User authentication method and apparatus, device, communication system, and storage medium

By utilizing multi-network element collaborative key generation and verification in a wireless communication system, the security and efficiency issues of user authentication are resolved, enabling accurate identity verification of end users and improving system security and efficiency.

WO2026000247A1PCT designated stage Publication Date: 2026-01-02BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/101676
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-26
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

In communication systems, existing technologies struggle to effectively authenticate users, especially in wireless communication environments where the network side's authentication efficiency and security for end users are insufficient.

Method used

Through the collaborative cooperation of multiple network elements, the user authentication process is realized by using personal passwords to generate and verify keys. This includes the first network element identifying the terminal user, the second network element sending authentication information to the terminal, the fourth network element generating an auxiliary key, and the terminal performing the authentication operation, thus ensuring the security and accuracy of user authentication.

Benefits of technology

It improves the security and efficiency of user authentication in wireless communication systems, ensures accurate identification and verification of user identities, and enhances the trust relationship between the network side and the terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024101676_02012026_PF_FP_ABST
    Figure CN2024101676_02012026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a user authentication method and apparatus, a device, a communication system, and a storage medium. The method is performed by a first network element. The method comprises: receiving first information sent by a second network element, wherein the first information is used for the first network element to determine a terminal and a first user of the terminal; on the basis of the first information and a first personal password, determining a first key; and sending second information to the second network element, wherein the second information is used for implementing user authentication for the first user, and the second information at least comprises the first key. By means of the solution of the present disclosure, user authentication can be performed on users using terminals.
Need to check novelty before this filing date? Find Prior Art

Description

User authentication method and apparatus, device, communication system, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the field of wireless communication, and in particular, to a user authentication method and apparatus, device, communication system, and storage medium. BACKGROUND

[0002] In a communication system, in order to provide services to a terminal, a network side needs to perform user authentication on a user using the terminal.

[0003] SUMMARY

[0004] The present disclosure relates to the field of wireless communication, and in particular, to a user authentication method and apparatus, device, communication system, and storage medium.

[0005] According to a first aspect of an embodiment of the present disclosure, a user authentication method is provided. The method is performed by a first network element. The method comprises: receiving first information sent by a second network element, wherein the first information is used for the first network element to determine a terminal and a first user of the terminal; determining a first key based on the first information and a first password; and sending second information to the second network element, wherein the second information is used to implement user authentication for the first user, and the second information at least comprises the first key.

[0006] According to a second aspect of an embodiment of the present disclosure, a user authentication method is provided. The method is performed by a second network element. The method comprises: sending fourth information to a terminal, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal; and wherein the user authentication is implemented based on a first key, and the first key is obtained based on at least a first password.

[0007] According to a third aspect of an embodiment of the present disclosure, a user authentication method is provided. The method is performed by a fourth network element. The method comprises: sending sixth information to a third network element, wherein the sixth information is used to trigger the third network element to generate a second key; and wherein the second key is used to determine a first key together with a first identifier, and the first key is used to implement user authentication for a first user of a terminal.

[0008] According to a fourth aspect of an embodiment of the present disclosure, a user authentication method is provided. The method is performed by a terminal. The method comprises: receiving fourth information sent by a second network element, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal; and performing user authentication according to the fourth information. And wherein the user authentication is implemented based on a first key, and the first key is obtained based on at least a first password.

[0009] According to a fifth aspect of the embodiments of the present disclosure, a user authentication apparatus is provided. The apparatus is arranged in a first network element. The apparatus comprises a transceiver and a processor. The transceiver is configured to receive first information sent by a second network element, wherein the first information is used by the first network element to determine a terminal and a first user of the terminal; and send second information to the second network element, wherein the second information is used to implement user authentication for the first user, and the second information comprises at least a first key. The processor is configured to determine the first key based on the first information and a first password.

[0010] According to a sixth aspect of the embodiments of the present disclosure, a user authentication apparatus is provided. The apparatus is arranged in a second network element. The apparatus comprises a transceiver. The transceiver is configured to send fourth information to a terminal, wherein the fourth information is used by the terminal to perform user authentication for a first user of the terminal; and wherein the user authentication is implemented based on a first key, and the first key is derived based on at least a first password.

[0011] According to a seventh aspect of the embodiments of the present disclosure, a user authentication apparatus is provided. The apparatus is arranged in a fourth network element. The apparatus comprises a transceiver. The transceiver is configured to send sixth information to a third network element, wherein the sixth information is used to trigger the third network element to generate a second key; and wherein the second key is used to determine a first key together with a first identifier, and the first key is used to implement user authentication for a first user of a terminal.

[0012] According to an eighth aspect of the embodiments of the present disclosure, a user authentication apparatus is provided. The apparatus is arranged in a terminal. The apparatus comprises a transceiver and a processor. The transceiver is configured to receive fourth information sent by a second network element, wherein the fourth information is used by the terminal to perform user authentication for a first user of the terminal. The processor is configured to perform the user authentication according to the fourth information. The user authentication is implemented based on a first key. The first key is derived based on at least a first password.

[0013] According to a ninth aspect of the embodiments of the present disclosure, a communication device is provided. The communication device comprises one or more processors; and a memory storing instructions. The instructions, when executed by the communication device, cause the communication device to implement the user authentication method according to any one of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0014] According to a tenth aspect of the embodiments of the present disclosure, a communication system is provided. The communication system comprises at least one of a first network element, a second network element, a fourth network element, and a terminal. The first network element is configured to implement the user authentication method according to the first aspect. The second network element is configured to implement the user authentication method according to the second aspect. The fourth network element is configured to implement the user authentication method according to the third aspect. The terminal is configured to implement the user authentication method according to the fourth aspect.

[0015] According to a twelfth aspect of the embodiments of the present disclosure, a program product is provided. The program product, when executed by a communication device, causes the communication device to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0016] According to a twelfth aspect of the embodiments of the present disclosure, a program product is provided. The program product, when executed by a communication device, causes the communication device to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0017] According to a thirteenth aspect of the embodiments of the present disclosure, a computer program is provided. The computer program, when executed on a computer, causes the computer to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0018] According to a fourteenth aspect of the embodiments of the present disclosure, a chip or chip system is provided. The chip or chip system comprises processing circuitry. The processing circuitry is configured to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0019] According to the embodiments of the present disclosure, user authentication can be performed on a user using a terminal.

[0020] It should be understood that the general description above and the detailed description below are only exemplary and explanatory, and do not constitute a limitation on the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0021] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments consistent with the present disclosure and serve to explain the principles of the present disclosure together with the specification.

[0022] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.

[0023] FIG. 2 is a schematic diagram of a key hierarchy in the related art.

[0024] FIG. 3 is a schematic diagram of interactions of a user authentication method according to an embodiment of the present disclosure.

[0025] FIG. 4 is a schematic diagram of a flow of a user authentication method according to an embodiment of the present disclosure.

[0026] FIG. 5 is a schematic diagram of a flow of a user authentication method according to an embodiment of the present disclosure.

[0027] FIG. 6 is a schematic diagram of a flow of a user authentication method according to an embodiment of the present disclosure.

[0028] FIG. 7 is a flow diagram of a user authentication method according to an embodiment of the present disclosure.

[0029] FIG. 8A is an interaction diagram of a user authentication method according to an embodiment of the present disclosure.

[0030] FIG. 8B is an interaction diagram of a user authentication method according to an embodiment of the present disclosure.

[0031] FIG. 8C is an interaction diagram of a user authentication method according to an embodiment of the present disclosure.

[0032] FIG. 9 is a diagram of a key hierarchy in a user authentication method according to an embodiment of the present disclosure.

[0033] FIG. 10A is an interaction diagram of an exemplary implementation of a user authentication method according to an embodiment of the present disclosure.

[0034] FIG. 10B is an interaction diagram of an exemplary implementation of a user authentication method according to an embodiment of the present disclosure.

[0035] FIG. 10C is an interaction diagram of an exemplary implementation of a user authentication method according to an embodiment of the present disclosure.

[0036] FIG. 11 is a structural diagram of a user authentication apparatus according to an embodiment of the present disclosure.

[0037] FIG. 12A is a structural diagram of a communication device according to an embodiment of the present disclosure.

[0038] FIG. 12B is a structural diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0039] Embodiments of the present disclosure provide a user authentication method and apparatus, a communication device, a communication system, a storage medium, and a program product.

[0040] In a first aspect, embodiments of the present disclosure provide a user authentication method. The method is performed by a first network element. The method comprises: receiving first information sent by a second network element, wherein the first information is used for the first network element to determine a terminal and a first user of the terminal; determining a first key based on the first information and a first personal password; and sending second information to the second network element, wherein the second information is used to implement user authentication for the first user, and the second information at least comprises the first key.

