User authentication methods, communication device and storage medium
By cooperating with the first and second network functions, a key generation request is sent to the third network function after the user authentication method is determined. This solves the problem that the UE authentication and authorization mechanism in the prior art does not support user authentication, and reduces signaling overhead and improves authentication efficiency.
Patent Information
- Application Number
- PCT/CN2024/094809
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-22
- Publication Date
- 2025-11-27
AI Technical Summary
In existing communication technologies, the UE's authentication and authorization mechanisms do not support user authentication and authorization, leading to increased signaling overhead for information exchange.
By collaborating with the first and second network functions, a key generation request is sent to the third network function after the user authentication method is determined, reducing the amount of information the UE needs to know and the signaling overhead on the network side, and simplifying the information interaction process.
It reduces the signaling overhead between the UE and the network, simplifies the user authentication process, and improves authentication efficiency.
Smart Images

Figure CN2024094809_27112025_PF_FP_ABST
Abstract
Description
User authentication method, communication device and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a user authentication method, a communication device and a storage medium. BACKGROUND
[0002] In the field of communication technology, the user to be identified can be a personal user using a user equipment (UE) with a clear subscription, or an application running on the UE or connected via the UE, or a personal user of a device connected through the UE as a gateway. The related security architecture supports authentication and authorization for the UE used to establish a connection, but does not support authentication and authorization for the user on or behind the UE.
[0003] SUMMARY
[0004] Embodiments of the present disclosure provide a user authentication method, a communication device and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a user authentication method is provided, which is executed by a first network function, and the method comprises:
[0006] receiving a first request sent by a user equipment (UE), wherein the first request comprises a user identifier of a first user, and the first user is a user using the UE;
[0007] sending a second request to a second network function, wherein the second request comprises the user identifier of the first user;
[0008] receiving a second response sent by the second network function;
[0009] in a case where it is determined according to the second response that a user authentication mode of the first user is a first mode, sending a third request to a third network function, wherein the third request is used to request the third network function to generate a second key of the UE according to a first key, the second key is used to generate a third key of the first user, and the third key is used for user authentication of the first user.
[0010] According to a second aspect of an embodiment of the present disclosure, a user authentication method is provided, which is executed by a second network function, and the method comprises: receiving a second request sent by a first network function, wherein the second request comprises a user identifier of a first user, and the first user is a user using a user equipment (UE); and sending a second response to the first network function according to configuration information of the first user, wherein the second response is used for the first network function to determine a user authentication mode of the first user.
[0011] According to a third aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a user equipment (UE), and the method comprises:
[0012] sending, to a first network function, a first request, the first request comprising a user identity of a first user, the first user being a user using the UE; the first request being used to cause the first network function to send, to a third network function, a third request in a case that a user authentication manner of the first user is a first manner; the third request being used to request the third network function to generate a second key of the UE according to a first key; the second key being used to generate a third key of the first user; the third key being used for user authentication of the first user.
[0013] According to a fourth aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a third network function, and the method comprises:
[0014] receiving a third request sent by a first network function; the third request being used to request the third network function to generate a second key of a user equipment (UE) according to a first key;
[0015] generating the second key according to the first key;
[0016] generating a third key of a first user according to the second key, the first user being a user using the UE;
[0017] sending, to the first network function, a third response, the third response being used to indicate whether the second key or the third key is generated successfully;
[0018] sending, to a second network function, a subscription identity of the UE, a user identity of the first user, and the third key.
[0019] According to a fifth aspect of embodiments of the present disclosure, a user authentication manner is provided, wherein the method is performed by a fourth network function, and the method comprises:
[0020] receiving a fourth request sent by a user equipment (UE), the fourth request being used for user authentication of a first user, the fourth request being protected by a fifth key of the first user;
[0021] sending, to a second network function, a fifth request, the fifth request being used to request a third key of the first user or a user authentication result of the first user; the fifth request comprising a user identity of the first user and a related subscription identity of the UE.
[0022] receiving a fifth response sent by the second network function;
[0023] obtaining the user authentication result of the first user according to the fifth response;
[0024] sending a fourth response to the UE according to the user authentication result.
[0025] According to a sixth aspect of the embodiments of the present disclosure, a first network function is provided, wherein the first network function comprises:
[0026] The first network function comprises a sending module, a receiving module and a processing module.
[0027] The receiving module is configured to receive a first request sent by a user equipment (UE), the first request comprising a user identifier of a first user, the first user being a user using the UE.
[0028] The sending module is configured to send a second request to a second network function, the second request comprising the user identifier of the first user.
[0029] The processing module is configured to, in a case where it is determined according to the second response that a user authentication manner of the first user is a first manner, send a third request to a third network function, the third request being used to request the third network function to generate a second key of the UE according to a first key, the second key being used to generate a third key of the first user, the third key being used for user authentication of the first user.
[0030] According to a seventh aspect of the embodiments of the present disclosure, a second network function is provided, wherein the second network function comprises:
[0031] The receiving module is configured to receive a second request sent by a first network function, the second request comprising a user identifier of a first user, the first user being a user using a user equipment (UE).
[0032] The sending module is configured to send a second response to the first network function according to configuration information of the first user, the second response being used for the first network function to determine a user authentication manner of the first user.
[0033] According to an eighth aspect of the embodiments of the present disclosure, a user equipment (UE) is provided, wherein the UE comprises:
[0034] The sending module is configured to send a first request to a first network function, the first request comprising a user identifier of a first user, the first user being a user using the UE, the first request being used to make the first network function send a third request to a third network function in a case where a user authentication manner of the first user is a first manner, the third request being used to request the third network function to generate a second key of the UE according to a first key, the second key being used to generate a third key of the first user, the third key being used for user authentication of the first user.
[0035] According to a ninth aspect of the embodiments of the present disclosure, a third network function is provided, wherein the third network function comprises:
[0036] a receiving module configured to receive a third request sent by a first network function, wherein the third request is used to request the third network function to generate a second key of a user equipment (UE) according to a first key;
[0037] a processing module configured to generate the second key according to the first key, and generate a third key of a first user according to the second key, wherein the first user is a user using the UE;
[0038] a sending module configured to send a third response to the first network function, wherein the third response is used to indicate whether the second key or the third key is generated successfully, and send a subscription identifier of the UE, a user identifier of the first user and the third key to a second network function.
[0039] According to a tenth aspect of the embodiments of the present disclosure, a fourth network function is provided, wherein,
[0040] the fourth network function comprises a receiving module, a sending module and a processing module;
[0041] the receiving module is configured to receive a fourth request sent by a user equipment (UE), wherein the fourth request is used for user authentication of a first user, and the fourth request is protected by a fifth key of the first user;
[0042] the sending module is configured to send a fifth request to a second network function, wherein the fifth request is used to request the third key of the first user or a user authentication result of the first user, and the fifth request comprises a user identifier of the first user and a related subscription identifier of the UE.
[0043] the receiving module is configured to receive a fifth response sent by the second network function;
[0044] the processing module is configured to obtain the user authentication result of the first user according to the fifth response;
[0045] the sending module is configured to send a fourth response to the UE according to the user authentication result.
[0046] According to an eleventh aspect of the embodiments of the present disclosure, a communication system is provided, wherein the communication system comprises a user equipment (UE), a first network function, a second network function, a third network function and a fourth network function;
[0047] the first network function is used to execute the user authentication method in any of the technical solutions of the first aspect;
[0048] The second network function is configured to perform the user authentication method of any of the technical solutions of the second aspect.
[0049] The UE is configured to perform the user authentication method of any of the technical solutions of the third aspect.
[0050] The third network function is configured to perform the user authentication method of any of the technical solutions of the fourth aspect.
[0051] The fourth network function is configured to perform the user authentication method of any of the technical solutions of the fifth aspect.
[0052] According to a twelfth aspect of the embodiments of the present disclosure, a communication device is provided, and the communication device comprises one or more processors; and the processor is configured to invoke instructions to cause the communication device to perform the user authentication method provided in any of the technical solutions of the first aspect to the fifth aspect.
[0053] According to a thirteenth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the user authentication method provided in any of the first aspect to the fifth aspect.
[0054] According to a fourteenth aspect of the embodiments of the present disclosure, a program product is provided, and the program product comprises a computer program, which, when executed on a communication device, causes the communication device to implement the user authentication method provided in any of the technical solutions of the first aspect to the fifth aspect.
[0055] The technical solution provided in the embodiments of the present disclosure interacts with the second network function, and in the case where it is determined that the user authentication method of the first user is the first method, a third request is sent to the third network function. In this scenario, the UE does not need to provide information to the first network function for the first network function to determine the user authentication method of the first user, thereby simplifying the amount of information that the UE needs to know and reducing the signaling overhead of the UE and the network side. Moreover, the first network function sends the third request to the third network function only after determining the user authentication method of the first user, thereby also reducing the signaling overhead of the information interaction between the first network function and the third network function.
[0056] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and are not limiting on the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0057] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments consistent with the present disclosure and serve to explain the principles of the present disclosure together with the specification.
[0058] FIG. 1 is a schematic diagram of an architecture of a communication system according to an example embodiment;
[0059] FIG. 2 is a schematic diagram of interactions of a user authentication method according to an example embodiment;
[0060] FIG. 3 is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0061] FIG. 4 is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0062] FIG. 5 is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0063] FIG. 6 is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0064] FIG. 7 is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0065] FIG. 8A is a schematic diagram of a key hierarchy architecture according to an example embodiment;
[0066] FIG. 8B is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0067] FIG. 8C is a schematic diagram of a flow of a user authentication method according to an example embodiment;
[0068] FIG. 9A is a schematic diagram of a structure of a first network function according to an example embodiment;
[0069] FIG. 9B is a schematic diagram of a structure of a second network function according to an example embodiment;
[0070] FIG. 9C is a schematic diagram of a structure of a UE according to an example embodiment;
[0071] FIG. 9D is a schematic diagram of a structure of a third network function according to an example embodiment;
[0072] FIG. 9E is a schematic diagram of a structure of a fourth network function according to an example embodiment;
[0073] FIG. 10A is a schematic diagram of a structure of a communication device according to an example embodiment;
[0074] FIG. 10B is a schematic diagram of a structure of a chip according to an example embodiment. DETAILED DESCRIPTION
[0075] Embodiments of the present disclosure provide a user authentication method, a communication device, a communication system and a storage medium.
[0076] The first aspect provides a user authentication method, wherein the method is performed by a first network function, and the method comprises:
[0077] receiving a first request sent by a user equipment (UE), wherein the first request comprises a user identifier of a first user, and the first user is a user using the UE;
[0078] sending a second request to a second network function, wherein the second request comprises the user identifier of the first user;
[0079] receiving a second response sent by the second network function;
[0080] in a case where it is determined according to the second response that a user authentication manner of the first user is a first manner, sending a third request to a third network function, wherein the third request is used to request the third network function to generate a second key of the UE according to a first key, the second key is used to generate a third key of the first user, and the third key is used for user authentication of the first user.
[0081] In this way, according to the first network function, information interaction is performed with the second network function according to the first request, and in a case where it is determined that the user authentication manner of the first user is the first manner, the third request is sent to the third network function. In this scenario, the UE does not need to provide information to the first network function for the first network function to determine the user authentication manner of the first user, thereby simplifying the amount of information that the UE needs to know and reducing signaling overhead between the UE and the network side. Moreover, the first network function sends the third request to the third network function only after determining the user authentication manner of the first user, thereby also reducing signaling overhead of information interaction between the first network function and the third network function.
[0082] In some embodiments of the first aspect, the second response comprises at least one of the following:
[0083] user authentication manner information, used to indicate the user authentication manner of the first user determined by the second network function;
[0084] related information of the first user, used for the first network function to determine the user authentication manner of the first user.
[0085] In this way, the first network function knows the user authentication manner of the first user through reception of the second response, and has the characteristic of being easy to implement.
[0086] In some embodiments of the first aspect, the related information of the first user comprises at least one of the following:
[0087] user authentication policy, used to determine the user authentication manner of the first user;
[0088] a first indication, used to indicate whether the preconfigured credential of the first user is valid.
[0089] In this way, there are various manners of the related information of the first user, and the implementation is not limited to any of the above manners.
[0090] In some embodiments of the first aspect, the preconfigured credential of the first user is invalid or missing, and the user authentication manner of the first user is the first manner; or the preconfigured credential of the first user is valid, and the user authentication manner of the first user is a second manner; the second manner is an authentication manner of performing user authentication by using the preconfigured credential.
[0091] The above scheme defines how to determine the user authentication manner of the first user in detail, and has the characteristic of simple implementation.
[0092] In some embodiments of the first aspect, the method further comprises:
[0093] receiving a third response sent by the third network function, the third response being used to indicate whether the second key and / or the third key is generated successfully.
[0094] Based on the above scheme, the third response will indicate whether the second key and / or the third key is generated successfully, and the first network function can send the first response indicating success or failure to the UE according to the third response. In some embodiments of the first aspect, the method further comprises: sending the first response to the UE according to the second response or the third response.
[0095] In this way, the first network function can send the first response to the UE according to the second response or the third response, so as to prompt the UE to generate the second key and / or the third key.
[0096] In some embodiments of the first aspect, the first response comprises at least one of:
[0097] first user authentication manner information, used to indicate the user authentication manner of the first user to the UE;
[0098] a failure cause, used to indicate that the second key and / or the third key fails to be generated.
[0099] In some embodiments of the first aspect,
[0100] when the third response indicates that the second key and / or the third key is generated successfully, the first response comprises the first user authentication manner information, and the first user authentication manner information indicates that the user authentication of the first user is performed in the first manner; or
[0101] In a case where the third response indicates that the second key and / or the third key generation fails, the first response comprises a failure cause; or
[0102] In a case where it is determined according to the second response that the user authentication manner of the first user is a second manner, the first response comprises the first user authentication manner information, and the first user authentication manner information indicates that the user authentication of the first user is performed in the second manner.
[0103] In some embodiments of the first aspect, the first request further comprises at least one of the following:
[0104] a subscription-related identifier of the UE;
[0105] capability information of the UE, the capability information being used to indicate a user authentication manner supported by the UE;
[0106] network slice information indicating a network slice supported and / or expected to be used by the UE.
