Wireless communication method and apparatus, and device

WO2025185719A8PCT designated stage Publication Date: 2025-10-02VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/081132
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-08
Filing Date
2025-03-06
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In the existing technology, terminal devices need to store serial numbers (SQNs) for a long time to prevent fake base stations from using intercepted AUTNs to spoof the network, resulting in terminal devices with poor storage capabilities being unable to achieve effective protection.

Method used

The network node generates second information (such as AUTN) based on the first information and the first key sent by the terminal device. The terminal device verifies the second information using the first key, avoiding the introduction of SQN storage and preventing fake base stations from impersonating the network.

Benefits of technology

It solves the need for long-term storage of SQNs in terminal devices, improves network security for devices with poor storage capacity, and prevents fake base stations from impersonating the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025081132_02102025_PF_FP_ABST
    Figure CN2025081132_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the field of communications, and discloses a wireless communication method and apparatus, and a device. The wireless communication method in embodiments of the present application comprises: a network node receives first information from a terminal device, wherein the first information comprises first challenge information; the network node executes a first operation on the basis of the first information and a first key, wherein the first operation comprises at least one of the following: generating second information; and sending the second information to the terminal device, wherein the second information is used for authentication or authorization.
Need to check novelty before this filing date? Find Prior Art

Description

Wireless communication method, device and equipment

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on March 8, 2024, with application number 202410267952.3 and invention name “Wireless Communication Methods, Devices and Equipment”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communications, and more specifically, to a wireless communication method, apparatus, and device. Background Art

[0004] To prevent the reuse of network authentication parameters, the network generates an authentication token (AUTN) based on a monotonically increasing sequence number (SQN) in addition to the random number (RAND) sent to the terminal device (UE). The AUTN includes the SQN. Upon receiving the AUTN, the UE determines whether the SQN is greater than the previously received one. If not, it is considered a duplicate AUTN and is ignored. This prevents fake base stations from using intercepted AUTNs to impersonate the network. However, the above solution requires the UE to store the SQN for a long time, which places a heavy burden on some UEs with poor storage capabilities, or even makes it impossible. Summary of the Invention

[0005] The embodiments of the present application provide a wireless communication method, apparatus, and device that can solve the problem of requiring a terminal device to store an SQN for a long time when preventing a pseudo base station from using an intercepted AUTN to impersonate a network.

[0006] In a first aspect, a wireless communication method is provided, comprising:

[0007] The network node receives first information from the terminal device, wherein the first information includes first challenge information;

[0008] The network node performs a first operation based on the first information and the first key;

[0009] The first operation includes at least one of the following:

[0010] generating second information;

[0011] sending the second information to the terminal device;

[0012] The second information is used for authentication or authorization.

[0013] In a second aspect, a wireless communication method is provided, including:

[0014] The terminal device sends first information to the network node, wherein the first information includes first challenge information;

[0015] The terminal device receives second information from the network node, wherein the second information is generated based on the first information and is used for authentication or authorization;

[0016] The terminal device verifies the second information based on the first key and at least one of the following:

[0017] The first information and the first challenge information.

[0018] According to a third aspect, a wireless communication device is provided, including:

[0019] a transceiver unit, configured to receive first information from a terminal device, wherein the first information includes first challenge information;

[0020] a processing unit, configured to perform a first operation based on the first information and a first key;

[0021] The first operation includes at least one of the following:

[0022] generating second information;

[0023] sending the second information to the terminal device;

[0024] The second information is used for authentication or authorization.

[0025] According to a fourth aspect, another wireless communication device is provided, comprising:

[0026] a transceiver unit, configured to send first information to a network node, wherein the first information includes first challenge information;

[0027] The transceiver unit is further configured to receive second information from the network node, wherein the second information is generated based on the first information and is used for authentication or authorization;

[0028] a processing unit, configured to verify the second information based on the first key and at least one of the following:

[0029] The first information and the first challenge information.

[0030] In a fifth aspect, a network side device is provided, which includes a transceiver, a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.

[0031] In a sixth aspect, a network-side device is provided, including a processor and a communication interface;

[0032] The communication interface is configured to receive first information from a terminal device, wherein the first information includes first challenge information;

[0033] The processor is configured to perform a first operation based on the first information and a first key;

[0034] The first operation includes at least one of the following:

[0035] generating second information;

[0036] sending the second information to the terminal device;

[0037] The second information is used for authentication or authorization.

[0038] In the seventh aspect, a terminal device is provided, which includes a transceiver, a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the second aspect are implemented.

[0039] In an eighth aspect, a terminal device is provided, comprising a processor and a communication interface;

[0040] The communication interface is configured to send first information to a network node, wherein the first information includes first challenge information; the communication interface is further configured to receive second information from the network node, wherein the second information is generated based on the first information and is used for authentication or authorization;

[0041] The processor is configured to verify the second information based on the first key and at least one of the following:

[0042] The first information and the first challenge information.

[0043] In the ninth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.

[0044] In the tenth aspect, a wireless communication system is provided, comprising: a terminal and a network side device, wherein the network side device can be used to execute the steps of the method described in the first aspect, and the terminal can be used to execute the steps of the method described in the second aspect.

[0045] In the eleventh aspect, a chip is provided, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method as described in the first aspect, or to implement the method as described in the second aspect.

[0046] In the twelfth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the wireless communication method as described in the first aspect or the second aspect.

[0047] In an embodiment of the present application, the network node generates the second information (such as AUTN) or sends the second information (such as AUTN) to the terminal device based on the first key and the first information or the first challenge information sent by the terminal device, so that the terminal device can verify the second information based on the first key and the first information including the first challenge information to prevent the pseudo base station from using the previously intercepted second information (such as AUTN) to counterfeit the network. In addition, when generating the second information (such as AUTN), the network node refers to the first information including the first challenge information sent by the terminal device, and the terminal device no longer introduces the SQN when verifying the second information (such as AUTN). This can solve the problem of requiring the terminal device to store the SQN for a long time when preventing the pseudo base station from using the previously intercepted AUTN to counterfeit the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0049] FIG1 is a schematic diagram of a communication system architecture provided in an embodiment of the present application.

