be an ACME server or a component within the ACME server. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The ACME server may be a first authentication device.

[0171] Taking the execution subject as the first authentication device as an example, the method can be implemented through the following steps: the first authentication device performs a first verification on the domain name or IP address of the network function network element; the first authentication device receives a certificate request, and the certificate request includes the identifier of the network function network element and / or the first information obtained based on the identifier of the network function network element, and the certificate request is used to request the first certificate corresponding to the identifier of the network function network element; after determining that the first verification is passed, the first authentication device performs a second verification on the identifier of the network function network element based on the identifier of the network function network element and / or the first information; after determining that the second verification is passed, the first authentication device issues the first certificate for the identifier of the network function network element.

[0172] In one possible implementation, the first information may include trust information, and the trust information includes at least one of the following: a second certificate of the network function network element, the second certificate including an identification of the network function network element; first signature information obtained by signing the identification of the network function network element; a first message verification code obtained based on a symmetric key and the identification of the network function network element.

[0173] In a possible implementation, the trust information includes the second certificate, and performing the second verification based on the first information includes: obtaining a root certificate of the second certificate; and verifying the second certificate based on the root certificate.

[0174] In a possible implementation, the first authentication device obtains the root certificate of the second certificate in, for example: the root certificate of the second certificate may come from the second authentication device, or may be pre-configured in the first authentication device.

[0175] In one possible implementation, the trust information includes the first signature information, which is obtained by signing the identification of the network function network element based on the private key of the second authentication device. The second verification based on the first information includes: obtaining the public key of the second authentication device; and verifying the first signature information based on the public key of the second authentication device.

[0176] In a possible implementation, the first authentication device obtains the public key of the second authentication device in, for example: the public key of the second authentication device may come from the second authentication device, or may be pre-configured in the first authentication device.

[0177] In one possible implementation, the trust information includes the first message verification code, and the second verification based on the first information includes: obtaining the symmetric key based on the identifier of the network function network element; obtaining the second message verification code based on the symmetric key and the identifier of the network function network element; and comparing the first message verification code with the second message verification code.

[0178] In a possible implementation, the first authentication device obtains the symmetric key in, for example: the symmetric key may come from the second authentication device, or may be pre-configured in the first authentication device.

[0179] In a possible implementation, the certificate request includes an identifier of the network function network element. In this case, the second verification method is to perform the verification based on the first key verification information stored in the network repository function network element.

[0180] In one possible implementation, the first key verification information is determined based on the public key of the account of the network function network element; the second verification is performed based on the identifier of the network function network element, including: obtaining the first key verification information from the network repository function network element based on the identifier of the network function network element; and verifying the first key verification information based on the public key of the account of the network function network element.

[0181] In a possible implementation manner, the certificate request further includes information of the network repository function network element, and the method further includes: determining the network repository function network element according to the information of the network repository function network element.

[0182] In one possible implementation, the verifying the first key verification information based on the public key of the account of the network function network element includes: determining the second key verification information based on the public key of the account of the network function network element; and comparing the second key verification information and the first key verification information.

[0183] In one possible implementation, the network repository function network element is determined based on the identifier of the network function network element or the information of the network repository function network element; and a request message is sent to the determined network repository function network element to request the first key verification information. The request message includes the identifier of the network function network element or indication information, and the indication information is used to instruct the acquisition of the first key verification information. The identifier of the network function network element or the information of the network repository function network element may be carried in a certificate request.

[0184] In a possible implementation, the first information includes the first token. In this case, the second verification is performed based on a token issued by a network repository function network element.

[0185] In one possible implementation, the first token is obtained based on the private key of the network repository function network element, and the second verification based on the first information includes: verifying the first token based on the public key of the network repository function network element.

[0186] In a possible implementation, the first token may also include one or more of the following information: information indicating that the first token is used for the verification; and / or information indicating the public key of the account of the network function network element.

[0187] In a possible implementation, the first token may also be pushed by the network repository function network element to the first authentication device after the first token is generated. Optionally, the network repository function network element may also push the identifier of the network function network element. Accordingly, after receiving the challenge response message, the first authentication device may query the first token corresponding to the identifier of the network function diagram pushed by the network repository function network element based on the identifier of the network function network element carried in the certificate request, thereby obtaining the first token. The first authentication device may also perform verification based on the first token, and the verification method may refer to the description in this application. In this implementation, the certificate request may not carry the first token but may carry the identifier of the network function network element, which is used by the first authentication device to determine the first token.

[0188] In addition, the first authentication device may also request the first token from the network repository function network element according to the identifier of the network function network element carried in the certificate request.

[0189] In one possible implementation, the certificate request includes the domain name or IP address of the network function network element. Before the first authentication device issues the first certificate, the method also includes: the first authentication device performs a third verification on the identifier of the network function network element based on the domain name or IP address of the network function network element.

[0190] Among them, the first authentication device can store the first association relationship between the domain name or IP address of the network function network element and the account of the network function network element after determining that the first verification is passed; and store the second association relationship between the identifier of the network function network element and the account of the network function network element after determining that the second verification is passed; the method also includes: the first authentication device determines the first account corresponding to the identifier of the network function network element in the certificate request based on the second association relationship; the first authentication device determines the domain name (or IP address) of the network function network element in the certificate request based on the first association relationship, and determines the corresponding second account based on the domain name or IP address; and determines that the first account is the same as the second account. The first authentication device can then determine that there is a third association relationship between the identifier of the NF associated with the same account and the domain name (or IP address) of the NF. The first authentication device performs a third verification on the identifier of the network function network element based on the domain name or IP address of the network function network element, including: comparing the domain name or IP address of the NF and the identifier of the NF in the third association relationship with the domain name or IP address of the NF and the identifier of the NF in the certificate request message. If they are the same, it can be determined that the third verification is passed; otherwise, if they are not the same, it can be determined that the third verification is failed.

[0191] The beneficial effects of the eighth aspect and its various possible implementations can be found in the description of the beneficial effects in the third aspect and its corresponding implementations, and will not be repeated here.

[0192] In a ninth aspect, a communication method is provided. The method may be implemented by a third communication device. The third communication device may be a network repository function network element, a component in the network repository function network element, or another network element, device, or component that supports network element registration. The components in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit.

[0193] Taking the execution subject as a network repository function network element as an example, the method can be implemented by the following steps:

[0194] In one possible implementation, the network repository function network element may further receive a registration request message from the network function network element, the registration request message including an identifier of the network function network element and first key verification information; the network repository function network element sends the first key verification information to the first authentication device. The network repository function network element may further determine, based on the identifier of the network function network element, to send the first key verification information to the first authentication device.

[0195] In one possible implementation, the network repository function network element may receive a request message sent by the first authentication device, the request message being used to request first key verification information. The request message includes an identifier of the network function network element, the identifier of the network function network element being used to determine the first key verification information of the network function network element. The indication information is used to indicate a request to obtain key verification information used to verify the identifier of the network function network element, i.e., the first key verification information.

[0196] In one possible implementation, the network repository function element sends the first key verification information to the first authentication device, including: the network repository function element obtains the first key verification information based on an identifier of the network function element, and pushes the first key information to the first authentication device if a push condition for the key verification information is met. The push condition for the key verification information includes, for example: the first authentication device subscribes to a push service for verification information, a registration request message from the network function element includes the identifier of the network function element, instruction information for instructing push, push is determined based on local configuration, or push is performed to the first authentication device by default after the key verification information is generated.

[0197] In a tenth aspect, a communication method is provided. The method may be implemented by a third communication device. The third communication device may be a network repository function network element, a component in the network repository function network element, or another network element, device, or component that supports network element registration. The components in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit.

[0198] Taking the execution subject as a network repository function network element as an example, the method can be implemented by the following steps:

[0199] The network repository function element may push the first token to the first authentication device after generating the first token according to the token request from the network function element. The first token may refer to the description in the first aspect.

[0200] Among them, the network repository function network element can push the first token to the first authentication device if the push conditions of the token are met. The token push conditions include, for example: a) the first authentication device subscribes to or orders the push service of the network function network element's token from the token provider. b) The network repository function network element is configured to push the token to the first authentication device after generating a token (including but not limited to the first token) for identifying the network function network element. c) The token request contains indication information, which instructs the network repository function network element to push the first token to the first authentication device. Accordingly, the first authentication device can also verify the identification of the network function network element based on the first token. The verification method can refer to the description in this application.

[0201] In one possible implementation, the network repository function network element may also obtain at least one of the following information from the network function network element: information indicating that the token of the network function network element is used for the verification; indication information of the public key of the account of the network function network element or the account public key.

[0202] In one possible implementation, the first token generated by the network repository function network element may include at least one of the following information: information indicating that the token of the network function network element is used for the verification; indication information of the public key of the account of the network function network element or the account public key.

[0203] In one possible implementation, the network repository function element may also push the identifier of the network function element. Accordingly, after receiving a challenge response message, account request, pre-authorization request, or certificate request carrying the identifier of the network function element, the first authentication device may query the first token corresponding to the identifier of the network function graph pushed by the network repository function element based on the identifier of the network function element carried in the challenge response message, account request, pre-authorization request, or certificate request, thereby obtaining the first token. In this implementation, the challenge response message, account request, pre-authorization request, or certificate request may not carry the first token but may carry the identifier of the network function element, which is used by the first authentication device to determine the first token.

[0204] In addition, the first authentication device may also request the first token from the network repository function network element according to the identifier of the network function network element carried in the challenge response message, account request, pre-authorization request or certificate request.

[0205] In an eleventh aspect, a communication device is provided. The device can implement the method described in any possible implementation of any of the first to tenth aspects. The device has the functions of the first, second, or third communication devices described above. The device is, for example, a terminal device, a functional module in a terminal device, a network device, or a functional module in a network device.

[0206] In an optional implementation, the device may include a module corresponding to the method / operation / step / action described in any possible implementation of any aspect from the first to the tenth aspect, and the module may be a hardware circuit, or software, or a hardware circuit combined with software. In an optional implementation, the device includes a processing unit (sometimes also referred to as a processing module) and a communication unit (sometimes also referred to as a transceiver module, a communication module, etc.). The transceiver unit can implement a sending function and a receiving function. When the transceiver unit implements the sending function, it can be called a sending unit (sometimes also referred to as a sending module). When the transceiver unit implements the receiving function, it can be called a receiving unit (sometimes also referred to as a receiving module). The sending unit and the receiving unit can be the same functional module, which is called a transceiver unit, and the functional module can implement a sending function and a receiving function; or, the sending unit and the receiving unit can be different functional modules, and the transceiver unit is a general term for these functional modules.

[0207] Exemplarily, when the apparatus is used to execute the method described in any one of the first to tenth aspects, the apparatus may include a communication unit and a processing unit.

[0208] In the twelfth aspect, an embodiment of the present application also provides a communication device, comprising a processor for executing a computer program (or computer executable instructions) stored in a memory. When the computer program (or computer executable instructions) is executed, the device executes the method described in any possible implementation of any aspect from the first to the tenth aspect.

[0209] In one possible implementation, the processor and memory are integrated;

[0210] In another possible implementation, the memory is located outside the communication device.

[0211] The communication device also includes a communication interface, which is used for the communication device to communicate with other devices, such as sending or receiving data and / or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module or other type of communication interface.

[0212] In the thirteenth aspect, a computer-readable storage medium is provided, which is used to store computer programs or instructions. When the computer-readable storage medium is executed, the method described in any possible implementation of any aspect from the first to the tenth aspect and the method shown in any possible implementation thereof are implemented.

[0213] In a fourteenth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the method described in any possible implementation of any one of the first to tenth aspects to be implemented.

[0214] In a fifteenth aspect, an embodiment of the present application further provides a communication device for executing the method described in any possible implementation of any one of the first to tenth aspects above.

[0215] In the sixteenth aspect, a chip system is provided, which includes a logic circuit (or it can be understood that the chip system includes a processor, and the processor may include a logic circuit, etc.), and may also include an input and output interface. The input and output interface can be used to input messages and can also be used to output messages. The input and output interfaces can be the same interface, that is, the same interface can implement both the sending function and the receiving function; or, the input and output interfaces include an input interface and an output interface, the input interface is used to implement the receiving function, that is, for receiving messages; the output interface is used to implement the sending function, that is, for sending messages. The logic circuit can be used to perform the operations other than the sending and receiving functions in the method described in any possible implementation of any one of the first to tenth aspects above; the logic circuit can also be used to transmit messages to the input and output interface, or receive messages from other communication devices from the input and output interface. The chip system can be used to implement the method described in any possible implementation of any one of the first to tenth aspects above. The chip system can be composed of a chip, or it can include a chip and other discrete devices.

[0216] Optionally, the chip system may further include a memory, which may be used to store instructions, and the logic circuit may call the instructions stored in the memory to implement corresponding functions.

[0217] In the seventeenth aspect, a communication method is provided, which may include the method implemented by the first communication device as shown in the first aspect and any possible implementation thereof, and the method implemented by the second communication device as shown in the second aspect and any possible implementation thereof. The communication method may include the method implemented by the first communication device as shown in the third aspect and any possible implementation thereof, and the method implemented by the second communication device as shown in the fourth aspect and any possible implementation thereof. The communication method may include the method implemented by the first communication device as shown in the fifth aspect and any possible implementation thereof, and the method implemented by the second communication device as shown in the sixth aspect and any possible implementation thereof. The communication method may include the method implemented by the first communication device as shown in the seventh aspect and any possible implementation thereof, and the method implemented by the second communication device as shown in the eighth aspect and any possible implementation thereof. Any of the above communication methods may also include the method implemented by the third communication device as shown in the ninth aspect and any possible implementation thereof, and / or the method implemented by the third communication device as shown in the tenth aspect and any possible implementation thereof.

[0218] In the eighteenth aspect, a communication system is provided, which may include a first communication device and a second communication device. The first communication device may be used to implement the method shown in the first aspect and any possible implementation thereof, and the second communication device may be used to implement the method shown in the second aspect and any possible implementation thereof. Alternatively, the first communication device may be used to implement the method shown in the third aspect and any possible implementation thereof, and the second communication device may be used to implement the method shown in the fourth aspect and any possible implementation thereof. Alternatively, the first communication device may be used to implement the method shown in the fifth aspect and any possible implementation thereof, and the second communication device may be used to implement the method shown in the sixth aspect and any possible implementation thereof. Alternatively, the first communication device may be used to implement the method shown in the seventh aspect and any possible implementation thereof, and the second communication device may be used to implement the method shown in the eighth aspect and any possible implementation thereof. The communication system may also include a third communication device for implementing the method shown in the ninth aspect and / or the tenth aspect and any possible implementation thereof.

[0219] The technical effects brought about by the above-mentioned eleventh to eighteenth aspects can be found in the description of the beneficial effects of the corresponding schemes in the above-mentioned first to tenth aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0220] FIG1 is a schematic diagram of a 5G network service-oriented architecture;

[0221] FIG2 is a flow chart of a communication method provided in an embodiment of the present application;

[0222] FIG3 is a flow chart of another communication method provided in an embodiment of the present application;

[0223] FIG4 is a flow chart of another communication method provided in an embodiment of the present application;

[0224] FIG5 is a flow chart of another communication method provided in an embodiment of the present application;

[0225] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;

[0226] FIG7 is a flow chart of another communication method provided in an embodiment of the present application;

[0227] FIG8 is a flow chart of another communication method provided in an embodiment of the present application;

[0228] FIG9 is a flow chart of another communication method provided in an embodiment of the present application;

[0229] FIG10 is a flow chart of another communication method provided in an embodiment of the present application;

[0230] FIG11 is a flow chart of another communication method provided in an embodiment of the present application;

[0231] FIG12 is a flow chart of another communication method provided in an embodiment of the present application;

[0232] FIG13 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0233] FIG14 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0234] The present application provides a communication method and apparatus. The method and apparatus are based on the same inventive concept. Since the method and apparatus solve similar problems, the implementation of the apparatus and method can refer to each other, and the repetitive parts will not be repeated.

[0235] To enhance the flexibility and agility of network deployment, NFV technology is used in the core network of mobile networks to subdivide the functions of network elements into different network functions. These functions are deployed in a virtualized form on the network platform, enabling rapid deployment of network functions. To simplify communication and access control between network elements, a service-based architecture is being adopted in 5G networks. Different network elements in a service-based architecture can interact with each other based on a service-based interface (SBI). For example, based on the SBI, network elements can use Hypertext Transfer Protocol Secure (HTTPS) to send service requests and obtain services.