[0041] In some embodiments in combination with the first aspect, the first personal password can be a personal password assigned to the first user.

[0042] In some embodiments of the first aspect, in some embodiments, the operation of determining the first key based on the first information and the first personal password can include: obtaining first identification information from the first information, wherein the first identification information is used to identify the terminal; determining a second key associated with the first identification information; and determining the first key based on the second key and the first personal password.

[0043] In some embodiments of the first aspect, in some embodiments, the first key can be determined based on at least one of the following parameters: the first numerical value, the user identifier of the first user, the length of the user identifier, the first personal password, the length of the first personal password, the identifier of the first network element, and the length of the identifier of the first network element.

[0044] In some embodiments of the first aspect, in some embodiments, the method can further include: receiving third information sent by a third network element, wherein the third information is used to provide the second key to the first network element; and associating the second key with the first identification information.

[0045] In some embodiments of the first aspect, in some embodiments, the third information can include at least one of the following: the second key; and second identification information, wherein the second identification information is associated with the first identification information.

[0046] In a second aspect, the embodiments of the present disclosure provide a user authentication method. The method is performed by a second network element. The method includes: sending fourth information to a terminal, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal; and wherein the user authentication is implemented based on a first key, and the first key is obtained based on at least a first personal password.

[0047] In some embodiments of the second aspect, in some embodiments, the first personal password can be a personal password assigned to the first user.

[0048] In some embodiments of the second aspect, in some embodiments, the fourth information includes at least one of the following: an identifier of the second network element; a first random number generated by the second network element; and a first message authentication code.

[0049] In some embodiments of the second aspect, in some embodiments, the first message authentication code is associated with the identifier of the second network element and the first random number, and the first message authentication code is calculated using the first key.

[0050] In some embodiments of the second aspect, in some embodiments, the method can further include: receiving fifth information sent by the terminal, wherein the fifth information is used for the second network element to perform user authentication for the first user; and performing the user authentication based on the fifth information.

[0051] In some embodiments of the second aspect, in some embodiments, the fifth information can comprise at least one of: a user identifier of the first user; a first random number obtained by the terminal from the fourth information; a second random number generated by the terminal; and the second message authentication code.

[0052] In some embodiments of the second aspect, in some embodiments, the second message authentication code can be associated with the user identifier of the first user, an identifier of the second network element, the first random number and the second random number, and the second message authentication code can be calculated using the first key.

[0053] In some embodiments of the second aspect, in some embodiments, the operation of performing user authentication according to the fifth information can comprise: based on the first random number and the identifier of the second network element stored locally by the second network element, and the second random number and the user identifier of the first user in the fifth information, and using the first key to calculate to obtain a third message authentication code; comparing the second message authentication code with the third message authentication code; in the case that the second message authentication code is consistent with the third message authentication code, determining that the terminal passes the user authentication.

[0054] In some embodiments of the second aspect, in some embodiments, the method can further comprise: sending first information to the first network element, wherein the first information is used by the first network element to determine the terminal and the first user; and receiving second information sent by the first network element, wherein the second information is used to implement user authentication, and the second information comprises at least the first key.

[0055] In some embodiments of the second aspect, in some embodiments, the first key can be determined according to at least one of the following parameters: a first numerical value used to identify a key derivation function; a user identifier of the first user; a length of the user identifier; a first personal password; a length of the first personal password; an identifier of the first network element; and a length of the identifier of the first network element.

[0056] In a third aspect, the embodiments of the present disclosure provide a user authentication method. The method is performed by a fourth network element. The method comprises: sending sixth information to a third network element, wherein the sixth information is used to trigger the third network element to generate a second key; and wherein the second key is used to determine a first key together with a first identification code, and the first key is used to implement user authentication for a first user of a terminal.

[0057] In some embodiments of the third aspect, in some embodiments, the first personal password can be a personal password assigned to the first user.

[0058] In some embodiments of the third aspect, in some embodiments, the sixth information can comprise: second identification information used to identify a terminal corresponding to the first user.

[0059] In some embodiments of the third aspect, in some embodiments, the method further includes: receiving seventh information sent by the fifth network element, wherein the seventh information is used for the fourth network element to determine that the terminal supports the second key; and determining, according to the seventh information, that the generation of the second key is triggered.

[0060] In some embodiments of the third aspect, in some embodiments, the seventh information includes at least one of: a user authentication characteristic related to the second key; a user authentication policy related to the second key; and second identification information used for identifying the terminal.

[0061] In some embodiments of the third aspect, in some embodiments, the method further includes: receiving eighth information sent by the third network element, wherein the eighth information is used for the fourth network element to determine that the second key is successfully obtained.

[0062] In some embodiments of the third aspect, in some embodiments, the method further includes: sending ninth information to the terminal, wherein the ninth information is used for the terminal to determine the user authentication based on the first key.

[0063] In a fourth aspect, the embodiments of the present disclosure provide a user authentication method. The method is performed by a terminal. The method includes: receiving fourth information sent by a second network element, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal; and performing the user authentication according to the fourth information. The user authentication is based on a first key, and the first key is obtained based on at least a first personal password.

[0064] In some embodiments of the fourth aspect, in some embodiments, the first personal password is a personal password assigned to the first user.

[0065] In some embodiments of the fourth aspect, in some embodiments, the fourth information includes at least one of: an identifier of the second network element; a first random number generated by the second network element; and a first message authentication code.

[0066] In some embodiments of the fourth aspect, in some embodiments, the first message authentication code is associated with the identifier of the second network element and the first random number, and the first message authentication code is calculated using the first key.

[0067] In some embodiments of the fourth aspect, in some embodiments, the operation of performing the user authentication according to the fourth information includes: calculating a fourth message authentication code based on the identifier of the second network element and the first random number in the fourth information and using the first key; comparing the first message authentication code with the fourth message authentication code; and determining that the network side passes the user authentication in a case where the first message authentication code is consistent with the fourth message authentication code.

[0068] In some embodiments of the fourth aspect, in some embodiments, the method further includes sending fifth information to the second network element, wherein the fifth information is used by the second network element to perform the user authentication for the first user.

[0069] In some embodiments of the fourth aspect, in some embodiments, the fifth information includes at least one of: a user identifier of the first user; a first random number obtained from the fourth information; a second random number generated by the terminal; a second message authentication code.

[0070] In some embodiments of the fourth aspect, in some embodiments, the second message authentication code is associated with the user identifier of the first user, an identifier of the second network element, the first random number and the second random number, and the second message authentication code is calculated using the first key.

[0071] In some embodiments of the fourth aspect, in some embodiments, the method further includes receiving ninth information, wherein the ninth information is used by the terminal to determine the user authentication based on the first key.

[0072] In some embodiments of the fourth aspect, in some embodiments, the method further includes determining a second key associated with the first user; and determining the first key based on the second key and the first personal password.

[0073] In some embodiments of the fourth aspect, in some embodiments, the method further includes associating the second key with first identification information, wherein the first identification information is used to identify the terminal.

[0074] In a fifth aspect, the embodiments of the present disclosure provide a user authentication apparatus. The apparatus is arranged in a first network element. The apparatus includes a transceiver module and a processing module. The transceiver module is configured to: receive first information sent by a second network element, wherein the first information is used by the first network element to determine a terminal and a first user of the terminal; and send second information to the second network element, wherein the second information is used to implement the user authentication for the first user, and the second information includes at least a first key. The processing module is configured to determine the first key based on the first information and a first personal password.

[0075] In some embodiments of the fifth aspect, in some embodiments, the first personal password can be a personal password assigned to the first user.

[0076] In some embodiments of the fifth aspect, in some embodiments, the processing module can be configured to: obtain first identification information from the first information, wherein the first identification information is used to identify the terminal; determine a second key associated with the first identification information; and determine the first key based on the second key and the first personal password.

[0077] In some embodiments of the fifth aspect, in some embodiments, the first key can be determined according to at least one of the following parameters: the first numerical value, an identifier of the first user, a length of the user identifier, the first personal password, a length of the first personal password, an identifier of the first network element, a length of the identifier of the first network element.

[0078] In some embodiments of the fifth aspect, in some embodiments, the transceiver module can be further configured to receive third information sent by a third network element, wherein the third information is used to provide the first network element with a second key; and the processing module can be further configured to associate the second key with the first identification information.

[0079] In some embodiments of the fifth aspect, in some embodiments, the third information can include at least one of the following: the second key, and second identification information, wherein the second identification information is associated with the first identification information.