[0050] FIG2 is a schematic flowchart of a wireless communication method provided according to an embodiment of the present application.

[0051] FIG3 is a schematic block diagram of a wireless communication device according to an embodiment of the present application.

[0052] FIG4 is a schematic block diagram of another wireless communication device provided according to an embodiment of the present application.

[0053] FIG5 is a schematic block diagram of a communication device provided according to an embodiment of the present application.

[0054] FIG6 is a schematic diagram of the hardware structure of a terminal provided according to an embodiment of the present application.

[0055] FIG7 is a schematic block diagram of a network-side device provided according to an embodiment of the present application.

[0056] FIG8 is a schematic block diagram of another network-side device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0057] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0058] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.

[0059] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.

[0060] It is worth noting that the technology described in the embodiments of the present application is not limited to the Internet of Things (IoT) system, but can also be used in other wireless communication systems, such as Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), Bluetooth systems, or other systems. In the embodiments of the present application, the terms "system" and "network" are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, but these techniques can also be applied to systems other than NR systems, such as 6G (6 th Generation, 6G) communication system.

[0061] Figure 1 shows a block diagram of a wireless communication system applicable to embodiments of the present application. The wireless communication system includes a terminal 11 and a network-side device 12. The network node described in embodiments of the present application may be the network-side device 12.

[0062] The terminal 11 may be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipborne equipment, pedestrian user equipment (PUE), smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM or self-service machine, etc. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. The vehicle-mounted device may also be referred to as a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip, or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application.

[0063] The network side device 12 may include an access network device or a core network device.

[0064] Access network equipment may also be referred to as radio access network (RAN) equipment, radio access network functions, or radio access network units. Access network equipment may include base stations, wireless local area network (WLAN) access points (APs), or wireless fidelity (WiFi) nodes. Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.

[0065] Among them, the core network equipment may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (EASDF), unified data management (UDM), unified data repository (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BSF), application function ( Function, AF), Network Data Analytics Function (NWDAF), Location Management Function (LMF), etc. It should be noted that in the embodiment of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.

[0066] To facilitate understanding of the technical solutions of the embodiments of the present application, the technical solutions of the present application are described in detail below through specific embodiments. The above related technologies can be combined arbitrarily with the technical solutions of the embodiments of the present application as optional solutions, and all of them fall within the scope of protection of the embodiments of the present application. The embodiments of the present application include at least part of the following contents.

[0067] FIG2 is a schematic flowchart of a wireless communication method 200 according to an embodiment of the present application. As shown in FIG2 , the wireless communication method 200 may include at least part of the following contents:

[0068] S210, the terminal device sends first information to the network node, wherein the first information includes first challenge information;

[0069] S220, the network node receives the first information from the terminal device;

[0070] S230, the network node performs a first operation based on the first information and the first key;

[0071] The first operation includes at least one of the following:

[0072] generating second information;

[0073] sending the second information to the terminal device;

[0074] Wherein, the second information is used for authentication or authorization;

[0075] S240, the terminal device receives the second information from the network node;

[0076] S250: The terminal device verifies the second information based on the first key and at least one of the following:

[0077] The first information and the first challenge information.

[0078] It should be understood that FIG2 shows the steps or operations of the wireless communication method 200, but these steps or operations are merely examples, and the present application may also perform other operations or variations of the operations in FIG2.

[0079] Exemplarily, the first key may be the same long-term key (LTK) configured for both the network node and the terminal device, or a key (KEY) derived from the LTK.

[0080] In an embodiment of the present application, the network node generates the second information (such as AUTN) or sends the second information (such as AUTN) to the terminal device based on the first key and the first information or the first challenge information sent by the terminal device, so that the terminal device can verify the second information based on the first key and the first information or the first challenge information to prevent the pseudo base station from using the intercepted second information (such as AUTN) to counterfeit the network. In addition, the network node refers to the first information or the first challenge information sent by the terminal device when generating the second information (such as AUTN). The terminal device no longer introduces the SQN when verifying the second information (such as AUTN), which can solve the problem of requiring the terminal device to store the SQN for a long time when preventing the pseudo base station from using the intercepted AUTN to counterfeit the network.

[0081] In some embodiments, the first challenge information is also referred to as first random information or a first random number (RAND1), etc., but is not limited thereto, such as character string information, sequentially increasing or decreasing quantity information, etc.

[0082] It should be understood that in the embodiment of the present application, the terminal device is aware of the first key in advance.

[0083] In some embodiments, the network node includes but is not limited to at least one of the following:

[0084] Authentication Server Function (AUSF), Unified Data Management (UDM), Authentication Center (AuC).

[0085] In an embodiment of the present application, the second information is used for authentication or authorization. For example, if the second information is AUTN, the terminal device can perform authentication or authorization based on the second information.

[0086] In some embodiments, the second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information;

[0087] The second operation includes but is not limited to at least one of the following:

[0088] performing encryption based on the first key;

[0089] performing hashing based on the first key;

[0090] Hash;

[0091] The XOR operation is performed based on the agreed information. For example, the agreed information may be a specific string, a value of a message counter, or the like.

[0092] For example, the first information or the first challenge information, or the hashed first information or the first challenge information may be used to replace the SQN in the AUTN to perform encryption, and so on.

[0093] In some embodiments, the wireless communication method 200 further includes:

[0094] The network node sends second challenge information.

[0095] The second challenge information is finally received by the terminal device.