[0107] The second aspect provides a user authentication method, wherein the method is performed by a second network function, and the method comprises the following steps of:
[0108] receiving a second request sent by a first network function, the second request comprising a user identifier of a first user, the first user being a user using a user equipment (UE);
[0109] sending, according to configuration information of the first user, a second response to the first network function, the second response being used for the first network function to determine a user authentication manner of the first user.
[0110] In some embodiments of the second aspect, the second response comprises at least one of the following:
[0111] user authentication manner information used to indicate the user authentication manner of the first user determined by the second network function;
[0112] related information of the first user, the related information of the first user being used for the first network function to determine the user authentication manner of the first user.
[0113] In some embodiments of the second aspect, the configuration information of the first user comprises at least one of the following:
[0114] user authentication policy used to determine the user authentication manner of the first user;
[0115] preconfigured credential information used to indicate whether the first user has a preconfigured credential and / or whether the preconfigured credential of the first user is valid.
[0116] In some embodiments of the second aspect, the second request further comprises at least one of:
[0117] a subscription-related identifier of the UE;
[0118] capability information of the UE, the capability information being used to indicate a user authentication manner supported by the UE;
[0119] network slice information indicating a network slice supported and / or expected to be used by the UE.
[0120] In some embodiments of the second aspect, the method further comprises:
[0121] receiving a fifth request sent by a fourth network function, the fifth request being used to request a third key of the first user or a user authentication result of the first user;
[0122] sending a fifth response to the fourth network function, the fifth response comprising the third key of the first user and / or the user authentication result of the first user.
[0123] In some embodiments of the second aspect, the method further comprises:
[0124] in a case where the fifth response comprises the third key of the first user, receiving the user authentication result of the first user sent by the fourth network function;
[0125] writing the user authentication result of the first user into configuration information of the first user.
[0126] A third aspect provides a user authentication method, wherein the method is performed by a user equipment (UE), and the method further comprises:
[0127] sending a first request to a first network function, the first request comprising a user identifier of a first user, the first user being a user using the UE; the first request being used to make the first network function send a third request to a third network function in a case where a user authentication manner of the first user is a first manner; the third request being used to request the third network function to generate a second key of the UE according to a first key; the second key being used to generate a third key of the first user; the third key being used for user authentication of the first user.
[0128] In some embodiments of the third aspect, the method further comprises:
[0129] receiving a first response sent by the first network function; the first response comprising at least one of:
[0130] first user authentication manner information, used to indicate the user authentication manner of the first user to the UE.
[0131] Failure cause, used to indicate that the second key and / or the third key generation fails.
[0132] In some embodiments of the third aspect, the method further comprises:
[0133] generating a fourth key according to the first key, in a case that the user authentication manner of the first user is a first manner;
[0134] generating a fifth key according to the fourth key.
[0135] In some embodiments of the third aspect, the generating the fourth key according to the first key comprises at least one of:
[0136] generating the fourth key according to the first key and a subscription identifier of the UE;
[0137] generating the fourth key according to the first key, a subscription identifier of the UE and a first string;
[0138] generating the fourth key according to the first key and a first string.
[0139] In some embodiments of the third aspect, the generating the fifth key according to the fourth key comprises:
[0140] generating the fifth key according to the fourth key and a user identifier of the first user;
[0141] generating the fifth key of the first user according to the fourth key, a user identifier of the first user and a second string;
[0142] generating the fifth key of the first user according to the fourth key and a second string.
[0143] In some embodiments of the fourth aspect, the method further comprises at least one of:
[0144] associating the fifth key of the first user and a user identifier of the first user;
[0145] associating the fifth key of the first user, a user identifier of the first user and a subscription identifier of the UE;
[0146] associating the fourth key and a subscription identifier of the UE.
[0147] In some embodiments of the third aspect, the method further comprises:
[0148] sending a fourth request to a fourth network function, the fourth request being used for user authentication of the first user, the fourth request being protected by the fifth key.
[0149] receiving a fourth response sent by the fourth network function, the fourth response comprising a user authentication result of the first user.
[0150] In some embodiments of the third aspect, the fourth request comprises at least one of:
[0151] a user identifier of the first user;
[0152] a subscription-related identifier of the UE.
[0153] A fourth aspect provides a user authentication method, wherein the method is performed by a third network function, and the method comprises:
[0154] receiving a third request sent by a first network function, the third request being used to request the third network function to generate a second key of a user equipment (UE) according to a first key;
[0155] generating the second key according to the first key;
[0156] generating a third key of a first user according to the second key, the first user being a user using the UE;
[0157] sending a third response to the first network function, the third response being used to indicate whether the second key or the third key is generated successfully;
[0158] sending, to the second network function, a subscription identifier of the UE, a user identifier of the first user, and the third key.
[0159] In some embodiments of the fourth aspect, the generating the second key according to the first key comprises at least one of:
[0160] generating the second key according to the first key and a subscription identifier of the UE;
[0161] generating the second key according to the first key, the subscription identifier of the UE, and a first string;
[0162] generating the second key according to the first key and the first string.
[0163] In some embodiments of the fourth aspect, the generating the third key of the first user according to the second key comprises:
[0164] generating the third key of the first user according to the second key and a user identifier of the first user;
[0165] generate a third key of the first user according to the second key, the user identifier of the first user and the second string; and generate the third key of the first user according to the second key and the second string.
[0166] In some embodiments of the fourth aspect, the method further comprises at least one of:
[0167] associating the third key of the first user with the user identifier of the first user;
[0168] associating the third key of the first user with the user identifier of the first user and the subscription identifier of the UE;
[0169] associating the second key with the subscription identifier of the UE.
[0170] The fifth aspect provides a first network function, wherein the first network function comprises a sending module, a receiving module and a processing module.
[0171] The receiving module is configured to receive a first request sent by a user equipment (UE), the first request comprising a user identifier of a first user, the first user being a user using the UE.
[0172] The sending module is configured to send a second request to a second network function, the second request comprising the user identifier of the first user.
[0173] The processing module is configured to, in a case where it is determined according to the second response that a user authentication mode of the first user is a first mode, send a third request to a third network function, the third request being used to request the third network function to generate a second key of the UE according to a first key, the second key being used to generate a third key of the first user, the third key being used for user authentication of the first user.
[0174] The seventh aspect provides a second network function, wherein the second network function comprises:
[0175] The receiving module is configured to receive a second request sent by a first network function, the second request comprising a user identifier of a first user, the first user being a user using a user equipment (UE).
[0176] The sending module is configured to send a second response to the first network function according to configuration information of the first user, the second response being used for the first network function to determine a user authentication mode of the first user.
[0177] The eighth aspect provides a user equipment (UE), wherein the UE comprises:
[0178] The sending module is configured to send a first request to a first network function, the first request comprising a user identifier of a first user, the first user being a user using the UE; the first request is used to cause the first network function to send a third request to a third network function in a case that a user authentication mode of the first user is a first mode; the third request is used to request the third network function to generate a second key of the UE according to a first key; the second key is used to generate a third key of the first user; and the third key is used for user authentication of the first user.
[0179] The ninth aspect provides a third network function, wherein the third network function comprises:
[0180] The receiving module is configured to receive a third request sent by a first network function; the third request is used to request the third network function to generate a second key of a user equipment (UE) according to a first key.
[0181] The processing module is configured to generate the second key according to the first key, and generate a third key of a first user according to the second key, the first user being a user using the UE.
[0182] The sending module is configured to send a third response to the first network function, the third response being used to indicate whether the second key or the third key is generated successfully, and send a subscription identifier of the UE, a user identifier of the first user, and the third key to a second network function.
[0183] The tenth aspect provides a fourth network function, wherein the fourth network function comprises a receiving module, a sending module, and a processing module.
[0184] The receiving module is configured to receive a fourth request sent by a user equipment (UE), the fourth request being used for user authentication of a first user, and the fourth request being protected by a fifth key of the first user.
[0185] The sending module is configured to send a fifth request to a second network function, the fifth request being used to request a third key of the first user or a user authentication result of the first user; the fifth request comprising a user identifier of the first user and a related subscription identifier of the UE.
[0186] The receiving module is configured to receive a fifth response sent by the second network function.
[0187] The processing module is configured to obtain the user authentication result of the first user according to the fifth response.
[0188] The sending module is configured to send a fourth response to the UE according to the user authentication result.
[0189] The eleventh aspect provides a communication system, wherein the communication system comprises a user equipment (UE), a first network function, a second network function, a third network function and a fourth network function;
[0190] The first network function is configured to perform the user authentication method provided in any of the technical solutions of the first aspect;
[0191] The second network function is configured to perform the user authentication method provided in any of the technical solutions of the second aspect;
[0192] The UE is configured to perform the user authentication method provided in any of the technical solutions of the third aspect;
[0193] The third network function is configured to perform the user authentication method provided in any of the technical solutions of the fourth aspect;
[0194] The fourth network function is configured to perform the user authentication method provided in any of the technical solutions of the fifth aspect.
[0195] The twelfth aspect provides a program product, wherein the program product comprises a computer program, and the computer program is configured to enable a communication device to implement the user authentication method described in the optional implementation manners of the first aspect to the fifth aspect when the computer program is executed by the communication device.
[0196] The thirteenth aspect provides a computer program, which is configured to enable a computer to perform the user authentication method described in the optional implementation manners of the first aspect to the fifth aspect when the computer program is executed by the computer.
[0197] It can be understood that the UE, the network device, the communication system, the program product and the computer program are all configured to perform the method provided in the embodiments of the present disclosure. Therefore, the beneficial effects achieved by the UE, the network device, the communication system, the program product and the computer program can refer to the beneficial effects in the corresponding method, which will not be described herein again.
[0198] The embodiments of the present disclosure provide a user authentication method, a communication device, a communication system and a storage medium. The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the mode after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.
[0199] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0200] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0201] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the aforementioned," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0202] In the embodiments of this disclosure, "multiple" refers to two or more.
[0203] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0204] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "A in one case, B in another", etc., may include the following technical methods depending on the situation: in some embodiments, A (A is executed regardless of B); in some embodiments, B (B is executed regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0205] In some embodiments, the notation "A or B" may include the following technical approaches, depending on the circumstances: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, selective execution from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0206] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments in the context, and should not be construed as redundant limitation because of the use of the prefix words. For example, the ordinal words in front of the description objects "field" in "first field" and "second field" do not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the ordinal words in front of the description objects "level" in "first level" and "second level" do not limit the priority between the "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are "information", and "first type of information" and "second type of information" can be the same information or different information, and the contents thereof can be the same or different.
[0207] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0208] In some embodiments, the terms of "…", "determining …", "in the case of …", "when …", "when …", "if …", "if …" and the like can be replaced with each other.
[0209] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0210] In some embodiments, the apparatus and the like can be interpreted as physical or virtual, and the name thereof is not limited to the name recorded in the embodiments. The terms of "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.
[0211] In some embodiments, “network” can be interpreted as the devices (e.g., access network devices, core network devices, etc.) included in the network.
[0212] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving cell,” “carrier,” “component carrier,” “bandwidth part (BWP),” etc. can be replaced with each other.
[0213] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user UE," "mobile station (MS)," "mobile UE (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access UE," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0214] In some embodiments, the access network device, the core network device, or the network device can be replaced with the UE. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the UE is replaced with communication between a plurality of UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and so on). In this case, the structure in which the UE has all or part of the functions of the access network device can also be provided. In addition, the terms "uplink," "downlink," and so on can also be replaced with terms corresponding to the inter-UE communication (e.g., "side"). For example, the uplink channel, the downlink channel, and so on can be replaced with the side channel, and the uplink, the downlink, and so on can be replaced with the sidelink.
[0215] In some embodiments, the UE can be replaced with the access network device, the core network device, or the network device. In this case, the structure in which the access network device, the core network device, or the network device has all or part of the functions of the UE can also be provided.
[0216] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.
[0217] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.
[0218] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0219] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0220] As shown in FIG. 1, the communication system 100 includes a UE (terminal) 101 and a network device 102. The network device 102 can include an access network device and / or a core network device.
[0221] In some embodiments, the UE 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a virtual reality (VR) UE device, an augmented reality (AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in smart grid, a wireless UE device in transportation safety, a wireless UE device in smart city, a wireless UE device in smart home, etc., but is not limited thereto.
[0222] In some embodiments, the UE is also referred to as a user equipment (UE).
[0223] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a UE to a wireless network, and the access network device may, for example, include at least one of an evolved NodeB (eNB), a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0224] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, at which time the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0225] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, and the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.
[0226] In some embodiments, the core network device can be one device including the first network element, or can be multiple devices or device groups each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0227] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0228] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1 or part of the subject, but are not limited thereto. The subjects shown in FIG. 1 are illustrative, and the communication system can include all or part of the subjects in FIG. 1, or other subjects other than FIG. 1. The number and form of each subject is arbitrary, and the connection relationship between the subjects is illustrative. The subjects can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0229] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based thereon, and the like. Further, a plurality of systems can be combined (for example, combination of LTE and NR).
[0230] However, in the scenario of satellite network access network using regenerative mode of UE, the core network function deployed on the satellite can or can not have the capability of store and forward, thus the network element selection information used in the prior art cannot meet the needs of core network function selection. How to select a core network function (such as MME) with S&F capability to serve the latency service of the UE is a problem to be solved. In addition, the spaceborne eNB serving the UE is constantly moving, thereby connecting to different ground stations and then possibly selecting different core network functions (such as MME, AMF), for which the prior art cannot solve the problem of network function selection.
[0231] Current network models are user subscription centric, which allows a communication operator to access the network based on a user subscription.
[0232] User authentication methods In some embodiments, current mobile networks are subscription centric, which allows a mobile operator to secure access to the network and respect legal obligations. From a use case perspective, this is sufficient when a user typically has one phone and one package and uses only a few services provided by the operator (e.g. phone and Short Message Service (SMS)). However, a person can own different kinds of devices (e.g. phone, tablet and / or laptop) to access various operator and non-operator services, some of which can belong to the user and some of which can be shared with others or belong to another party. Things are getting more and more connected (e.g. sensors, gateways, actuators, etc.) and there is a wide variety of relationships between the owner of a thing, the subscriber and the actual user of the thing.