[0236] Figure 1 is a schematic diagram of a network architecture based on a service-oriented architecture, which can include the service-oriented architecture of 5G and future mobile communication systems. The network architecture shown in Figure 1 may include terminal devices, access network devices, and core network devices. Terminal devices access the data network (DN) through access network devices and core network devices. The core network devices include various NF network elements. For example, the NF network elements in the service-oriented network architecture include some or all of the following network elements: unified data management (UDM) network element, unified data repository (UDR) network element, network exposure function (NEF) network element (not shown in the figure), application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, user plane function (UPF) network element, network data analytics function (NWDAF) network element, NRF (not shown in the figure), and location management function (LMF) network element (not shown in the figure). The description and function of the above network elements can be referred to the relevant 5G protocols and will not be expanded here.

[0237] Access network equipment can be radio access network (RAN) equipment. Examples include base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), next-generation NodeBs (gNBs) in 5G mobile communication systems, future mobile communication systems such as the 6th generation (6G), next-generation base stations in open RAN (O-RAN or ORAN) mobile communication systems or cloud radio access network (CRAN) mobile communication systems, base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems. Access network equipment can also be modules or units that perform some of the functions of a base station, such as centralized units (CUs) or distributed units (DUs). Access network equipment can be macro base stations, micro base stations, indoor stations, relay nodes, donor nodes, and the like. The access network device may also be an open access network (open RAN, O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The access network device may also be a communication system that integrates two or more of the above systems. The embodiments of the present application do not limit the specific technology and specific device form used by the wireless access network device.

[0238] Terminal devices can be user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, urban air vehicles (such as drones and helicopters), ships, robots, robotic arms, smart home devices, etc.

[0239] Access network equipment and terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; or in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of access network equipment and terminal devices.

[0240] It can be understood that the above network elements and communication equipment are examples of an implementation method of a 5G network under a service-oriented architecture. This application does not exclude the existence of network elements or devices with the above network element functions in 6G or newer wireless communication systems, which have other names or other forms.

[0241] In Figure 1, Nudr, Npcf, Namf, Nudm, Nsmf, Naf, and Nnwdaf are service-oriented interfaces provided by the UDR, PCF, AMF, UDM, SMF, AF, and NWDAF, respectively, and are used to invoke corresponding service-oriented operations. N1, N2, N3, N4, and N6 are interface serial numbers, and their meanings are as follows:

[0242] 1) N1: The interface between the AMF network element and the terminal device, which can be used to transmit non-access stratum (NAS) signaling (such as QoS rules from the AMF network element) to the terminal device.

[0243] 2) N2: The interface between the AMF network element and the access network equipment, which can be used to transmit radio bearer control information from the core network side to the access network equipment.

[0244] 3) N3: The interface between the access network equipment and the UPF network element, mainly used to transmit uplink and downlink user plane data between the access network equipment and the UPF network element.

[0245] 4) N4: The interface between the SMF network element and the UPF network element, which can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information on the user plane.

[0246] 5) N6: Interface between UPF network element and DN, used to transmit uplink and downlink user data flows between UP network element F and DN.

[0247] It is understood that the above-mentioned network element or function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). As a possible implementation method, the above-mentioned network element or function can be implemented by a single device, or can be implemented by multiple devices together, or can be a functional module within a single device, which is not specifically limited in the embodiments of the present application.

[0248] In addition, each of the above NF network elements can also be referred to as NF for short. For example, the AMF network element can be referred to as AMF for short.

[0249] It can be understood that Figure 1 is an example of a 5G service-oriented network architecture. The present application can also be applied to service-oriented architectures in other 5G or future mobile networks (such as 6G) other than Figure 1 to implement the issuance of certificates (or digital certificates) for NF network elements in the service-oriented network architecture.

[0250] In current 5G systems, to ensure secure NF interactions, NFs must be authenticated and / or authorized, such as through OAM or NRF. In 5G systems, NF authentication and authorization can be based on NF certificates (or public key certificates), transport layer security (TLS), or Hypertext Transfer Protocol (HTTP).

[0251] The NF certificate is issued by a CA. The CA can be a local CA belonging to the 5G network operator or a third-party CA that does not belong to the operator. The NF certificate usually includes the following information: the certificate serial number (serial number), the name of the certificate subject (such as NF). The name of the certificate subject is, for example, the subject name (SubjectName), the subject alias (SubjectAltName), the subject public key information, the certificate validity period, the certificate issuer (issuer, such as CA) or the signature. The subject public key information includes, for example, the public key of the certificate subject, the public key cryptographic algorithm identifier, the relevant key parameters, etc. The signature can be a digital signature of the certificate by the CA using its private key.

[0252] NF certificates are typically configured in the NF's software or hardware by the operator through Operational Management (OAM). Traditionally, NF or network element certificate management (including configuration, renewal, and revocation) is performed manually by administrators. This certificate management method is extremely labor-intensive and time-consuming. More importantly, manual management is not only prone to errors but also increases the security risk of insider attacks, significantly increasing the risk of security incidents and attacks across the entire system. Therefore, in the current service-oriented architecture of 5G networks, NF network element certificate management needs to be improved.

[0253] ACME is a certificate management challenge developed by the Internet Engineering Task Force (IETF). A client's ACME identifier (ID) can be used by a CA or ACME server to verify that the client controls the ACME identifier and issue a certificate containing the ACME identifier. However, the current ACME process is not compatible with the service-oriented architecture of 5G networks.

[0254] Among them, in the current ACME process, the ACME identifier is the domain name or IP address of the network element, and the subject of the issued certificate is also the domain name or IP address by default. There is a lack of an ACME certificate management mechanism based on the unique identifier of the NF network element in the 5G system. Therefore, there is a lack of automated authentication of the unique identifier of the NF network element (that is, the ACME server automatically verifies that the NF network element has control over the unique identifier of the NF network element) and automated certificate management. In other words, the current ACME process cannot be adapted to the 5G service-oriented architecture. The unique identifier of the NF network element may be referred to as the NF identifier in this application.

[0255] For example, the NF identifier can be an NF instance ID, or other identifier that can be used to uniquely identify the NF, which is not specifically limited in this application. Currently, the ACME certificate management mechanism does not support the use of the NF identifier as a certificate subject or ACME identifier.

[0256] The present application provides a network element authentication method for providing a NF network element authentication method based on an NF identifier to verify the authenticity of the NF identifier, verify that the NF identifier is not forged, or verify that the NF identifier has not been tampered with. The authentication of the NF network element by a first authentication device (or referred to as a first authentication network element) can be performed based on the ACME protocol, thereby achieving an automated and efficient NF network element authentication and certificate management mechanism.

[0257] The following describes the network elements and devices used in the method provided by this application. The method can be implemented by the NF to be verified and the first authentication device.

[0258] The NF may be an NF to be verified in a service-oriented architecture network. Specifically, the NF network element may be an AMF or SMF network element, without limitation. The NF may serve as an ACME client (or simply a client) of the ACME process.

[0259] The first authentication device can be a device that verifies the NF based on the ACME process. After the domain name of the NF network element is verified, the first authentication device can issue a certificate for the NF. For example, the first authentication device can serve as an ACME server (or simply a server) in the ACME process. For example, the first authentication device can be a CA or a server that supports the ACME process. Hereinafter, the certificate issued by the first authentication device after authenticating the NF based on the ACME process is referred to as the first certificate.

[0260] The ACME process can include an account phase, an order and challenge phase, and a certificate issuance phase. During the account phase, a client can request the server to register or update an ACME account (hereinafter referred to as an account). During the registration process, the server can obtain the client's account public key. After the account is successfully registered, all messages sent by the client to the server are signed using the client's account private key (or account private key). Accordingly, the server can verify the signature using the client's account public key (or account public key) to ensure that the message is sent by the client with the registered account. During the order and challenge phase, the server can indicate to the client the challenge method required for the authentication process and verify the client based on the method and the ACME identifier associated with the challenge, verifying that the client has control over the ACME identifier. During the certificate issuance phase, the client can request the server to issue a certificate. The server can issue a certificate including the ACME identifier to the client that passes the verification in the order and challenge phases.

[0261] The method described in this application can be applied to the account phase, order and challenge phase, pre-authorization phase, and certificate issuance phase of the ACME process. The following will introduce the process in stages. Figure 2 shows a flowchart of the method described in this application applied to the order and challenge phase; Figure 6 shows a flowchart of the method described in this application applied to the account phase; Figure 9 shows a flowchart of the method described in this application applied to the pre-authorization phase; and Figure 12 shows a flowchart of the method described in this application applied to the account phase.

[0262] In some embodiments, the method may also be performed by one or more of an OAM, NRF, or a token generation device. The OAM device may be an operation and maintenance network entity within the operator's network, which may be responsible for the maintenance and management of NF network elements, etc. For example, it may provide information such as the initialization configuration of the NF network element or the domain name registered for the NF network element. The token generation device in this application may be an NRF, or other network element or device that supports token generation.

[0263] As shown in FIG2 , in the order and challenge phases of the ACME process, a network element verification method provided in an embodiment of the present application may include the following steps shown in S101 to S105:

[0264] S101: NF sends an order request, the order request includes the NF's identity, and the order request is used to request to create or update an order for issuing a first certificate for the NF's identity. Correspondingly, the first authentication device receives the order request.

[0265] S102: The first authentication device sends a challenge message to the NF. The challenge message includes verification method information, which indicates the verification method (challenge method or authorization method) for the NF's identity in the order. Correspondingly, the NF receives the challenge message from the first authentication device.

[0266] The challenge message may include an order object, which indicates the challenge that the NF needs to complete before the first authentication device issues the first certificate. Optionally, the order object may include the above-mentioned verification method information.

[0267] In this application, the verification method of the NF identification may include verification based on the trust information of the network function network element (or called a challenge based on trust information, a trust challenge or an initial trust challenge, etc.), verification based on the first key verification information stored by the NRF (or called a challenge based on NRF registration or an NRF registration challenge, etc.), or verification based on the first token issued by the NRF (or called a token-based challenge or a token challenge, etc.). The verification method information will be introduced below in conjunction with the verification method of the first authentication device, which will not be explained here.

[0268] The challenge mode may be determined according to the NF's identifier. That is, if the order request includes the NF's identifier, the first authentication device may determine the verification mode as an initial trust challenge, an NRF registration challenge, or a token challenge.

[0269] In S102, the verification method information may be used to indicate one or more of the above verification methods. For example, the verification method information may include information corresponding to any one or more of the above verification methods, such as the verification method number, index, or identifier.

[0270] S103: The NF sends a challenge response message according to the verification method information. Correspondingly, the first authentication device receives the challenge response message.

[0271] The challenge response message may include the NF's identifier and / or first information. The first information is obtained based on the NF's network element identifier. The NF's identifier and / or first information may be used to verify the NF's identifier in the order.

[0272] The challenge response message may also include information about the public key of the NF's account, such as the NF's account public key identifier, so that the first server (i.e., the server) can verify the authenticity of the message, and also represent that the NF's identifier is associated with the account. For example, based on the NF's identifier and the association, the corresponding NF's account public key can be found. In this application, the association relationship, the corresponding relationship, and the binding relationship can be interchangeable, that is, this application does not distinguish between the three. In other words, association, corresponding, and binding can be interchangeable.

[0273] In this application, if the verification method includes verification based on the trust information of the network function network element, the challenge response message may include the first information, and the first information may include the trust information (or initial trust information). The trust information may include at least one of the second certificate of the NF, the first signature information, or the first message authentication code.

[0274] (1) The second certificate may be issued by a second authentication device and may include the NF's identifier. The second certificate may be signed by the second authentication device using its private key. The second authentication device may include, for example, an OAM or NRF, or a CA. The second certificate may be used to prove that the identifier belongs to the NF, or in other words, that the NF is bound to the ID.

[0275] (2) The first signature information may be signature information obtained by the second authentication device using the private key of the second authentication device to sign information or a message including the identification of the NF.

[0276] (3) The first message authentication code may be obtained based on the symmetric key and the identifier of the NF. The symmetric key may also be called a shared symmetric key, and may be a symmetric key shared by the NF and the first authentication device. The shared key may be provided by the second authentication device (such as an OAM) to the NF and the first authentication device, or may be pre-configured in the NF and the first authentication device. For example, the shared key may be associated with the identifier of the NF, indicating that the shared key is shared by the first authentication device and the NF to which the identifier of the NF belongs. Therefore, the first authentication device may determine the shared key shared with the NF based on the identifier of the NF.

[0277] As an example, the first message authentication code can be a numerical value obtained by processing the NF's identifier through a hash function and a symmetric key. For example, the NF's identifier can be used as part of a message (such as a challenge response message, or a partial message of a challenge response message), and the message can also include other information, such as ACME account information, etc., without specific restrictions. The first message authentication code can be a message digest of the message. For example, a hash-based message authentication code (HMAC) or a hash value of the message can be generated by a hash function and a symmetric key, and the hash operation message authentication code can be used as the first message authentication code. It can be understood that the message digest or hash value of the message containing the NF's identifier can also be obtained by other means as the first message authentication code, and this application does not impose any restrictions.

[0278] Optionally, the NF can obtain the trust information from the second authentication device. The trust information can be understood as the authentication or initial trust proof of the NF's identity by the second authentication device. The first authentication device can authenticate the NF based on the trust information provided by the second authentication device. The effect is that the authentication performed by the second authentication device is not based on the ACME process, such as authentication that requires manual participation, or a relatively long-term authentication. In order to achieve automated authentication of the NF's identity, or in other words, in order to achieve authentication that meets the authentication cycle or requirements of the ACME process, the first authentication device can authenticate the NF's identity based on the trust information provided by the second authentication device.

[0279] If the verification method includes verification based on the first key verification information stored by the NRF, the challenge response message may include the NF's identifier. The first key verification information may be obtained based on the public key of the NF's ACME account.

[0280] After receiving the challenge response message from the NF, the first authentication device needs to establish an association between the NF's identifier and the account public key. This means that the NF's account public key stored on the first authentication device can be found using the NF's identifier. Consequently, in subsequent steps, after receiving the first key verification message from the NRF, the NF's account public key can be retrieved using the NF's identifier, allowing the second key verification message to be generated based on the account public key for comparison.

[0281] The first authentication device can obtain the first key verification information stored by the NRF based on the NF's identifier and perform verification. The first key verification information stored by the NRF can be determined by the NF based on the public key of the NF's account. The NF can also send the first key verification information to the NRF. The NF can carry the first key verification information in a registration request message or an update request message sent to the NRF. The registration request can be used to request the NRF to register the NF. The update request can be used to request the NRF to update the NF's information.

[0282] For example, the first key verification information may be a digest or hash value determined by the NF according to the public key of the NF's account, for example, represented as a key authentication (keyAuthorization) parameter.

[0283] For example, the value of the keyAuthorization parameter can satisfy:

[0284] Challenge token||'.'||base64url(Thumbprint(AccPubKey)).

[0285] Challenge token identifies a challenge token, which can be included in a challenge message from the first authentication device and uniquely identifies a challenge. '||' represents string concatenation. Base64url represents the string encoding method. Thumbprint represents the use of the SHA-256 hash function to generate a digest or hash value. AccPubKey represents the account public key.

[0286] If the verification method includes verification based on a first token issued by the NRF, the challenge response message may include first information, and the first information may include the first token, that is, the first token may be determined based on the identifier of the NF. This application does not make specific requirements on the method in which the NRF generates the first token. In addition, the first token may be issued by a network element or device other than the NRF that supports token generation, or in other words, the actions performed by the NRF in various embodiments of verification based on the first token may be performed by a network element or device other than the NRF that supports token generation.

[0287] For example, the first token of the NF may be generated by the NRF based on the token request of the NF, and the NRF may provide the first token to the NF. The token request may include the identifier of the NF. Optionally, the first token may also include the public key of the NF's account or indication information of the public key of the NF's account, such as the public key identifier (account key identifier, AccKid) or the public key identifier of the account, to prove the association between the NF and the account. The indication information of the public key of the NF's account may be included in the token request.

[0288] It is understood that the first token in this application may be a token used to verify the identity of the NF. For example, the NF may include indication information in the token request, indicating that the token is used to verify the identity of the NF by the first authentication device. Furthermore, the first token may also include indication information indicating that the token is used to verify the identity of the NF by the first authentication device.