[0096] In some embodiments, the second challenge information is also referred to as second random information or a second random number (RAND2), etc., but is not limited thereto, such as character string information, sequentially increasing or decreasing quantity information, etc.

[0097] For example, the network node sends second challenge information to the terminal device.

[0098] For another example, the network node broadcasts the second challenge information, and the terminal device receives the second challenge information.

[0099] For another example, the network node sends the second challenge information to the base station system, the base station system broadcasts the second challenge information, and the terminal device receives the second challenge information.

[0100] Exemplarily, the network node sends a message carrying the second challenge information to the base station system. The message does not set a receiving target, or the set receiving target does not include the terminal device identifier (for example, a group identifier), or although it includes the terminal device identifier, it also includes or may include more other terminal device identifiers. Therefore, the message is not for the terminal device, and the base station cannot or is unable to directly send the content of the message to the terminal device. The base station is required to send a broadcast message carrying the second challenge information by broadcasting. The broadcast message does not carry a receiving target or carries a group identifier or a terminal device identifier list. The terminal device that receives the broadcast message determines whether it is related to it (for example, the terminal device belongs to the group indicated by the group identifier, and the identifier of the terminal device is included in the terminal device identifier list in the broadcast message). If the broadcast message does not include a receiving target, the terminal device that receives the broadcast decides whether to process and respond.

[0101] In some implementations, the network node sends the second challenge information before the network node receives the first information from the terminal device.

[0102] In some implementations, the network device sends the second information together with the second challenge information.

[0103] In some embodiments, the first information further includes at least one of the following: identification information, first response information;

[0104] The first response information is generated based on the second challenge information; and the identification information is used to indicate the terminal device or a contracted user of the terminal device.

[0105] For example, the identification information is a Global Unique Temporary Identifier (GUTI), a Subscriber User Permanent Identifier (SUPI), a Subscriber User Concealed Identifier (SUCI), and the like.

[0106] Exemplarily, the second challenge information is RAND2. In this case, the first response information is response information (Response, RES) calculated for RAND2.

[0107] In some embodiments, the second information is further generated based on the first key and the second challenge information. In other words, the network node can generate the second information based on the first information, the first key and the second challenge information, thereby generating the second information more accurately.

[0108] In some embodiments, the second information is further generated based on the first key, the second challenge information, and the first response information. In other words, the network node can generate the second information based on the first information, the first key, the second challenge information, and the first response information, thereby more accurately generating the second information.

[0109] In some embodiments, the second information includes at least one of the following: the first information, fourth information;

[0110] The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following:

[0111] The first information, the first challenge information, and the first response information.

[0112] Exemplarily, the fourth information may be information obtained through encryption or hashing operations, such as the generation of message authentication code (MAC) information in AUTN based not only on RAND2 but also on at least one of the first information, the first challenge information, and the first response information.

[0113] Therefore, in an embodiment of the present application, the network node generates the second information (such as AUTN) or sends the second information (such as AUTN) to the terminal device based on the first key and the first information or the first challenge information sent by the terminal device, so that the terminal device can verify the second information based on the first key and the first information or the first challenge information to prevent the pseudo base station from using the intercepted second information (such as AUTN) to counterfeit the network. In addition, the network node refers to the first information or the first challenge information sent by the terminal device when generating the second information (such as AUTN). The terminal device no longer introduces the SQN when verifying the second information (such as AUTN), which can solve the problem of requiring the terminal device to store the SQN for a long time when preventing the pseudo base station from using the intercepted AUTN to counterfeit the network.

[0114] The technical solution of this application is described below through Example 1 and Example 2.

[0115] Example 1 may specifically include some or all of the following steps S1-1 to S1-26.

[0116] S1-1. The application function (AF) of the application server (Application Server) sends a first activation message to the network exposure function (NEF).

[0117] The first activation information includes at least one of the following:

[0118] Business information (such as service ID or AF ID);

[0119] Device information (such as device ID) (optional);

[0120] Information 2 (such as random number 2 (RAND2)) (optional);

[0121] Information 3 (such as application data 1 in the following line) (optional).

[0122] Exemplarily, the first activation information may be:

[0123] Activate(Service ID,[Device ID],[RAND2],[Downlink Application Data 1]).

[0124] Exemplarily, the information 3 may be carried through the application container (AC) field.

[0125] S1-2.NEF obtains information about AMF / SMF based on the service information and sends the first activation information to AMF / SMF.

[0126] S1-3. The AMF / SMF sends a second activation message to the gNB / UE based on the service information and / or device information.

[0127] The second activation information includes at least one of the following:

[0128] Business information (such as service ID or AF ID);

[0129] Information 2 (such as RAND2) (optional).

[0130] Exemplarily, the second activation information may be:

[0131] Activate(Service ID,[RAND2]).

[0132] S1-4.AMF / SMF cache information 3 (such as application data 1 below).

[0133] S1-5. The gNB / UE broadcasts the third activation information.

[0134] The third activation information includes at least one of the following:

[0135] Information 2 (such as RAND2) (optional).

[0136] Exemplarily, the third activation information may be:

[0137] Activate([RAND2]).

[0138] S1-6. The device receives the third activation message and determines the response condition. If the response condition is met, the device sends the networking information / message to the gNB / UE.

[0139] The networking information / message includes at least one of the following:

[0140] Information 4, including business information (optional);

[0141] Information 6, including service information, device information, and information 7 (such as random number 1 (RAND1)) (optional);

[0142] Information 10 (optional), including application registration and authentication information;

[0143] Information 11 (optional), including uplink application data.

[0144] For example, the networking information / message may be:

[0145] Networking (Service ID, NC (Service ID, Device ID, [RAND1], [Application registration authentication information (Device ID, Auth-Info)], [Uplink application data (Data)]).