[0080] In a sixth aspect, the embodiments of the present disclosure provide a user authentication apparatus. The apparatus is arranged in a second network element. The apparatus includes a transceiver module. The transceiver module is configured to send fourth information to a terminal, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal; and wherein the user authentication is based on a first key, and the first key is obtained based on at least a first personal password.

[0081] In some embodiments of the sixth aspect, in some embodiments, the first personal password can be a personal password assigned to the first user.

[0082] In some embodiments of the sixth aspect, in some embodiments, the fourth information includes at least one of the following: an identifier of the second network element, a first random number generated by the second network element, and a first message authentication code.

[0083] In some embodiments of the sixth aspect, in some embodiments, the first message authentication code is associated with the identifier of the second network element and the first random number, and the first message authentication code is calculated using the first key.

[0084] In some embodiments of the sixth aspect, in some embodiments, the transceiver module can be further configured to receive fifth information sent by the terminal, wherein the fifth information is used for the second network element to perform user authentication for the first user. The apparatus can further include a processing module. The processing module is configured to perform the user authentication according to the fifth information.

[0085] In some embodiments of the sixth aspect, in some embodiments, the fifth information can include at least one of the following: a user identifier of the first user, a first random number obtained by the terminal from the fourth information, a second random number generated by the terminal, and a second message authentication code.

[0086] In some embodiments of the sixth aspect, in some embodiments, the second message authentication code can be associated with the user identifier of the first user, the identifier of the second network element, the first random number and the second random number, and the second message authentication code can be calculated using the first key.

[0087] In some embodiments of the sixth aspect, in some embodiments, the processing module can be configured to: based on the first random number and the identifier of the second network element stored locally by the second network element, and the second random number and the user identifier of the first user in the fifth information, and using the first key to calculate, to obtain a third message authentication code; compare the second message authentication code with the third message authentication code; in the case that the second message authentication code is consistent with the third message authentication code, determine that the terminal passes the user authentication.

[0088] In some embodiments of the sixth aspect, in some embodiments, the transceiver module can be further configured to: send first information to the first network element, wherein the first information is used for the first network element to determine the terminal and the first user; receive second information sent by the first network element, wherein the second information is used to implement the user authentication, and the second information at least includes the first key.

[0089] In some embodiments of the sixth aspect, in some embodiments, the first key can be determined according to at least one of the following parameters: the first numerical value, the first user identifier of the user, the length of the user identifier, the first personal password, the length of the first personal password, the identifier of the first network element, and the length of the identifier of the first network element.

[0090] In a seventh aspect, the embodiments of the present disclosure provide a user authentication apparatus. The apparatus is arranged in a fourth network element. The apparatus includes a transceiver module. The transceiver module is configured to send sixth information to a third network element, wherein the sixth information is used to trigger the third network element to generate a second key; and wherein the second key is used to determine a first key together with a first identification code, and the first key is used to implement user authentication for a first user of a terminal.

[0091] In some embodiments of the seventh aspect, in some embodiments, the first personal password can be a personal password assigned to the first user.

[0092] In some embodiments of the seventh aspect, in some embodiments, the sixth information can include: second identification information, used to identify the terminal corresponding to the first user.

[0093] In some embodiments combining with the seventh aspect, in some embodiments, the transceiver module can be further configured to receive seventh information sent by the fifth network element, wherein the seventh information is used for the fourth network element to determine that the terminal supports the second key. The apparatus can further include a processing module. The processing module is configured to determine, according to the seventh information, to trigger generation of the second key.

[0094] In some embodiments combining with the seventh aspect, in some embodiments, the seventh information can include at least one of the following: a user authentication characteristic related to the second key; a user authentication policy related to the second key; second identification information used for identifying the terminal.

[0095] In some embodiments combining with the seventh aspect, in some embodiments, the transceiver module can be further configured to receive eighth information sent by the third network element, wherein the eighth information is used for the fourth network element to determine that the second key is successfully obtained.

[0096] In some embodiments combining with the seventh aspect, in some embodiments, the transceiver module can be further configured to send ninth information to the terminal, wherein the ninth information is used for the terminal to determine the user authentication based on the first key.

[0097] In an eighth aspect, the embodiments of the present disclosure provide a user authentication apparatus. The apparatus is arranged in a terminal. The apparatus includes a transceiver module and a processing module. The transceiver module is configured to receive fourth information sent by a second network element, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal. The processing module is configured to perform the user authentication according to the fourth information. The user authentication is implemented based on a first key. The first key is obtained based on at least a first personal password.

[0098] In some embodiments combining with the eighth aspect, in some embodiments, the first personal password can be a personal password assigned to the first user.

[0099] In some embodiments combining with the eighth aspect, in some embodiments, the fourth information can include at least one of the following: an identifier of the second network element; a first random number generated by the second network element; a first message authentication code.

[0100] In some embodiments combining with the eighth aspect, in some embodiments, the first message authentication code is associated with the identifier of the second network element and the first random number, and the first message authentication code is calculated by using the first key.

[0101] In some embodiments combining with the eighth aspect, in some embodiments, the processing module can be configured to: based on the identifier of the second network element and the first random number in the fourth information, and by using the first key, to calculate a fourth message authentication code; compare the first message authentication code with the fourth message authentication code; and in the case that the first message authentication code is consistent with the fourth message authentication code, determine that the network side passes the user authentication.

[0102] In some embodiments combining with the eighth aspect, in some embodiments, the transceiver module is further configured to send fifth information to the second network element, wherein the fifth information is used by the second network element to perform the user authentication for the first user.

[0103] In some embodiments combining with the eighth aspect, in some embodiments, the fifth information comprises at least one of: a user identifier of the first user; a first random number obtained from the fourth information; a second random number generated by the terminal; a second message authentication code.

[0104] In some embodiments combining with the eighth aspect, in some embodiments, the second message authentication code is associated with the user identifier of the first user, an identifier of the second network element, the first random number and the second random number, and the second message authentication code is calculated using the first key.

[0105] In some embodiments combining with the eighth aspect, in some embodiments, the transceiver module is further configured to receive ninth information, wherein the ninth information is used by the terminal to determine the user authentication based on the first key.

[0106] In some embodiments combining with the eighth aspect, in some embodiments, the processing module is further configured to determine a second key associated with the first user, and determine the first key according to the second key and the first password.

[0107] In some embodiments combining with the eighth aspect, in some embodiments, the processing module is further configured to associate the second key with first identification information, wherein the first identification information is used to identify the terminal.

[0108] In a ninth aspect, the embodiments of the present disclosure provide a communication device. The communication device comprises: one or more processors; and a memory storing instructions. The instructions, when executed by the communication device, cause the communication device to implement the user authentication method according to any one of the first aspect, the second aspect, the third aspect, the fourth aspect, and possible implementation manners thereof.

[0109] In a tenth aspect, the embodiments of the present disclosure provide a communication system. The communication system comprises at least one of: a first network element, a second network element, a fourth network element, and a terminal. The first network element is configured to implement the user authentication method according to any one of the first aspect and possible implementation manners thereof. The second network element is configured to implement the user authentication method according to any one of the second aspect and possible implementation manners thereof. The fourth network element is configured to implement the user authentication method according to any one of the third aspect and possible implementation manners thereof. The terminal is configured to implement the user authentication method according to any one of the fourth aspect and possible implementation manners thereof.

[0110] In a thirteenth aspect, an embodiment of the present disclosure provides a computer program. The computer program, when executed on a computer, causes the computer to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, the fourth aspect, and possible implementation manners thereof.

[0111] In a twelfth aspect, an embodiment of the present disclosure provides a program product. The program product, when executed by a communication device, causes the communication device to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, the fourth aspect, and possible implementation manners thereof.

[0112] In a thirteenth aspect, an embodiment of the present disclosure provides a computer program. The computer program, when executed on a computer, causes the computer to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, the fourth aspect, and possible implementation manners thereof.

[0113] In a fourteenth aspect, an embodiment of the present disclosure provides a chip or a chip system. The chip or the chip system includes processing circuitry. The processing circuitry is configured to perform the user authentication method according to any one of the first aspect, the second aspect, the third aspect, the fourth aspect, and possible implementation manners thereof.

[0114] It can be understood that the above-mentioned user authentication apparatus, communication device, communication system, storage medium, program product, computer program, chip, and chip system are all used to perform the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here again.

[0115] Embodiments of the present disclosure provide a user authentication method and apparatus, a communication device, a communication system, a storage medium, and a program product. In some embodiments, the terms of the user authentication method, the communication method, the information processing method, and the information transmission method can be replaced with each other, and the terms of the user authentication apparatus, the communication apparatus, the communication device, the network device, the network function, and the network entity can be replaced with each other, and the terms of the communication system and the information processing system can be replaced with each other.