[0289] At least one of the above-mentioned NF identification, the indication information of the public key of the NF account, or the indication information used to indicate that the token is used by the first authentication device to verify the NF identification can be carried in the claim or authorization scope of the first token.

[0290] S104: The first authentication device verifies the NF identifier according to the NF identifier and / or the first information.

[0291] The verification method performed by the first authentication device may correspond to the verification method information. For example, the first authentication device may verify the NF identifier based on the NF identifier and / or the first information according to the verification method indicated by the verification method information. The following describes the verification method for the NF identifier by the first authentication device in conjunction with Methods 1 to 3, which will not be discussed here.

[0292] S105: The NF obtains a first certificate by sending a certificate request message, where the certificate request is used to complete the order.

[0293] The NF can send an order request to the first authentication device. The first authentication device can then issue a first certificate corresponding to the NF's identity based on the order request. Accordingly, the NF can obtain the first certificate issued by the first authentication device. The first certificate can be understood as a certificate issued for the NF's identity. The first certificate can also be considered to be associated with the NF's identity, meaning that the NF's identity corresponds to the first certificate.

[0294] For example, the certificate request is a certificate signing request (CSR).

[0295] In one possible embodiment, a certificate request may be sent based on the order status. For example, the NF may send a certificate request when the order is complete. For example, the NF may consider the order complete after a certain period of time has passed since the order request was sent, or after the NF receives a response message indicating order completion. The response message may be sent by the first authentication device after the order is completed. The NF may also send an order status inquiry message to the first authentication device to inquire whether the order is complete. If the first authentication device has completed the order, a response message indicating order completion may be sent.

[0296] In addition, in another possible embodiment, the certificate request does not need to be sent when the order is completed. If the first authentication device has not completed the order when receiving the certificate request, it can reply with a rejection or a response message indicating that the order is not completed.

[0297] In S105 , when the order is in a completed state and the verification corresponding to the identifier of the NF in the order is passed, the first authentication device may issue the first certificate of the NF according to the certificate request after receiving the certificate request.

[0298] In one possible embodiment, the certificate request may include the NF's identifier. Accordingly, the first authentication device may determine to issue the first certificate to the NF based on the NF's identifier. For example, if the NF's identifier in the certificate request has been verified, the first authentication device may issue the certificate corresponding to the certificate request. For another example, in S104, if the first authentication device determines that the NF's identifier has been verified, the first authentication device may store the association between the NF's account and the NF's identifier. When the first authentication device receives a certificate request sent by the NF via a certain account, it may obtain the association between the NF's identifier and the account carried in the certificate request and compare the association with the stored association between the account and the NF's identifier. If the comparison result indicates that the two associations are consistent (or, if the two associations contain the same NF's identifier, and the same NF's identifier corresponds to the same NF's account in both associations), it indicates that the NF's identifier has been verified and is bound to the account. In this case, the first authentication device may issue the first certificate. If the comparison result is inconsistent, the certificate request may be rejected. Therefore, during the certificate issuance process, the association between the NF's identifier and the NF's account can be verified, which can further improve the security of certificate issuance.

[0299] Based on the process shown in Figure 3, the first authentication device can verify the NF's identity based on the NF's identity and / or the first information from the NF to support or adapt to the NF verification method based on the NF's identity in the order and challenge stages in the ACME protocol.

[0300] The following uses methods 1 to 3 as examples to introduce a method in which the first authentication device in this application verifies the NF identifier based on the NF identifier and / or the first information.

[0301] Mode 1: The verification mode includes performing verification based on the trust information of the network function network element, and the first authentication device performs the verification based on the trust information.

[0302] Mode 1 may include Mode 1-1, Mode 1-2, and Mode 1-3, which are described below.

[0303] Method 1-1: If the verification method includes verification based on the trust information of the network function network element, and the trust information includes the second certificate, the first authentication device can verify the second certificate based on the public key of the second authentication device.

[0304] The public key of the second authentication device may be configured in the first authentication device. Alternatively, the public key of the second authentication device may be included in the root certificate corresponding to the second certificate. The first authentication device first verifies the second certificate using the root certificate configured in the first authentication device. If verification is successful, the public key of the second authentication device is obtained. The second certificate includes the NF's identity. If verification is determined to be successful based on the public key of the second authentication device, this indicates that the NF's identity has been verified.

[0305] Method 1-2: If the verification method includes verification based on the trust information of the network function network element, and the trust information includes the first signature information, the first authentication device can verify the first signature information based on the public key of the second authentication device.

[0306] Among them, if the first authentication device determines that the first signature information has passed the verification based on the public key of the second authentication device, it may indicate that the NF's identification verification has passed; otherwise, if the first authentication device determines that the first signature information has not passed the verification based on the public key of the second authentication device, it may indicate that the NF's identification verification has failed.

[0307] Method 1-3: If the verification method includes verification based on the trust information of the network function network element, and the trust information includes a first message verification code, the first authentication device can generate a second message verification code based on the symmetric key and the NF identifier, and compare the first message verification code with the second message verification code to see if they are consistent or inconsistent, and determine whether the NF identifier verification is passed or not based on the comparison result.

[0308] The method used by the first authentication device to generate the second message authentication code is the same as the method used by the NF to generate the first message authentication code. If the first message authentication code and the second message authentication code are consistent, it indicates that the NF's identity verification has passed. If the first message authentication code and the second message authentication code are inconsistent, it indicates that the NF's identity verification has failed. The symmetric key can be provided by the second authentication device to the first authentication device, or it can be configured in the first authentication device. The symmetric key and the NF's identity are provided or configured together in the first authentication device, so that the first authentication device can obtain the first shared key based on the NF's identity in the message.

[0309] Method 2: If the verification method includes verification based on the first key verification information stored in the NRF, and the NRF can store the NF's identifier and the first key verification information, the first authentication device can obtain the first key verification information from the NRF based on the NF's identifier, or in other words, obtain the NF's identifier stored in the NRF based on the NF's identifier.

[0310] In Method 2, the challenge response message in S103 may also include information about the NF's account's public key, such as the NF's account public key identifier, to allow the server to verify the authenticity of the message. This also indicates that the NF's identifier is associated with the account. For example, based on the NF's identifier and this association, the corresponding NF's account public key can be found.

[0311] The first authentication device may verify the first key verification information based on the public key of the NF account, and determine the verification result of the NF's identity based on the verification result of the first key verification information. If the first authentication device determines that the first key verification information is verified successfully based on the public key of the NF account, it may be determined that the verification of the NF's identity is successful. If the first authentication device determines that the first key verification information is not verified successfully based on the public key of the NF account, it indicates that the verification of the NF's identity is not successful.

[0312] Specifically, if the first key verification information and the second key verification information are the same, it means that the first key verification information verification is passed, or in other words, the verification of the NF identification is passed; if the first key verification information and the second key verification information are different, it means that the first key verification information verification is failed, or in other words, the verification of the NF identification is failed.

[0313] The method for verifying the first key verification information based on the public key of the NF's account is, for example, that the first authentication device generates the second key verification information based on the public key of the NF's account in the same manner as the NF generates the first key verification information, and compares the first key verification information with the second key verification information to determine whether they are identical. In other words, the first key verification information can be a digest or hash value determined by the NF based on the public key of the NF's account, and the first authentication device can use the same algorithm to determine a new digest or hash value based on the public key of the NF's account. The new digest or hash value is the second key verification information.

[0314] In a possible embodiment of the second mode, the first authentication device may request the first key verification information from the NRF according to the identifier of the NF, and the NRF provides the first key verification information to the first authentication device based on the request of the first authentication device.

[0315] The first authentication device can obtain the account public key of the NF based on the NF's identifier and the association between the NF's identifier and the account's public key (for example, as described in step S103), and generate second key verification information for verifying whether the first key verification information and the second key verification information are the same.

[0316] Exemplarily, the first key verification information may be carried in a registration request message or an update request message sent by the NF to the NRF. The message may also carry the identifier of the NF. For example, the identifier of the NF and / or the first key verification information may be carried in the NF configuration (NF profile) in the registration request message or the update request message. After verifying the message, the NRF may store the correspondence between the identifier of the NF and the first key verification information. The first authentication device may send a request message to the NRF, which may include the identifier of the NF for requesting the first key verification information. Optionally, the request message may also include an identifier for indicating that the first key verification information is obtained. The NRF may search for the corresponding first key verification information based on the identifier of the NF in the request message, and send the first key verification information to the first authentication device.

[0317] It can be understood that the registration request message or update request message sent by the NF to the NRF can be sent before or after the challenge response message, and this application does not specifically limit it.

[0318] Optionally, the challenge response message sent by the NF to the first authentication device may also include the identifier or address of the NRF. The identifier or address of the NRF can be used by the first authentication device to determine the NRF that stores the first key verification information of the NF. Therefore, the first authentication device can determine the NRF that stores the first key verification information of the NF based on the identifier or address of the NRF, thereby sending the above-mentioned request message to the NRF. The address of the NRF can also be pre-configured in the first authentication device, that is, the default NRF can be used to store the first key verification information of the NF. In addition, the first authentication device can also determine the NRF that stores the first key verification information of the NF based on the identifier of the NF. For example, the first authentication device queries the NRF registered with the NF based on the identifier of the NF, and the NRF is the NRF that stores the first key verification information of the NF.

[0319] In another possible embodiment of method 2, the NRF pushes the first key verification information and the NF identifier to the first authentication device. The first authentication device searches for the NF account public key corresponding to the NF identifier based on the NF identifier and generates the second key verification information.

[0320] Exemplarily, the first key verification information may be carried in a request message sent by the NF to the NRF. The request message may also carry the NF's identifier. After registering the NF, the NRF may push the NF's identifier and the first key verification information to the first authentication device if the push conditions for the first key verification information are met. The push conditions for the first key verification information may include, for example, any one or more of the following: a) the first authentication device has subscribed to or ordered the NF's key verification information push service from the NRF. b) the NRF is configured to push the key verification information (including but not limited to the first key verification information) generated by the NF for identifying the NF to the first authentication device. c) when the first key verification information is included in the NF's registration request message or update request message, the first key verification information is pushed to the first authentication device by default, or it can be understood that the first key verification information carried in the registration request message or update request message can be used to instruct the NRF to push the key verification information to the first authentication device. d) the registration request message or update request message contains instruction information, which instructs the NRF to push the first key verification information to the first authentication device.

[0321] It can be understood that the timing of the NRF pushing the first key verification information to the first authentication device can be executed before or after the NF sends the challenge response message to the first authentication device, and this application does not specifically limit it.

[0322] In this implementation, the first authentication device can search for the public key of the NF account corresponding to the NF identifier in the challenge response message, and generate the second key verification information as described in step S103 above to verify whether the first key verification information and the second key verification information are the same.

[0323] Method 3: If the verification method includes verification based on a first token issued by the NRF, the first authentication device may verify the first token based on the NRF's public key. For example, the first authentication device may verify the signature of the first token based on the NRF's public key, where the signature may be obtained by signing the first token based on the NRF's private key.

[0324] Optionally, in method 3, the challenge response message in S103 may also include information about the public key of the NF's account, such as the NF's account public key identifier, so that the server can verify the authenticity of the message, which also represents that the first token is associated with the account.

[0325] In one possible implementation of mode 3, the NF may send a token request to a token provider to request the token provider to generate a token. After obtaining the first token generated by the token provider, the NF may send the first token to the first authentication device. For example, the NF token provider may be an NRF or other network element or device that supports token generation.

[0326] In another possible implementation of mode 3, after generating the first token, the token provider may push the first token to the first authentication device if the token push condition is met. For example, the identification of the NF and the first token are pushed. The token push condition includes, for example: a) the first authentication device subscribes to or orders the push service of the first token of the NF from the token provider. b) The NRF is configured to push the token to the first authentication device after generating a token (including but not limited to the first token) for identifying the NF. c) The token request contains indication information, which instructs the NRF to push the first token to the first authentication device.

[0327] In this implementation, the challenge response message may not carry the first token but may carry the identifier of the NF. The first authentication device may search for the first token corresponding to the identifier of the NF from the NRF based on the identifier of the NF in the challenge response message.

[0328] In another possible implementation of method 3, the first authentication device may also request the NRF to obtain a first token corresponding to the NF identifier based on the NF identifier carried in the challenge response message, and the NRF may feedback the first token based on the NF identifier from the first authentication device. This implementation may refer to the implementation of method 2 in which the first authentication device requests the NRF for the first key verification information.

[0329] It can be understood that in S104, the first authentication device can verify the identity of the NF according to one or more of the above methods 1 to 3. The first authentication device can determine which method to use to verify the identity of the NF based on the verification method information. For example, if the verification method information is used to indicate that the verification method of the identity of the NF includes verification based on the first token issued by the NRF, then in S104, the first authentication device can determine that the verification of the identity of the NF can be performed through method 3 based on the verification method information. In addition, the first authentication device can also determine which method to use to verify the identity of the NF based on the information contained in the challenge response message. For example, if the challenge response message contains the first token, then in S104, the first authentication device can determine that the verification of the identity of the NF can be performed through method 3 based on the first token.

[0330] In a possible embodiment, the NF may obtain the trust information in this application before performing ACME account registration (or before obtaining the NF's account public key), or the NF may obtain any of the above trust information after performing ACME account registration (or after obtaining the NF's account public key). If any of the above trust information is obtained after performing ACME account registration (or after obtaining the NF's account public key), the NF's trust information may be determined based on the NF's account information. The account information is, for example, an account identifier (Acc ID) or an account public key (AccPubKey) or an account public key identifier (AccKid).

[0331] For example, if the trust information includes a second certificate, the OAM may issue the second certificate based on the NF's identification and account information after the NF completes account registration (or obtains the NF's account public key), and the second certificate may include the NF's identification and account information. If the trust information includes first signature information, the OAM may sign the information or message including the NF's identification and account information based on the OAM's private key after the NF completes account registration (or obtains the NF's account public key) to obtain the first signature information. If the trust information includes a first message authentication code, the NF's identification and account information may be calculated or processed using the first shared key to generate the first message authentication code after the NF completes account registration (or obtains the NF's account public key).

[0332] In this embodiment, the trust information can be used to prove the account of the NF, or to prove the association between the account of the NF and the identifier of the NF. For example, the information of the account of the NF can be an account public key or an account public key identifier, etc. When the first authentication device receives a message from the NF, it can verify whether the identifier and account of the NF that sent the message meet the association between the account of the NF and the identifier of the NF proved by the trust information based on the association relationship, thereby further improving security. Among them, the NF can obtain the information of the account of the NF during the account registration or account establishment stage of the ACME process, and then obtain the trust information based on the identifier and account information of the NF, that is, the generation or issuance of the trust information needs to be performed after the account registration (or after obtaining the account public key of the NF).

[0333] If the first authentication device verifies the identity of the NF based on the first key verification information of the NF, the NF needs to generate the first key verification information based on the account public key (as described in S103) to verify the NF's account. In addition, if the first information includes the NF's first token, and the NF has completed account registration before generating the first token (or after obtaining the NF's account public key), the first token generated by the NRF may also include the NF's account information to verify the NF's account.

[0334] It can be understood that in Modes 1 to 3, the challenge response message carries the NF's identifier and / or the first information for use in verifying the NF's identifier. Modes 1 to 3 can also be applied when the NF's identifier and / or the first information are carried in messages other than the challenge response message. The first authentication device can refer to the descriptions of Modes 1 to 3 and verify the NF's identifier based on the NF's identifier and / or the first information carried in the other message. For example, the challenge response message involved in Modes 1 to 3 can be replaced with other messages in the ACME process, such as an account request, a pre-authorization request, or a certificate request, or can be a newly introduced message in the ACME process, without specific limitation.

[0335] In a possible embodiment of the present application, the challenge response message in S103 may further include the second signature information of the NF, and the second signature information may be obtained based on the private key signature of the NF's account. For example, the second signature information may be obtained by the NF signing the challenge response message using the private key of the account, obtaining the second signature information, and adding the second signature information to the challenge response message. For another example, the second signature information may be obtained by the NF signing the information or message including the NF's identification and / or the first information using the private key of the account. After obtaining the second signature information, the NF may construct a challenge response message based on the information or message including the NF's identification and / or the first information and the second signature information.

[0336] In this embodiment, the challenge response message may optionally include information indicating the public key of the NF's account (e.g., an account public key identifier) ​​to indicate the public key of the NF's account. Accordingly, the first authentication device may obtain the public key of the NF's account based on the public key indication information and verify the second signature information based on the public key to ensure that the account is not being misused.