[0146] Exemplarily, some information may be carried through a network container (NC) field.

[0147] Exemplarily, the information 10 may be carried via the AC field.

[0148] Exemplarily, the information 11 may be carried via the AC field.

[0149] S1-7. The gNB / UE verifies the service information and determines whether the service information sent by the device is included in the service information received from the network side. If not, the network information / message is not processed.

[0150] S1-8. gNB / UE optionally selects AMF / SMF based on service information, and gNB / UE sends information 5 to AMF / SMF; optionally, gNB / UE also sends information 10 to AMF / SMF.

[0151] For example, the information sent by the gNB / UE to the AMF / SMF is:

[0152] Send (NC(Service ID,Device ID,[RAND1],[application registration authentication information],[uplink application data])).

[0153] S1-9.AMF / SMF verifies the device information and determines whether the device information sent by the device is in the device information received from NEF / AF. If not, no processing is performed.

[0154] If the device information sent by the device is in the device information received from NEF / AF, AMF / SMF determines whether to skip S1-10 to S1-14, execute S1-15 and subsequent steps, or select the network function (NF) type based on whether the context related to the device information is saved and whether information 10 is included.

[0155] Exemplarily, if S1-10 is to be executed, information 11 (such as uplink application data) continues to be cached.

[0156] S1-10~S1-11.AMF / SMF sends authentication information to AAA-Server (optionally through AAA-Proxy).

[0157] The authentication information includes: information 10 (optional) and device information (optional).

[0158] Exemplarily, the authentication information may be: authentication (Device ID, [application registration authentication information]).

[0159] S1-12. If the AAA-Server has not authenticated the device, it authenticates the device based on information 10.

[0160] S1-13~S1-14.AAA-Server sends result information to AMF / SMF (optionally through AAA-Proxy).

[0161] S1-15.AMF / SMF sends service information, device information (optional), information 13 (including service information (optional), device information (optional)), and information 3 (optional) to the gNB / UE.

[0162] For example, the information sent by the AMF / SMF to the gNB / UE may be:

[0163] Send (Service ID, Device ID, NC (Device ID, [downlink application data 1])).

[0164] Exemplarily, information 13 may be carried via the NC field.

[0165] S1-16. The gNB / UE sends information 13 (optional) and information 3 (optional) to the device.

[0166] For example, the information sent by the gNB / UE to the device may be:

[0167] Send (NC (Device ID, [downlink application data 1])).

[0168] For example, information 13 and information 3 may be encrypted by AMF / SMF.

[0169] S1-17~S1-18.AMF / SMF sends information 11 and device information to NEF / AF (optional).

[0170] For example, the information sent by AMF / SMF to NEF / AF may be:

[0171] Go online (Device ID, [uplink application data]).

[0172] S1-19~S1-20. Optionally, the device sends information 14 (including device information (optional)) and information 15 (optional) (including application data) to the gNB / UE.

[0173] For example, the information sent by the device to the gNB / UE may be:

[0174] Send (NC (Service ID, Device ID, [uplink application data 2 (Data)])).

[0175] For example, the information 14 may be carried via the NC field.

[0176] Exemplarily, the information 15 may be carried via the AC field.

[0177] Exemplarily, the gNB / UE forwards information 14 and information 15 (optional) to the AMF / SMF.

[0178] S1-21~S1-22. Optionally, AMF / SMF sends information 15 and device information to NEF / AF (optional).

[0179] For example, the information sent by AMF / SMF to NEF / AF may be:

[0180] Go online (Device ID, [uplink application data 2]).

[0181] S1-23~S1-24. Optionally, AF sends business information, device information, and information 16 (such as the following application data 2) to AMF / SMF through NEF.

[0182] For example, the information sent by AF to AMF / SMF via NEF is:

[0183] Send (Service ID, Device ID, [downlink application data 2]).

[0184] Exemplarily, the information 16 may be carried via the AC field.

[0185] S1-25~S1-26.AMF / SMF sends service information, device information, information 16, and information 17 (including device information (optional)) to the gNB / UE.

[0186] For example, the information sent by the AMF / SMF to the gNB / UE may be:

[0187] Send (Service ID, Device ID, NC (Device ID, [downlink application data 2])).

[0188] Exemplarily, the information 17 may be carried via the NC field.

[0189] Exemplarily, the gNB / UE forwards information 16 and information 17 to the device.

[0190] For example, the information forwarded by the gNB / UE to the device may be:

[0191] Send (NC(Device ID,[downlink application data 2])).

[0192] Example 2 may specifically include some or all of the following steps S2-1 to S2-25.

[0193] S2-1. The device sends the following to the gNB / UE:

[0194] Device information (such as Device ID);

[0195] Algorithm information (optional);

[0196] Information a (such as RAND1) (optional);

[0197] Authentication information;

[0198] Information b (such as uplink application data 1) (optional).

[0199] For example, the information sent by the device to the gNB / UE may be:

[0200] Send (NC(Device ID, [Algo], [RAND1], authentication information, [uplink application data 1])).

[0201] S2-2. gNB / UE sends to AMF / SMF:

[0202] Device information (such as Device ID);

[0203] Algorithm information (optional);

[0204] Information a (such as RAND1) (optional);

[0205] Authentication information;

[0206] Information b (such as uplink application data 1) (optional).

[0207] For example, the information sent by the gNB / UE to the AMF / SMF may be:

[0208] Send (NC(Device ID,[Algo],[RAND1]),authentication information,[uplink application data 1]).

[0209] S2-3.AMF / SMF selects NF, and AMF / SMF cache information b (uplink application data 1).

[0210] S2-4.AMF / SMF sends authentication information 1 to the AAA-Proxy device (AAA-Proxy).

[0211] Among them, the authentication information 1 includes: information b (such as uplink application data 1)), device information.