[0116] Embodiments of the present disclosure are not exhaustive, but are only a part of the embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or parts or all of the steps of different embodiments can be combined arbitrarily, and an embodiment can be combined with the optional implementation manners of other embodiments.

[0117] In the embodiments of the present disclosure, the terms and / or descriptions among the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0118] The terms used in the embodiments of the present disclosure are only for the purpose of describing particular embodiments and are not used as limitations of the present disclosure.

[0119] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "an", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", or can represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, or can be understood as plural expression.

[0120] In the embodiments of the present disclosure, "plurality" means two or more than two.

[0121] In some embodiments, the terms "at least one (at least one, at least one, at least one)", "one or more" and the like can be replaced with each other.

[0122] In some embodiments, the writing methods such as "at least one of A, B", "A and / or B", "A in one case, B in another case", "in response to a case A, in response to another case B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selected to be executed (A and B are selectively executed); in some embodiments, A and B (A and B are executed). When there are more branches such as A, B, C, the above is similar.

[0123] In some embodiments, the writing methods such as "A or B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selected to be executed (A and B are selectively executed). When there are more branches such as A, B, C, the above is similar.

[0124] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description object is "information", and "second information" and "first information" can be the same information or different information, and the contents thereof can be the same or different.

[0125] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0126] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0127] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0128] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0129] In some embodiments, a "network" can be interpreted as an apparatus and / or equipment included in the network (for example, an access network device, a core network device, and the like).

[0130] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like can be replaced with each other.

[0131] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0132] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced with the communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and so on) can also apply the embodiments of the present disclosure. In this case, the structure in which the terminal has all or part of the functions of the access network device can also be provided. Further, the terms "uplink," "downlink," and so on can be replaced with the terms corresponding to the communication between terminals (e.g., "side"). For example, the uplink channel, the downlink channel, and so on can be replaced with the side channel, and the uplink, the downlink, and so on can be replaced with the sidelink.

[0133] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the structure in which the access network device, the core network device, or the network device has all or part of the functions of the terminal can also be provided.

[0134] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country in which the location is situated.

[0135] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0136] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0137] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1, the communication system 100 includes a terminal 101 and a network device 102.

[0138] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, etc., but is not limited thereto.

[0139] In some embodiments, the network device 102 can be one device including the first network element 1021, the second network element 1022, the third network element 1023, the fourth network element 1024, the fifth network element 1025, and the like, or can be multiple devices or device groups including all or part of the first network element 1021, the second network element 1022, the third network element 1023, the fourth network element 1024, the fifth network element 1025, and the like. In some embodiments, the network element can be virtual or physical. In an example, the network element can be a network function, and the like. In an example, the network element can be a network function entity, a network device, and the like. It can be understood that the network element, the network function, the network function entity, the network device, and the like can be replaced with each other. In some embodiments, the core network 103 includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next generation core (NGC), and the like.

[0140] In some embodiments, the first network element 1021 can be a user profile server, for example.

[0141] In some embodiments, the first network element 1021 can be responsible for maintaining configuration information of a user, saving authentication information of the user, managing a key, and the like, and the name thereof is not limited thereto.

[0142] In some embodiments, the second network element 1022 can be a user authentication and authorization function (UAAF), for example.

[0143] In some embodiments, the second network element 1022 can be responsible for authentication and authorization related to a user, and the like, and the name thereof is not limited thereto.

[0144] In some embodiments, the third network element 1023 can be an authentication server function (AUSF), for example.

[0145] In some embodiments, the third network element 1023 can be responsible for 3GPP and non-3GPP access authentication, and the like, and the name thereof is not limited thereto.

[0146] In some embodiments, the fourth network element 1024 can be an access and mobility management function (AMF), for example.

[0147] In some embodiments, the fourth network element 1024, for example, can be used for mobility management of a user, without limitation of name.

[0148] In some embodiments, the fifth network element 1025, for example, can be a unified data management (UDM) function.

[0149] In some embodiments, the fifth network element 1025, for example, can be responsible for user identity management, policy management, user configuration management, etc., without limitation of name.

[0150] In some embodiments, the first network element 1021 and the fifth network element 1025 can be independently deployed. In an example, the first network element 1021 and the fifth network element 1025 can be respectively deployed on different devices. In some embodiments, the first network element 1021 and the fifth network element 1025 can be integrated deployed. In an example, the first network element 1021 and the fifth network element 1025 can be deployed on the same device. For example, the first network element 1021 can be a network function integrated in the fifth network element 1025.

[0151] In some embodiments, the second network element 1022 and the third network element 1023 can be independently deployed. In an example, the second network element 1022 and the third network element 1023 can be respectively deployed on different devices. In some embodiments, the second network element 1022 and the third network element 1023 can be integrated deployed. In an example, the second network element 1022 and the third network element 1023 can be deployed on the same device. For example, the second network element 1022 can be a network function integrated in the third network element 1023. For example, the third network element 1023 can be a network function integrated in the second network element 1022.

[0152] In some embodiments, a security anchor function (SEAF) can be integrated in the fourth network element 1024. In some embodiments, the SEAF can be used to provide an authentication function through the fourth network element 1024. It should be noted that, in some embodiments, the SEAF can also be independent of the fourth network element 1024.

[0153] In some embodiments, the above-mentioned communication system 100 can be a 4G communication system or a 5G communication system. It should be noted that the communication system 100 can also be other communication systems, for example, a 6G communication system, and the embodiments of the present disclosure do not make specific limitations thereto.

[0154] In a communication system, in order to provide services to a terminal, the network side needs to perform user authentication on a user using the terminal.

[0155] In some embodiments, user authentication can be performed for a user (e.g., a natural person user) of a terminal, or a non-3GPP device, without pre-configured credentials between the terminal and the network side for implementing the user authentication. For example, the credentials can be derived based on a key K AUSF derived. In some embodiments, the terminal can receive a user identity (UID) input by a user and send to the network side for implementing the user authentication.

[0156] FIG. 2 is a schematic diagram of a key hierarchy in the related art. As shown in FIG. 2, in the hierarchy of key derivation, a key K AUSF may be used as a root key. The key K AUSF may be obtained through, for example, primary authentication under 5G. Based on the key K AUSF and a user permanent identifier (SUPI), a key K UIA may be derived. Then, based on the key K UIA and a UID, a key K USER corresponding to a user can be derived. For example, based on the key K UIA and a UID-1 of a first user, a key K USER-1 corresponding to the first user can be obtained. For example, based on the key K UIA and a UID-2 of a second user, a key K USER-2 corresponding to the second user can be obtained. In some embodiments, the derivation of the key K USER and the derivation of the key K UIA may be implemented by the terminal and / or the AUSF. The key K USER may be used for user authentication of a user on the terminal.

[0157] In some embodiments, a terminal can be shared among multiple users. In this case, each user can connect to the network side through the terminal. In some cases, a user can obtain a UID of another user. Then, if the user inputs the UID of the other user into the terminal, the UID received by the network side is the UID of the other user, instead of the UID of the user currently using the terminal. The key K USER derived by the terminal and the network side can be associated with the other user. Based on the key K USERUser authentication of the terminal can result in a user achieving successful user authentication on the terminal through another user's UID. This can result in security problems. For example, a network-side service for the terminal can be for another user, rather than the user who is using the terminal.

[0158] Therefore, how to ensure the authenticity of the UID sent by the terminal to the network side is a problem to be solved.

[0159]

[0160] In step S301, the terminal 101 obtains a user identifier and a first personal password.

[0161] In some embodiments, the terminal 101 can obtain a user identifier and a first personal password.

[0162] In some embodiments, the user identifier can be a user identifier of a first user. In some embodiments, the user identifier can be used to identify the first user.

[0163] In some embodiments, the user identifier can include a UID. In some embodiments, the user identifier can include a UID of the first user. For example, the user identifier can be a UID assigned to the first user by the network side. For example, the user identifier can be a UID set by the first user and verified by the network side. It can be understood that the user identifier can also include other information for identifying the first user, which is not limited in the embodiments of the present disclosure.

[0164] In some embodiments, the first personal password can be a personal password of the first user. The first personal password can be a password known only to the first user.

[0165] In some embodiments, the first personal password can be a personal password assigned to the first user. In some embodiments, the first personal password can be statically assigned. In some embodiments, the first personal password can be dynamically assigned.