[0233] In some embodiments, each service typically performs its own identity verification, typically based on a username and password. But it becomes more and more cumbersome for a user to manage different credentials for more and more services. So-called identity providers solve this problem by providing identity information to entities and authenticating to the services of these entities. This mechanism can be used on top of any data connection, but integration or interworking with an operator network provides additional advantages.
[0234] In some embodiments, identifying a user and distinguishing the identity of a user (provided by some external party or the operator) in an operator network would allow the operator to provide an enhanced user experience and optimized performance, as well as to provide services to devices that do not belong to the 3GPP network. Network settings and customized services can be adjusted according to the needs of the user, independent of the subscription used to establish the connection. By acting as an identity provider, the operator can take additional information from the network into account to charge based on the identifier of the user and provide differentiated services.
[0235] In some embodiments, the user to be identified can be a personal user of a UE with a specific subscription, or an application running on the UE or connected via the UE, or a device behind a gateway UE. The 3GPP security architecture supports authentication and authorization of UEs with subscription related identities for establishing connections, but does not support authentication and authorization of users on (using) or behind the UE. Therefore, it is necessary to study how to enhance the 3GPP security architecture to support authentication and authorization of users.
[0236] In some embodiments, the 3GPP security architecture consists of a User Application, a Provider Application, a Mobile Equipment (ME), a Universal Subscriber Identity Module (USIM), a Serving Network (SN), a Home Network (HN), and the like.
[0237] In some embodiments, the 3GPP security framework includes Network Access Security (I), Network Domain Security (II), User Domain Security (III), Application Domain Security (IV), and (SBA: Service-based Architecture) Domain Security (V).
[0238] In some embodiments, the functions of Network Access Security (I) include a set of security functions that enable a UE to securely authenticate and access services over a network, including 3GPP access and non-3GPP access, prevent attacks on the (radio) interface, and secure context transfer from a Serving Network (SN) to an Access Network (AN) to achieve access security.
[0239] In some embodiments, the functions of Network Domain Security (II) include a set of security functions that enable network nodes to securely exchange signaling data and user plane data.
[0240] In some embodiments, the functions of User Domain Security (III) include a set of security functions that ensure user access to mobile equipment security.
[0241] In some embodiments, Application Domain Security (IV) includes a set of security functions that enable applications in the user domain and the application domain to securely exchange messages. Application domain security is beyond the scope of 3GPP.
[0242] In some embodiments, the functions of the Service-based Architecture (SBA) domain security (V) include a set of security functions that enable network functions of the SBA architecture to securely communicate within the service network domain and with other network domains.
[0243] The security domains described above mainly support network access security and connection security.
[0244] In some embodiments, the current mobile networks authenticate the access users are centered on the subscription, which enables the mobile operator to protect the access to the network and respect legal obligations. From a use case perspective, this is sufficient when the user typically has one phone and one package and uses only some services provided by the operator, such as phone and short message service (SMS). However, a person can have different kinds of devices (e.g., phone, tablet, and / or laptop) to access various operator and non-operator services, some of which can belong to the user and some of which can be shared with others or belong to another party. Things are getting more and more connected (e.g., sensors, gateways, actuators, etc.) and there are various kinds of relationships between the owner of a thing, the subscriber, and the actual user of the thing.
[0245] In some embodiments, each service typically performs its own user authentication, usually based on a username and password. But it becomes more and more cumbersome for the user to manage different credentials for more and more services. So-called identity providers solve this problem by providing identity information to entities and authenticating to the services accessed by these entities. This mechanism can be used on top of any data connection, but the integration or interworking with the operator network provides additional advantages.
[0246] In some embodiments, identifying the user and distinguishing the user identity in the operator network (provided by some external party or the operator) will enable the operator to provide enhanced user experience and optimized performance, as well as to provide services to devices that do not belong to the 3GPP network. The network settings and customized services can be adjusted according to the user's needs, regardless of the subscription used to establish the connection. By acting as an identity provider, the operator can take into account additional information from the network to charge based on the user's identifier and provide differentiated services.
[0247] In some embodiments, the user to be identified can be a personal user of the UE with a specific subscription, or an application running on the UE or connected via the UE, or a personal user of a device connected via the gateway of the subscribed UE. The 3GPP security architecture supports authentication and authorization for the UE based on subscription-related identity for establishing a connection, but does not support authentication and authorization of the user on (using) or behind the UE. Therefore, it is necessary to study how to enhance the 3GPP security architecture to support the authentication and authorization of the user.
[0248] FIG. 2 is an interaction diagram illustrating a user authentication method according to an exemplary embodiment. As shown in FIG. 2, the present embodiment relates to a user authentication method for the communication system 100, the method comprising:
[0249] S2101: The UE sends a first request to a first network function.
[0250] In some embodiments, the first network function can be a core network function.
[0251] In some embodiments, the first network function can be a network function related to mobility management, network registration and / or session management of the UE. Exemplarily, the second network function can be an AMF or a security anchor function (SEcurity Anchor Function, SEAF) or a session management function (Session Management Function, SMF).
[0252] In some embodiments, the first request can be a non-access stratum (Non Access Stratum, NAS) message sent by the UE to the second network function.
[0253] In some embodiments, the first request is for activation or registration of the first user.
[0254] In some embodiments, the first user can be any user using the UE. Exemplarily, the first user can be a person or other device using the UE.
[0255] In some embodiments, the registration of the first user can also be understood as the activation of the first user. After the first user completes the registration or completes the activation, the first user is authorized to use the UE legally; or, after the first user completes the registration or completes the activation, the first user is authorized to use one or more services of the UE legally.
[0256] After the first user completes the registration or activation, the first user is authorized to use the UE legally, or the first user is authorized to use one or more services of the UE legally. That is, in some cases, "user registration" and "user activation" are equivalent and interchangeable.
[0257] In some embodiments, the first request can comprise, but not limited to, at least one of the following:
[0258] a subscription related identifier of the UE;
[0259] a user identifier of the first user;
[0260] network slice information indicating a network slice supported or expected to be used by the UE;
[0261] a second indicator.
[0262] In some embodiments, the subscription related identifier of the UE can comprise a subscription identifier of the UE or an identifier having a mapping relationship with the subscription identifier. Exemplarily, the subscription identifier of the UE can comprise a Subscription Permanent Identifier (SUPI) of the UE.
[0263] The subscription related identifier can comprise a subscription concealed identifier (SUCI) and / or a Globally Unique Temporary Identifier (GUTI).
[0264] In some embodiments, the first network function is an AMF or an SEAF or an SMF, and the subscription related identifier of the UE can be a GUTI.
[0265] The first user can generally refer to any user using the UE.
[0266] In some embodiments, the first request can be an activation request or a login request of the first user, and these first requests will carry the user identifier of the first user.
[0267] In some embodiments, the first request can further comprise capability information of the UE, which can be used to indicate the authentication capability supported by the UE.
[0268] In some embodiments, the first request can further comprise, but not limited to, network slice information of a network slice supported by the UE or the first user.
[0269] In some embodiments, the capability information can indicate whether the UE supports user authentication. If the UE does not support user authentication, user authentication of the user cannot be performed. In some embodiments, the capability information can also indicate the way of user authentication supported by the UE, for example, the UE can support user authentication with configured user authentication credential, or support user authentication based on key derivation. Generally, the configured credential can be pre-set in the UE. In some embodiments, the configured credential can also be pre-set in the UE according to installation or update of an application program of an application layer. Exemplarily, the credential can include, but is not limited to, a digital certificate.
[0270] S2102: The first network function sends a second request to the second network function.
[0271] In some embodiments, after receiving the first request, the first network function sends the second request to the second network function.
[0272] In some embodiments, the first network function determines that the first request contains the user identity of the first user, and sends the second request to the second network function.
[0273] In some embodiments, the second request includes part or all of the content of the first request, and exemplarily, the second request includes the user identity of the first user in the first request. In some embodiments, the second request indicates at least one of the following:
[0274] a first indicator for indicating authentication of the first user;
[0275] a subscription-related identity of the UE;
[0276] a user identity of the first user;
[0277] capability information of the UE for indicating user authentication capability of the UE;
[0278] network slice information for indicating a network slice supported or expected to be used by the UE.
[0279] In some embodiments, the second network function can also be a core network function.
[0280] In some embodiments, the second network function can include, but is not limited to, a network function storing configuration information and / or subscription information of a user. Exemplarily, the second network function can include, but is not limited to, a User Profile Server (UPS) and / or a User Data Mangement (UDM), a Unified Data Repository (UDR), a User Identity Management Function (UIMF). Of course, this is only an example of the second network function, and the specific implementation is not limited to this example.
[0281] Correspondingly, the second network function receives the first request sent by the first network function.
[0282] S2103: The second network function sends a second response to the first network function.
[0283] In some embodiments, the second network function stores at least subscription information of one or more users.
[0284] In some embodiments, the second request is used to request user authentication mode information of the first user, configuration information of the first user and / or related information of the first user.
[0285] In some embodiments, the related information of the first user can be part of the configuration information of the first user. In other embodiments, the related information of the first user can be information generated according to the configuration information of the first user.
[0286] In some embodiments, the second response includes at least one of the following:
[0287] User authentication mode information, used to indicate a user authentication mode of the first user determined by the second network function;
[0288] Related information of the first user, used by the first network function to determine the user authentication mode of the first user.
[0289] If the user authentication mode of the first user is determined by the second network function, the second network function generates the user authentication mode information.
[0290] If the user authentication mode of the first user is not determined by the second network function, the second network function returns the related information of the first user to the first network function.
[0291] In some embodiments, the configuration information of the first user can include at least one of the following:
[0292] A user authentication policy, which can be used by the network function to determine the user authentication mode of the first user. Specifically, the user authentication policy can include one or more rules for determining the user authentication mode of the first user, and the second network function or the first network function can determine the user authentication mode of the first user according to these rules. For example, the user authentication mode for the first user can be determined according to the type of UE currently requested by the first user and / or the scenario in which the UE is used, in combination with the user authentication policy.
[0293] Preconfigured credential information, which is used to indicate whether the first user has preconfigured credentials and / or whether the preconfigured credentials of the first user are valid.
[0294] For example, the preconfigured credentials can include, but are not limited to, digital certificates and the like. The preconfigured credentials can be pre-set in the UE or an application used for user login. Of course, the above is only an example, and the specific implementation is not limited to the above example.
[0295] In some embodiments, whether the preconfigured credentials are valid can include, but is not limited to, at least one of the following:
[0296] Whether the preconfigured credentials are within a valid period (valid time range);
[0297] Whether the number of uses of the preconfigured credentials exceeds the maximum number of times;
[0298] Whether the UE is located within a valid use area or a specified scenario corresponding to the preconfigured credentials.
[0299] For example, the valid use area can be indicated by geographic location information or by network area information. That is, the valid use area includes a geographic area and / or a network area. For example, the network area can include one or more tracking areas or one or more cells.
[0300] For example, the specified scenario can include, but is not limited to, a service scenario and / or a network slice use scenario, and the like.
[0301] If no preconfigured credentials are set for the first user, it means that the first user lacks preconfigured credentials.
[0302] In some embodiments, the related information of the first user includes at least one of the following:
[0303] A user authentication policy, which is used to determine the user authentication mode of the first user;
[0304] A first indication, which is used to indicate whether the preconfigured credentials of the first user are valid.
[0305] In some embodiments, the preconfigured credentials of the first user are invalid or missing, and the user authentication mode of the first user is the first mode.
[0306] In some embodiments, the preconfigured credential of the first user is valid, and the user authentication manner of the first user is a second manner; the second manner is an authentication manner in which the preconfigured credential is used for user authentication.
[0307] In summary, whether to perform user authentication on the first user and / or the user authentication manner of the first user can be determined by the first network function or the second network function. Illustratively, the first network function or the second network function determines whether to perform user authentication on the first user and / or the user authentication manner of the first user according to the configuration information of the first user.
[0308] In some embodiments, there are multiple optional manners for determining whether to perform user authentication on the user according to the configuration information, which can specifically include but are not limited to any one of the following:
[0309] Manner 1:
[0310] Whether the configuration information of the first user is activated determines whether to perform user authentication on the first user.
[0311] In some embodiments, it is determined not to perform user authentication on the first user when the configuration information of the user is not activated, and / or it is determined to perform user authentication on the first user when the configuration information of the first user is activated.
[0312] For example, the configuration information is configured with a state and the state of the configuration information is indicated by the state information, so that the second network device can provide the configuration information of any state to the first network device and the configuration information includes the state information, so that the first network device receives the configuration information and the state information from the second network device, and determines whether the corresponding configuration information is activated according to the state information.
[0313] For another example, the configuration information is configured with a state and the state of the configuration information is indicated by the state information, so that the second network function can only provide the configuration information of the activated state to the first network function. If a certain configuration information is not activated, the first network function cannot receive the corresponding configuration information from the second network function, at this time the first network function can determine whether the corresponding configuration information is activated according to whether the corresponding configuration information is successfully received.
[0314] It is worth noting that: in some cases, the first network function can also determine whether to perform user authentication on the first user according to whether the user has configuration information. For example, the first network function fails to obtain the configuration information of the first user or the configuration information is incorrect, and it can be considered that the corresponding first user is not subjected to user authentication. For another example, the first network function successfully obtains the configuration information of the first user, and then performs user authentication on the first user according to the obtained configuration information. In this way, the illegal use of the UE by the illegal user who does not submit user information and / or submits incorrect user information can be reduced, and the use safety of the UE is improved.
[0315] Method 2:
[0316] According to whether the subscription-related identifier in the configuration information of the first user can identify the UE, it is determined whether to perform user authentication on the user.
[0317] For example, according to whether the subscription-related identifier of the UE matches the subscription-related identifier recorded in the configuration information of the first user, it is determined whether to perform user authentication on the first user. In this way, the UE or device identified by the subscription-related identifier recorded in the configuration information can be a device that the user is allowed to use when the user subscribes to the network. The subscription-related identifier recorded in the configuration information can also be the identifier of the UE and / or device that the network actively collects according to the historical use and / or historical user authentication of the user to the mobile network.