[0337] Similarly, other messages sent by the NF to the first authentication device in this application may also include signature information obtained by signing with the private key of the NF's account. The first authentication device can verify this signature information using the public key of the NF's account to ensure that the account of each message sent by the NF is authentic. Other messages include order requests, account requests, pre-authorization requests, certificate requests, etc., which are not specifically limited.

[0338] The following describes an exemplary implementation of the communication method provided by this application for verifying the identification of the NF in the order and challenge stages of the ACME process through the flowcharts shown in Figures 3 to 5. This implementation is provided as an exemplary illustration of the communication method shown in this application and should not be used as a limitation on the implementation of the communication method shown in this application. For example, based on the various flowcharts in this application, if the arrangement and combination of the process messages and the information carried by the messages is changed, or the execution sequence between the steps is changed, then the changed process should also belong to the implementation of the communication method shown in this application.

[0339] In the process shown in Figure 3, the NF is described as an ACME client and the first authentication device as an ACME server. In this process, during the order and challenge phase, the NF's identity is verified through a trust challenge (also known as trust information verification or trust information challenge). Optionally, during the order and challenge phase, a challenge related to the NF's domain name or IP address can also be performed. For example, a domain name challenge can be a domain name service (DNS) challenge, and an IP address challenge can be an IP challenge. This application does not provide detailed descriptions.

[0340] FIG3 may include the following steps:

[0341] S2-a: The NF obtains or configures the NF identity and trust information.

[0342] The NF identifier may include an NF instance identifier. Optionally, the NF identifier may also include a domain name and / or IP address of the NF.

[0343] In this application, the domain name of the NF may be the NF fully qualified domain name (FQDN).

[0344] The trust information may be the second certificate, the first signature information, or the first message authentication code described in this application. For details, refer to the introduction in this application, and no further details will be given in the flowchart.

[0345] As an example, in a 5G system, the NF configuration file of an NF includes an NF instance identifier and may also include a domain name and / or IP address. The NF configuration file can be configured with the above-mentioned trust information to prove that the NF configuration file belongs to the NF, that is, the NF configuration file can include trust information.

[0346] S2-b: The first authentication device obtains or configures information for verifying the trust information of the NF.

[0347] For example, when the trust information includes a second certificate, the information used to verify the trust information may include the public key or root certificate of the second authentication device used to verify the second certificate. For another example, when the trust information includes first signature information, the information used to verify the trust information may include the public key or root certificate of the second authentication device used to verify the first signature information. For another example, when the trust information includes a first message authentication code, the information used to verify the trust information may include the symmetric key used to verify the first message authentication code.

[0348] Optionally, in S2-b, the first authentication device may obtain information for verifying the trust information of the NF from the second authentication device (such as OAM), or may obtain information for verifying the trust information of the NF according to local configuration.

[0349] S2-A1: NF generates an account key pair, including the client account private key and the corresponding account public key.

[0350] S2-A2: The NF sends an account request (or account request message) to the first authentication device, creating a new client account for the NF on the first authentication device. The account request may include the NF's account public key. The message may be signed with the NF's account private key to prove that the account belongs to the NF.

[0351] S2-A3: The first authentication device creates an account and stores the NF's account public key. The first authentication device can perform integrity verification on the account request based on the account public key in the account request.

[0352] S2-A4: The first authentication device sends an account response message to the NF. The account response message includes an identifier for the account's public key. The identifier for the account's public key is typically the account's uniform resource locator (URL). This application does not limit the form of the public key.

[0353] It should be noted that the above description is about the account creation process. Furthermore, for other account management processes, such as account updates and account inquiries, S2-A1 is not necessary. Furthermore, the request message in step S2-A2 may no longer include the account's public key, but may instead carry information indicating the account's public key, such as an account public key identifier. This public key information can be used by the first authentication device to retrieve the stored public key of the account corresponding to the information and perform the corresponding integrity verification in S2-A3. This is not further described here; please refer to IETF Draft for Comments 8555 (IETF RFC 8555).

[0354] After the account is created, the message sent by the client to the server may include indication information of the NF's account public key, such as the account public key identifier. In addition, the message sent by the NF to the first authentication device needs to be signed with the NF's account private key, so that the first authentication device can obtain the NF's account public key stored in SA1 based on the indication information of the account public key, and use the public key to verify the message to prove that the message is sent from the client NF. Therefore, unless otherwise specified, the message sent by the NF to the first authentication device in the following process includes indication information of the account public key, such as the account public key identifier and the signature information generated by signing with the NF's account private key (such as the second signature information in this application). For example, the message sent by the NF (as a client) to the first authentication device (as a server) may include the NF's account public key, so the first authentication device can obtain the NF's account public key from the challenge response message.

[0355] The above S2-A1 to S2-A4 may be steps belonging to the account stage in the ACME process.

[0356] S2-B1: NF sends an order request to the first authentication device.

[0357] Among them, the order request includes one or a group of ACME identifiers, including identifier type and name. It should be noted that the ACME identifier is not limited to the domain name or IP address. For example, the ACME identifier can be (or include) an NF identifier, such as an NF instance identifier, or other identifiers that can be used to uniquely identify the NF. This application does not specifically limit this. When the ACME identifier is an NF identifier, optionally, the NF identifier can also be used as indication information to indicate that a challenge method corresponding to the NF identifier needs to be adopted. For example, when the ACME identifier is an NF identifier, the NF identifier can be used to instruct the first authentication device to select a challenge method applicable to the NF identifier when determining the challenge method. For another example, when the ACME identifier is an NF identifier, the NF identifier can be used to indicate that the identifier supported by the NF is not limited to the domain name or IP address of the NF, but also supports the identifier as the NF identifier, that is, it is used to indicate that the NF at least supports the challenge method applicable to the NF identifier, or indicates that the first authentication device is supported to select a challenge method applicable to the NF identifier.

[0358] It can be understood that in the verification based on trust information, the challenge method applicable to the NF identification may include the verification based on the trust information of the network function network element introduced in this application.

[0359] It can also be understood that S2-B1 can be used as an example of S101 in the process shown in FIG. 2 .

[0360] S2-B2: The first authentication device sends a challenge message. The challenge message may include an indication of the verification method that the NF needs to complete, that is, verification method information. The verification method information may be used to instruct the verification to be performed based on the trust information of the network function element.

[0361] The notification message may be sent based on the order request, and the verification method information may be determined based on the identifier of the NF in the order request.

[0362] S2-B2 can be used as an exemplary implementation of S102 in the process of FIG. 2 .

[0363] Before S2-B2, the first authentication device can determine the challenge method. For example, if the ACME identifier in S2-B1 includes an NF identifier, the first authentication device can determine the challenge method to be sent based on the ACME identifier. For example, if the server determines that the ACME identifier type is an NF identifier, other challenge methods different from the DNS challenge or IP challenge can be selected, such as the initial trust challenge used in this embodiment. It should be noted that if the server determines that the ACME identifier type is a domain name or an IP address, the challenge method selected by the server may include a DNS challenge or an IP challenge, as well as an initial trust challenge or other challenge methods. In other words, the inclusion of the NF identifier in the ACME identifier is not a mandatory condition for this application.

[0364] S2-B3: Optionally, the NF performs corresponding operations according to the challenge method required by the first authentication device to enable the server to perform verification.

[0365] In the case of a challenge based on trust information, S2-B3 can be skipped.

[0366] S2-B4: The NF sends a challenge response message to the first authentication device, the response message also including the NF's identity and trust information. As described in S103, the trust information may include one or more of the second certificate, the first signature information, or the first message authentication code.

[0367] Optionally, the challenge response message may also include indication information of the NF's account public key or second signature information, etc., which is used to verify the NF's account to further improve security.

[0368] S2-B4 can be used as an exemplary implementation of S103 in the process of FIG. 2 .

[0369] For example, in an optional implementation of S2-B4 or S103, the challenge response message in the ACME protocol can be modified by adding a new NF identifier (e.g., NF instance ID) and / or trust information to the message. Alternatively, for the initial trust challenge, the Uniform Resource Locator (URL) information in the challenge response message can be removed. In another optional implementation, the URL is assigned a null value or a pseudo-URL value (the specific form is not limited), and the NF identifier and / or trust information is sent to the server out-of-band. For example, the 3rd Generation Partnership Project (3GPP) signaling sent by the NF to the server includes at least two parts: one part is an ACME protocol container, which includes the existing ACME protocol challenge response message, for example, the URL is assigned a null value or a pseudo-URL value; the other part may not be in the container but is part of the signaling, and includes the NF identifier and / or trust information. In this implementation, this part of the ACME protocol does not need to be modified. This implementation method is also applicable to other ACME protocol-related messages used to carry NF identification and / or trust information, which are not described in detail in this application.

[0370] S2-B5: After receiving the challenge response message, the first authentication device verifies the challenge.

[0371] The verification shown in S2-B5 may include the verification shown in S2-B5-1 and / or S2-B5-2.

[0372] The challenge response message may include the second signature information. Accordingly, in S2-B5-1, the first authentication device can verify the second signature information based on the NF's account public key to ensure that the challenge response message passes verification, that is, to ensure that the message has not been tampered with. For example, the first authentication device can receive and store the account public key from the NF according to S2-A2 and S2-A3.

[0373] In S2-B5-2, the first authentication device can verify the trust information. For details, please refer to the description of method 1 in this application, which will not be repeated here.

[0374] S2-B5 or S2-B5-2 can be used as an exemplary implementation of S104 in the process of FIG. 2 .

[0375] S2-B6: After the challenge is passed, the first authentication device stores the association between the NF's identifier and the NF's account.

[0376] This association enables the server to verify whether the ACME identifier (or NF identifier) ​​contained in the CSR is the same as the NF identifier in step S2-B1 (i.e., the NF identifier in the association relationship) during the certificate issuance process. In addition, during the issuance process, the first authentication device does not need to verify the trust information described in step S2-B5-2 again. It should be noted that the association relationship can be one account associated with multiple NF identifiers, or multiple accounts associated with one NF identifier, or one account associated with one NF identifier, and this application does not limit this.

[0377] S2-C1: The NF sends a certificate request (eg, CSR) to the first authentication server.

[0378] The certificate request may include the NF identifier. For example, the NF identifier may be used as an ACME identifier. Alternatively, the NF identifier may be included in the certificate request as information other than the ACME identifier.

[0379] S2-C2: The first authentication server verifies the certificate request.

[0380] The verification of the certificate request may include verifying the signature of the certificate request using the public key of the NF's account.

[0381] In addition, as described in S2-B6, the first authentication device may verify the association between the account of the certificate request and the NF identifier included in the certificate request based on the stored association between the NF identifier and the account. If the association between the NF identifiers included in the certificate request is included in the association between the NF identifier and the account stored by the first authentication device, it means that the NF identifier has passed the challenge verification and the certificate can be issued.

[0382] S2-C3: The first authentication server issues a first certificate. Accordingly, the NF obtains the first certificate. The first certificate may be carried in a certificate response message.

[0383] S2-C1 to S2-C3 may be used as an exemplary implementation of S105.

[0384] Optionally, the verification step shown in S2-B5-2 can also be performed in the S2-C2 process, that is, S2-B5-2 is not performed in S2-B5.

[0385] The above are the steps involved in the process of Figure 3.

[0386] In another implementation of the process shown in Figure 3, S2-a can be replaced by S2-c: the first authentication device obtains trust information after generating the account key pair at S2-A1 or receiving the account response message at S2-A3. In this case, the trust information can be determined based on the NF's account information. The account information may include, for example, an account identifier, an account public key, or an account public key identifier.

[0387] For example, the trust information may be a second certificate including the identification and account information of the NF, first signature information obtained by signing information or a message including the identification and account information of the NF according to the private key of the OAM, or a first message verification code obtained by calculating or processing the identification and account information of the NF through the first shared key.

[0388] It is understood that either S2-a or S2-c can be implemented alternatively. The difference is that S2-c can be executed after the NF's account key pair is generated or after the NF's ACME account is created. Therefore, the trust information in S2-c can be determined based on the NF's account information, thereby additionally verifying the NF's account information to further ensure security. The implementation method can refer to the description of the case where trust information is determined based on the NF's account information in this application, and will not be repeated in the flowchart.

[0389] In the process shown in FIG4 , the NF is introduced as an ACME client and the first authentication device is introduced as an ACME server. In this process, the NF's identity is verified by the NRF registration challenge (or verification or challenge based on the NRF registration) during the order and challenge phase. Optionally, the order and challenge phase may also include a challenge related to the NF's domain name or IP address. For example, the domain name-related challenge may be a DNS challenge, and the IP address-related challenge may be an IP challenge, which will not be described in detail in this application. FIG4 may include the following steps:

[0390] S3-A1 to S3-A4 can refer to S2-A1 to S2-A4. That is, the steps in the account phase of the ACME process in the process of FIG4 can refer to the steps in the account phase of the ACME process shown in FIG3.

[0391] S3-B1: NF sends an order request to the first authentication device.

[0392] S3-B1 can refer to the description of S2-B1, but the difference between the two is that in the NRF registration challenge, the challenge method applicable to the NF identification may include the verification based on the first key verification information stored in the NRF introduced in this application.

[0393] S3-B2: The first authentication device sends a challenge message. The challenge message may include an indication of the verification method that the NF needs to complete, that is, verification method information. The verification method information may be used to instruct the NF to perform verification based on the first key verification information stored in the NRF.

[0394] The notification message may be sent based on the order request, and the verification method information may be determined based on the identifier of the NF in the order request.

[0395] S3-B2 can be used as an exemplary implementation of S102 in the process of FIG. 2 .

[0396] Before S3-B2, the first authentication device can determine the challenge method. For example, if the ACME identifier in S2-B1 includes an NF identifier, the first authentication device can determine the challenge method to be sent based on the ACME identifier. For example, if the server determines that the ACME identifier type is an NF identifier, other challenge methods different from DNS challenges or IP challenges can be selected, such as the NRF registration challenge used in this embodiment. It should be noted that if the server determines that the ACME identifier type is a domain name or an IP address, the challenge method selected by the server may include a DNS challenge or an IP challenge, or an NRF registration challenge or other challenge methods. In other words, the inclusion of an NF identifier in the ACME identifier is not a mandatory condition for this application.

[0397] S3-B3-1: NF sends a registration request message to NRF.

[0398] The registration request message includes first key verification information. The first key verification information may be determined based on the public key of the NF account. For example, the first key verification information may be keyAuthorization.

[0399] Optionally, the registration request message may also include an identifier of the NF.

[0400] In this step, the NF can register with the NEF via a registration request message. The purpose of this registration process is to register the NF's configuration file on the NRF server. This configuration file may include the first key verification information and the NF's identifier. Furthermore, the first key verification information may be carried in the registration request message in addition to the NF's configuration file, without limitation.

[0401] In a possible embodiment, the configuration file of the NF may also include one or more of the following parameters: NF type (NF type), network identifier to which the NF belongs (such as the ID of the public land mobile network (PLMN) to which the NF belongs), single-network slice selection assistance information (S-NSSAI) to which the NF belongs, identifier of the slice instance (network slice instance ID, NSI ID) to which the NF belongs, IP address or FQDN of the NF, NF set identifier (set ID), NF service set identifier (service set ID), etc., which are not limited here.

[0402] Optionally, S3-B3-1 to S3-B3-3 are the registration process of the NF to the NRF. S3-B3-1 to S3-B3-3 can be understood as the NF performing corresponding operations to enable the server to perform verification according to the challenge method required by the first authentication device, where the corresponding operations in this process include the NF requesting registration from the NRF.

[0403] S3-B3-2: After verifying the registration request message from the NF, the NRF stores the first key verification information.

[0404] For example, the first key verification information is included in the NF configuration file in the registration request message. Accordingly, in S3-B3-2, the NRF may store the NF configuration file. For another example, the first key verification information is included in addition to the NF configuration file in the registration request message. Accordingly, in S3-B3-2, the NRF may store the NF configuration file and the first key verification information.

[0405] S3-B3-3: NRF sends a registration response message to NF, indicating that NF registration is successful.

[0406] The registration request message in step S3-B3-1 may include information that can be used by the NRF to verify the NF's identity, such as an OAM signature. Alternatively, the NRF may possess other information that can be used to authenticate the NF. This application does not limit the method for protecting registration. (See also 3GPP standard 33.501 regarding NF registration methods.)