[0166] ​In some embodiments, the first personal password can comprise a personal identification number (PIN). In some embodiments, the first personal password can comprise a random code. In some embodiments, the first personal password can comprise a verification code. It can be understood that the first personal password can also comprise other forms of passwords, which are not limited in the embodiments of the present disclosure. The first personal key can be valid for a long time, or can have a predetermined validity period, and become invalid after the validity period. In summary, the terminal can obtain a personal password associated with a user of the terminal. The first personal password can be assigned by an operator.

[0167] In some embodiments, the terminal 101 can obtain the user identifier and the first personal password of the first user through user input of the first user.

[0168] In some embodiments, the terminal 101 can obtain the user identifier and / or the first personal password from the network side.

[0169] In some embodiments, the user can obtain the user identifier and / or the first personal password through an operator portal. In some embodiments, the operator portal can be a website, an application, a mini program, etc.

[0170] In step S302, the terminal 101 sends tenth information to the fourth network element 1024.

[0171] In some embodiments, the terminal 101 can send the tenth information. For example, in some embodiments, the terminal can send capability information of the terminal to the AMF. In some embodiments, the terminal can send the capability information of the terminal and terminal identification information to the AMF.

[0172] In some embodiments, the fourth network element 1024 can receive the tenth information. In some embodiments, the fourth network element 1024 can receive the tenth information sent by the terminal 101.

[0173] In some embodiments, the tenth information can be used for the fourth network element 1024 to obtain the capability of the terminal 101.

[0174] In some embodiments, the tenth information can be used to implement registration of the terminal 101.

[0175] In some embodiments, the name of the tenth information is not limited, which can be, for example, capability information, capability reporting information, registration information, request information, etc.

[0176] In some embodiments, the tenth information can comprise at least one of the following: third identification information, capability information.

[0177] In some embodiments, the third identification information can be used to identify the terminal 101. In some embodiments, the third identification information can be identification information of the terminal 101.

[0178] In some embodiments, the third identification information can comprise at least one of: a subscriber confidentiality identifier (SUCI), a global unique temporary UE identity (GUTI).

[0179] In some embodiments, the capability information can be used to indicate a support capability of the terminal 101 for user authentication.

[0180] In some embodiments, the capability information can be used to indicate whether the terminal 101 supports user authentication. In an example, the capability information can be used to indicate that the terminal 101 supports user authentication. For example, the capability information can indicate that the terminal 101 supports user authentication by a first value of a specific field. In an example, the capability information can be used to indicate that the terminal 101 does not support user authentication. For example, the capability information can indicate that the terminal 101 does not support user authentication by a second value of a specific field. The capability information can also indicate the type of user authentication supported by the terminal, for example, some terminals only support UID based authentication, while some terminals can support PIN based authentication.

[0181] In some embodiments, the capability information can be used to indicate whether the terminal 101 supports user authentication based on the first key. In an example, the capability information can be used to indicate that the terminal 101 supports user authentication based on the first key. For example, the capability information can indicate that the terminal 101 supports user authentication based on the first key by a first value of a specific field. In an example, the capability information can be used to indicate that the terminal 101 does not support user authentication based on the first key. For example, the capability information can indicate that the terminal 101 does not support user authentication based on the first key by a second value of a specific field.

[0182] In some embodiments, the capability information can be used to indicate whether the terminal 101 supports user authentication based on the second key. In some embodiments, the capability information can be used to indicate whether the terminal 101 supports user authentication derived by the second key. In an example, the capability information can be used to indicate that the terminal 101 supports user authentication based on the second key. For example, the capability information can indicate that the terminal 101 supports user authentication based on the second key by a first value of a specific field. In an example, the capability information can be used to indicate that the terminal 101 does not support user authentication based on the second key. For example, the capability information can indicate that the terminal 101 does not support user authentication based on the second key by a second value of a specific field.

[0183] In some embodiments, the support for user authentication based on the first key can be equivalent to the support for user authentication based on the second key.

[0184] In some embodiments, the second key derivation can refer to a derivation based on from the third key to the second key, and / or a derivation of the first key based on the second key. In some embodiments, the second key derivation can refer to a derivation of the first key based on the second key. In some embodiments, the second key derivation can refer to a derivation based on from the third key to the second key, and a derivation of the first key based on the second key. In some embodiments, the support for user authentication based on the second key derivation can include the support for user authentication based on the first key and / or the support for user authentication based on the second key. In some embodiments, the support for user authentication based on the second key derivation can include the support for user authentication based on the first key.

[0185] In some embodiments, the first key can be derived based on the second key. In an example, the support for user authentication based on the first key can include the support for user authentication based on the second key.

[0186] In some embodiments, the second key can be derived based on the third key. In an example, the support for user authentication based on the second key can include the support for user authentication based on the third key.

[0187] In some embodiments, the first key can be derived based on the third key, for example, the second key can be derived based on the third key, and the first key can be derived based on the second key.

[0188] In some embodiments, the tenth information can be carried in a registration request message. In some embodiments, the terminal 101 can send a registration request message to the fourth network element 1024. The registration request message can carry the tenth information.

[0189] In step S303, the terminal 101 performs a primary authentication procedure with the network side.

[0190] In some embodiments, the primary authentication procedure can be performed between the terminal 101 and the network side. In some embodiments, the primary authentication procedure can be performed between the terminal 101, the third network element 1023, and the fourth network element 1024. That is, one or more network elements of the core network side can authenticate the terminal. For example, perform the primary authentication procedure.

[0191] In some embodiments, the primary authentication procedure can be used to implement user authentication for the user of the terminal 101.

[0192] In some embodiments, the third network element 1023 can derive the third key in the primary authentication procedure. In some embodiments, the third network element 1023 can enable derivation of the third key in the primary authentication procedure.

[0193] In some embodiments, the terminal 101 can derive the third key in the primary authentication procedure. In some embodiments, the terminal 101 can enable derivation of the third key in the primary authentication procedure.

[0194] In some embodiments, the terminal 101 and the third network element 1023 can simultaneously derive the third key through the primary authentication procedure. In an example, the third network element 1023 can save the derived third key. In an example, the terminal 101 can save the derived third key.

[0195] In some embodiments, the third key can be used as a root key in a key hierarchy for user authentication.

[0196] In some embodiments, the third key can include K AUSF .

[0197] In step S304, the fifth network element 1025 sends seventh information to the fourth network element 1024.

[0198] In some embodiments, the fourth network element 1024 can receive the seventh information sent by the fifth network element 1025 after step S303 is successfully completed.

[0199] In some embodiments, the fifth network element 1025 can determine that the terminal 101 supports user authentication based on derivation of the second key. In some embodiments, the capability information can indicate that the terminal 101 supports user authentication based on derivation of the second key. In some embodiments, according to the support for user authentication based on derivation of the second key indicated by the capability information, the fifth network element 1025 can determine that the terminal 101 supports user authentication based on derivation of the second key.

[0200] In some embodiments, the fourth network element 1024 can obtain the seventh information from the fifth network element 1025 in a case where it is determined that the terminal 101 supports user authentication based on derivation of the second key.

[0201] In some embodiments, the fourth network element 1024 can send a request message to the fifth network element 1025. In some embodiments, the request message can be used to request the fifth network element 1025 for subscription information related to the terminal 101. In some embodiments, the fifth network element 1025 can send a response message to the fourth network element 1024. In some embodiments, the response message can carry the seventh information.

[0202] In some embodiments, the fourth network element 1024 can obtain the seventh information through an Nudm_SDM_Get procedure. In some embodiments, the fourth network element 1024 can send an Nudm_SDM_Get request message to the fifth network element 1025. In some embodiments, the fifth network element 1025 can send an Nudm_SDM_Get response message to the fourth network element 1024.

[0203] In some embodiments, the request message can include the second identification information.

[0204] In some embodiments, the second identification information can be used to identify the terminal 101.

[0205] In some embodiments, there can be an association relationship between the second identification information and the third identification information. In some embodiments, there can be a mapping relationship between the second identification information and the third identification information.

[0206] In some embodiments, the second identification information can be determined by the fourth network element 1024 according to the received third identification information. In some embodiments, the second identification information can be determined by the fourth network element 1024 according to the association relationship between the second identification information and the third identification information.

[0207] In some embodiments, the second identification information can include a subscription permanent identifier (SUPI).

[0208] In some embodiments, the response message can be sent by the fifth network element 1025 for the request message. In some embodiments, the response message can carry the seventh information.

[0209] In some embodiments, the seventh information can be used by the fourth network element 1024 to determine that the terminal 101 supports the second key.

[0210] In some embodiments, the seventh information can be used to support subscription information related to the terminal 101.