[0318] In some embodiments, when the subscription-related identifier of the UE matches the subscription-related identifier recorded in the configuration information, it is determined to perform user authentication on the first user; and / or, when the subscription-related identifier of the UE does not match the subscription-related identifier recorded in the configuration information, it is determined not to perform user authentication on the first user.
[0319] In some embodiments, the subscription-related identifier of the UE can include but is not limited to SUCI and / or SUPI. The subscription-related identifier recorded in the configuration information can include but is not limited to SUPI.
[0320] Method 3:
[0321] According to whether the configuration information of the first user records an authentication policy for the first user authentication, it is determined whether to perform the first user authentication on the user.
[0322] In some embodiments, the authentication policy can be configured by a core network function, an operation management and maintenance server, and / or a service server.
[0323] In some embodiments, the authentication policy can be used by the first network function to determine whether to perform user authentication on the user, and / or the authentication method for authenticating the first user.
[0324] In some embodiments, the configuration information records an authentication policy for the first user authentication, it is determined to perform the user authentication on the first user; and / or, the configuration information does not record the authentication policy for the first user authentication, it is determined not to perform the user authentication on the first user.
[0325] In some embodiments, the authentication policy indicates to perform the user authentication on the first user, it is determined to perform the user authentication on the first user; and / or, the authentication policy indicates not to perform the user authentication on the first user, it is determined not to perform the user authentication on the first user.
[0326] Option 4:
[0327] According to whether the UE and / or the UE supports the user authentication, it is determined whether to perform the user authentication on the first user.
[0328] In some embodiments, the UE supports the user authentication, it is determined to perform the user authentication on the user; and / or, the UE does not support the user authentication, it is determined not to perform the user authentication on the user.
[0329] In some embodiments, according to the first information sent by the UE, it is determined whether the UE and / or the UE supports the user authentication; the first information comprises the capability information of the UE and / or the capability information of the UE.
[0330] For example, in the case of receiving the first information, the second information recorded in the user profile is ignored, and it is directly determined according to the first information whether the UE supports the user authentication.
[0331] In some embodiments, in the case of not receiving the first information, according to the second information of the configuration information, it is determined whether the UE supports the user authentication; the second information is used to indicate the capability of the UE.
[0332] In some embodiments, no matter whether the first information is received, the first network function directly determines according to the second information in the configuration information whether the UE and / or the UE supports the user authentication.
[0333] The above is only an example of whether the first network function or the second network function performs the user authentication on the user, and the specific implementation is not limited to the above example.
[0334] There are various ways to determine the authentication mode of the user when it is determined to perform the user authentication on the user, and the specific implementation is not limited to any one of the above.
[0335] For example, when it is determined to perform the user authentication on the user, it is determined to perform the authentication mode on the user, which can include but is not limited to at least one of the following:
[0336] According to the configuration information, it is determined to perform the authentication mode on the first user;
[0337] According to the local information of the first network function, a first user authentication mode is determined.
[0338] In some embodiments, the first user authentication mode can be any one of the extended authentication protocol (EAP) authentication modes. For example, the alternative authentication modes of the first user authentication can include, but are not limited to, EAP-MD5 (Extented Authentication Protocol-Message Digest Algorithm 5), EAP-PSK (Extented Authentication Protocol-Pre-shared key), EAP-TLS (Extented Authentication Protocol-Transport Layer Security), EAP-LEAP (Extented Authentication Protocol-Lightweight Extensible Authentication), and EAP-PEAP (Extented Authentication Protocol-Protected Extensible Authentication). The above are only examples of the EAP authentication mode, and the specific implementation is not limited to any one of the above examples.
[0339] For example, when the third-party authentication is required, the second network function needs to interact with the third-party authentication server to obtain the first user authentication result. If the third-party authentication is not required, the second network function can complete the first user authentication of the first user by itself. For example, the third-party authentication server can include, but is not limited to, an AAA (Authentication Authorization Accounting) server.
[0340] In some embodiments, the second network function can be various core network functions capable of identity authentication, exemplarily, the core network function can include but is not limited to an authentication server function (AUSF), a UDM, a user authentication and authorization function (UAAF), and / or a user information management function (UIMF).
[0341] In some embodiments, it is determined to perform user authentication on the user, and the authentication manner for the user is determined according to the configuration information of the user.
[0342] In some embodiments, it is determined not to perform user authentication on the first user, and there is no need to determine the authentication manner for the first user.
[0343] In some embodiments, the first user is authenticated by default, in which case, it can be directly determined whether the first user needs to be authenticated, and the authentication manner for the user is directly determined.
[0344] In some embodiments, according to the configuration information, it is determined how to perform user authentication on the first user.
[0345] In some embodiments, if the first request carries the first indicator, the first network function can determine the user authentication manner for the first user according to the first request, in which case, the first network function can determine the user authentication manner for the first user without sending the second request to the second network function.
[0346] Exemplarily, the first indicator indicates that the first user has a credential, and it is considered that the second manner is used to perform user authentication on the first user, otherwise, it is considered that the first manner is used to perform user authentication on the first user.
[0347] Exemplarily, the first indicator indicates that the first user has a valid credential, and it is considered that the second manner is used to perform user authentication on the first user, otherwise, it is considered that the first manner is used to perform user authentication on the first user.
[0348] S2104: The first network function sends a third request to a third network function.
[0349] In some embodiments, the third network function can be a core network function.
[0350] In some embodiments, the third network function can be a network function capable of generating a key.
[0351] In some embodiments, the third network function can include, but is not limited to, an Authentication Server Function (AUSF).
[0352] In some embodiments, the first network function sends a third request to the third network function in a case that the user authentication mode of the first user is the first mode.
[0353] In some embodiments, the third request is used to request the third network function to generate a second key of the UE according to the first key.
[0354] In some embodiments, the second key is used to generate a third key of the first user.
[0355] In some embodiments, the third key is used for user authentication of the first user.
[0356] In some embodiments, the third request includes part or all of the content of the first request.
[0357] In some embodiments, the third request includes, but is not limited to, at least one of the following:
[0358] a user identity of the first user;
[0359] a subscription-related identity of the UE, for example, a subscription identity of the UE;
[0360] user authentication mode information.
[0361] Of course, the above is only an example of the third request, and the specific implementation is not limited to the above example.
[0362] S2105: The third network function generates a second key.
[0363] In some embodiments, the second key is used for third key generation of one or more users of the UE.
[0364] In some embodiments, the second key can be an intermediate key for generating the third key.
[0365] In some embodiments, the second key is an intermediate key common to multiple users of the UE.
[0366] In some embodiments, the third network function generates the second key according to the first key.
[0367] In some embodiments, the first key can be a key corresponding to the first network function, for example, the first network function is an AUSF, and the first key can be Kausf.
[0368] In some embodiments, the first key can be an intermediate key for generating an integrity key and / or a confidentiality key of the UE communication.
[0369] The integrity key can be used for integrity protection of user plane and / or control plane information interaction of the UE communication. The confidentiality key can be used for confidentiality protection of user plane and / or control plane information interaction of the UE communication. The confidentiality protection involves encryption and / or decryption of information.
[0370] In some embodiments, the third network function generating the third key can include, but is not limited to, at least one of the following:
[0371] generating the second key according to the first key and a subscription identifier of the UE;
[0372] generating the second key according to the first key, a subscription identifier of the UE, and a first string;
[0373] generating the second key according to the first key and a first string.
[0374] In some embodiments, the first string can be a string of one or more letters, numbers, or special symbols pre-set. Exemplarily, the first string can include two or more characters.
[0375] In some embodiments, the third network function further determines the lifetime information of the second key.
[0376] In some embodiments, the lifetime information of the second key can include, but is not limited to, at least one of the following:
[0377] time length information for indicating a valid use time length of the second key;
[0378] times information for indicating a valid times of the second key.
[0379] In some embodiments, without creating the lifetime information of the second key, the second key can be a one-time key by default; or the second key is valid between one on-off of the UE by default.
[0380] In some embodiments, the third network function generates the second key according to the first key without generating the second key.
[0381] In some embodiments, the third network function generates the second key according to the third request and the first key.
[0382] In some embodiments, the third network function generates the second key in a case that the user authentication manner of the first user is a first manner.
[0383] In some embodiments, the first network function does not generate the second key if the second response indicates that the user authentication mode is the second mode.
[0384] In some embodiments, the user is authenticated according to the first user preconfigured credential if the user authentication mode is the second mode.
[0385] In some embodiments, S2105 is an optional step if the first network function has generated the second key at a historical time.
[0386] S2106: The third network function generates a third key of the first user.
[0387] In some embodiments, the third network function generates the third key of the first user according to the second key.
[0388] In some embodiments, the third network function generating the third key of the first user comprises at least one of:
[0389] generating the third key of the first user according to the second key and a user identity of the first user;
[0390] generating the third key of the first user according to the second key, the user identity of the first user and a second string;
[0391] generating the third key of the first user according to the second key and the second string;
[0392] In some embodiments, the third key is generated according to the second key, a user identity of the first user and a device identity of the third network function. Exemplarily, the third network function is an AUSF, and the device identity of the third network function can be an identity of the AUSF.
[0393] In some embodiments, the second string can be determined by a protocol agreement or a predefined manner.
[0394] In some embodiments, S2106 can be an optional step. For example, the third network function pre-generates the third key, and the third network function locally stores a generation record. If the third network function determines that the third key has been generated at a historical time, the step can be skipped.
[0395] S2107: The third network function sends a user identity of the first user and the third key to the second network function.
[0396] In some embodiments, the third network function sends the user identity of the first user, the third key and a subscription identity of the UE to the second network function.
[0397] In some embodiments, the user identity of the first user and the third key sent by the third network function to the second network function are to be stored by the second network function into the configuration information of the first user.
[0398] S2108: The third network function sends a third response to the first network function.
[0399] In some embodiments, the third response is used to indicate whether the generation of the second key and / or the third key is successful.
[0400] In some embodiments, the third response is sent to the first network function according to the result of the generation of the second key after the third network function performs the generation of the one or more second keys.
[0401] In some embodiments, the third response is sent to the first network function according to the result of the generation of the third key after the third network function performs the generation of the one or more third keys.
[0402] S2109: The first network function sends the first response to the UE.
[0403] In some embodiments, the first network function sends the first response to the UE according to the second response.
[0404] In some embodiments, if the second response indicates that the user authentication mode of the first user is the second mode, the steps S2104 to S2108 can be skipped and S2109 is performed. At this time, the user authentication information contained in the first response can indicate that the user authentication mode of the first user is the second mode.
[0405] In some embodiments, if the second response indicates that no user authentication is required for the first user, the first network function can send a second response indicating failure to the UE. Illustratively, at this time, the second response can include a failure cause. For example, the failure cause can indicate that no user authentication is required, and / or that the UE does not support the user authentication mode selected by the network function for the first user, etc.
[0406] In some embodiments, if the third response indicates that the generation of the second key or the third key is successful, the first network function sends the first response containing user authentication mode information to the UE.
[0407] In some embodiments, if the third response indicates that the generation of the second key or the third key fails, the first network function sends the first response to the UE, and the first response can indicate the failure cause of the generation of the second key or the third key.
[0408] In some embodiments, the first response includes at least one of:
[0409] first user authentication mode information, used to indicate the user authentication mode of the first user to the UE.
[0410] a failure cause, used to indicate that the second key and / or the third key fails to be generated.
[0411] In some embodiments, the first user authentication manner information indicates that the user authentication of the first user is performed in a first manner; or
[0412] In a case where the third response indicates that the second key and / or the third key fails to be generated, the first response comprises a failure cause; or
[0413] In a case where it is determined according to the second response that the user authentication manner of the first user is a second manner, the first response comprises the first user authentication manner information, and the first user authentication manner information indicates that the user authentication of the first user is performed in a second manner.
[0414] In some embodiments, after the third network function completes the generation of the second key and / or the third key, the third network function can further perform the following operations:
[0415] associating the third key of the first user, the user identifier of the first user;
[0416] associating the third key of the first user, the user identifier of the first user, and the subscription identifier of the UE;
[0417] associating the second key and the subscription identifier of the UE.
[0418] In some embodiments, the associating the third key of the first user, the user identifier of the first user, can comprise that the third network function locally and correspondingly stores the third key and the user identifier of the first user, or sends the third key and the user identifier of the first user to the second network function, and the second network function writes the third key of the first user into configuration information of the first user.
[0419] In some embodiments, the associating the third key of the first user, the user identifier of the first user, and the subscription identifier of the UE can comprise that the third network function locally and correspondingly stores the third key, the user identifier of the first user, and the subscription identifier of the UE, or sends the third key, the subscription identifier of the UE, and the user identifier of the first user to the second network function, and the second network function writes the third key of the first user and the subscription identifier of the UE into configuration information of the first user.
[0420] In some embodiments, the associating the second key and the subscription identifier of the UE can comprise: the third network function locally storing the second key and the subscription identifier of the UE, or the third network function sending the second key and the subscription identifier of the UE to the second network function, and the second network function writing the second key and the subscription identifier of the UE into the subscription data of the UE.
[0421] S2110: The UE generates a fourth key.
[0422] In some embodiments, the UE generates the fourth key according to the first key.
[0423] In some embodiments, the UE locally generates the fourth key according to the first key.
[0424] In some embodiments, the UE uses the same key derivation function (KDF) and / or parameters as the first network function, for example, the UE also generates the fourth key by taking the first key as input.
[0425] In some embodiments, the fourth key is generated according to the subscription-related identifier of the UE and the first key.
[0426] In some embodiments, the fourth key is generated according to the subscription-related identifier of the UE, the first key and a first string. In the embodiments of the present disclosure, the fourth key generated by the UE corresponds to the second key generated by the third network function.
[0427] In some embodiments, the fourth key is generated according to the first key and the first string.
[0428] In some embodiments, the fourth key can be used for one or more key generations for user authentication of the UE. Different users use different keys for user authentication. In some embodiments, the first key is a root key for the third network function to derive a third key and the first key is also a root key for the UE to derive a fifth key. The second key is an intermediate key for the third network function to derive the third key and the fourth key is also an intermediate key for the UE to derive the fifth key.