[0407] It is understood that in the process shown in S3-B1-1 to S3-B3-3, the registration request message can also be replaced by an update request. Accordingly, the registration-related content can be replaced by the update of NF information. For example, after the NF completes registration with the NRF, the NF can provide the NF configuration file (and / or other information, such as the first key verification information) to the NRF via an update message, so that the NRF can update the NF configuration file.

[0408] S3-B4: The NF sends a challenge response message to the first authentication device.

[0409] The challenge response message may include the identifier of the NF.

[0410] Optionally, the message may further include address information of the NRF, so that the server can determine the NRF storing the first key verification information and obtain information about the NF from the NRF.

[0411] It is understandable that S3-B4 can be used as an exemplary implementation of S103 in the process of Figure 2. The challenge response message can refer to the description of S103.

[0412] S3-B5: After receiving the challenge response message, the first authentication device verifies the challenge.

[0413] The verification shown in S3-B5 may include the verification shown in S3-B5-1 and / or S3-B5-2.

[0414] Among them, the challenge response message may include the identifier of the public key of the account and the second signature information. Accordingly, in S3-B5-1, the first authentication device can obtain the stored public key of the NF account based on the identifier of the public key of the account to verify the second signature information, ensuring that the challenge response message passes the verification, that is, ensuring that the message has not been tampered with. For example, the first authentication device can receive and store the account public key from the NF based on S3-A2 and S3-A3. The first authentication device can associate the identifier of the public key of the NF account based on the identifier of the NF in the challenge response message and store the association relationship, so that the first authentication device can obtain the identifier of the NF account public key or the NF account public key based on the identifier of the NF in subsequent steps, and further obtain the second key verification information (as described in method 2).

[0415] In addition, in S3-B5-2, the first authentication device can obtain the first key verification information stored in the NRF and verify the first key verification information. For details, please refer to the description of method 2 in this application.

[0416] As specifically shown in Figure 4, the first authentication device can obtain the first key verification information from the NRF through S3-B5-2a1 to S3-B5-2a3. In S3-B5-2a1, the first authentication device can send a request message to the NRF, and the request message may include the identifier of the NF, and the identifier of the NF may be included in the challenge response message. In S3-B5-2a2, the NRF queries the configuration file of the NF according to the identifier of the NF to obtain the first key verification information corresponding to the identifier of the NF. In S3-B5-2a3, the NRF sends a response message to the first authentication device, which carries the first key verification information, so the first authentication device can obtain the first key verification information from the NRF.

[0417] Optionally, the response message in S3-B5-2a3 may also include the trust information of the NF, and the trust information may refer to the description in Figure 3 or the process of Figure 3. The response message may be sent by the NF to the NRF through a registration request or an update request. Accordingly, after obtaining the trust information, the first authentication device may also verify the trust information. The verification method may refer to the description in S2-B5 in Figure 3, or may refer to the description of method 1 in this application, which will not be repeated. The trust information may be carried in the request message (such as a registration request or an update request) sent by the NF to the NRF, so the NRF can obtain the trust information from the NF. That is to say, the identity of the NF can be verified based on the trust challenge and the NRF registration challenge. In addition, the first authentication device may also perform verification based only on the trust information in the response message. For example, the response message does not contain the first key verification information, but contains trust information.

[0418] In addition, the response message in S3-B5-2a3 can be signed by the private key of the NRF, and accordingly, the first authentication device can verify the signature based on the public key of the NRF. In addition, if the response message in S3-B5-2a3 is not signed by the private key of the NRF, a secure channel can be established between the NRF and the first authentication device, and the message between the NRF and the first authentication device can be transmitted through the secure channel. For example, the secure channel can be a channel based on a security protocol such as the TLS protocol or the network layer security protocol, which is not limited in this application.

[0419] It should be noted that the response message in S3-B5-2a3 may not include the public key identifier of the NF's account. The first authentication device can search for the stored public key identifier of the NF's account based on the NF's identifier, and then obtain the public key of the NF's account.

[0420] In addition, the first authentication device can obtain the first key verification information from the NRF through S3-B5-2b1 to S3-B5-2b2. In S3-B5-2b1, the NRF can push the first key verification information of the NF to the first authentication device. For example, referring to the description in Method 2, if the push conditions are met, the NRF can push the NF's identifier and the first key verification information to the first authentication device. Correspondingly, in S3-B5-2b2, the first authentication device can search for the corresponding first key verification information based on the NF's identifier.

[0421] Optionally, in the embodiment of the first key verification information pushed by NRF shown in S3-B5-2b1 to S3-B5-2b2, the first key verification information pushed by NRF can be signed by the private key of NRF, and accordingly, the first authentication device can use the public key of NRF to verify the signature.

[0422] It should be noted that the message sent by NRF to the first authentication device in S3-B5-2b1 (carrying the first key verification information) may not include the public key identifier of the NF's account. The first authentication device can search for the stored public key identifier of the NF's account based on the NF's identifier, and then obtain the public key of the NF's account.

[0423] S3-B5 or S3-B5-2 can be used as an exemplary implementation of S104 in the process of FIG. 2 .

[0424] S3-B6 can refer to the description of S2-B6.

[0425] S3-C1 to S3-C3 can refer to the description of S2-C1 to S2-C3. The difference is that in the description of S2-C1 to S2-C3, the content related to the verification of trust information can be replaced by verification based on the first key verification information stored in the NRF in S3-C1 to S3-C3.

[0426] Optionally, the verification step shown in S3-B5-2 can also be performed in the S3-C2 process, that is, S3-B5-2 is not performed in S3-B5.

[0427] The above are the steps involved in the process of Figure 4.

[0428] In the process shown in FIG5 , the NF is introduced as an ACME client and the first authentication device is introduced as an ACME server. In this process, the NF's identity is verified by a token challenge (or token-based verification or challenge, etc.) during the order and challenge phase. Optionally, the order and challenge phase may also include a challenge related to the NF's domain name or IP address. For example, a domain name-related challenge may be a DNS challenge, and an IP address-related challenge may be an IP challenge, which will not be described in detail in this application. FIG5 may include the following steps:

[0429] S4-A1 to S4-A4 can refer to S2-A1 to S2-A4. That is, the steps in the account phase of the ACME process in the process of FIG5 can refer to the steps in the account phase of the ACME process shown in FIG3.

[0430] S4-B1: NF sends an order request to the first authentication device.

[0431] S4-B1 can refer to the description of S2-B1, but the difference between the two is that, in the token challenge, the challenge method applicable to the NF identifier may include the verification based on the first token introduced in this application.

[0432] S4-B2: The first authentication device sends a challenge message. The challenge message may include an indication of the verification method that the NF needs to perform, i.e., verification method information. This verification method information may be used to instruct verification based on the first token. The first token is described in the process of Figure 2 and is not further described here.

[0433] The notification message may be sent based on the order request, and the verification method information may be determined based on the identifier of the NF in the order request.

[0434] S4-B2 can be used as an exemplary implementation of S102 in the process of FIG. 2 .

[0435] Before S4-B2, the first authentication device can determine the challenge method. For example, if the ACME identifier in S4-B1 includes an NF identifier, the first authentication device can determine the challenge method to be sent based on the ACME identifier. For example, if the server determines that the ACME identifier type is an NF identifier, other challenge methods different from the DNS challenge or IP challenge can be selected, such as the first token challenge used in this embodiment. It should be noted that if the server determines that the ACME identifier type is a domain name or an IP address, the challenge method selected by the server may include a DNS challenge or an IP challenge, or may include a first token challenge or other challenge methods. In other words, the inclusion of the NF identifier in the ACME identifier is not a mandatory condition for this application.

[0436] S4-B3-1: The NF sends a token request to the NRF. The token request may be used to request the NRF to issue a first token.

[0437] The token request may include the identifier of the NF, and correspondingly, the first token may include the identifier of the NF.

[0438] In addition, the token request may also include information such as the domain name or IP address of the NF.

[0439] Optionally, the token request may also include information for indicating that the token of NF is used for verification of the first token challenge. This information can be used to indicate that the token is a token for applying for an ACME certificate, to distinguish tokens used in other scenarios. Accordingly, the first token may carry the information for indicating that the token of NF is used for verification of the first token challenge to indicate the function of the first token. In addition, the token request may also include information indicating the public key of the account of NF (such as the public key identifier of the account) or the public key of the account. Accordingly, NRF may add information indicating the public key of the account (such as the public key identifier of the account) or the public key of the account in the first token to prove the account of NF.

[0440] Optionally, the NF can send a token request to the NRF after registering with the NRF.

[0441] S4-B3-2: The NRF performs verification based on the token request. After the verification is successful, the NRF generates a first token.

[0442] For example, the NRF can verify the legitimacy of the NF that sends the token request.

[0443] In addition, the declaration or authorization scope in the first token may include one or more of the identification of the NF, information indicating the public key of the NF's account (such as the public key identifier of the account) or the public key of the account, or information used to indicate that the NF's token is used for verification of the first token challenge.

[0444] After the first token is generated, as shown in method 3, the first authentication device can obtain the first token in two ways.

[0445] In one embodiment, the NF may obtain a first token from the NRF and provide the first token to the first authentication device. For example, the first token may be carried in a challenge response message. As shown in steps S4-B4-a1 to S4-B4-a2, it includes: S4-B4-a1: the NRF sends a token response message to the NF, which carries the first token. Accordingly, the NF may receive the first token. S4-B4-a2: the NF sends the first token to the first authentication device, and accordingly, the first authentication device obtains the first token. The first token may be carried in a challenge response message sent by the NF to the first authentication device.

[0446] In this implementation, S4-B4-a2 can be used as an exemplary implementation of S103 in the process of FIG. 2 .

[0447] In another approach, the NRF can push the first token to the first authentication device. For example, as shown in steps S4-B4-b1 to S4-B4-b3, in S4-B4-b1, the NRF can determine that the token push conditions are met after generating the first token. The token push conditions can refer to the description of approach 3. In S4-B4-b2, the NRF can send the NF identifier and the first token to the first authentication device. In S4-B4-b3, the first authentication device can search for the first token from the identifier and corresponding token of at least one NF pushed by the NRF based on the NF identifier.

[0448] Optionally, the first token sent by the NRF to the first authentication device may be signed by the private key of the NRF, and accordingly, the first authentication device may verify the signature using the public key of the NRF.

[0449] S4-B5: The first authentication device verifies the first token, that is, performs token challenge verification.

[0450] If the first token comes from the NF, then in S4-B5, the first authentication device can verify the message carrying the first token using the public key of the NF's account. For example, if the first authentication device obtains the first token through S4-B4-a2, the first token can be included in the challenge response message, and the challenge response message is signed by the private key of the NF's account, then the first authentication device can verify the signature using the public key of the NF's account.

[0451] If the first token comes from the NRF, the first token may be signed by the private key of the NRF. Then, in S4-B5, the first authentication device may verify the first token according to the public key of the NRF.

[0452] S4-B6: After verifying the first token, the first authentication device stores the association between the NF's account and the NF's identifier.

[0453] If the challenge verification in S4-B5 passes, it means that the account information (or the public key identifier of the account) contained in the first token is associated with the identifier of the NF carried in the first token. Therefore, in S4-B6, the association between the identifier of the NF and the account can be stored, which is used to verify the identifier and account of the NF involved in the certificate request during the certificate issuance stage.

[0454] S4-C1 to S4-C3 can refer to the description of S2-C1 to S2-C3. The difference is that in the description of S2-C1 to S2-C3, the content related to the verification of the trust information can be replaced by the verification based on the first token in S4-C1 to S4-C3.

[0455] The above are the steps involved in the process of Figure 5.

[0456] It is understood that the process in FIG5 is described by taking the NRF generating the first token of the NF as an example. In some scenarios, the first token may also be generated by a device or network element other than the NRF. Such a device or network element may be used to execute the actions related to the first token executed by the NRF.

[0457] As shown in FIG6 , in the account phase of the ACME process, a network element verification method provided in an embodiment of the present application may include the following steps shown in S501 to S503:

[0458] S501: The NF sends an account request, wherein the account request includes the NF's identification and / or first information. Correspondingly, the first authentication device receives the certificate request.

[0459] The identification of the NF and / or the first information may be used to verify the identification of the NF.

[0460] It can be understood that, with reference to the description related to the process in Figure 2, the verification of the NF identity in this application may include verification based on the trust information of the network function network element (or called a challenge based on trust information, a trust challenge or an initial trust challenge, etc.), verification based on the first key verification information stored in the NRF (or called a challenge based on NRF registration or an NRF registration challenge, etc.) or verification based on the first token issued by the NRF (or called a token-based challenge or a token challenge, etc.).

[0461] When verifying the NF's identity based on the NF's identity, the first authentication device may perform verification based on the first key verification information stored by the NRF. When verifying the NF's identity based on the first information, the first authentication device may perform verification based on the trust information of the network function network element, wherein the first information includes the trust information; or, when verifying the NF's identity based on the first information, the first authentication device may perform verification based on the first token issued by the NRF, wherein the first information may include the first token.

[0462] Optionally, the identifier of the NF may be carried in the EAB identifier (EAB-ID) field in the account request. The EAB identifier field may be used to carry an identifier or information related to the account requested to be established by the account request. Therefore, through the account registration process, the first authentication device may determine, based on the EAB identifier field, that the content carried by the field is associated with the account. Specifically in the present application, after account registration, the first authentication device may determine that the identifier of the NF carried in the EAB field is associated with the account. In addition, the identifier of the NF and / or the first information may also be sent to the server out-of-band, for example, refer to the description of sending the identifier of the NF and / or the first information out-of-band in S2-B4.

[0463] Whether the account request carries the first information, and / or whether the first information includes trust information or the first token, can be determined by the NF based on verification method information sent by a first authentication device, an OAM device, or a network element, or can be determined based on verification method information pre-configured or stored locally by the NF, or can be determined based on protocol definitions. The first authentication device can determine the verification method information based on local configuration, OAM instructions, or protocol definitions. For verification method information, refer to the description of the process in Figure 3.

[0464] S502: The first authentication device verifies the NF identifier according to the NF identifier and / or the first information.

[0465] Among them, the verification method of the NF identifier may include verification based on the trust information of the network function network element, verification based on the first key verification information stored in the NRF, or verification based on the first token issued by the NRF. The above verification methods can refer to the description of the verification method of the NF identifier shown in S104 and will not be repeated here. For example, the instructions for verification based on the trust information of the network function network element can refer to Method 1, the instructions for verification based on the first key verification information stored in the NRF can refer to Method 2, and the instructions for verification based on the first token issued by the NRF can refer to Method 3. The difference is that the message names related to the challenge response message in Methods 1 to 3 are replaced with account requests or related messages.

[0466] After the first authentication device completes verification of the NF's identity, it can send an account response message to the NF, as described in S2-A4. Upon receiving the account response message, the NF can complete the order phase (including order request, challenge request, challenge response, verification, and other steps corresponding to S2-B1 through S2-B6) using the ACME protocol and the ACME identifier (e.g., domain name or IP address, not the NF's identity) according to the ACME protocol. Unlike steps S2-B1 through S2-B6, the order phase here is executed entirely using the ACME identifier and in accordance with the existing ACME protocol.

[0467] S503: The NF obtains a first certificate issued by the first authentication device for the NF's identity by sending a certificate request message.

[0468] The NF may send a certificate request (e.g., a CSR) to the first authentication device. After confirming that the NF's identity has been verified in S502 and that the ACME identifier has been verified according to the order phase, the first authentication device may issue a first certificate corresponding to the NF's identity based on the certificate request. Accordingly, the NF may obtain the first certificate issued by the first authentication device.

[0469] Based on the process shown in FIG6 , it is possible to support or adapt the account phase in the ACME protocol to implement NF identification verification and certificate issuance.

[0470] It is understood that the changes to the account phase of the ACME protocol in this method embodiment include, for example, at least one of the following:

[0471] Difference 1: In the account request at the account stage, the NF identifier is additionally carried.

[0472] Difference 2: For verification methods based on the trust information of network function elements, the account request may also include the trust information. Alternatively, the trust information may also be carried in messages other than the request message, which is not limited in this application.

[0473] Difference 3: Regarding the verification method for the first key verification information stored by the NRF, after sending the account request, the NF may also send a registration request or an update request to the NRF, carrying the first key verification information, so that the NRF stores the first key verification information. In addition, the first authentication device may also obtain and verify the first key verification information from the NRF before sending the account response message.