[0212] Exemplarily, the authentication information 1 may be: authentication (Device ID, [uplink application data 1]).

[0213] S2-5. The AAA-Proxy device (AAA-Proxy) sends authentication information 1 to the AAA-Server (AAA-Server).

[0214] S2-6. The AAA-Server sends authentication information 2 to the AAA-Proxy.

[0215] Authentication information 2 includes: device information (optional), information c (such as RAND2) (optional), and authentication information (such as AC-MT1 (Auth-info)) (optional).

[0216] Exemplarily, the authentication information 2 may be: authentication ([Device ID], [RAND2], [AC-MT1 (Auth-info)).

[0217] S2-7.AAA-Proxy sends authentication information 2 to AMF / SMF.

[0218] S2-8.AMF / SMF sends authentication information 3 to gNB / UE.

[0219] The authentication information 3 includes information d (such as RAND2) (optional).

[0220] S2-9. The gNB / UE sends authentication information 3 to the device.

[0221] S2-10. The device sends networking information / messages to the gNB / UE.

[0222] The networking information / message includes:

[0223] Device information (such as Device ID);

[0224] Information d (optional), including device information (such as Device ID) and application registration and authentication information;

[0225] Information e (optional), including uplink application data.

[0226] For example, the networking information / message may be:

[0227] Networking (NC (Device ID, [Application registration authentication information (Device ID, Auth-Info)], [Uplink application data]).

[0228] S2-11. gNB / UE sends to AMF / SMF:

[0229] Device information (such as Device ID);

[0230] Information d (optional), including device information (such as Device ID) and application registration and authentication information;

[0231] Information e (optional), including uplink application data.

[0232] For example, the information sent by the gNB / UE to the AMF / SMF is:

[0233] Send (NC (Device ID, [application registration authentication information], [uplink application data]).

[0234] S2-12.AMF / SMF verifies the device information and determines whether the device information sent by the device is in the device information received from NEF / AF. If not, no processing is performed.

[0235] If the device information sent by the device is in the device information received from NEF / AF, AMF / SMF determines whether to skip S2-13 to S2-18, execute S2-19 and subsequent steps, or select the network function (NF) type based on whether the context related to the device information is saved and whether information d is included.

[0236] Exemplarily, if S2-13 is to be executed, information b (such as uplink application data) continues to be cached.

[0237] S2-13~S2-14.AMF / SMF sends authentication information 4 to AAA-Server (can be sent through AAA-Proxy).

[0238] Among them, authentication information 4 includes: information d (optional) and device information (optional).

[0239] Exemplarily, the authentication information 4 may be: authentication (Device ID, [application registration authentication information]).

[0240] If the AAA-Server has not authenticated the device before, it authenticates the device based on information d.

[0241] S2-16~S2-17.AAA-Server sends result information to AMF / SMF (optionally through AAA-Proxy).

[0242] S2-18.AMF / SMF sends service information, device information (optional), information f (including service information (optional), device information (optional)), and downlink application data 1 (optional) to the gNB / UE.

[0243] For example, the information sent by the AMF / SMF to the gNB / UE may be:

[0244] Send (Service ID, Device ID, NC (Device ID, [downlink application data 1])).

[0245] Exemplarily, the information f may be carried via the NC field.

[0246] S2-19. The gNB / UE sends information f (optional) and downlink application data 1 (optional) to the device.

[0247] For example, the information sent by the gNB / UE to the device may be:

[0248] Send (NC (Device ID, [downlink application data 1])).

[0249] S2-20~S2-21.AMF / SMF sends information e and device information to NEF / AF (optional).

[0250] For example, the information sent by AMF / SMF to NEF / AF may be:

[0251] Go online (Device ID, [uplink application data]).

[0252] S2-22~S2-23. Optionally, AF sends business information, device information, and information g (such as the following application data 2) to AMF / SMF through NEF.

[0253] For example, the information sent by AF to AMF / SMF via NEF is:

[0254] Send (Service ID, Device ID, [downlink application data 2]).

[0255] Exemplarily, the information g may be carried through the AC field.

[0256] S2-24. The AMF / SMF sends service information, device information, and information h to the gNB / UE (optional).

[0257] Among them, information h includes device information and information g (such as the following application data 2) (optional).

[0258] For example, the information sent by the AMF / SMF to the gNB / UE may be:

[0259] Send (Service ID, Device ID, NC (Device ID, [downlink application data 2])).

[0260] Exemplarily, the information h may be carried via the NC field.

[0261] S2-25. The gNB / UE forwards information h to the device.

[0262] For example, the information forwarded by the gNB / UE to the device may be:

[0263] Send (NC(Device ID,[downlink application data 2])).

[0264] The wireless communication method provided in the embodiments of the present application may be performed by a wireless communication device or a processing unit in the wireless communication device for performing the wireless communication method. The embodiments of the present application take the wireless communication device performing the wireless communication method as an example to illustrate the wireless communication device provided in the embodiments of the present application.

[0265] FIG3 shows a schematic block diagram of a wireless communication device 300 according to an embodiment of the present application. As shown in FIG3 , the wireless communication device 300 includes:

[0266] The transceiver unit 310 is configured to receive first information from a terminal device, wherein the first information includes first challenge information;

[0267] A processing unit 320 is configured to perform a first operation based on the first information and the first key;

[0268] The first operation includes at least one of the following:

[0269] generating second information;

[0270] sending the second information to the terminal device;

[0271] The second information is used for authentication or authorization.

[0272] In some embodiments, the second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information;

[0273] The second operation includes at least one of the following:

[0274] performing encryption based on the first key;

[0275] performing hashing based on the first key;

[0276] Hash;

[0277] Performs an XOR based on the agreed information.