[0429] If the user is a legal user of the UE, at this time, the second key derived by the first network function and the fourth key derived by the UE are the same, and the third key derived by the first network function and the fifth key derived by the UE are the same.
[0430] In some embodiments, the authentication mode information indicates that the first mode is used for user authentication, the fourth key is generated according to the first key of the UE, and the fifth key is generated according to the fourth key.
[0431] In some embodiments, the authentication manner information indicates that the user authentication is performed in a second manner, and the user authentication is performed according to the credential of the user.
[0432] In some embodiments, in a case where the first response is a success response, the UE generates a fourth key.
[0433] In some embodiments, in a case where the first response is a failure response, the UE does not generate the fourth key.
[0434] In some embodiments, in a case where the first response is a success response, the third response can include user authentication information.
[0435] In some embodiments, the UE further determines the lifetime information of the fourth key.
[0436] In some embodiments, the lifetime information of the fourth key can include, but is not limited to, at least one of the following:
[0437] time length information for indicating a valid use time length of the fourth key;
[0438] times information for indicating a valid number of times of the fourth key.
[0439] In some embodiments, without creating the lifetime information of the fourth key, the fourth key can be a one-time key by default; or the fourth key is valid between one power-on and one power-off of the UE by default.
[0440] In some embodiments, if the third response includes the first key identifier, the UE associates the fourth key and the first key identifier after generating the fourth key.
[0441] S2111: The UE generates a fifth key.
[0442] In some embodiments, the UE generates the fifth key of the first user according to the fourth key. The fifth key of the first user corresponds to the third key generated by the third network function for the first user.
[0443] In some embodiments, the same third key and / or fifth key can be used when a user uses different UEs, or different third keys and fifth keys can be used when a user uses different UEs at different times.
[0444] In some embodiments, the key derivation function used by the UE to generate the fifth key according to the fourth key can be the same as the KDF used by the third network function to generate the third key according to the second key.
[0445] In some embodiments, the UE generates the fifth key according to the fourth key and the user identifier of the first user.
[0446] In some embodiments, the UE generates the fifth key according to the fourth key, the user identity of the first user, and the length of the user identity of the first user.
[0447] In some embodiments, the UE generates the fifth key according to the fourth key, the user identity of the first user, the device identity of the third network function, and the length of the user identity of the first user.
[0448] In some embodiments, the UE generates the fifth key according to the fourth key, the user identity of the first user, the device identity of the third network function, and the length of the device identity of the first network function.
[0449] In some embodiments, the UE generates the fifth key according to the fourth key, the user identity of the first user, the device identity of the third network function, the length of the user identity of the first user, and the length of the device identity of the first network function.
[0450] In some embodiments, the UE can also generate a third key identity. If the user of the UE is legitimate, the third key identity generated by the UE should be the same as the second key identity. Of course, the generation of the third key identity by the UE is an optional step. For example, the fourth keys of different users can be distinguished by using user identities.
[0451] In some embodiments, after the UE completes the generation of the fourth key and / or the fifth key, the UE can perform at least one of the following operations:
[0452] associating the fifth key of the first user with the user identity of the first user;
[0453] associating the fifth key of the first user, the user identity of the first user, and the subscription identity of the UE;
[0454] associating the fourth key and the subscription identity of the UE.
[0455] The "associating" here can at least include "corresponding storage".
[0456] S2112: The UE sends a fourth request to the fourth network function.
[0457] In some embodiments, the fourth request is used for user authentication of the first user.
[0458] In some embodiments, the fourth request is protected by the fifth key. Illustratively, part or all of the content of the fourth request is integrity protected and / or confidentiality protected by the fifth key. Also illustratively, the protection of the fourth request by the fifth key can further include digitally signing the fourth request by the fifth key.
[0459] In some embodiments, the fourth network function can be a core network function.
[0460] In some embodiments, the fourth network function can be a network function that performs user authentication.
[0461] In some embodiments, the fourth network function can include, but not limited to, a User Authentication and Authorization Function (UAAF) or an application server or an Authentication, Authorization, Accounting (AAA) server.
[0462] In some embodiments, the fourth request includes at least one of:
[0463] a user identity of the first user;
[0464] a subscription-related identity of the UE.
[0465] In some embodiments, if the fourth network function is a UAAF, the subscription-related identity of the UE carried by the fourth request can include a GPSI.
[0466] S2113: The fourth network function sends a fifth request to the second network function.
[0467] In some embodiments, the fifth request is used to request a third key of the first user or a user authentication result of the first user.
[0468] In some embodiments, the fifth request can include part or all of the content of the fourth request.
[0469] In some embodiments, the fifth request can include a user identity of the first user and / or a subscription-related identity of the UE. For example, the fifth request can include a user identity of the first user and / or a SUPI.
[0470] S2114: The second network function sends a fifth response to the fourth network function.
[0471] In some embodiments, the fifth response includes a third key of the first user and / or a user authentication result of the first user.
[0472] In some embodiments, the second network function determines a third key of the first user or a user authentication result of the first user according to the user identity of the first user carried by the fifth request, by querying the locally stored configuration information of the first user.
[0473] If the user authentication of the first user is completed, the second network function can store the user authentication result of the first user, and in this case, the second network function can return the user authentication result of the first user to the fourth network function in the fifth response.
[0474] If the user authentication of the first user is not completed, the second network function does not store the user authentication result of the first user locally, and in this case, the second network function can return the third key of the first user to the fourth network function in the fifth response.
[0475] S2115: The fourth network function sends the fourth response to the UE.
[0476] In some embodiments, the fourth network function sends the fourth response to the UE according to the fifth response.
[0477] In some embodiments, if the fifth response includes the user authentication result of the first user, the fourth network function sends the fourth response to the UE according to the user authentication result of the first user included in the fifth response.
[0478] In some embodiments, if the fifth response includes the third key, the fourth request is verified using the third key, and if the fourth request passes the verification, it is considered that the first user passes the user authentication. If the fourth request does not pass the verification, it is considered that the first user does not pass the user authentication.
[0479] In some embodiments, the fourth request is integrity-verified, decrypted, or descrambled using the third key. If the integrity verification is successful, the decryption is successful, or the descrambling is successful, it is considered that the first user passes the user authentication, otherwise it is considered that the first user does not pass the user authentication.
[0480] In some embodiments, the fourth response includes the user authentication result of the first user.
[0481] In some embodiments, the user authentication result indicates that the user authentication passes or the user authentication does not pass (i.e., the user authentication fails).
[0482] S2116: The fourth network function sends the user authentication result of the first user to the second network function.
[0483] In some embodiments, the fourth network function sends the user authentication result of the first user to the second network function in the case that the fifth response does not include the user authentication result of the first user.
[0484] In some embodiments, the fourth network function sends the user authentication result of the first user to the second network function in the case that the fifth response does not include the third key of the first user.
[0485] In some embodiments, in a case that the fifth response comprises the user authentication result of the first user, the fourth network function does not send the user authentication result of the first user to the second network function. It is worth noting that not all of the above steps are mandatory steps, for example, the first user has a history of activation before this activation, then the network side has generated the second key and the third key, and the UE side also generates the fourth key and the fifth key. In this case, S2101 to S2111 are optional steps. For another example, the UE has activated one or more users, at this time the first user uses the UE for the first time, but in this case, the network side has completed the generation of the second key and the UE has completed the generation of the fourth key, in this case, the steps of the third network function generating the second key and the UE generating the fourth key are optional steps. It is also worth noting that in some embodiments, a user logs in the UE, the UE determines that it is a new user logging in and needs to perform user authentication, but before the UE completes the login, the user stops using the UE, and S2111 to S2116 are optional steps.
[0486] As shown in FIG. 3, the embodiments of the present disclosure provide a user authentication method, which is performed by a first network function. The method can comprise:
[0487] S3101: receiving a first request.
[0488] In some embodiments, the first network function can be a core network function, which can include but is not limited to AMF and / or SEAF.
[0489] In some embodiments, the first network function receives the first request from a UE.
[0490] In some embodiments, the first request indicates at least one of:
[0491] a subscription-related identifier of the UE;
[0492] a user identifier of the first user;
[0493] a user authentication capability of the UE;
[0494] network slice information.
[0495] In some embodiments, the first network function can also be a core network function.
[0496] S3102: sending a second request.
[0497] In some embodiments, the first network function sends the second request to a second network function.
[0498] In some embodiments, the second network function can include but is not limited to UDM, UDR, UIMF, and / or UPS, etc.
[0499] In some embodiments, optional implementation of S3102 can refer to any one of optional implementation of S2102.
[0500] S3103: receiving a second response.
[0501] In some embodiments, the first network function receives the second response sent by the second network function.
[0502] In some embodiments, the related description of the second response can refer to S2103 of the corresponding embodiment of FIG. 2.
[0503] S3104: sending a third request.
[0504] In some embodiments, the first network function sends the third request to a third network function.
[0505] In some embodiments, the description of the third network function can refer to the corresponding embodiment of FIG. 2. Exemplarily, the third network function can be AUSF.
[0506] In some embodiments, optional implementation of S3104 can refer to any one of optional implementation of S2104.
[0507] S3105: receiving a third response.
[0508] In some embodiments, the first network function receives the third response sent by the third network function.
[0509] In some embodiments, the third response indicates whether the second key of the UE is generated successfully, and / or the third response indicates whether the third key of the first user is generated successfully.
[0510] In some embodiments, the related description of the third response can refer to the related description of the corresponding embodiment of FIG. 2.
[0511] S3106: sending a first response.
[0512] In some embodiments, the first network function sends the first response to the UE.
[0513] In some embodiments, the first network function sends the first response to the UE according to the second response and / or the third response.
[0514] In some embodiments, the related description of the second response can refer to S2109 of the corresponding embodiment of FIG. 2.
[0515] In some embodiments, S3102 and S3103 are optional steps if the first network function locally caches the configuration information of the first user, the related information of the first user, or the user authentication manner information received from the second network function at a historical time.
[0516] In some embodiments, S3104 and S3105 are optional steps if the user authentication manner of the first user is determined as the second manner, and directly enter the step of sending the first response.
[0517] In some embodiments, if the UE rejects the login of the specified user and the first user is not the specified user, the network side can also implicitly indicate that the user authentication of the first user fails by refusing to send the first response. In this case, S3106 is also an optional step.
[0518] In summary, in the embodiments of the present disclosure, S3101 to S3106 can be executed individually or in any combination.
[0519] As shown in FIG. 4, the embodiments of the present disclosure provide a user authentication method, which is performed by a second network function. The method can include:
[0520] S4101: receiving a second request.
[0521] In some embodiments, the second network function can be a core network function, which can include but is not limited to UDM, UDR, UIMF, or UPS, etc.
[0522] In some embodiments, the second network function receives the second request sent by the first network function. For example, the second network function receives the second request sent by the AMF or the SAEF.
[0523] Exemplarily, the second request includes the following information: See the corresponding embodiments of FIG. 2.
[0524] S4102: sending a second response.
[0525] In some embodiments, the second network function sends the first response to the first network function. In some embodiments, the second network function sends the first response to the first network function after receiving the first request.
[0526] In some embodiments, the second network function sends the second response to the first network function according to the configuration information of the first user.
[0527] The second response includes at least one of the following:
[0528] user authentication manner information, used to indicate the user authentication manner of the first user determined by the second network function;
[0529] The related information of the first user is used for the first network function to determine a user authentication mode of the first user.
[0530] In some embodiments, the optional implementation of S4102 can refer to S2103.
[0531] S4103: receiving a third key and a user identifier of the first user.
[0532] In some embodiments, the second network function receives the third key and the user identifier of the first user sent by the third network function.
[0533] In some embodiments, the second network function associates the third key and the user identifier of the first user.
[0534] In some embodiments, the association of the third key and the user identifier of the first user can include at least one of the following:
[0535] storing the third key and the user identifier of the first user correspondingly;
[0536] writing the third key and the user identifier of the first user into configuration information of the first user.
[0537] S4104: receiving a fifth request.
[0538] In some embodiments, the second network function receives the fifth request sent by the fourth network function.
[0539] In some embodiments, the related description of the fifth request can refer to the corresponding embodiments of FIG. 2.
[0540] S4105: sending a fifth response.
[0541] In some embodiments, the related description of the fifth response can refer to the corresponding embodiments of FIG. 2.
[0542] In some embodiments, the optional implementation of S4105 can refer to S2114.
[0543] S4106: receiving a user authentication result of the first user.
[0544] In some embodiments, the second network function receives the user authentication result of the first user sent by the fourth network function. Exemplarily, in the case that the fifth response does not contain the user authentication result of the first user, the second network function receives the user authentication result of the first user sent by the fourth network function.
[0545] In some embodiments, the user authentication result of the first user is written into the configuration information of the first user.
[0546] In some embodiments, part of S4101-S4106 is an optional step. For example, the first user prepares to use the UE, after the key generation required for completing the user authentication, the first user no longer uses the UE, then the UE can stop S4101-S4106 at this time.
[0547] In some embodiments, after the first user has completed the user authentication, the generated user authentication result will be stored in the third network function, then the fifth network function will no longer generate the user authentication result of the first user, then the second network function will not receive the user authentication result of the first user from the fifth network function, then S4106 is an optional step. In summary, S4101-S4106 in the embodiments of the present disclosure can be executed separately or in any combination.
[0548] As shown in FIG. 5, the embodiments of the present disclosure provide a user authentication method, executed by a UE. The method can include:
[0549] S5101: sending a first request.
[0550] In some embodiments, the UE sends the first request to the first network function.
[0551] In some embodiments, the optional implementation of S5101 can refer to S2101 of the corresponding embodiment of FIG. 2.
[0552] S5102: receiving a first response.
[0553] In some embodiments, the UE receives the first response sent by the first network function.
[0554] In some embodiments, the first response includes at least one of:
[0555] First user authentication mode information, used to indicate the user authentication mode of the first user to the UE;
[0556] Failure reason, used to indicate the failure of the second key and / or the third key generation.
[0557] S5103: generating a fourth key.
[0558] In some embodiments, the optional implementation of S5103 can refer to S2110 of the corresponding embodiment of FIG. 2.
[0559] S5104: generating a fifth key.
[0560] In some embodiments, the optional implementation of S5104 can refer to S2111 of the corresponding embodiment of FIG. 2.