[0474] Distinction 4: Optionally, the account response message can be used to indicate that the NF's identity verification has passed. For example, the NF and / or the first authentication device may assume that the account response message indicates that the NF's identity verification has passed. Furthermore, the account response message may also carry additional indication information to indicate that the NF's identity verification has passed.

[0475] The following describes an exemplary implementation of a method for verifying the NF identifier in the account stage of the ACME process in the communication method provided by the present application through the flowcharts shown in Figures 7 and 8.

[0476] In the process shown in Figure 7, the NF is introduced as an ACME client and the first authentication device is introduced as an ACME server. In this process, the NF's identity is verified through a trust challenge (also known as trust information verification or trust information challenge) at the account stage. For example, Figure 7 may include the following steps:

[0477] S6-a and S6-b can refer to the descriptions of S2-a and S2-b, respectively. Furthermore, S6-a can be replaced by S6-c. In S6-c, the NF can obtain trust information after generating the account key pair. This trust information can be determined based on the NF's account information, thus enabling additional verification of the NF's account information to further ensure security.

[0478] S6-A1: NF generates an account key pair, including the client account private key and the corresponding account public key.

[0479] S6-A2: The NF sends an account request (or account request message) to the first authentication device, for creating a new client account for the NF on the first authentication device.

[0480] The account request includes trust information. Furthermore, the account request may also include the NF's identifier. For example, the NF's identifier and / or the first information may be included in the EAB identifier field, indicating the association between the account and the NF's identifier, which is stored by the first authentication device after account creation. Furthermore, as described in S2-B4, the NF's identifier and / or the first information may also be sent to the server out-of-band.

[0481] S6-A2 can be used as an exemplary implementation of S501 shown in FIG6 .

[0482] S6-A3: After receiving the account request, the first authentication device verifies the trust information.

[0483] In S6-A3, the first authentication device may verify the trust information with reference to Method 1 in this application, or may verify the trust information with reference to the process of S2-B5, which will not be repeated here.

[0484] S6-A3 can be used as an exemplary implementation of S502 shown in FIG6 .

[0485] In S6-A3, the first authentication device may also create an account for the NF. In addition, the first authentication device may also store the association relationship between the account and the identifier of the NF.

[0486] S6-A4: After the verification is successful, the first authentication device sends an account response message to the NF.

[0487] Furthermore, after the trust information is verified successfully at S6-A3, the first authentication device can associate the created account with the NF's identity. This allows the first authentication device to issue a certificate based on the NF's identity based on the ACME process, for example, after the account is created, using a domain name or IP address verification process based on existing technologies. That is, after S6-A4, the order and challenge phases can be performed according to existing technologies for the NF's domain name or IP address, and the first certificate can be issued through the certificate issuance phase. Steps S6-C1 to S6-C3 of the issuance phase can refer to the steps described in S2-C1 to S2-C3, respectively, and will not be further described. The difference from steps S2-C1 to S2-C3 is that the NF's identity is replaced with the NF's domain name or IP address. After the first authentication device completes verification of the NF's domain name or IP address, it determines the NF's identity based on the account corresponding to the NF's domain name or IP address and the association between the account and the NF's identity stored in S6-A3, and issues a certificate based on the NF's identity.

[0488] S6-C1 to S6-C3 can be used as an exemplary implementation of S503 shown in Figure 6. The difference is that the NF carries the NF domain name or IP address in the certificate request, and the first authentication device performs verification based on the NF domain name or IP address. When issuing a certificate, it issues a certificate identified by the NF.

[0489] The above are the steps involved in the process of Figure 7.

[0490] In the process shown in FIG8 , the NF is introduced as an ACME client and the first authentication device is introduced as an ACME server. In this process, the NF's identity is verified through the NRF registration challenge (or verification or challenge based on NRF registration) at the account stage. For example, FIG8 may include the following steps:

[0491] S7-A1: NF generates an account key pair, including the client account private key and the corresponding account public key.

[0492] The NF can calculate the first key verification information based on the account public key as described in S102. Unlike S102, the "challenge token" used to calculate the first key verification information is replaced by a random number generated by the NF, rather than being sent to the NF by the first authentication device.

[0493] S7-a: The NF sends a registration request message to the NRF.

[0494] The registration request message includes first key verification information.

[0495] S7-b: After verifying the registration request of the NF, the NRF stores the first key verification information.

[0496] S7-c: NRF sends a registration response message to NF.

[0497] S7-a, S7-b and S7-c can refer to the descriptions in S3-B3-1, S3-B3-2 and S3-B3-3 respectively.

[0498] It can be understood that the registration request message can also be replaced by an update request message, and the registration response can also be replaced by an update response. The corresponding implementation method refers to the description in this application.

[0499] S7-A2: The NF sends an account request (or account request message) to the first authentication device, for creating a new client account for the NF on the first authentication device.

[0500] Referring to the description in Method 2, the account request may include the NF identifier.

[0501] In addition, the account request also includes the "challenge token" used in S7-A1 to calculate the first key verification information. The "challenge token" is used by the first authentication device to calculate the second key verification information.

[0502] S7-A2 can be used as an exemplary implementation of S501 shown in FIG6 .

[0503] S7-A3: After receiving the account request, the first authentication device obtains the first key verification information according to the identifier of the NF and performs verification.

[0504] In S7-A3, the first authentication device can obtain the first key verification information stored by the NRF based on the identifier of the NF and verify the first key verification information. For details, please refer to the description of Method 2 in this application. Among them, the second key verification information used to verify the first key verification information is generated by replacing the "challenge token" in the parameter with the "challenge token" in the account request message of S7-A2.

[0505] Specifically, as shown in Figure 8, the first authentication device can obtain the first key verification information from the NRF through S7-A3-a1 to S7-A3-a3. S7-A3-a1 to S7-A3-a3 can refer to the description of S3-B5-2a1 to S3-B5-2a3 respectively, and will not be repeated here.

[0506] Optionally, the response message in S7-A3-a3 may also include the NF's trust information. Accordingly, after obtaining the trust information, the first authentication device may also verify the trust information. The verification method may refer to the description in S2-B5 in Figure 3, or refer to the description in Method 1 in this application, which will not be repeated here.

[0507] In addition, the first authentication device can obtain the first key verification information from the NRF through S7-A3-b1 to S7-A3-b2. S7-A3-b1 to S7-A3-b3 can refer to the description of S3-B5-2b1 to S3-B5-2b2 respectively, and will not be repeated here.

[0508] S7-A3 can be used as an exemplary implementation of S502 shown in FIG6 .

[0509] In S7-A3, the first authentication device can also create an account for the NF.

[0510] In addition, the first authentication device may also store the association relationship between the account and the identifier of the NF.

[0511] S7-A4: After the first authentication device passes the verification, it sends an account response message to the NF.

[0512] Furthermore, after successfully verifying the first key verification information, the first authentication device can associate the created account with the NF's identity. Thus, the first authentication device can issue a certificate based on the NF's identity based on the ACME process, for example, after the account is created, using a domain name or IP address verification process known in the art. That is, after S7-A4, the order and challenge phases can be performed for the NF's domain name or IP address in accordance with known techniques, and the first certificate can be issued through the certificate issuance phase. Steps S7-C1 through S7-C3 of the issuance phase can refer to the steps described in S2-C1 through S2-C3, respectively, and will not be further described. The difference from steps S2-C3 through S2-C4 is that the NF's identity is replaced with the NF's domain name or IP address. After the first authentication device completes verification of the NF's domain name or IP address, it determines the NF's identity based on the account corresponding to the NF's domain name or IP address and the association between the account and the NF's identity stored in S7-A3, and issues a certificate for the NF's identity.

[0513] S7-C1 to S7-C3 may be used as an exemplary implementation of S503 shown in FIG6 .

[0514] The above are the steps involved in the process of Figure 8.

[0515] It is understood that in the process shown in Figure 8, S7-a, S7-b, and S7-c can be included in the NF's registration process with the NRF. This registration process can be independent of the ACME process or included in the ACME process, and this application does not specifically limit this. For example, the registration process can be performed before or after the NF sends the account request step shown in S7-A2.

[0516] Optionally, the pre-authorization request may also include a "challenge token" used to calculate the first key verification information. This "challenge token" (e.g., a random number) may be generated by the NF and used by the first authentication device to calculate the second key verification information. Further descriptions of different verification methods are provided below.

[0517] In addition, the method described in this application can also be used in the pre-authorization stage (or pre-authorization process, account pre-authorization stage, or account pre-authorization process) of the ACME process. The pre-authorization process can be performed after the account stage or during the account creation / update process, and before the order stage (or before the order request is sent). Furthermore, once pre-authorization is complete, the ACME process no longer requires challenges and verifications for orders initiated by accounts that have obtained pre-authorization. Alternatively, it can be assumed that orders initiated by accounts that have obtained pre-authorization have passed challenges.

[0518] As shown in FIG9 , for the pre-authorization process, the method provided in this application may include the following steps shown in S801 to S805:

[0519] S801: The NF sends a pre-authorization request, wherein the pre-authorization request includes the NF's identification and / or first information. Correspondingly, the first authentication device receives the pre-authorization request.

[0520] The pre-authorization request may be used to request pre-authorization for an account.

[0521] The pre-authorization request may also include information indicating the public key of the NF's account, such as an account public key identifier, etc. Alternatively, the pre-authorization request may include the NF's account public key, so the first authentication device may obtain the NF's account public key from the pre-authorization request.

[0522] The pre-authorization request may be signed by the private key of the NF's account, such as including signature information obtained based on the private key. Correspondingly, the first authentication device may verify the signature by the public key of the NF's account.

[0523] It can be understood that the pre-authorization request can be made after the NF receives the account stage, for example, after receiving the account response message used to identify the account registration result, the pre-authorization request is sent.

[0524] S802: The first authentication device verifies the NF identifier according to the NF identifier and / or the first information.

[0525] Among them, the verification method of the NF identifier may include verification based on the trust information of the network function network element, verification based on the first key verification information stored in the NRF, or verification based on the first token issued by the NRF. The above verification methods can refer to the description of the verification method of the NF identifier shown in S104 and will not be repeated here. For example, the instructions for verification based on the trust information of the network function network element can refer to method 1, the instructions for verification based on the first key verification information stored in the NRF can refer to method 2, and the instructions for verification based on the first token issued by the NRF can refer to method 3. The difference is that the message names related to the challenge response messages in methods 1 to 3 are replaced with pre-authorization requests or related messages. In addition, for method 2, when calculating the second verification information, the "token" parameter of S801 needs to be used.

[0526] Whether the pre-authorization request carries the first information, and / or whether the first information includes trust information or the first token, can be determined by the NF based on verification method information sent by a first authentication device, an OAM device, or a network element, or can be determined based on verification method information pre-configured or stored locally by the NF, or can be determined based on protocol definitions. The first authentication device can determine the verification method information based on local configuration, OAM instructions, or protocol definitions. For verification method information, refer to the description of the process in Figure 3.

[0527] S803: After the NF's identity verification is successful, the first authentication device pre-authorizes the NF. In other words, the first authentication device pre-authorizes the NF's account.

[0528] In S803, after the NF's identifier is verified, the first authentication device can store the account and the NF's identifier as a pre-authorized account and identifier. For pre-authorized accounts and NF identifiers, the corresponding order request does not need to perform steps such as order challenge and challenge verification, and will be directly marked as verified. For example, for pre-authorized accounts and NF identifiers, the corresponding order request does not execute the steps corresponding to S2-B2 to S2-B5 in the ACME order process. In steps similar to S2-B6, the first authentication device can store the association between the NF identifier and the NF's account after determining that the NF's identifier is verified (rather than based on the challenge passing from S2-B2 to S2-B5).

[0529] S804: The first authentication device sends a pre-authorization response message to the NF. The pre-authorization response message may be used to indicate a pre-authorization result, such as whether the pre-authorization is successful or unsuccessful.

[0530] The pre-authorization response message may represent the end of the pre-authorization phase or the pre-authorization process.

[0531] As an example, after the pre-authorization phase is completed, the order and challenge phase may include the following steps S8-B1 to S8-B2:

[0532] S8-B1: The NF sends an order request to the first authentication device, wherein the order request may include the NF's identifier, the identifier of the public key of the NF's account, and the second signature information.

[0533] S8-B2: The first authentication device verifies the NF's identifier and the association between the NF's identifier and the account.

[0534] The first authentication device can obtain the account public key based on the public key identifier of the NF's account and verify the second signature information to ensure that the order request message has passed verification, that is, to ensure that the message has not been tampered with. After verification, the NF's identifier and NF's account information (account public key identifier) ​​are compared with the pre-authorized NF's identifier and NF's account information (account public key identifier) ​​stored in S803. If they are the same, the order request has passed verification and the order status is updated (e.g., updated to a status indicating verification).

[0535] S805: The NF obtains the first certificate issued by the first authentication device for the NF's identity through the certificate request message.

[0536] The NF may send a certificate request (e.g., a CSR) to the first authentication device. After confirming that the NF's identity has been verified at S5-B2, the first authentication device may issue a first certificate corresponding to the NF's identity based on the certificate request. Accordingly, the NF may obtain the first certificate issued by the first authentication device.

[0537] Based on the process shown in FIG9 , it is possible to support or adapt the verification of the NF's identity and the issuance of the certificate in the pre-authorization phase of the ACME protocol.

[0538] The following describes an exemplary implementation of a method for verifying the NF identifier during the issuance phase of the ACME process in the communication method provided by this application, using the flowcharts shown in Figures 10 and 11. Figures 10 and 11 illustrate an example in which the pre-authorization phase is performed after the account phase and before the order phase.

[0539] In the process shown in Figure 10, the NF is introduced as an ACME client and the first authentication device is introduced as an ACME server. In this process, the NF's identity is verified through a trust challenge (also known as trust information verification or trust information challenge) during the pre-authorization stage. For example, Figure 10 may include the following steps:

[0540] S9-a and S9-b can refer to the descriptions of S2-a and S2-b, respectively. Furthermore, S9-a can be replaced by S9-c, which can refer to the description of S2-c. That is, the trust information in S9-c can be determined based on the NF's account information, thus enabling additional verification of the NF's account information to further ensure security.

[0541] S9-A1 to S9-A4 can refer to S2-A1 to S2-A4. That is, the steps in the account phase of the ACME process in the process of FIG10 can refer to the steps in the account phase of the ACME process shown in FIG3.

[0542] S9-d1: After completing the account creation, the NF sends a pre-authorization request to the first authentication device.

[0543] The pre-authorization request includes trust information. Referring to the description of Method 1, the trust information may include one or more of the second certificate, the first signature information, or the first message authentication code. In addition, the pre-authorization request may also include the NF identifier.

[0544] S9-d1 can be used as an exemplary implementation of S801 in the process shown in FIG9 .

[0545] S9-d2: After receiving the pre-authorization request, the first authentication device verifies the trust information.

[0546] In S9-d2, the first authentication device can verify the trust information with reference to Method 1 in this application, which will not be repeated here.

[0547] S9-d2 can be used as an exemplary implementation of S802 shown in FIG9 .

[0548] After the trust information is verified, the first authentication device may pre-authorize the NF, as described in S803. In addition, the first authentication device may also send a pre-authorization response message to the NF, as described in S804.

[0549] Furthermore, S8-B1 and S8-B2 can also be executed between the NF and the first authentication device. That is, for a pre-authorized account and NF ID, the corresponding order request does not execute steps S2-B2 to S2-B5 in the ACME order process. Instead, the first authentication device can store the NF ID and the association between the NF ID and the account.

[0550] S9-C1 to S9-C3 can refer to the steps shown in S2-C1 to S2-C3, and will not be repeated here.

[0551] S9-C1 to S9-C3 may be used as an exemplary implementation of S804 shown in FIG9 .

[0552] In the process shown in Figure 11, the NF is introduced as an ACME client and the first authentication device is introduced as an ACME server. In this process, the NF's identity is verified through the NRF registration challenge (or verification or challenge based on the NRF registration) during the pre-authorization stage. For example, Figure 11 may include the following steps:

[0553] S10-A1: NF generates an account key pair, including the client account private key and the corresponding account public key.

[0554] The NF can calculate the first key verification information based on the account public key as described in S102. Unlike S102, the "challenge token" used to calculate the first key verification information is replaced by a random number generated by the NF, rather than being sent to the NF by the first authentication device.