[0278] In some embodiments, the transceiver unit 310 is further configured to send a second challenge message.

[0279] In some embodiments, the transceiver unit 310 is specifically configured to:

[0280] The wireless communication apparatus 300 sends the second challenge information before receiving the first information from the terminal device.

[0281] In some embodiments, the first information further includes at least one of the following: identification information, first response information;

[0282] The first response information is generated based on the second challenge information; and the identification information is used to indicate the terminal device or a contracted user of the terminal device.

[0283] In some embodiments, the second information is further generated based on the first key and the second challenge information, or the second information is further generated based on the first key, the second challenge information and the first response information.

[0284] In some embodiments, the second information includes at least one of the following: the first information, fourth information;

[0285] The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following:

[0286] The first information, the first challenge information, and the first response information.

[0287] In some embodiments, the wireless communication device 300 includes at least one of the following:

[0288] Authentication service function AUSF, unified data management UDM, authentication center AuC.

[0289] In some embodiments, the transceiver unit 310 may be a communication interface or transceiver, or an input / output interface of a communication chip or a system on chip. The processing unit 320 may be embedded in or independent of a processor of a network node in the form of hardware.

[0290] It should be understood that the wireless communication device 300 according to the embodiment of the present application may correspond to the network node in the method embodiment of the present application, and the various units in the wireless communication device 300 are respectively for implementing the corresponding processes of the network node in the method 200 shown in Figure 2. For the sake of brevity, they will not be repeated here.

[0291] Therefore, in an embodiment of the present application, the network node generates the second information (such as AUTN) based on the first key and the first information or the first challenge information sent by the terminal device, or sends the second information (such as AUTN) to the terminal device, so that the terminal device can verify the second information based on the first key and the first information or the first challenge information to prevent the pseudo base station from using the intercepted second information (such as AUTN) to counterfeit the network. In addition, the network node refers to the first information or the first challenge information sent by the terminal device when generating the second information (such as AUTN), and the terminal device no longer introduces the SQN when verifying the second information (such as AUTN), which can solve the problem of requiring the terminal device to store the SQN for a long time when preventing the pseudo base station from using the intercepted AUTN to counterfeit the network.

[0292] FIG4 shows a schematic block diagram of a wireless communication device 400 according to an embodiment of the present application. As shown in FIG4 , the wireless communication device 400 includes:

[0293] The transceiver unit 410 is configured to send first information to a network node, wherein the first information includes first challenge information;

[0294] The transceiver unit 410 is further configured to receive second information from the network node, wherein the second information is generated based on the first information and is used for authentication or authorization;

[0295] The processing unit 420 is configured to verify the second information based on the first key and at least one of the following:

[0296] The first information and the first challenge information.

[0297] In some embodiments, the second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information;

[0298] The second operation includes at least one of the following:

[0299] performing encryption based on the first key;

[0300] performing hashing based on the first key;

[0301] Hash;

[0302] Performs an XOR based on the agreed information.

[0303] In some embodiments, the transceiver unit 410 is further configured to receive second challenge information.

[0304] In some embodiments, the transceiver unit 410 is specifically configured to:

[0305] Before the wireless communication device 400 sends the first information to the network node, the second challenge information is received.

[0306] In some embodiments, the first information further includes at least one of the following: identification information, first response information;

[0307] The first response information is generated based on the second challenge information; and the identification information is used to indicate the wireless communication device or a subscriber of the wireless communication device.

[0308] In some embodiments, the second information is further generated based on the first key and the second challenge information, or the second information is further generated based on the first key, the second challenge information and the first response information.

[0309] In some embodiments, the second information includes at least one of the following: the first information, fourth information;

[0310] The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following:

[0311] The first information, the first challenge information, and the first response information.

[0312] In some embodiments, the network node includes at least one of the following:

[0313] Authentication service function AUSF, unified data management UDM, authentication center AuC.

[0314] In some embodiments, the transceiver unit 410 may be a communication interface or transceiver, or an input / output interface of a communication chip or a system on chip. The processing unit 420 may be embedded in or independent of a processor of the terminal in the form of hardware.

[0315] It should be understood that the wireless communication device 400 according to the embodiment of the present application may correspond to the terminal device in the method embodiment of the present application, and the various units in the wireless communication device 400 are respectively for implementing the corresponding processes of the terminal device in the method 200 shown in Figure 2. For the sake of brevity, they will not be repeated here.

[0316] Therefore, in an embodiment of the present application, the network node generates the second information (such as AUTN) based on the first key and the first information or the first challenge information sent by the terminal device, or sends the second information (such as AUTN) to the terminal device, so that the terminal device can verify the second information based on the first key and the first information or the first challenge information to prevent the pseudo base station from using the intercepted second information (such as AUTN) to counterfeit the network. In addition, the network node refers to the first information or the first challenge information sent by the terminal device when generating the second information (such as AUTN), and the terminal device no longer introduces the SQN when verifying the second information (such as AUTN), which can solve the problem of requiring the terminal device to store the SQN for a long time when preventing the pseudo base station from using the intercepted AUTN to counterfeit the network.

[0317] The wireless communication device in the embodiments of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or a network-side device, or can be a device other than a terminal or a network-side device. For example, the terminal can include but is not limited to the types of terminals 11 listed above, the network-side device can include but is not limited to the types of network-side devices 12 listed above, and other devices can be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiments of the present application.

[0318] The wireless communication device provided in the embodiment of the present application can implement each process implemented in the method embodiment of Figure 2 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0319] As shown in FIG5 , an embodiment of the present application further provides a communication device 500 , including a processor 501 and a memory 502 , where the memory 502 stores programs or instructions that can be executed on the processor 501 .