[0561] In some embodiments, after the UE completes the fourth key and / or the fifth key generation, the UE can further perform at least one of the following operations:
[0562] associating the fifth key of the first user with a user identity of the first user;
[0563] associating the fifth key of the first user, the user identity of the first user, and a subscription identity of the UE;
[0564] associating the fourth key and the subscription identity of the UE.
[0565] The "associating" here can at least include "corresponding storage".
[0566] S5105: sending a fourth request.
[0567] In some embodiments, the optional implementation of S5105 can refer to S2112 of the corresponding embodiment of FIG. 2.
[0568] S5106: receiving a fourth response.
[0569] In some embodiments, one or more of the first request, the first response, the fourth key, the fifth key, the fourth request, and the fourth response can refer to the related parts of the corresponding embodiment of FIG. 2, which will not be repeated here.
[0570] In some embodiments, S5101 to S5104 can be optional steps. For example, if a user uses the UE for the first time, S5101 to S5104 are optional steps. In this case, the UE can determine whether to directly start from S5105 according to whether the fifth key is stored locally. For example, if the UE determines that the fifth key is stored locally, the UE directly sends the fourth request protected by the fifth key. Otherwise, the UE starts from S5101. In summary, in the embodiments of the present disclosure, S5101 to S51069 can be executed individually or in any combination.
[0571] As shown in FIG. 6, the embodiments of the present disclosure provide a user authentication method, which is performed by a third network function. The method can include:
[0572] S6101: receiving a third request.
[0573] In some embodiments, the third network function can include but is not limited to a UAAF.
[0574] In some embodiments, the third network function receives the fourth request sent by the first network function. The first network function can include but is not limited to an AMF and / or a UIMF.
[0575] In some embodiments, the fourth request is used to request user authentication mode information of the first user, configuration information of the first user, or related information of the first user.
[0576] In some embodiments, the third request can include, but is not limited to, at least one of the following:
[0577] User identification of the first user;
[0578] Subscription-related identification of the UE; network slice information;
[0579] Capability information of the UE.
[0580] S6102: generating a second key.
[0581] In some embodiments, the third network function generates the second key according to the first key of the UE.
[0582] In some embodiments, the optional implementation of S6102 can refer to S2105 of the corresponding embodiment of FIG. 2.
[0583] S6103: generating a third key.
[0584] In some embodiments, the optional implementation of S5103 can refer to S2106 of the corresponding embodiment of FIG. 2.
[0585] S6104: sending a third response.
[0586] In some embodiments, the third network function sends the third response to the first network function.
[0587] It is worth noting that S6102 and S6103 are optional steps. For example, if the third network function caches the third key of the first user or the local record indicates that the third key of the first user has been generated, the third network function can not perform S6102 and S6103. In summary, S6101 to S6104 in the embodiments of the present disclosure can be executed individually or in any combination.
[0588] As shown in FIG. 7, the embodiments of the present disclosure provide a user authentication method, which is executed by a fourth network function. The method can include:
[0589] S7101: receiving a fourth request.
[0590] In some embodiments, the fourth network function receives the fourth request sent by the UE.
[0591] In some embodiments, the fourth request can be carried by a NAS message.
[0592] In some embodiments, the fourth request can include, but is not limited to, at least one of the following:
[0593] a subscription-related identity of the UE;
[0594] a user identity of the first user.
[0595] In some embodiments, the subscription-related identity can comprise a SUPI, a SUCI, a GPSI and / or a GUTI of the UE.
[0596] In some embodiments, the fourth request can further comprise capability information of the UE, which can be used to indicate authentication capabilities supported by the UE.
[0597] S7102: sending a fifth request.
[0598] In some embodiments, the fourth network function sends the fifth request to the second network function.
[0599] In some embodiments, the optional embodiment manners of S7102 can refer to the corresponding embodiment S2113 of FIG. 2.
[0600] In some embodiments, the related description of the fifth request can refer to the corresponding embodiment of FIG. 2.
[0601] S7103: receiving a fifth response.
[0602] In some embodiments, the fourth network function receives the fifth response sent by the second network function.
[0603] In some embodiments, the related description of the fifth response can refer to the corresponding embodiment of FIG. 2.
[0604] S7104: sending a fourth response.
[0605] In some embodiments, the related description of the fifth response can refer to the corresponding embodiment of FIG. 2.
[0606] In some embodiments, the optional embodiment manners of S7104 can refer to the corresponding embodiment S2115 of FIG. 2.
[0607] S7105: sending a user authentication result of the first user.
[0608] In some embodiments, the fourth network function sends the user authentication result of the first user to the second network function.
[0609] In some embodiments, the optional embodiment manners of S7105 can refer to the corresponding embodiment S2116 of FIG. 2.
[0610] In some embodiments, some of the steps in S7101-S7105 are optional steps. For example, if the fourth network function locally stores the historical user authentication result of the first user and the user authentication result is still valid, then S7102 and S7103 are optional steps.
[0611] In some embodiments, S7105 is an optional step. For example, if the fifth response includes the user authentication result of the first user or the fourth network function locally caches the user authentication result of the first user, it means that the second network function has already stored the user authentication result of the first user, and at this time S7105 is an optional step.
[0612] Embodiments of the present disclosure propose a key hierarchy for deriving (or said to be derived) the key for identity authentication of the UE or multiple users using the UE. Illustratively, the UE performs user authentication after the main authentication is passed.
[0613] The key Kausf derived during the first user authentication of the UE is used as the root key of the key hierarchy. The root key can be used to derive the key generation for other users of the UE.
[0614] As shown in FIG. 8A, after the UE successfully authenticates for the first time (e.g., the UE successfully registers), the UE can interact with the AUSF to activate the UE. However, if the UE is pre-configured with credentials and receives a user activation request of the UE, the AMF will interact with the UIMF to obtain the user identity profile (UIP) of the user instead of interacting with the AUSF. Therefore, the UE needs to indicate to the AMF whether it has pre-configured credentials for user authentication. When the AMF receives an indication that there is no pre-configured credential, the AMF will interact with the AUSF instead of the UIMF.
[0615] Embodiments of the present disclosure propose a user authentication method based on the Kausf-based key hierarchy, without requiring the UE to indicate to the network that there is a lack of pre-configured credentials for user authentication.
[0616] Embodiments of the present disclosure propose a key hierarchy for deriving the specific credentials of multiple users on / behind the UE for user authentication. The UE performs user authentication after the main authentication is passed. The key Kausf derived during the main identity authentication of the UE is used as the root of the key hierarchy, for deriving the credentials (i.e., Kuser) for user authentication of the users on / behind the UE. Kuser is derived during the user activation process each time the user logs in. The derived Kuser needs to be specific to each user and associated with the user identity of the user.
[0617] In some embodiments, the user authentication method should be finally decided by the network. If the user authentication policy is configured in the UIP, the AMF should first determine the user identity authentication policy according to the UIP, and based on the user authentication policy and the availability of user authentication credentials in the network, the AMF then decides whether it should interact with the AUSF to obtain the key.
[0618] In some other embodiments, the user authentication method can be independent of the key, for example, another user authentication method can include using pre-configured credentials.
[0619] As shown in FIG. 8B,
[0620] The network registration process can specifically include:
[0621] 0a. The UE sends a registration request to the AMF or SEAF;
[0622] 0b. Main authentication process, here the main authentication process is the authentication of the UE, not the authentication of the user.
[0623] 0c. The AMF or SEAF sends a registration acceptance to the UE;
[0624] 0d. The UE sends a registration completion to the AMF or SEAF.
[0625] Exemplarily,
[0626] When the UE is registered to the network, the main authentication between the UE and the network is successful, in this process, the key Kausf is derived and stored in the UE and the AUSF. After the UE registration is completed, the first user logs in the UE and starts the user activation process.
[0627] 1. The UE sends a user activation request in a secure NAS message, which contains at least GUTI, User ID-1 and user authentication capability. User-ID-1 is the user identity of user 1.
[0628] 2. Based on the domain part of the user identity, the AMF finds the UIMF in the specified domain and sends a Nuimf_UserActivation_UIP Request message to the UIMF to obtain the configuration information associated with the user identity. The message contains SUPI, User ID-1 and UE function for user authentication. The UIMF can be set independently or integrated with the UDM. Exemplarily, the UIMF and the UDM can be set in the same location.
[0629] 3. The UIMF decides whether and how to perform the user authentication procedure based on the UIP information associated with the User ID-1 or SUPI. For example, when the user authentication policy stored in the UIP indicates that the user authentication credential needs to be derived in the user activation procedure, or when there is no credential associated with the user ID-1 in the UIP, the UIMF determines that the user authentication needs to be triggered, and the user authentication method is to generate Kuia for user authentication if the received user authentication function supports.
[0630] If the UIMF decides to trigger the user authentication, the UIMF returns a Nuimf_UserActivation_UIP response message to the AMF, which can include the user authentication method information indicating the selected user authentication method. The user authentication method indicates that Kuia needs to be derived for user authentication. Alternatively, the UIMF just sends the relevant information in the UIP to the AMF. The relevant information can indicate the user authentication policy and / or the availability of the credential associated with the user ID-1.
[0631] 5. If the relevant information or UIP is received from the UIMF instead of the user authentication method information, the AMF decides whether and how to trigger the user authentication. For example, when the received user authentication policy indicates that the key needs to be derived in the user activation procedure or the user authentication credential is missing, the AMF determines that the user authentication needs to be triggered and derives Kuia for user authentication if the UE supports.
[0632] 6. Based on the determined user authentication method of deriving Kuia, the AMF sends an Nausf_UserAuthentication_Authenticate Request message to the AUSF of the UE, which includes the SUPI of the UE, the user ID-1, etc.
[0633] 7. When receiving the Nausf_UserAuthentication_Authenticate Request from the AMF, the AUSF determines that the user authentication needs to derive Kuia from Kausf of the UE. The AUSF derives Kuia and associates Kuia with the SUPI of the UE.
[0634] 8. Based on the received User ID-1, the AUSF further derives Kuser-1 from Kuia.
[0635] 9. The AUSF sends the derived Kuser-1 associated with the User ID-1 to the UIMF. The UIMF includes Kuser-1 in the user identity profile (UIP) and associates it with the user ID-1 and the SUPI-identified link subscription.
[0636] 10. The AUSF returns the Nausf_UserAuthentication_Authenticate response to the AMF and indicates that Kuia is derived.
[0637] 11. The AMF sends the User Activation response to the UE using the selected user authentication method.
[0638] 12. When the selected user authentication method indicates that Kuia needs to be derived, the UE derives Kuia from Kausf in the same way as the AUSF. The UE associates Kuia with its SUPI.
[0639] 13. Based on the received User ID-1, the UE further derives Kuser-1 from Kuia. The UE associates Kuser-1 with User ID-1 and its SUPI.
[0640] 14. The UE initiates User Authentication of User ID-1 to the UAAF through the application layer, and the UAAF is protected using the derived Kuser.
[0641] After the first user logs in, other users (such as user-2, …, User-n) also log in the UE. The user activation process is started for each logged-in UE.
[0642] 15. According to the received User ID-n, the UE and the AUSF derive Kuser-n from Kuia. The UE associates Kuser-n with User-ID-n and SUPI.
[0643] 16. The AUSF sends the derived Kuser-n associated with User-ID-n to the UIMF. The UIMF includes Kuser-n in the user identity profile (UIP) and associates it with User ID-n and the linked subscription (i.e. SUPI).
[0644] After the UE derives Kuser in the user activation process, the UE can initiate user authentication to the UAAF.
[0645] As shown in FIG. 8C, the user authentication method provided by the embodiments of the present disclosure includes:
[0646] 1. The user sends a user authentication request message to the UAAF over a Multipath Quick UDP (User Datagram Protocol) Internet Connections (MPQUIC) protocol at the application layer, which is protected by TLS using Kuser-n. This message contains at least the UE's User-ID-n and GPSI. The MPQUIC protocol is an extension of the Quick UDP (User Datagram Protocol) Internet Connections (QUIC) protocol. This MPQUIC protocol enables devices to perform data transfer and data exchange over multiple networks based on a single connection.
[0647] 2. Upon receiving the user authentication request, the UAAF sends an Authentication Key Request to the UIMF, which contains the User-ID-n and the UE's GPSI.
[0648] 3. The UIMF first retrieves the UIP based on the received User-ID-n. Then, the UIMF finds the subscription information in the retrieved UIP based on the SUPI mapped from the received GPSI. The UIMF can need to interact with the UDM and / or UDR to obtain the mapped SUPI upon receiving the UE's GPSI. Based on the subscription information indicated by the SUPI, the UIMF is able to obtain Kuser-n associated with the User-ID-n and the SUPI. If the user authentication result associated with the User-ID-n and the SUPI is stored in the UIP, it will also be obtained.
[0649] 4. The UIMF returns the obtained Kuser-n or user authentication result to the UAAF.
[0650] 5. If the UAAF receives the authentication result, the UAAF proceeds to step #8.
[0651] If the UAAF receives Kuser-n, the UAAF verifies the authenticity of the User-n received from the UE using Kuser-n received from the UIMF.
[0652] 6. The UAAF registers the user authentication result obtained using Kuser-n to the UPS / UDM.
[0653] 7. The UIMF associates and stores the user authentication result with the User-ID-n and the SUPI.
[0654] 8. The UAAF sends the User Authentication Response and the result of the authentication to the UE. The UE associates the result of the user authentication with the user identity and its SUPI.
[0655] In some embodiments, the AMF can perform at least one of the following operations:
[0656] The AMF shall be able to receive and understand the user authentication method determined by the UIMF.
[0657] The AMF shall be able to determine whether and how to trigger the user authentication based on the check of the user identity profile received from the UIMF and the UE capabilities to support user authentication received from the UE. The user identity profile here is one of the aforementioned configuration information.
[0658] The AMF shall be able to decide when to send the user authentication request to the AUSF based on the user authentication method determined by the UIMF or the AMF itself.
[0659] The AMF shall be able to receive the user authentication response from the AUSF indicating whether Kuia is derived or not.
[0660] Based on the successful derivation of Kuia on the AUSF, the AMF shall be able to send the selected user authentication method to the UE.