[0211] In some embodiments, the name of the seventh information is not limited, which can be, for example, subscription information, configuration information, terminal information, etc.

[0212] In some embodiments, the seventh information can include at least one of the following: user authentication characteristics related to the second key, user authentication policy related to the second key, and the second identification information.

[0213] In some embodiments, the user authentication characteristics related to the second key can include authentication characteristics related to the second key subscribed by the user.

[0214] In some embodiments, the user authentication policy related to the second key can comprise a user subscription authentication policy related to the second key.

[0215] In some embodiments, the user authentication characteristic and / or the user authentication policy related to the second key can indicate derivation of the second key for the terminal 101.

[0216] In some embodiments, the user authentication characteristic and / or the user authentication policy related to the second key can be information locally retrieved by the fifth network element 1025. In some embodiments, the user authentication characteristic and / or the user authentication policy related to the second key can be retrieved by the fifth network element 1025 according to the second identification information.

[0217] It should be noted that the seventh information can further comprise other information, which is not limited in the embodiments of the present disclosure.

[0218] In step S305, the fourth network element 1024 determines to trigger user authentication.

[0219] In some embodiments, in the case that the user authentication characteristic and / or the user authentication policy related to the second key can indicate derivation of the second key for the terminal 101, the fourth network element 1024 can determine to trigger user authentication based on derivation of the second key. In some embodiments, the fourth network element 1024 can determine to implement user authentication based on derivation of the second key according to the user authentication characteristic and / or the user authentication policy related to the second key in the seventh information.

[0220] In some embodiments, the fourth network element 1024 can determine to interact with the third network element 1023 to trigger user authentication based on derivation of the second key.

[0221] In some embodiments, the fourth network element 1024 can determine to trigger derivation of the second key.

[0222] In some embodiments, in the case that the terminal 101 does not subscribe to the user authentication characteristic, the method can jump to step S311. In some embodiments, the fourth network element 1024 can fail to receive the seventh information from the fifth network element 1025, or the seventh information can not comprise the user authentication characteristic and / or the user authentication policy, or the seventh information can indicate that the terminal 101 does not subscribe to the user authentication characteristic. In this case, the fourth network element 1024 can determine that the terminal 101 does not subscribe to the user authentication characteristic.

[0223] In step S306, the fourth network element 1024 sends the sixth information to the third network element 1023.

[0224] In some embodiments, the fourth network element 1024 can send sixth information. In some embodiments, the fourth network element 1024 can send the sixth information in a case where it is determined that user authentication based on the second key derivation is triggered.

[0225] In some embodiments, the third network element 1023 can receive the sixth information.

[0226] In some embodiments, the sixth information can be used to trigger the third network element 1023 to derive the second key. In some embodiments, the sixth information can be used to trigger the third network element 1023 to generate the second key.

[0227] In some embodiments, the name of the sixth information is not limited, which can be, for example, authentication indication information, key derivation indication information, key derivation request information, and the like.

[0228] In some embodiments, the sixth information can include the second identification information.

[0229] In some embodiments, the sixth information can be carried in a request message. In some embodiments, the fourth network element 1024 can send a request message to the third network element 1023. The request message can include the sixth information.

[0230] In some embodiments, the request message can be a Nausf_UserAuthentication_Authenticate request message.

[0231] In step S307, the third network element 1023 determines the second key.

[0232] In some embodiments, the third network element 1023 determines the second key according to the sixth information.

[0233] In some embodiments, the third network element 1023 can perform derivation of the second key under the trigger of the sixth information.

[0234] In some embodiments, the third network element 1023 can generate the second key based on the third key.

[0235] In some embodiments, the process of deriving the second key based on the third key can use at least one of the following parameters: the second value, unified identity authentication (UIA), the length of the UIA, the second identification information, the length of the second identification information.

[0236] In some embodiments, the second value can be used to identify a key derivation function.

[0237] In some embodiments, the second value, the UIA, the length of the UIA, the second identification information, the length of the second identification information, and the like can constitute an input of a key derivation function (KDF), so as to derive the second key based on the third key.

[0238] In some embodiments, the second key can be used as an intermediate key in a key hierarchy for user authentication.

[0239] In some embodiments, the second key can include K UIA .

[0240] In step S308, the third network element 1023 sends third information to the first network element 1021.

[0241] In some embodiments, the third network element 1023 can send the third information. In some embodiments, the first network element 1021 can receive the third information.

[0242] In some embodiments, the third information can be used to provide the second key to the first network element 1021.

[0243] In some embodiments, the third information can be used to register the second key to the first network element 1021.

[0244] In some embodiments, the name of the third information is not limited, which can be, for example, key registration information, key reporting information, key providing information, and the like.

[0245] In some embodiments, the third information can include at least one of the following: the second key, the second identification information.

[0246] In some embodiments, the second identification information and the second key can constitute a data pair.

[0247] In some embodiments, the third information can be sent from the third network element 1023 to the first network element 1021 through a key registration process. In some embodiments, the third information can be sent through a Nuimf_UIA_KeyRegistration process.

[0248] In step S309, the first network element 1021 associates the second key with the first identification information.

[0249] In some embodiments, the first network element 1021 can obtain the second key and the second identification information according to the third information.

[0250] In some embodiments, step S309 can include: the first network element 1021 determines the first identification information according to the second identification information; and the first network element 1021 associates the second key with the first identification information.

[0251] In some embodiments, the first identification information and the second identification information can be associated. In some embodiments, there can be a correspondence between the first identification information and the second identification information. In some embodiments, there can be a mapping relationship between the first identification information and the second identification information.

[0252] In some embodiments, the association relationship between the first identification information and the second identification information can be saved in the first network element 1021. In some embodiments, the first network element 1021 can locally retrieve the corresponding first identification information according to the second identification information.

[0253] In some embodiments, the association relationship between the first identification information and the second identification information can be saved in another network element. For example, the other network element can be a fifth network element, a unified data repository (UDR), or other network elements. In some embodiments, the first network element 1021 can retrieve the corresponding first identification information from the other network element according to the second identification information. For example, the first network element 1021 can send the second identification information to the other network element; the other network element can retrieve the corresponding first identification information according to the second identification information, and send the retrieved first identification information to the first network element 1021. For example, the first network element 1021 can send the second identification information to the other network element; the other network element can retrieve the association relationship between the first identification information and the second identification information according to the second identification information, and send the retrieved association relationship to the first network element 1021; the first network element 1021 determines the first identification information corresponding to the second identification information according to the received association relationship.

[0254] In some embodiments, the first identification information can be used to identify the terminal 101.

[0255] In some embodiments, the first identification information can include a generic public subscription identifier (GPSI).

[0256] In some embodiments, the first network element 1021 can establish an association relationship between the first identification information and the second key. In some embodiments, the first network element 1021 can establish a mapping relationship between the first identification information and the second key.

[0257] In step S310, the third network element 1023 sends eighth information to the fourth network element 1024.

[0258] In some embodiments, the third network element 1023 can send the eighth information. In some embodiments, the fourth network element 1024 can receive the eighth information.

[0259] In some embodiments, the eighth information can be used by the fourth network element 1024 to determine that the second key is successfully derived.

[0260] In some embodiments, the name of the eighth information is not limited, which can be, for example, derivation success indication information, etc.

[0261] In some embodiments, the eighth information can indicate that the derivation of the second key is successful. In some embodiments, the eighth information can indicate that the third network element 1023 successfully generates the second key.

[0262] In some embodiments, the eighth information can be carried in a response message. In some embodiments, the third network element 1023 can send a response message to the fourth network element 1024. The response message can contain the eighth information.

[0263] In some embodiments, the response message can be a Nausf_UserAuthentication_Authenticate response message.

[0264] In step S311, the fourth network element 1024 sends ninth information to the terminal 101.

[0265] In some embodiments, the fourth network element 1024 can send the ninth information. In some embodiments, the terminal 101 can receive the ninth information.

[0266] In some embodiments, the ninth information can be used by the terminal 101 to determine the user authentication based on the first key.

[0267] In some embodiments, the name of the ninth information is not limited, which can be, for example, user authentication indication information, user authentication method information, etc.

[0268] In some embodiments, the ninth information can indicate the user authentication method adopted for the user authentication of the first user.

[0269] In some embodiments, the ninth information can indicate that the user authentication method adopted for the user authentication of the first user is the user authentication based on the first key.

[0270] In some embodiments, the ninth information can indicate that the user authentication method adopted for the user authentication of the first user is the user authentication based on the second key.

[0271] In some embodiments, the ninth information can be carried in a registration accept message. In some embodiments, the fourth network element 1024 can send a registration accept message to the terminal. The registration accept message can carry the ninth information.