[0320] For example, when the communication device 500 is a terminal, the program or instruction is executed by the processor 501 to implement the various steps performed by the terminal in the above-mentioned wireless communication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0321] For another example, when the communication device 500 is a network node, the program or instruction is executed by the processor 501 to implement the various steps performed by the network node in the above-mentioned wireless communication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0322] The present application also provides a terminal, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps performed by the terminal in the method embodiment shown in FIG2 . This terminal embodiment corresponds to the aforementioned terminal-side method embodiment, and each implementation process and implementation method of the aforementioned method embodiment is applicable to this terminal embodiment and can achieve the same technical effects. Specifically, FIG6 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.

[0323] The terminal 600 includes but is not limited to: a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609 and at least some of the components of the processor 610.

[0324] Those skilled in the art will appreciate that the terminal 600 may also include a power supply (such as a battery) to power various components. The power supply may be logically connected to the processor 610 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The terminal structure shown in FIG6 does not limit the terminal. The terminal may include more or fewer components than shown, or may combine certain components, or have different component arrangements, which will not be described in detail here.

[0325] It should be understood that in an embodiment of the present application, the input unit 604 may include a graphics processing unit (GPU) 6041 and a microphone 6042, and the graphics processor 6041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 606 may include a display panel 6061, and the display panel 6061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 607 includes a touch panel 6071 and at least one of other input devices 6072. The touch panel 6071 is also called a touch screen. The touch panel 6071 may include two parts: a touch detection device and a touch controller. Other input devices 6072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.

[0326] In the embodiment of the present application, after receiving downlink data from a network-side device, the radio frequency unit 601 may transmit the data to the processor 610 for processing. Furthermore, the radio frequency unit 601 may send uplink data to the network-side device. Typically, the radio frequency unit 601 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.

[0327] The memory 609 can be used to store software programs or instructions and various data. The memory 609 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 609 may include a volatile memory or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 609 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.

[0328] Processor 610 may include at least one processing unit. Optionally, processor 610 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 610.

[0329] In some embodiments, the radio frequency unit 601 is used to send first information to a network node, wherein the first information includes first challenge information; the radio frequency unit 601 is also used to receive second information from the network node, wherein the second information is generated based on the first information and the second information is used for authentication or authorization; the processor 610 is used to verify the second information based on a first key and at least one of the following: the first information, the first challenge information.

[0330] It can be understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the method embodiment and achieve the same or corresponding technical effects. To avoid repetition, it will not be repeated here.

[0331] The present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps performed by the network node in the method embodiment shown in FIG2 . This network-side device embodiment corresponds to the aforementioned network node method embodiment, and each implementation process and implementation method of the aforementioned method embodiment is applicable to this network-side device embodiment and can achieve the same technical effects. For the sake of brevity, they are not further described here.

[0332] Specifically, embodiments of the present application also provide a network-side device. As shown in Figure 7, the network-side device 700 includes an antenna 71, a radio frequency device 72, a baseband device 73, a processor 74, and a memory 75. Antenna 71 is connected to radio frequency device 72. In the uplink direction, radio frequency device 72 receives information via antenna 71 and sends the received information to baseband device 73 for processing. In the downlink direction, baseband device 73 processes the information to be transmitted and sends it to radio frequency device 72. Radio frequency device 72 processes the received information and then sends it through antenna 71.

[0333] The method executed by the network node in the above embodiment may be implemented in the baseband device 73 , which includes a baseband processor.

[0334] The baseband device 73 may include, for example, at least one baseband board, on which at least two chips are arranged, as shown in Figure 7, one of which is, for example, a baseband processor, which is connected to the memory 75 through a bus interface to call the program in the memory 75 and execute the operations performed by the network node shown in the above method embodiment.

[0335] The network side device may further include a network interface 76, which is, for example, a Common Public Radio Interface (CPRI).

[0336] Specifically, the network side device 700 of the embodiment of the present application also includes: instructions or programs stored in the memory 75 and executable on the processor 74. The processor 74 calls the instructions or programs in the memory 75 to execute the method executed by each unit shown in Figure 3 and achieve the same technical effect. To avoid repetition, it will not be described here.

[0337] The embodiment of the present application further provides a network side device. As shown in FIG8 , the network side device 800 includes: a processor 801, a network interface 802, and a memory 803. The network interface 802 is, for example, a common public radio interface (CPRI).

[0338] Specifically, the network side device 800 of the embodiment of the present application also includes: instructions or programs stored in the memory 803 and can be run on the processor 801. The processor 801 calls the instructions or programs in the memory 803 to execute the method executed by each unit shown in Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0339] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned wireless communication method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0340] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.

[0341] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned wireless communication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0342] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0343] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned wireless communication method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0344] An embodiment of the present application also provides a communication system, including: a terminal device and a network node, wherein the terminal device can be used to execute the steps performed by the terminal device in the wireless communication method as described above, and the network node can be used to execute the steps performed by the network node in the wireless communication method as described above.

[0345] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0346] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.

[0347] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.

Claims

1. A wireless communication method, comprising: The network node receives first information from the terminal device, wherein the first information includes first challenge information; The network node performs a first operation based on the first information and the first key; The first operation includes at least one of the following: generating second information; sending the second information to the terminal device; The second information is used for authentication or authorization.

2. The method according to claim 1, wherein The second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information; The second operation includes at least one of the following: performing encryption based on the first key; performing hashing based on the first key; Hash; Performs an XOR based on the agreed information.

3. The method according to claim 1 or 2, wherein: The method further comprises: The network node sends second challenge information.

4. The method according to claim 3, wherein: The network node sends the second challenge information, including: Before the network node receives the first information from the terminal device, the network node sends the second challenge information.

5. The method according to claim 3 or 4, wherein: The first information further includes at least one of the following: identification information, first response information; The first response information is generated based on the second challenge information; and the identification information is used to indicate the terminal device or a contracted user of the terminal device.