[0555] S10-a: The NF sends a registration request message to the NRF.

[0556] S10 - b: After verifying the registration request of the NF, the NRF stores the first key verification information.

[0557] S10-c: The NRF sends a registration response message to the NF.

[0558] For S10-a, S10-b and S10-c, reference can be made to the descriptions in S3-B3-1, S3-B3-2 and S3-B3-3, respectively.

[0559] It can be understood that the registration request message can also be replaced by an update request message, and the registration response can also be replaced by an update response. The corresponding implementation method refers to the description in this application.

[0560] S10-A2 to S10-A4 can refer to S2-A2 to S2-A4. That is, the steps in the account phase of the ACME process in the process of FIG11 can refer to the steps in the account phase of the ACME process shown in FIG3.

[0561] S10-d1: After completing the account creation (eg, after receiving the account response message), the NF sends a pre-authorization request to the first authentication device.

[0562] The pre-authorization request may include the NF's identifier. The pre-authorization request also includes the "challenge token" used in S10-A1 to calculate the first key verification information. The "challenge token" is used by the first authentication device to calculate the second key verification information as described in S102.

[0563] S10-d1 can be used as an exemplary implementation of S801 shown in FIG9 .

[0564] S10-d2: After receiving the pre-authorization request, the first authentication device performs verification based on the NF's identification.

[0565] In S10-d2, the first authentication device can obtain the first key verification information stored by the NRF based on the identifier of the NF and verify the first key verification information. For details, please refer to the description of Method 2 in this application. It should be noted that when calculating the second key verification information used to verify the first key verification information, the "challenge token" parameter comes from the pre-authorization request described in S10-d1.

[0566] Specifically, as shown in Figure 11, the first authentication device can obtain the first key verification information from the NRF through S10-d2-a1 to S10-d2-a3. S10-d2-a1 to S10-d2-a3 can refer to the description of S3-B5-2a1 to S3-B5-2a3 respectively, and will not be repeated here.

[0567] Optionally, the response message in S10-d2-a3 may also include the NF's trust information. Accordingly, after obtaining the trust information, the first authentication device may also verify the trust information. The verification method may refer to the description in S2-B5 in Figure 3, or refer to the description in Method 1 in this application, which will not be repeated here.

[0568] In addition, the first authentication device can obtain the first key verification information from the NRF through S10-d2-b1 to S10-d2-b3. S10-d2-b1 to S10-d2-b3 can refer to the description of S3-B5-2b1 to S3-B5-2b3 respectively, and will not be repeated here.

[0569] S10-d2 can be used as an exemplary implementation of S802 shown in FIG9 .

[0570] Furthermore, S8-B1 and S8-B2 can also be executed between the NF and the first authentication device. That is, for a pre-authorized account and NF ID, the corresponding order request does not execute steps S2-B2 to S2-B5 in the ACME order process. Instead, the first authentication device can store the NF ID and the association between the NF ID and the account.

[0571] In addition, the first authentication device may also send a pre-authorization response message to the NF, as described in reference to S804.

[0572] S10-C1 to S10-C2 can refer to the steps shown in S2-C1 to S2-C2, and will not be repeated here.

[0573] S10 - C1 to S10 - C2 may be used as an exemplary implementation of S804 shown in FIG. 9 .

[0574] The above are the steps involved in the process of Figure 11.

[0575] It is understood that in the process shown in Figure 1, S10-a, S10-b, and S10-c can be included in the NF's registration process with the NRF. This registration process can be independent of the ACME process or included in the ACME process, and this application does not specifically limit this. For example, the registration process can be performed before or after the NF sends the account request shown in S10-A2.

[0576] S10 - a , S10 - b and S10 - c may also be executed after the account stage, for example, after the NF receives the corresponding message of account creation and / or before sending the pre-authorization request.

[0577] As shown in FIG12 , in the issuance phase of the ACME process, a network element verification method provided in an embodiment of the present application may include the following steps shown in S1101 to S1104:

[0578] S1101: The first authentication device performs a first verification on the domain name or IP address of the NF.

[0579] For example, the first verification may include a DNS challenge for the domain name of the NF and / or an IP address challenge for the IP address of the NF.

[0580] Optionally, the first authentication device may store the first association relationship after determining that the first verification is passed. The first association relationship may include an association relationship between the NF's account information (such as the NF's account's public key identifier or public key, etc.) and the NF's domain name, and / or an association relationship between the NF's account information (such as the NF's account's public key identifier or public key, etc.) and the NF's IP address.

[0581] It can be understood that S1101 includes the account establishment phase, order and challenge phases of the ACME process. S1101 corresponds to steps S2-A1 to S2-A4 (account phase) and steps S2-B1 to S2-B5 (order and challenge phase). It should be noted that S1101 is the existing ACME process for verifying the domain name or IP address of the NF.

[0582] S1102: The NF sends a certificate request, where the certificate request includes the NF's identifier and / or first information.

[0583] The certificate request also includes the domain name or IP address of the NF.

[0584] The NF's identification and / or the first information and / or the NF's domain name or IP address may be used to verify the NF's identification.

[0585] It can be understood that, with reference to the description related to the process in Figure 2, the verification of the NF identification in this application may include verification based on the trust information of the network function network element, verification based on the first key verification information stored in the NRF, or verification based on the first token issued by the NRF.

[0586] When verifying the NF's identity based on the NF's identity, the first authentication device may perform verification based on the first key verification information stored by the NRF. When verifying the NF's identity based on the first information, the first authentication device may perform verification based on the trust information of the network function network element, wherein the first information includes the trust information; or, when verifying the NF's identity based on the first information, the first authentication device may perform verification based on the first token issued by the NRF, wherein the first information may include the first token.

[0587] Whether the certificate request carries the first information, and / or whether the first information includes trust information or the first token, can be determined by the NF based on verification method information sent by a first authentication device, an OAM device, or a network element, or can be determined based on verification method information pre-configured or stored locally within the NF, or can be determined based on protocol definitions. The first authentication device can determine the verification method information based on local configuration, OAM instructions, or protocol definitions. For verification method information, refer to the description of the process in FIG3 .

[0588] S1103: The first authentication device performs a second verification on the NF identifier according to the NF identifier and / or the first information.

[0589] Among them, the verification method of the NF identifier may include verification based on the trust information of the network function network element, verification based on the first key verification information stored in the NRF, or verification based on the first token issued by the NRF. The above verification methods can refer to the description of the verification method of the NF identifier shown in S104 and will not be repeated here. For example, the instructions for verification based on the trust information of the network function network element can refer to method 1, or refer to the process of Figure 3, Figure 7 or Figure 10; the instructions for verification based on the first key verification information stored in the NRF can refer to method 2, or refer to the process of Figure 4, Figure 8 or Figure 11; the instructions for verification based on the first token issued by the NRF can refer to method 3 or refer to the process of Figure 5 or Figure 9. The difference is that in the verification process of the issuance stage, the message names related to the challenge response message in methods 1 to 3 can be replaced with certificate requests or related messages.

[0590] Optionally, after determining that the second verification is passed, the first authentication device may store a second association relationship, where the second association relationship may include an association relationship between the identifier of the NF and the account that sends the certificate request.

[0591] S1104: After determining that the second verification is passed, the first authentication network element issues a first certificate corresponding to the NF identifier.

[0592] Based on the process shown in Figure 12, the first authentication device can perform a second verification based on the certificate request and, upon determining that the second verification has passed, issue a first certificate corresponding to the NF's identity. Accordingly, the NF can obtain the first certificate issued by the first authentication device. Based on the process shown in Figure 12, it is possible to support or adapt the verification of the NF's identity and the issuance of a certificate during the certificate issuance phase of the ACME protocol.

[0593] In a possible embodiment, the first authentication device may issue the first certificate after performing a third verification on the identifier of the NF according to the domain name or IP address of the NF, so as to further improve security.

[0594] As an example of performing a third verification, the first authentication device can determine the account associated with the NF's identifier (referred to as the first account) based on the second association relationship. This account can be the account that sent the certificate request. Additionally, the first authentication device can determine the account associated with the NF's domain name (or IP address) (referred to as the second account) based on the NF's domain name (or IP address) in the certificate request message and the first association relationship. If the first account and the second account are identical (i.e., the accounts' public keys or public key identifiers are identical), it can be determined that the NF's identifier and the NF's domain name (or IP address) associated with the same account have an association relationship, i.e., a third association relationship. The third association relationship can be an association relationship between the NF's domain name (or IP address) and the NF's identifier. The first authentication device can perform a third verification based on this third association relationship, namely, comparing the NF's domain name (or IP address) and NF's identifier in the third association relationship with the NF's domain name (or IP address) and NF's identifier in the certificate request message. If they are identical, the third verification can be determined to have succeeded; otherwise, if they are different, the third verification can be determined to have failed.

[0595] In S1104, the first authentication device may issue a first certificate if it is determined that the third verification is passed.

[0596] It is understood that, in order to implement the functions in the above embodiments, the base station and the terminal include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in conjunction with the units and method steps of the various examples described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a computer software-driven hardware manner depends on the specific application scenario and design constraints of the technical solution.

[0597] Figures 13 and 14 are schematic diagrams of possible communication devices provided in embodiments of the present application. These communication devices can be used to implement the functions of network elements or devices, such as the NF, first authentication device, or second authentication device, in the above-mentioned method embodiments, thereby also achieving the beneficial effects of the above-mentioned method embodiments. In the embodiments of the present application, the communication device can be a NF, a first authentication device, or a second authentication device, or can also be a component applied to the above-mentioned modules or network elements, such as a functional module or chip.

[0598] As shown in Figure 13, communication device 1300 includes a processing unit 1310 and a transceiver unit 1320. Communication device 1300 is used to implement the functions of the NF, first authentication device, or second authentication device in the method embodiments shown in any of the flowcharts in Figures 2 to 12 above. Transceiver unit 1320 can be used to perform receiving and / or transmitting operations. Processing unit 1310 can be used to perform other operations besides receiving and transmitting.

[0599] For example, when communication device 1300 is used to implement the NF functionality in the method embodiment shown in FIG2 , transceiver unit 1320 may be used to send an order request, receive a challenge message, and send a challenge response message. Furthermore, transceiver unit 1320 may also be used to obtain a first certificate by sending a certificate request.

[0600] For another example, when communication device 1300 is used to implement the functions of the first authentication device in the method embodiment shown in FIG2 , transceiver unit 1320 may be configured to receive an order request, send a challenge message, and receive a challenge response message. Furthermore, processing unit 1310 may also be configured to perform verification based on the NF's identifier and / or the first information. Transceiver unit 1320 may also receive a certificate request, and processing unit 1310 may also issue a first certificate.

[0601] The functions of the processing unit 1310 and the transceiver unit 1320 in other embodiments can be referred to the actions in the embodiments and will not be described in detail.

[0602] For a more detailed description of the processing unit 1310 and the transceiver unit 1320 , reference may be made to the relevant description in the method embodiment shown in FIG. 3 .

[0603] As shown in Figure 14, the communication device 1400 includes at least one processor 1410 and an interface circuit 1420. The processor 1410 and the interface circuit 1420 are coupled to each other. It will be understood that the interface circuit 1420 can be a transceiver or an input / output interface. Optionally, the communication device 1400 may also include at least one memory 1430 for storing instructions executed by the processor 1410, or storing input data required by the processor 1410 to execute instructions, or storing data generated after the processor 1410 executes instructions. When the communication device 1400 is used to implement the method shown in Figure 4, the processor 1410 is used to implement the functions of the processing unit 1310 described above, and the interface circuit 1420 is used to implement the functions of the transceiver unit 1320 described above.

[0604] When the aforementioned communication device is a chip implemented in a NF, a first authentication device, or a second authentication device, the chip implements the functions of the NF, the first authentication device, or the second authentication device in the aforementioned method embodiments. The chip can receive information sent by other network elements or devices via other modules (e.g., communication interfaces) within the NF, the first authentication device, or the second authentication device, or the chip can send information to other modules (e.g., communication interfaces) within the NF, the first authentication device, or the second authentication device. The information is sent by the NF, the first authentication device, or the second authentication device to other network elements or devices.

[0605] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0606] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions executable by a processor. The software instructions can be composed of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, removable hard disk, CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a NF network element, a management device, a first authentication device, a second device, or a CMF network element. The processor and storage medium can also exist as discrete components in a NF network element, a management device, a first authentication device, a second device, or a CMF network element.

[0607] An embodiment of the present application also provides a communication system, including one or more network elements or devices in an NF, a first authentication device or a second authentication device for implementing the above-mentioned method embodiment, and is used to implement any communication method described in Figures 2 to 12.

[0608] An embodiment of the present application further provides a computer-readable storage medium, which is used to store computer programs or instructions. When the computer-readable storage medium is executed, the method shown in the above method embodiment is implemented.

[0609] The embodiment of the present application also provides a computer program product, which, when executed on a computer, enables the method shown in the method embodiment to be implemented.

[0610] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0611] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0612] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of this application, the character " / " indicates that the previous and next associated objects are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0613] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

Claims

1. A communication method, characterized in that: include: Sending an order request, where the order request includes an identifier of the network function network element, and the order request is used to request creation of an order for issuing a first certificate for the identifier of the network function network element; receiving a challenge message, the challenge message including verification method information, the verification method information being used to indicate a method for verifying the identifier of the network function network element in the order; Sending a challenge response message according to the verification mode information, the challenge response message including the identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, the identifier of the network function network element and / or the first information being used to verify the identifier of the network function network element in the order; The first certificate is obtained by sending a certificate request message, where the certificate request message is used to complete the order.

2. The method according to claim 1, wherein The verification method is to perform the verification according to the trust information of the network function network element, and the first information includes the trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; or First signature information obtained by signing the identification of the network function network element; or A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

3. The method according to claim 1, wherein The challenge response message includes the identifier of the network function network element, and the verification method is to perform the verification according to the first key verification information stored in the network repository function network element.

4. The method according to claim 3, wherein The method further comprises: A registration request message is sent to the network repository function network element, where the registration request message includes an identifier of the network function network element and first key verification information, where the first key verification information is determined based on a public key of an account of the network function network element.

5. The method according to claim 1, wherein The verification method is to perform the verification based on a first token issued by an operation and maintenance network entity within the operator network, and the first information includes the first token.

6. The method according to claim 5, wherein The first token is obtained according to a private key of the network repository function network element.

7. The method according to claim 5 or 6, characterized in that The first token includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

8. The method according to claim 5 or 6, wherein: The method further comprises: Send at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

9. The method according to any one of claims 1 to 8, wherein: The challenge response message also includes second signature information obtained according to the private key of the account of the network function network element.

10. The method according to any one of claims 1 to 9, wherein: The certificate request message includes the identifier of the network function network element.

11. The method according to any one of claims 1 to 10, wherein: The challenge response message also includes indication information of the public key of the network function network element.

12. A communication method, characterized in that: include: receiving an order request, the order request including an identifier of a network function network element, the order request being used to request creation of an order for issuing a first certificate for the identifier of the network function network element; Determining a verification method for verifying the identifier of the network function network element according to the identifier of the network function network element; Sending a challenge message, wherein the challenge message includes verification mode information, and the verification mode information is used to indicate the verification mode; receiving a challenge response message corresponding to the verification mode information, where the challenge response message includes an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element; Performing the verification according to the identifier of the network function network element and / or the first information; A certificate request message is received, where the certificate request message is used to complete the order, and the first certificate is issued if the verification passes.

13. The method according to claim 12, wherein: The verification method is to perform the verification according to the trust information of the network function network element, and the first information includes the trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; or First signature information obtained by signing the identification of the network function network element; or A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

14. The method according to claim 13, wherein The trust information includes the second certificate, and the verification according to the first information includes: Obtaining a root certificate of the second certificate; The second certificate is verified against the root certificate.

15. The method according to claim 13 or 14, characterized in that The trust information includes the first signature information, where the first signature information is obtained by signing the identifier of the network function network element according to the private key of the second authentication device, and the verification based on the first information includes: Obtaining a public key of the second authentication device; The first signature information is verified according to the public key of the second authentication device.

16. The method according to any one of claims 13 to 15, wherein: The trust information includes the first message verification code, and performing the verification according to the first information includes: Obtaining the symmetric key according to the identifier of the network function network element; Obtaining a second message authentication code according to the symmetric key and the identifier of the network function network element; The first message authentication code is compared with the second message authentication code.