[0661] In some embodiments, the AUSF can perform at least one of the following operations:
[0662] The AUSF shall be able to determine the derivation of the key Kuia based on the specific request from the AMF, i.e., the user authentication request.
[0663] The AUSF shall be able to associate the derived Kuser with the user identity and SUPI.
[0664] The AUSF shall be able to respond to the AMF indicating whether Kuia is derived or not.
[0665] In some embodiments, the UIMF can perform at least one of the following operations:
[0666] The UIMF shall be able to send the determined user authentication method or the related UIP information to the AMF.
[0667] The UIMF shall be able to retrieve the SUPI from the UDM and / or UDR based on the GPSI received from the UAAF.
[0668] The UIMF shall be able to retrieve the Kuser from the UIP information based on the user identity in the UAAF and the SUPI retrieved from the UDM and / or UDR.
[0669] The UIMF shall be able to associate Kuser from the AUSF with the user identity and SUPI.
[0670] The UIMF shall be able to associate user authentication result from the UAAF with the user identity and SUPI.
[0671] In some embodiments, the UAAF can perform at least one of the following operations:
[0672] The UAAF shall be able to receive the GPSI and the user identity in the user authentication request from the UE.
[0673] The UAAF shall be able to include the GPSI in the identity verification key request to the UIMF.
[0674] The UAAF shall be able to support the MPQUIC protocol for user authentication with the UE.
[0675] In some embodiments, the UE can perform at least one of the following operations:
[0676] In the user authentication request, the UE shall be able to send the GPSI of the UE together with the user identity to the UAAF.
[0677] The user UE shall be able to associate the derived Kuser with the user identity and its SUPI.
[0678] The UE shall be able to associate user authentication result from the UAAF with the user identity and its SUPI.
[0679] The UE shall be able to support the MPQUIC protocol for user authentication with the UAAF.
[0680] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners in other embodiments.
[0681] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners in other embodiments.
[0682] The embodiments of the present disclosure further provide a device for implementing any one of the above methods, for example, providing a device, the above device includes units or modules for implementing each step performed by the UE in any one of the above methods. For another example, another device is provided, including units or modules for implementing each step performed by a network device (for example, an access network device, or a core network device, etc.) in any one of the above methods.
[0683] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the units or modules of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.
[0684] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the process of configuring the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0685] As shown in FIG. 9A, the embodiments of the present disclosure provide a first network function, comprising:
[0686] The receiving module 9101 is configured to receive a first request sent by a user equipment (UE), wherein the first request comprises a user identifier of a first user, and the first user is a user using the UE.
[0687] The sending module 9102 is configured to send a second request to a second network function, wherein the second request comprises the user identifier of the first user.
[0688] The receiving module 9101 is configured to receive a second response sent by the second network function.
[0689] The sending module 9102 is configured to, in a case where it is determined according to the second response that the user authentication mode of the first user is the first mode, send a third request to a third network function; the third request is used to request the third network function to generate a second key of the UE according to a first key; the second key is used to generate a third key of the first user; and the third key is used for user authentication of the first user.
[0690] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first network function.
[0691] In some embodiments, the first network function further includes a processing module.
[0692] In some embodiments, the processing module can be used by the first network function to perform steps related to information processing in any one of the user authentication methods.
[0693] In some embodiments, the sending module can be used by the first network function to perform steps related to information sending in any one of the user authentication methods.
[0694] In some embodiments, the receiving module can be used by the first network function to perform steps related to information sending in any one of the user authentication methods.
[0695] In some embodiments, the processing module is configured to, in a case where the user authentication mode supported by the UE is the first mode, generate a second key according to a first key of the UE.
[0696] In some embodiments, the second response includes at least one of the following:
[0697] User authentication mode information, used to indicate the user authentication mode of the first user determined by the second network function;
[0698] Related information of the first user, used by the first network function to determine the user authentication mode of the first user.
[0699] In some embodiments, the related information of the first user includes at least one of the following:
[0700] User authentication policy, used to determine the user authentication mode of the first user;
[0701] First indication, used to indicate whether the preconfigured credential of the first user is valid.
[0702] In some embodiments, the preconfigured credential of the first user is invalid or missing, and the user authentication manner of the first user is the first manner; or, the preconfigured credential of the first user is valid, and the user authentication manner of the first user is a second manner; the second manner is an authentication manner using the preconfigured credential for user authentication.
[0703] In some embodiments, the receiving module is configured to receive a third response sent by the third network function, the third response being used to indicate whether the second key and / or the third key is generated successfully.
[0704] In some embodiments, the sending module is configured to send a first response to the UE according to the second response or the third response.
[0705] In some embodiments, the first response comprises at least one of:
[0706] first user authentication manner information, used to indicate a user authentication manner of the first user to the UE;
[0707] a failure cause, used to indicate a failure of the second key and / or the third key generation.
[0708] In some embodiments, in a case where the third response indicates that the second key and / or the third key is generated successfully, the first response comprises the first user authentication manner information, and the first user authentication manner information indicates that the first manner is used for user authentication of the first user; or,
[0709] in a case where the third response indicates that the second key and / or the third key is generated unsuccessfully, the first response comprises the failure cause; or,
[0710] In a case where it is determined according to the second response that the user authentication manner of the first user is the second manner, the first response comprises the first user authentication manner information, and the first user authentication manner information indicates that the second manner is used for user authentication of the first user.
[0711] In some embodiments, the first request further comprises at least one of:
[0712] a subscription-related identifier of the UE;
[0713] capability information of the UE, the capability information being used to indicate a user authentication manner supported by the UE;
[0714] network slice information, indicating a network slice supported and / or expected to be used by the UE.
[0715] As shown in FIG. 9B, the embodiments of the present disclosure provide a second network function execution, wherein the second network function comprises:
[0716] The receiving module 9201 is configured to receive a second request sent by a first network function, wherein the second request comprises a user identifier of a first user, and the first user is a user using a user equipment (UE);
[0717] The sending module 9202 is configured to send a second response to the first network function according to configuration information of the first user, wherein the second response is used for the first network function to determine a user authentication mode of the first user.
[0718] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the second network function.
[0719] In some embodiments, the second network function can comprise a processing module.
[0720] In some embodiments, the processing module can be used for the second network function to perform steps related to information processing in any one of the user authentication methods.
[0721] In some embodiments, the sending module can be used for the second network function to perform steps related to information sending in any one of the user authentication methods.
[0722] In some embodiments, the receiving module can be used for the second network function to perform steps related to information sending in any one of the user authentication methods.
[0723] In some embodiments, the second response comprises at least one of the following:
[0724] User authentication mode information, used for indicating a user authentication mode of the first user determined by the second network function;
[0725] Related information of the first user, used for the first network function to determine the user authentication mode of the first user.
[0726] In some embodiments, the configuration information of the first user comprises at least one of the following:
[0727] User authentication policy, used for determining the user authentication mode of the first user;
[0728] Preconfigured credential information, used for indicating whether the first user has a preconfigured credential and / or whether the preconfigured credential of the first user is valid.
[0729] In some embodiments, the second request further comprises at least one of the following:
[0730] a subscription-related identifier of the UE;
[0731] capability information of the UE, the capability information being used to indicate a user authentication manner supported by the UE;
[0732] network slice information indicating a network slice supported and / or expected to be used by the UE.
[0733] In some embodiments, the receiving module is configured to receive a fifth request sent by a fourth network function, the fifth request being used to request a third key of the first user or a user authentication result of the first user;
[0734] The sending module is configured to send a fifth response to the fourth network function, the fifth response including the third key of the first user and / or the user authentication result of the first user.
[0735] In some embodiments, the receiving module is configured to receive, in a case where the fifth response includes the third key of the first user, the user authentication result of the first user sent by the fourth network function;
[0736] The processing module is configured to write the user authentication result of the first user into configuration information of the first user.
[0737] As shown in FIG. 9C, the embodiments of the present disclosure provide a user equipment (UE), wherein the UE includes:
[0738] The sending module 9301 is configured to send a first request to a first network function, the first request including a user identifier of a first user, the first user being a user using the UE; the first request being used to cause the first network function to send a third request to a third network function in a case where a user authentication manner of the first user is a first manner; the third request being used to request the third network function to generate a second key of the UE according to a first key; the second key being used to generate a third key of the first user; the third key being used for user authentication of the first user.
[0739] In some embodiments, the UE further includes a receiving module and / or a processing module.
[0740] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the UE.
[0741] In some embodiments, the receiving module is configured to receive a first response sent by the first network function; the first response including at least one of the following:
[0742] first user authentication manner information, used to indicate the user authentication manner of the first user to the UE.
[0743] failure cause, used to indicate that the second key and / or the third key generation fails.
[0744] In some embodiments, the processing module is configured to generate a fourth key according to the first key in a case that the user authentication manner of the first user is a first manner; and generate a fifth key according to the fourth key.
[0745] In some embodiments, the processing module is configured to perform at least one of the following:
[0746] generate the fourth key according to the first key and a subscription identifier of the UE;
[0747] generate the fourth key according to the first key, a subscription identifier of the UE, and a first string;
[0748] generate the fourth key according to the first key and a first string.
[0749] In some embodiments, the processing module is configured to perform at least one of the following:
[0750] generate a fifth key according to the fourth key and a user identifier of the first user;
[0751] generate the fifth key of the first user according to the fourth key, a user identifier of the first user, and a second string;
[0752] generate the fifth key of the first user according to the fourth key and a second string.
[0753] In some embodiments, the processing module is further configured to perform at least one of the following:
[0754] associate the fifth key of the first user with the user identifier of the first user;
[0755] associate the fifth key of the first user, the user identifier of the first user, and a subscription identifier of the UE;
[0756] associate the fourth key with the subscription identifier of the UE.
[0757] In some embodiments, the sending module is configured to send a fourth request to a fourth network function, the fourth request being used for user authentication of the first user, the fourth request being protected by the fifth key;
[0758] The receiving module is configured to receive a fourth response sent by the fourth network function, the fourth response including a user authentication result of the first user.
[0759] In some embodiments, the fourth request comprises at least one of:
[0760] a user identifier of the first user;
[0761] a subscription-related identifier of the UE.
[0762] As shown in FIG. 9D, the embodiments of the present disclosure provide a third network function, wherein the third network function comprises:
[0763] a receiving module 9401 configured to receive a third request sent by a first network function, wherein the third request is used to request the third network function to generate a second key of a user equipment (UE) according to a first key;
[0764] a processing module 9402 configured to generate the second key according to the first key, and generate a third key of a first user according to the second key, wherein the first user is a user using the UE;
[0765] a sending module 9403 configured to send a third response to the first network function, wherein the third response is used to indicate whether the generation of the second key or the third key is successful, and send a subscription identifier of the UE, a user identifier of the first user, and the third key to a second network function.
[0766] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the third network function.
[0767] In some embodiments, the processing module can be used for the third network function to perform information processing related steps in any one of the user authentication methods.
[0768] In some embodiments, the sending module can be used for the third network function to perform information sending related steps in any one of the user authentication methods.
[0769] In some embodiments, the receiving module can be used for the third network function to perform information sending related steps in any one of the user authentication methods.
[0770] In some embodiments, the processing module is configured to perform at least one of:
[0771] generate the second key according to the first key and a subscription identifier of the UE;
[0772] generate the second key according to the first key, the subscription identifier of the UE, and a first string;
[0773] generate the second key according to the first key and the first string.
[0774] In some embodiments, the processing module is configured to perform at least one of the following:
[0775] generating a third key of the first user according to the second key and a user identity of the first user;
[0776] generating a third key of the first user according to the second key, a user identity of the first user and a second string;
[0777] generating a third key of the first user according to the second key and a second string.
[0778] In some embodiments, the processing module is configured to perform at least one of the following:
[0779] associating the third key of the first user, the user identity of the first user;
[0780] associating the third key of the first user, the user identity of the first user and a subscription identity of the UE;
[0781] associating the second key and the subscription identity of the UE.
[0782] As shown in FIG. 9E, embodiments of the present disclosure provide a fourth network function, wherein the fourth network function comprises: a sending module 9501, a receiving module 9502 and a processing module 9503;
[0783] The receiving module 9502 is configured to receive a fourth request sent by a user equipment (UE), the fourth request being used for user authentication of a first user, and the fourth request being protected by a fifth key of the first user;
[0784] The sending module 9501 is configured to send a fifth request to a second network function, the fifth request being used for requesting a third key of the first user or a user authentication result of the first user, and the fifth request comprising a user identity of the first user and a related subscription identity of the UE;
[0785] The receiving module 9502 is configured to receive a fifth response sent by the second network function;
[0786] The processing module 9503 is configured to obtain the user authentication result of the first user according to the fifth response;
[0787] The sending module 9501 is configured to send a fourth response to the UE according to the user authentication result.
[0788] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the fourth network function.
[0789] In some embodiments, the processing module is configured to perform, by the fourth network function, a step related to information processing in any one of the user authentication methods.
[0790] In some embodiments, the sending module is configured to perform, by the fourth network function, a step related to information sending in any one of the user authentication methods.
[0791] In some embodiments, the receiving module is configured to perform, by the fourth network function, a step related to information sending in any one of the user authentication methods.
[0792] In some embodiments, the fifth response comprises a third key of the first user and / or a user authentication result of the first user.
[0793] In some embodiments, the processing module is configured to, in a case that the fifth response comprises the third key of the first user, verify the fourth request according to the third key of the first user; and generate a user authentication result of the first user passing the user authentication in a case that the fourth request is verified successfully.
[0794] In some embodiments, the sending module is configured to, in a case that the fifth response comprises the third key of the first user, send the user authentication result of the first user to the second network function.
[0795] The embodiments of the present disclosure further provide a communication device, which can comprise: one or more processors; wherein the processor is configured to invoke instructions to cause the communication device to perform the user authentication method implemented by any one of the preceding embodiments.
[0796] In some embodiments, as shown in FIG. 10A and / or FIG. 10B, the communication device 8100 further comprises one or more memories 8102 configured to store instructions. Optionally, all or part of the memory 8102 can also be located outside the communication device 8100.
[0797] The communication device can be the UE and the network device described above. In some embodiments, the network device can be a master node and / or a secondary node.