6. The method according to any one of claims 3 to 5, wherein The second information is further generated based on the first key and the second challenge information, or the second information is further generated based on the first key, the second challenge information and the first response information; The first response information is generated based on the second challenge information.

7. The method according to any one of claims 3 to 6, wherein The second information includes at least one of the following: the first information and the fourth information; The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following: the first information, the first challenge information, and the first response information; The first response information is generated based on the second challenge information.

8. The method according to any one of claims 1 to 7, wherein The network node includes at least one of the following: Authentication service function AUSF, unified data management UDM, authentication center AuC.

9. A wireless communication method, comprising: The terminal device sends first information to the network node, wherein the first information includes first challenge information; The terminal device receives second information from the network node, wherein the second information is generated based on the first information and is used for authentication or authorization; The terminal device verifies the second information based on the first key and at least one of the following: The first information and the first challenge information.

10. The method according to claim 9, wherein: The second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information; The second operation includes at least one of the following: performing encryption based on the first key; performing hashing based on the first key; Hash; Performs an XOR based on the agreed information.

11. The method according to claim 9 or 10, wherein: The method further comprises: The terminal device receives second challenge information.

12. The method according to claim 11, wherein The terminal device receives the second challenge information, including: Before the terminal device sends the first information to the network node, the terminal device receives the second challenge information.

13. The method according to claim 11 or 12, wherein: The first information further includes at least one of the following: identification information, first response information; The first response information is generated based on the second challenge information; and the identification information is used to indicate the terminal device or a contracted user of the terminal device.

14. The method according to any one of claims 11 to 13, wherein The second information is further generated based on the first key and the second challenge information, or the second information is further generated based on the first key, the second challenge information and the first response information; The first response information is generated based on the second challenge information.

15. The method according to any one of claims 11 to 14, wherein The second information includes at least one of the following: the first information and the fourth information; The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following: the first information, the first challenge information, and the first response information; The first response information is generated based on the second challenge information.

16. The method according to any one of claims 9 to 15, wherein The network node includes at least one of the following: Authentication service function AUSF, unified data management UDM, authentication center AuC.

17. A wireless communication device, comprising: a transceiver unit, configured to receive first information from a terminal device, wherein the first information includes first challenge information; a processing unit, configured to perform a first operation based on the first information and a first key; The first operation includes at least one of the following: generating second information; sending the second information to the terminal device; The second information is used for authentication or authorization.

18. The device according to claim 17, wherein The second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information; The second operation includes at least one of the following: performing encryption based on the first key; performing hashing based on the first key; Hash; Performs an XOR based on the agreed information.

19. The device according to claim 17 or 18, wherein The transceiver unit is further configured to send second challenge information.

20. The device according to claim 19, wherein The transceiver unit is specifically used for: The second challenge information is sent before the wireless communication apparatus receives the first information from the terminal device.

21. The device according to claim 19 or 20, wherein The first information further includes at least one of the following: identification information, first response information; The first response information is generated based on the second challenge information; and the identification information is used to indicate the terminal device or a contracted user of the terminal device.

22. The device according to any one of claims 19 to 21, wherein The second information is further generated based on the first key and the second challenge information, or the second information is further generated based on the first key, the second challenge information and the first response information; The first response information is generated based on the second challenge information.

23. The device according to any one of claims 19 to 22, wherein The second information includes at least one of the following: the first information and the fourth information; The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following: the first information, the first challenge information, and the first response information; The first response information is generated based on the second challenge information.

24. The device according to any one of claims 17 to 23, wherein The wireless communication device includes at least one of the following: Authentication service function AUSF, unified data management UDM, authentication center AuC.

25. A wireless communication device comprising: a transceiver unit, configured to send first information to a network node, wherein the first information includes first challenge information; The transceiver unit is further configured to receive second information from the network node, wherein the second information is generated based on the first information and is used for authentication or authorization; a processing unit, configured to verify the second information based on the first key and at least one of the following: The first information and the first challenge information.

26. The device according to claim 25, wherein The second information includes third information; wherein the third information includes information obtained by performing a second operation on part or all of the content of the first information; The second operation includes at least one of the following: performing encryption based on the first key; performing hashing based on the first key; Hash; Performs an XOR based on the agreed information.

27. The device according to claim 25 or 26, wherein The transceiver unit is further configured to receive second challenge information.

28. The apparatus according to claim 27, wherein The transceiver unit is specifically used for: Before the wireless communication device sends the first information to the network node, the second challenge information is received.

29. The device according to claim 27 or 28, wherein The first information further includes at least one of the following: identification information, first response information; The first response information is generated based on the second challenge information; and the identification information is used to indicate the wireless communication device or a subscriber of the wireless communication device.

30. The device according to any one of claims 27 to 29, wherein The second information is further generated based on the first key and the second challenge information, or the second information is further generated based on the first key, the second challenge information and the first response information; The first response information is generated based on the second challenge information.

31. The device according to any one of claims 27 to 30, wherein The second information includes at least one of the following: the first information and the fourth information; The fourth information is generated based on the second challenge information, or the fourth information is generated based on the second challenge information and at least one of the following: the first information, the first challenge information, and the first response information; The first response information is generated based on the second challenge information.

32. The device according to any one of claims 25 to 31, wherein The network node includes at least one of the following: Authentication service function AUSF, unified data management UDM, authentication center AuC.

33. A network-side device, comprising a transceiver, a processor, and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 1 to 8 are implemented.

34. A terminal device comprising a transceiver, a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 9 to 16 are implemented.

35. A readable storage medium storing a program or instruction, wherein the program or instruction, when executed by a processor, implements the steps of the wireless communication method according to any one of claims 1 to 8, or implements the steps of the wireless communication method according to any one of claims 9 to 16.