[0272] In some embodiments, the ninth information in step S311 can not indicate the user authentication method adopted for the user authentication of the first user in the case where the terminal 101 does not subscribe to the user authentication feature.

[0273] In step S312, the terminal 101 determines the second key.

[0274] In some embodiments, the terminal 101 can determine the second key after receiving the ninth information.

[0275] In some embodiments, the terminal 101 can determine the second key according to the ninth information. In some embodiments, the terminal 101 can determine that the user authentication based on the first key is adopted according to the ninth information. In this case, the terminal 101 can determine the second key.

[0276] In some embodiments, the terminal 101 can generate the second key based on the third key.

[0277] In some embodiments, the process of deriving the second key based on the third key can use at least one of the following parameters: the second value, the UIA, the length of the UIA, the second identification information, the length of the second identification information.

[0278] In some embodiments, the parameters such as the second value, the UIA, the length of the UIA, the second identification information, and the length of the second identification information can constitute the input of the KDF, so as to derive the second key based on the third key.

[0279] It should be noted that the process of determining the second key by the terminal 101 in step S312 and the process of determining the second key by the third network element 1023 in step S307 can be independent of each other.

[0280] In some embodiments, the terminal 101 can associate the second key with the first identification information.

[0281] In some embodiments, the generation of the second key can be implemented in the registration process through steps S301 to S312.

[0282] In step S313, the terminal 101 sends eleventh information to the second network element 1022.

[0283] In some embodiments, the terminal 101 can send the eleventh information. In some embodiments, the second network element 1022 can receive the eleventh information.

[0284] In some embodiments, after the derivation of the second key is completed, the terminal 101 can initiate a user authentication procedure. In some embodiments, the terminal 101 can initiate the user authentication procedure to the network side when a user logs in to the terminal 101. In some embodiments, the terminal 101 can initiate the user authentication procedure to the network side when a first user logs in to the terminal 101.

[0285] In some embodiments, the terminal 101 can initiate the user authentication procedure by sending the eleventh information.

[0286] In some embodiments, the eleventh information can be used to initiate the user authentication.

[0287] In some embodiments, the name of the eleventh information is not limited, which can be, for example, authentication initiation information, authentication trigger information, etc.

[0288] In some embodiments, the eleventh information can include at least one of the following: a user identifier of the first user, the first identification information.

[0289] In some embodiments, the eleventh information can be transmitted through the control plane. In some embodiments, the terminal 101 can send the eleventh information to the second network element 1022 via the fourth network element 1024.

[0290] In some embodiments, the eleventh information can be transmitted through the user plane.

[0291] In some embodiments, the eleventh information can be carried in a user authentication request message. In some embodiments, the terminal 101 can send the user authentication request message to the second network element 1022. The user authentication request message can include the eleventh information.

[0292] In step S314, the second network element 1022 sends the first information to the first network element 1021.

[0293] In some embodiments, the second network element 1022 can send the first information. In some embodiments, the first network element 1021 can receive the first information.

[0294] In some embodiments, the first information can be used for the first network element 1021 to determine the terminal 101, and the first user of the terminal 101.

[0295] In some embodiments, the first information can be used for the first network element 1021 to perform user authentication for the first user of the terminal 101.

[0296] In some embodiments, the first information can be used for the first network element 1021 to determine the first key.

[0297] In some embodiments, the first information can be used to request the first key.

[0298] In some embodiments, the name of the first information is not limited, which can be, for example, key request information, key derivation indication information, and the like.

[0299] In some embodiments, the first information can include at least one of the following: a user identifier of the first user, the first identification information.

[0300] In some embodiments, the first information can be carried in an authentication key request message. In some embodiments, the second network element 1022 can send the authentication key request message to the first network element 1021. The authentication key request message can contain the first information.

[0301] In step S315, the first network element 1021 determines the first key.

[0302] In some embodiments, the first network element 1021 can determine the first key according to the first information.

[0303] In some embodiments, the first network element 1021 can determine the first key according to the first information and the first password.

[0304] In some embodiments, step S315 can include: obtaining the first identification information from the first information; determining a second key associated with the first identification information; determining the first key according to the second key and the first password.

[0305] In some embodiments, the first network element 1021 can determine the corresponding second key according to the first identification information in the first information according to the association relationship between the first identification information and the second key.

[0306] In some embodiments, after obtaining the second key corresponding to the first identification information, the first network element 1021 can generate the first key based on the second key.

[0307] In some embodiments, the process of deriving the first key based on the second key can use at least one of the following parameters: the first value, the user identifier of the first user, the length of the user identifier, the first password, the length of the first password, the identifier of the first network element 1021, the length of the identifier of the first network element 1021.

[0308] In some embodiments, the first value can be used to identify the key derivation function.

[0309] In some embodiments, the first number, the user identifier of the first user, the length of the user identifier, the first personal password, the length of the first personal password, the identifier of the first network element 1021, the length of the identifier of the first network element 1021, and the like can constitute the input of the KDF, so as to derive the first key based on the second key.

[0310] In some embodiments, the first personal password can be provided by the network side to the first network element 1021. In some embodiments, the first personal password can be provided by the operator server to the first network element 1021. In some embodiments, the first personal password can be sent to the first network element 1021 and saved at the same time of being provided to the user.

[0311] In some embodiments, the first network element 1021 can determine the first personal password according to the user identifier of the first user.

[0312] In some embodiments, the first key can be used as the final key in the key hierarchy of user authentication.

[0313] In some embodiments, the first key can include K USER .

[0314] In step S316, the first network element 1021 sends the second information to the second network element 1022.

[0315] In some embodiments, the first network element 1021 can send the second information. In some embodiments, the second network element 1022 can receive the second information.

[0316] In some embodiments, the first network element 1021 can send the second information after obtaining the first key.

[0317] In some embodiments, the second information can be used to implement the user authentication for the first user.

[0318] In some embodiments, the second information can be used to indicate the first key.

[0319] In some embodiments, the name of the second information is not limited, which can be, for example, key reporting information, key notification information, and the like.

[0320] In some embodiments, the second information can include at least one of the following: the user identifier of the first user, the first key.

[0321] In some embodiments, the second information can be carried in an authentication key response message. In some embodiments, the first network element 1021 can send the authentication key response message to the second network element 1022. The authentication key response message can contain the second information.

[0322] In some embodiments, the second network element 1022 can obtain the first key corresponding to the first user by the second information.

[0323] In step S317, the second network element 1022 sends the fourth information to the terminal 101.

[0324] In some embodiments, the second network element 1022 can send the fourth information. In some embodiments, the terminal 101 can receive the fourth information.

[0325] In some embodiments, the fourth information can be used for the terminal 101 to perform user authentication for the first user of the terminal 101.

[0326] In some embodiments, the fourth information can be used for triggering the terminal 101 to perform user authentication.

[0327] In some embodiments, the name of the fourth information is not limited, which can be, for example, authentication request information, authentication challenge information, authentication trigger information, etc.

[0328] In some embodiments, the fourth information can include at least one of the following: an identifier of the second network element 1022, a first random number, a first message authentication code.

[0329] In some embodiments, the identifier of the second network element 1022 can be used to identify the second network element 1022. In an example, the second network element 1022 can be a UAAF, and its identifier can be a UAAF ID.

[0330] In some embodiments, the first random number can be generated by the second network element 1022.

[0331] In some embodiments, the first random number can be generated by the second network element 1022 according to a preset rule.

[0332] In some embodiments, the first random number can be denoted as RAND-N.

[0333] In some embodiments, the first message authentication code can be used to implement verification of authentication messages between the second network element 1022 and the terminal 101.

[0334] In some embodiments, the first message authentication code can be used for the terminal 101 to verify the fourth information. In some embodiments, the first message authentication code can be used for the terminal 101 to verify a message carrying the fourth information.

[0335] In some embodiments, the first message authentication code can be associated with the identifier of the second network element 1022 and the first random number.

[0336] In some embodiments, the first message authentication code can be computed with the first key.

[0337] In some embodiments, the first message authentication code can be computed by a hash based on the identifier of the second network element 1022, the first random number, the first key. In some embodiments, the first message authentication code can comprise a hash value computed based on the identifier of the second network element 1022, the first random number, the first key.

[0338] In some embodiments, the first message authentication code can be denoted as MAC N.

[0339] In some embodiments, the fourth information can be carried in an extensible authentication protocol (EAP) request message. In some embodiments, the fourth information can be carried in an EAP challenge message.

[0340] In step S318, the terminal 101 determines the first key.