[0798] In some embodiments, the communication device 8100 further comprises one or more transceivers 8103. When the communication device 8100 comprises one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0799] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.
[0800] Optionally, the communication device 8100 further includes one or more interface circuits 8104 connected with the memory 8102, which can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0801] The communication device 8100 described in the above embodiments can be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited to this, and the structure of the communication device 8100 can not be limited by FIG. 10A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, UE device, smart UE device, cellular phone, wireless device, handset, mobile unit, vehicle-mounted device, network device, cloud device, artificial intelligence device, etc.; (6) other, etc.
[0802] FIG. 10B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 10B can be referred to, but is not limited thereto.
[0803] The chip 8200 includes one or more processors 8201 for invoking instructions to cause the chip 8200 to perform any of the above user authentication methods.
[0804] In some embodiments, chip 8200 further includes one or more interface circuits 8202 that are wired to memory 8203, which can be used to receive signals from or send signals to memory 8203 or other devices. For example, interface circuit 8202 can read instructions stored in memory 8203 and send those instructions to processor 8201. Alternately, the terms interface circuit, interface, transceiver pin, transceiver, and the like can be used interchangeably.
[0805] In some embodiments, chip 8200 further includes one or more memories 8203 for storing instructions. Alternately, all or part of memory 8203 can be external to chip 8200.
[0806] The present disclosure also provides a storage medium having stored thereon instructions which, when executed by a communication device 8100, cause communication device 8100 to perform any of the above methods. Alternately, the storage medium is an electronic storage medium. Alternately, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other devices. Alternately, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.
[0807] The present disclosure also provides a program product which, when executed by a communication device 8100, causes communication device 8100 to perform any of the above user authentication methods. Alternately, the program product is a computer program product.
[0808] The present disclosure also provides a computer program which, when executed on a computer, causes the computer to perform any of the above user authentication methods.
[0809] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure embodiments following, in general, the principles of the present disclosure and including such features to the present disclosure as come within the true spirit and scope of the present disclosure. Specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0810] It should be understood that the present embodiments are not limited to the precise structures as set forth above and shown in the attached drawings and that various modifications and changes can be made without departing from the scope thereof, the scope being indicated by the true spirit of the claims.
Claims
A user authentication method in which, The method is performed by a first network function, and the method comprises: receiving a first request sent by a user equipment (UE), the first request comprising a user identifier of a first user, the first user being a user using the UE; sending a second request to a second network function, the second request comprising the user identifier of the first user; receiving a second response sent by the second network function; in a case where it is determined according to the second response that a user authentication mode of the first user is a first mode, sending a third request to a third network function, the third request being used to request the third network function to generate a second key of the UE according to a first key, the second key being used to generate a third key of the first user, the third key being used for user authentication of the first user. The method of claim 1, wherein, The second response comprises at least one of the following: user authentication mode information, used to indicate a user authentication mode of the first user determined by the second network function; and related information of the first user, used for the first network function to determine the user authentication mode of the first user. The method of claim 2, wherein, The related information of the first user comprises at least one of the following: a user authentication policy, used to determine the user authentication mode of the first user; and a first indication, used to indicate whether a preconfigured credential of the first user is valid. The method of claim 3, wherein, The first user authentication mode of the first user is the first mode in a case where the preconfigured credential of the first user is invalid or missing; or The first user authentication mode of the first user is a second mode in a case where the preconfigured credential of the first user is valid, the second mode being an authentication mode using the preconfigured credential for user authentication. The method according to any one of claims 1 to 4, wherein The method further comprises: receiving a third response sent by the third network function, the third response being used to indicate whether the second key and / or the third key is generated successfully. The method of claim 5, wherein, The method further comprises: sending a first response to the UE according to the second response or the third response. The method of claim 6, wherein, The first response comprises at least one of the following: first user authentication mode information, used to indicate the user authentication mode of the first user to the UE; and a failure cause, used to indicate a failure of the second key and / or the third key. According to the method of claim 7, in a case where the third response indicates that the second key and / or the third key is generated successfully, the first response comprises the first user authentication mode information, and the first user authentication mode information indicates that the first user is authenticated in the first mode; or in a case where the third response indicates that the second key and / or the third key is generated unsuccessfully, the first response comprises the failure cause; or in a case where it is determined according to the second response that the user authentication mode of the first user is the second mode, the first response comprises the first user authentication mode information, and the first user authentication mode information indicates that the first user is authenticated in the second mode. The first request further comprises at least one of the following: a subscription-related identifier of the UE; and The method according to any one of claims 1 to 8, wherein capability information of the UE, the capability information being used to indicate a user authentication mode supported by the UE. Network slice information indicating a network slice supported and / or expected to be used by the UE. A user authentication method in which, The method is performed by a second network function, and the method comprises: receiving a second request sent by a first network function, the second request comprising a user identifier of a first user, the first user being a user using a user equipment (UE); sending, to the first network function, a second response according to configuration information of the first user, the second response being used for the first network function to determine a user authentication mode of the first user. The method of claim 10, wherein, The second response comprises at least one of: user authentication mode information used for indicating the user authentication mode of the first user determined by the second network function; related information of the first user used for the first network function to determine the user authentication mode of the first user. The method according to claim 10 or 11, wherein The configuration information of the first user comprises at least one of: a user authentication policy used for determining the user authentication mode of the first user; preconfigured credential information used for indicating whether the first user has a preconfigured credential and / or whether the preconfigured credential of the first user is valid. The second request further comprises at least one of: The method according to any one of claims 10 to 12, wherein a subscription-related identifier of the UE; capability information of the UE, the capability information being used for indicating a user authentication mode supported by the UE; network slice information indicating a network slice supported and / or expected to be used by the UE. The method further comprises: The method according to any one of claims 10 to 13, wherein receiving a fifth request sent by a fourth network function, the fifth request being used for requesting a third key of the first user or a user authentication result of the first user; sending, to the fourth network function, a fifth response comprising the third key of the first user and / or the user authentication result of the first user. The method further comprises: The method of claim 14, wherein, in a case where the fifth response comprises the third key of the first user, receiving a user authentication result of the first user sent by the fourth network function; writing the user authentication result of the first user into the configuration information of the first user. The method is performed by a user equipment (UE), and the method further comprises: A user authentication method in which, sending, to a first network function, a first request comprising a user identifier of a first user, the first user being a user using the UE; the first request being used for causing the first network function to send, to a third network function, a third request in a case where a user authentication mode of the first user is a first mode; the third request being used for requesting the third network function to generate, according to a first key, a second key of the UE; the second key being used for generating a third key of the first user; the third key being used for user authentication of the first user. The method further comprises: The method of claim 16, wherein, receiving a first response sent by the first network function; the first response comprising at least one of: first user authentication mode information used for indicating the user authentication mode of the first user to the UE; a failure cause used for indicating a failure of the generation of the second key and / or the third key. The method further comprises: The method according to claim 16 or 17, wherein in a case where the user authentication mode of the first user is the first mode, generating a fourth key according to the first key; generating a fifth key according to the fourth key. The method of claim 18, wherein, The generating the fourth key according to the first key comprises at least one of the following: generating the fourth key according to the first key and a subscription identifier of the UE; generating the fourth key according to the first key, the subscription identifier of the UE and a first string; generating the fourth key according to the first key and the first string. The method of claim 18 or 19, wherein, The generating the fifth key according to the fourth key comprises: generating the fifth key according to the fourth key and a user identifier of the first user; generating the fifth key of the first user according to the fourth key, the user identifier of the first user and a second string; generating the fifth key of the first user according to the fourth key and the second string. The method according to any one of claims 16 to 20, wherein The method further comprises at least one of the following: associating the fifth key of the first user and the user identifier of the first user; associating the fifth key of the first user, the user identifier of the first user and the subscription identifier of the UE; associating the fourth key and the subscription identifier of the UE. The method according to any one of claims 18 to 20, wherein The method further comprises: sending a fourth request to a fourth network function, the fourth request being used for user authentication of the first user, the fourth request being protected by the fifth key; receiving a fourth response sent by the fourth network function, the fourth response comprising a user authentication result of the first user. The method of claim 22, wherein, The fourth request comprises at least one of the following: the user identifier of the first user; the subscription related identifier of the UE. A user authentication method in which, The method executed by a third network function comprises: receiving a third request sent by a first network function, the third request being used for requesting the third network function to generate a second key of a user equipment (UE) according to a first key; generating the second key according to the first key; generating a third key of a first user according to the second key, the first user being a user using the UE; sending a third response to the first network function, the third response being used for indicating whether the second key or the third key is generated successfully; sending a subscription identifier of the UE, a user identifier of the first user and the third key to the second network function. The method of claim 24, wherein, The generating the second key according to the first key comprises at least one of the following: generating the second key according to the first key and a subscription identifier of the UE; generating the second key according to the first key, the subscription identifier of the UE and a first string; generating the second key according to the first key and the first string. The method of claim 24 or 25, wherein, The generating the third key of the first user according to the second key comprises at least one of the following: generating the third key of the first user according to the second key and a user identifier of the first user; generating the third key of the first user according to the second key, the user identifier of the first user and a second string; generating the third key of the first user according to the second key and the second string. The method according to any one of claims 24 to 26, wherein The method further comprises at least one of the following: associating the third key of the first user and the user identifier of the first user; associating the third key of the first user, the user identifier of the first user and the subscription identifier of the UE; associating the second key and the subscription identifier of the UE. A user authentication method in which, The method is performed by a fourth network function, and the method comprises: receiving a fourth request sent by a user equipment (UE), the fourth request being used for user authentication of a first user, the fourth request being protected by a fifth key of the first user; sending a fifth request to a second network function, the fifth request being used for requesting a third key of the first user or a user authentication result of the first user, the fifth request comprising a user identity of the first user and a related subscription identity of the UE; receiving a fifth response sent by the second network function; obtaining a user authentication result of the first user according to the fifth response; sending a fourth response to the UE according to the user authentication result. The method of claim 28, wherein, The fifth response comprises the third key of the first user and / or the user authentication result of the first user. The method of claim 29, wherein, The obtaining of the user authentication result of the first user according to the fifth response comprises: in a case where the fifth response comprises the third key of the first user, verifying the fourth request according to the third key of the first user; generating a user authentication result of the first user passing the user authentication in a case where the fourth request is verified successfully. The method of claim 30, wherein, The method further comprises: in a case where the fifth response comprises the third key of the first user, sending the user authentication result of the first user to the second network function. A first network function, wherein, The first network function comprises a sending module, a receiving module and a processing module. The receiving module is configured to receive a first request sent by a user equipment (UE), the first request comprising a user identity of a first user, the first user being a user using the UE. The sending module is configured to send a second request to a second network function, the second request comprising the user identity of the first user. The processing module is configured to, in a case where it is determined according to the second response that a user authentication manner of the first user is a first manner, send a third request to a third network function, the third request being used for requesting the third network function to generate a second key of the UE according to a first key, the second key being used for generating a third key of the first user, the third key being used for the user authentication of the first user. A second network function, wherein, The second network function comprises: a receiving module configured to receive a second request sent by a first network function, the second request comprising a user identity of a first user, the first user being a user using a user equipment (UE); a sending module configured to send a second response to the first network function according to configuration information of the first user, the second response being used for the first network function to determine a user authentication manner of the first user. A user equipment, UE, wherein, The UE comprises: The sending module is configured to send a first request to a first network function, the first request comprising a user identifier of a first user, the first user being a user using the UE; the first request being used to cause the first network function to send a third request to a third network function in a case where a user authentication mode of the first user is a first mode; the third request being used to request the third network function to generate a second key of the UE according to a first key; the second key being used to generate a third key of the first user; the third key being used for user authentication of the first user. A third network function, wherein, The third network function comprises: The receiving module is configured to receive the third request sent by the first network function; the third request being used to request the third network function to generate a second key of a user equipment (UE) according to a first key; The processing module is configured to generate the second key according to the first key; generate a third key of a first user according to the second key, the first user being a user using the UE; The sending module is configured to send a third response to the first network function, the third response being used to indicate whether the second key or the third key is generated successfully; send a subscription identifier of the UE, a user identifier of the first user, and the third key to the second network function. A fourth network function, wherein The fourth network function comprises a receiving module, a sending module, and a processing module; The receiving module is configured to receive a fourth request sent by a user equipment (UE), the fourth request being used for user authentication of a first user, the fourth request being protected by a fifth key of the first user; The sending module is configured to send a fifth request to a second network function, the fifth request being used to request the third key of the first user or a user authentication result of the first user; the fifth request comprising a user identifier of the first user and a related subscription identifier of the UE; The receiving module is configured to receive a fifth response sent by the second network function; The processing module is configured to obtain the user authentication result of the first user according to the fifth response; The sending module is configured to send a fourth response to the UE according to the user authentication result. A communication system wherein, The communication system comprises a user equipment (UE), a first network function, a second network function, a third network function, and a fourth network function; The first network function is used to perform the user authentication method of any one of claims 1 to 9; The second network function is used to perform the user authentication method of any one of claims 10 to 15; The UE is used to perform the user authentication method of any one of claims 16 to 23; The third network function is used to perform the user authentication method of any one of claims 24 to 27; The fourth network function is used to perform the user authentication method of any one of claims 28 to 31. A communication device, wherein, The communication device comprises: One or more processors; The processor is used to call instructions to cause the communication device to perform the user authentication method of any one of claims 1 to 9, 10 to 15, 16 to 23, 24 to 27, or 28 to 31. A storage medium, wherein, The storage medium stores instructions which, when executed on the communication device, cause the communication device to perform the user authentication method of any one of claims 1-9, 10-15, 16-23, 24-27, or 28-31. A program product, wherein, The program product comprises a computer program which, when executed by a communication device, enables the communication device to implement the user authentication method of any one of claims 1-9, 10-15, 16-23, 24-27, or 28-31.
Citation Information
Patent Citations
User authentication in first network using subscriber identity module for second legacy network
CN112219415A
Authentication and security method and device and storage medium
CN116419218A
Registration method and device of user equipment, computer readable medium and electronic equipment
CN117098111A
Section secondary authentication method and system based on key integrity detection
CN117915322A
Reuse of security context for access and registration
WO2023247221A1