17. The method according to claim 12, wherein The challenge response message includes the identifier of the network function network element, and the verification method is to perform the verification according to the first key verification information stored in the network repository function network element.

18. The method according to claim 17, wherein The first key verification information is determined based on a public key of an account of the network function network element; The performing the verification according to the identifier of the network function network element includes: Obtaining the first key verification information from the network repository function network element according to the identifier of the network function network element; The first key verification information is verified according to the public key of the account of the network function network element.

19. The method according to claim 12, wherein The verification method is to perform the verification based on a first token issued by an operation and maintenance network entity within the operator network, and the first information includes the first token.

20. The method according to claim 19, wherein The first token is obtained according to the private key of the operation and maintenance network entity, and the verification according to the first information includes: The first token is verified according to the public key of the operation and maintenance network entity.

21. The method according to claim 19 or 20, wherein: The first token includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

22. The method according to claim 19 or 20, wherein: The method further comprises: Send at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

23. The method according to any one of claims 12 to 22, wherein: The challenge response message further includes second signature information obtained according to a private key of the account of the network function network element, and the method further includes: Obtaining the public key of the network function network element; The second signature information is verified according to the public key of the account of the network function network element.

24. The method according to claim 23, wherein After the second signature information is verified and the verification is passed, the method further includes: Determine an association between the identifier of the network function network element and the account.

25. The method according to claim 23 or 24, wherein: The challenge response message also includes indication information of the public key of the network function network element.

26. The method according to any one of claims 12 to 25, wherein: The certificate request message includes the identifier of the network function network element.

27. A communication method, characterized in that: include: Sending an account request, where the account request is used to request creation or update of an account for a network function network element, the account request including an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, and the identifier of the network function network element and / or the first information is used to verify the identifier of the network function network element; An account response message is received, where the account response message is used to indicate that the account creation is complete; and the network function network element obtains a first certificate issued for the identifier of the network function network element by sending a certificate request message.

28. The method of claim 27, wherein: The first information includes trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; First signature information obtained by signing the identification of the network function network element; A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

29. The method of claim 27, wherein: The first information includes a first token.

30. The method of claim 29, wherein The first token is obtained according to the private key of the operation and maintenance network entity within the operator network.

31. The method according to claim 29 or 30, wherein The first token also includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

32. The method according to claim 29 or 30, wherein: The method further comprises: Send at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

33. The method according to any one of claims 27 to 32, wherein: The identifier of the network function network element in the account request is carried in the external account binding identifier field.

34. The method according to any one of claims 27 to 33, wherein: The account request further includes second signature information obtained according to a private key of the account of the network function network element.

35. The method according to any one of claims 27 to 34, wherein: The certificate request message includes the identifier of the network function network element.

36. The method according to any one of claims 27 to 35, wherein: The account request and / or the certificate request message further includes indication information of the public key of the network function network element.

37. A communication method, characterized in that: include: receiving an account request, where the account request is used to request creation or update of an account for a network function network element, and the account request includes an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element; The identifier of the network function network element is verified according to the identifier of the network function network element and / or the first information.

38. The method of claim 37, wherein: The first information includes trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; First signature information obtained by signing the identification of the network function network element; A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

39. The method of claim 38, wherein The trust information includes the second certificate, and the verification according to the first information includes: Obtaining a root certificate of the second certificate; The second certificate is verified against the root certificate.

40. The method according to claim 38 or 39, wherein The trust information includes the first signature information, where the first signature information is obtained by signing the identifier of the network function network element according to the private key of the second authentication device, and the verification based on the first information includes: Obtaining a public key of the second authentication device; The first signature information is verified according to the public key of the second authentication device.

41. The method according to any one of claims 38 to 40, wherein: It is characterized by: The trust information includes the first message verification code, and performing the verification according to the first information includes: Obtaining the symmetric key according to the identifier of the network function network element; Obtaining a second message authentication code according to the symmetric key and the identifier of the network function network element; The first message authentication code is compared with the second message authentication code.

42. The method of claim 37, wherein: The account request includes the identifier of the network function network element, and the verification method is to perform the verification according to the first key verification information stored in the network repository function network element.

43. The method of claim 42, wherein: The first key verification information is determined based on a public key of an account of the network function network element; The performing the verification according to the identifier of the network function network element includes: Obtaining the first key verification information from the network repository function network element according to the identifier of the network function network element; The first key verification information is verified according to the public key of the account of the network function network element.

44. The method of claim 43, wherein: The verifying the first key verification information according to the public key of the account of the network function network element includes: Determining second key verification information according to the public key of the account of the network function network element; The second key verification information and the first key verification information are compared.

45. The method of claim 37, wherein The first information includes a first token.

46. ​​The method of claim 45, wherein The first token is obtained according to a private key of an operation and maintenance network entity within the operator network, and the verification according to the first information includes: The first token is verified according to the public key of the operation and maintenance network entity.

47. The method according to claim 45 or 46, wherein The first token includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

48. The method according to claim 45 or 46, wherein The method further comprises: Receive at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

49. The method according to any one of claims 37 to 48, wherein: The account request further includes second signature information obtained according to a private key of the account of the network function network element, and the method further includes: Obtaining the public key of the network function network element; The second signature information is verified according to the public key of the account of the network function network element.

50. The method of claim 49, wherein After the second signature information is verified and the verification is passed, the method further includes: Determine an association between the identifier of the network function network element and the account.

51. The method according to claim 49 or 50, wherein The account request and / or certificate request message includes indication information of the public key of the network function network element.

52. The method according to any one of claims 37 to 51, wherein: The certificate request message includes the identifier of the network function network element.

53. A communication method, characterized in that: include: receiving an account response message, the account response message being used to indicate that the account creation or the account update is complete, the account response message including indication information of the account; Sending a pre-authorization request, the pre-authorization request including indication information of the account of the network function network element, the pre-authorization request also including an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, the pre-authorization request being used to request pre-authorization of the account and verification of the identifier of the network function network element; receiving a pre-authorization response message, wherein the pre-authorization response message is used to indicate that the pre-authorization of the account is completed and that the verification is passed; A first certificate issued for the identifier of the network function network element is obtained by sending a certificate request.

54. The method of claim 53, wherein: The first information includes trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; First signature information obtained by signing the identification of the network function network element; A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

55. The method of claim 53, wherein: The first information includes a first token.

56. The method of claim 55, wherein: The first token is obtained according to the private key of the operation and maintenance network entity within the operator network.

57. The method according to claim 55 or 56, wherein The first token includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

58. The method according to claim 55 or 56, wherein The method further comprises: Send at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

59. The method according to any one of claims 53 to 58, wherein: The pre-authorization request also includes second signature information obtained according to the private key of the account of the network function network element.

60. The method according to any one of claims 53 to 59, wherein: The certificate request message includes the identifier of the network function network element.

61. The method according to any one of claims 53 to 60, wherein: The certificate request also includes indication information of the public key of the network function network element.

62. A communication method, characterized in that: include: Sending an account response message, where the account response message is used to indicate that the account creation or update is complete, and the account response message includes indication information of the account; receiving a pre-authorization request, the pre-authorization request including indication information of the account of the network function network element, the pre-authorization request also including an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, the pre-authorization request being used to request pre-authorization of the account and to request verification of the identifier of the network function network element; Verifying the identifier of the network function network element according to the identifier of the network function network element and / or the first information; When it is determined that the verification is passed, a pre-authorization response message is sent, and the pre-authorization response message is used to indicate that the pre-authorization of the account is completed; and / or, a certificate request message is received, and when it is determined that the verification is passed, a first certificate is issued for the identifier of the network function network element.

63. The method of claim 62, wherein: The first information includes trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; First signature information obtained by signing the identification of the network function network element; A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

64. The method of claim 63, wherein: The trust information includes the second certificate, and the verification according to the first information includes: Obtaining a root certificate of the second certificate; The second certificate is verified against the root certificate.

65. The method according to claim 63 or 64, wherein The trust information includes the first signature information, where the first signature information is obtained by signing the identifier of the network function network element according to the private key of the second authentication device, and the verification based on the first information includes: Obtaining a public key of the second authentication device; The first signature information is verified according to the public key of the second authentication device.

66. The method according to any one of claims 63 to 65, wherein: The trust information includes the first message verification code, and performing the verification according to the first information includes: Obtaining the symmetric key according to the identifier of the network function network element; Obtaining a second message authentication code according to the symmetric key and the identifier of the network function network element; The first message authentication code is compared with the second message authentication code.

67. The method of claim 62, wherein: The pre-authorization request includes the identifier of the network function network element, and the verification method is to perform the verification according to the first key verification information stored in the network repository function network element.

68. The method of claim 67, wherein The first key verification information is determined based on a public key of an account of the network function network element; The performing the verification according to the identifier of the network function network element includes: Obtaining the first key verification information from the network repository function network element according to the identifier of the network function network element; The first key verification information is verified according to the public key of the account of the network function network element.

69. The method of claim 68, wherein The verifying the first key verification information according to the public key of the account of the network function network element includes: Determining second key verification information according to the public key of the account of the network function network element; The second key verification information and the first key verification information are compared.

70. The method of claim 62, wherein The first information includes a first token.

71. The method of claim 70, wherein The first token is obtained according to a private key of an operation and maintenance network entity within the operator network, and the verification according to the first information includes: The first token is verified according to the public key of the operation and maintenance network entity.

72. The method of claim 70 or 71, wherein: The first token includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

73. The method of claim 70 or 71, wherein: The method further comprises: Receive at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

74. The method according to any one of claims 62 to 73, wherein: The pre-authorization request further includes second signature information obtained according to a private key of the account of the network function network element, and the method further includes: Obtaining the public key of the network function network element; The second signature information is verified according to the public key of the account of the network function network element.

75. The method of claim 74, wherein After the second signature information is verified and the verification is passed, the method further includes: Determine an association between the identifier of the network function network element and the account.

76. The method according to any one of claims 62 to 75, wherein: The certificate request includes the identifier of the network function network element.

77. The method according to any one of claims 62 to 76, wherein: The certificate request also includes indication information of the public key of the network function network element.

78. A communication method, characterized in that: include: Sending a challenge response message, wherein the challenge response message is used to instruct the first authentication device to perform a first verification on the domain name or IP address of the network function network element; Sending a certificate request, where the certificate request includes the identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, and the certificate request is used to request a first certificate corresponding to the identifier of the network function network element; The identifier of the network function network element and / or the first information is used by the first authentication device to perform a second verification on the identifier of the network function network element; Obtaining the first certificate, where the first certificate is issued by the first authentication device after determining that the second verification is passed; The first verification is based on the domain name or Internet Protocol address of the network function network element; and / or, The second verification is a verification based on the identifier of the network function network element and / or the first information.

79. The method of claim 78, wherein The first information includes trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; First signature information obtained by signing the identification of the network function network element; A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

80. The method of claim 78, wherein The certificate request includes the identifier of the network function network element, and the verification method is to perform the verification according to the first key verification information stored in the network repository function network element.

81. The method of claim 80, wherein The method further comprises: A registration request message is sent to the network repository function network element, where the registration request message includes an identifier of the network function network element and first key verification information, where the first key verification information is determined based on a public key of an account of the network function network element.

82. The method of claim 78, wherein The first information includes a first token.

83. The method of claim 82, wherein The first token is obtained according to the private key of the operation and maintenance network entity within the operator network.

84. The method of claim 82 or 83, wherein: The first token includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

85. The method of claim 82 or 83, wherein: The method further comprises: Send at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

86. The method according to any one of claims 78 to 85, wherein: The certificate request further includes second signature information obtained according to a private key of the account of the network function network element.

87. The method according to any one of claims 78 to 86, wherein: The certificate request includes the domain name or IP address of the network function network element, and the domain name or IP address of the network function network element is used to perform a third verification on the identifier of the network function network element.

88. A communication method, characterized in that include: Performing a first verification on the domain name or IP address of the network function element; receiving a certificate request, the certificate request including an identifier of the network function network element and / or first information obtained based on the identifier of the network function network element, the certificate request being used to request a first certificate corresponding to the identifier of the network function network element; After determining that the first verification passes, performing a second verification on the identifier of the network function network element according to the identifier of the network function network element and / or the first information; After determining that the second verification is passed, the first certificate is issued for the identifier of the network function network element.

89. The method of claim 88, wherein The first information includes trust information; The trust information includes at least one of the following: a second certificate of the network function network element, wherein the second certificate includes an identifier of the network function network element; First signature information obtained by signing the identification of the network function network element; A first message authentication code is obtained according to the symmetric key and the identifier of the network function network element.

90. The method of claim 89, wherein The trust information includes the second certificate, and performing the second verification according to the first information includes: Obtaining a root certificate of the second certificate; The second certificate is verified against the root certificate.

91. The method of claim 89 or 90, wherein: The trust information includes the first signature information, where the first signature information is obtained by signing the identifier of the network function network element according to the private key of the second authentication device, and performing the second verification according to the first information includes: Obtaining a public key of the second authentication device; The first signature information is verified according to the public key of the second authentication device.

92. The method according to any one of claims 89 to 91, wherein: It is characterized by: The trust information includes the first message verification code, and performing the second verification according to the first information includes: Obtaining the symmetric key according to the identifier of the network function network element; Obtaining a second message authentication code according to the symmetric key and the identifier of the network function network element; The first message authentication code is compared with the second message authentication code.

93. The method of claim 88, wherein The pre-authorization request includes the identifier of the network function network element, and the second verification method is to perform verification based on the first key verification information stored in the network repository function network element.

94. The method of claim 93, wherein The first key verification information is determined based on a public key of an account of the network function network element; The performing the second verification according to the identifier of the network function network element includes: Obtaining the first key verification information from the network repository function network element according to the identifier of the network function network element; The first key verification information is verified according to the public key of the account of the network function network element.

95. The method of claim 94, wherein The verifying the first key verification information according to the public key of the account of the network function network element includes: Determining second key verification information according to the public key of the account of the network function network element; The second key verification information and the first key verification information are compared.

96. The method of claim 88, wherein The first information includes a first token.

97. The method of claim 96, wherein The first token is obtained according to a private key of an operation and maintenance network entity within the operator network, and the second verification is performed according to the first information, including: The first token is verified according to the public key of the operation and maintenance network entity.

98. The method of claim 96 or 97, wherein: The first token also includes: Information indicating that the first token is used for the verification; and / or, Indication information of the public key of the account of the network function network element.

99. The method of claim 96 or 97, wherein: The method further comprises: Send at least one of the following: Information used to indicate that the token of the network function network element is used for the verification; Indication information of the public key of the account of the network function network element.

100. The method according to any one of claims 88 to 99, wherein: The certificate request further includes second signature information obtained according to a private key of the account of the network function network element, and the method further includes: Obtaining the public key of the network function network element; The second signature information is verified according to the public key of the account of the network function network element.

101. The method of claim 100, wherein: After the second signature information is verified and the verification is passed, the method further includes: Determine an association between the identifier of the network function network element and the account.

102. The method according to any one of claims 88 to 101, wherein: The certificate request also includes a domain name or IP address of a network function network element. Before the first authentication device issues the first certificate, the method further includes: A third verification is performed on the identifier of the network function network element according to the domain name or IP address of the network function network element.

103. A communication device, characterized in that The method comprises a unit or module for executing the method according to any one of claims 1 to 102.

104. A communication device, characterized in that The device comprises a processor configured to execute computer programs or instructions to implement the method according to any one of claims 1 to 102.

105. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by the communication device, the method according to any one of claims 1 to 102 is implemented.

106. A computer program product, characterized in that When the computer program product is executed by a computer, the computer executes the method according to any one of claims 1 to 102.

107. A communication system, characterized in that include: a first communication device and a second communication device; The first communication device is used to execute the method according to any one of claims 1 to 11, and the second communication device is used to execute the method according to any one of claims 12 to 26; or The first communication device is used to execute the method according to any one of claims 27 to 36, and the second communication device is used to execute the method according to any one of claims 37 to 52; or The first communication device is used to execute the method according to any one of claims 53 to 61, and the second communication device is used to execute the method according to any one of claims 62 to 77; or The first communication device is used to execute the method according to any one of claims 78 to 87, and the second communication device is used to execute the method according to any one of claims 88 to 102.

Citation Information

Patent Citations

  • Communication method and network element equipment

    CN117082507A

  • Secure communication method and device

    CN117118622A

  • Key management

    WO2021165925A1