[0341] In some embodiments, the terminal 101 can determine the first key upon receiving the fourth information. In some embodiments, the terminal 101 can be triggered by the fourth information to generate the first key.

[0342] In some embodiments, the terminal 101 can determine the first key after generating the second key. In some embodiments, the terminal 101 generating the first key can be independent of the fourth information.

[0343] In some embodiments, the terminal 101 can derive the first key based on the second key.

[0344] In some embodiments, the process of deriving the first key based on the second key can use at least one of the following parameters: the first number, the user identifier of the first user, the length of the user identifier, the first password, the length of the first password, the identifier of the first network element 1021, the length of the identifier of the first network element 1021.

[0345] In some embodiments, the first number, the user identifier of the first user, the length of the user identifier, the first password, the length of the first password, the identifier of the first network element 1021, the length of the identifier of the first network element 1021, and the like parameters can constitute the input of the KDF, so as to derive the first key based on the second key.

[0346] In some embodiments, the first password can be obtained in step S301.

[0347] In step S319, the terminal 101 performs user authentication.

[0348] In some embodiments, after obtaining the first key, the terminal 101 can perform user authentication based on the first key.

[0349] In some embodiments, the terminal 101 can perform user authentication based on the first key according to the fourth information.

[0350] In some embodiments, the step S319 can include: the terminal 101 calculates a fourth message authentication code based on the identifier of the second network element 1022 and the first random number in the fourth information, and the generated first key; the terminal 101 compares the first message authentication code with the fourth message authentication code; in the case that the first message authentication code and the fourth message authentication code are consistent, the terminal 101 determines that the network side passes the authentication of the first user.

[0351] In some embodiments, the fourth message authentication code can be denoted as XMAC N.

[0352] In some embodiments, the first message authentication code is obtained by the second network element 1022 based on the identifier of the second network element 1022, the first random number, and the first key generated by the first network element 1021, and the fourth message authentication code is obtained by the terminal 101 based on the identifier of the second network element 1022, the first random number, and the first key generated by the terminal 101. In this case, in the case that the first key generated by the first network element 1021 is the same as the first key generated by the terminal 101, the first message authentication code and the fourth message authentication code can be consistent. In other words, the first message authentication code and the fourth message authentication code are consistent, which means that the first key generated by the first network element 1021 and the first key generated by the terminal 101 can be the same. In some instances, the first message authentication code and the fourth message authentication code being consistent can mean that the fourth information is not tampered. In an example, this can mean that the identifier of the second network element 1022 and / or the first random number obtained by the terminal 101 from the fourth information are not tampered in the transmission process.

[0353] In some embodiments, on the terminal 101, the first key is derived based on the second key and a first personal password obtained by the terminal 101; and on the first network element 1021, the first key is derived based on the second key and a first personal password obtained by the first network element 1021. In this case, in the case that the first personal password obtained by the terminal 101 is the same as the first personal password obtained by the first network element 1021, the first key generated by the first network element 1021 and the first key generated by the terminal 101 can be the same. In other words, the first key generated by the first network element 1021 and the first key generated by the terminal 101 are the same, which means that the first personal password obtained by the terminal 101 and the first personal password obtained by the first network element 1021 can be the same.

[0354] In some embodiments, in the case that the first personal password obtained by the terminal 101 is the same as the first personal password obtained by the first network element 1021, and in the case that the fourth information is not tampered, the first message authentication code and the fourth message authentication code can be consistent.

[0355] In some embodiments, the first message authentication code and the fourth message authentication code are consistent, which can also be considered that the first message authentication code and the fourth message authentication code match.

[0356] In some embodiments, the user authentication can include that the network side authenticates the first user. In some embodiments, the user authentication can include that the terminal 101 authenticates the network side. In some embodiments, in the case that the first message authentication code and the fourth message authentication code are consistent, the terminal 101 can determine that the terminal 101 completes the authentication to the network due to the first user. In some embodiments, the terminal 101 can determine that the terminal 101 logged in by the first user completes the authentication to the network.

[0357] In step S320, the terminal 101 sends fifth information to the second network element 1022.

[0358] In some embodiments, the terminal 101 can send the fifth information. In some embodiments, the second network element 1022 can receive the fifth information.

[0359] In some embodiments, in the case that the terminal 101 completes the user authentication, the terminal 101 can send the fifth information. In some embodiments, in the case that it is determined that the network side authenticates the first user, the terminal 101 can send the fifth information.

[0360] In some embodiments, the fifth information can be used for the second network element 1022 to perform the user authentication for the first user.

[0361] In some embodiments, the fifth information can be used for triggering the second network element 1022 to perform the user authentication.

[0362] In some embodiments, the name of the fifth information is not limited, which can be, for example, authentication request information, authentication challenge information, authentication trigger information, authentication response information, and the like.

[0363] In some embodiments, the fifth information can include at least one of the following: a user identifier of the first user, the first random number, the second random number, the second message authentication code. In an example, the fifth information can include the user identifier of the first user, the second random number, the second message authentication code. In an example, the fifth information can include the user identifier of the first user, the first random number, the second random number, the second message authentication code.

[0364] In some embodiments, the second random number can be generated by the terminal 101.

[0365] In some embodiments, the second random number can be generated by the terminal 101 according to a preset rule.

[0366] In some embodiments, the second random number can be denoted as RAND_U.

[0367] In some embodiments, the second message authentication code can be used to implement verification of the authentication message between the second network element 1022 and the terminal 101.

[0368] In some embodiments, the second message authentication code can be used by the second network element 1022 to verify the fifth information. In some embodiments, the second message authentication code can be used by the second network element 1022 to verify the message carrying the fifth information.

[0369] In some embodiments, the second message authentication code can be associated with the user identifier of the first user, the identifier of the second network element 1022, the first random number, and the second random number.

[0370] In some embodiments, the second message authentication code can be calculated using the first key.

[0371] In some embodiments, the second message authentication code can be calculated by hashing based on the user identifier of the first user, the identifier of the second network element 1022, the first random number, the second random number, and the first key. In some embodiments, the first message authentication code can include a hash value calculated based on the user identifier of the first user, the identifier of the second network element 1022, the first random number, the second random number, and the first key.

[0372] In some embodiments, the second message authentication code can be denoted as MAC_U.

[0373] In some embodiments, the fifth information can be carried in an EAP response message. In some embodiments, the fifth information can be carried in an EAP challenge message.

[0374] In step S321, the second network element 1022 performs user authentication.

[0375] In some embodiments, after receiving the fifth information, the second network element 1022 can perform user authentication based on the first key.

[0376] In some embodiments, the second network element 1022 can perform user authentication based on the first key according to the fifth information.

[0377] In some embodiments, step S321 can include: the second network element 1022 calculating a third message authentication code based on the user identification information of the first user and the second random number in the fifth information, and the identifier of the second network element 1022 and the first random number locally, and the first key; the second network element 1022 comparing the third message authentication code with the second message authentication code; in the case that the third message authentication code and the second message authentication code are consistent, the second network element 1022 determines that the terminal 101 passes the user authentication.

[0378] In some embodiments, the third message authentication code can be denoted as XMAC_U.

[0379] In some embodiments, the third message authentication code is obtained by the second network element 1022 based on the user identifier of the first user, the identifier of the second network element 1022, the first random number, the second random number, and the first key generated by the first network element 1021, and the second message authentication code is obtained by the terminal 101 based on the user identifier of the first user, the identifier of the second network element 1022, the first random number, the second random number, and the first key generated by the terminal 101. In this case, in the case that the first key generated by the first network element 1021 is the same as the first key generated by the terminal 101, the third message authentication code and the second message authentication code can be consistent. In other words, the third message authentication code and the second message authentication code are consistent, which means that the first key generated by the first network element 1021 and the first key generated by the terminal 101 can be the same. In some instances, the third message authentication code and the second message authentication code being consistent can mean that the fifth information is not tampered with. In an example, this can mean that the user identifier of the first user and the second random number obtained by the second network element 1022 from the fifth information are not tampered with in the transmission process.

[0380] In some embodiments, on the terminal 101, the first key is derived based on the second key and a first personal password obtained by the terminal 101; and on the first network element 1021, the first key is derived based on the second key and a first personal password obtained by the first network element 1021. In this case, in the case that the first personal password obtained by the terminal 101 is the same as the first personal password obtained by the first network element 1021, the first key generated by the first network element 1021 and the first key generated by the terminal 101 can be the same. In other words, the first key generated by the first network element 1021 and the first key generated by the terminal 101 are the same, which means that the first personal password obtained by the terminal 101 and the first personal password obtained by the first network element 1021 can be the same.

[0381] In some embodiments, in the case that the first personal password obtained by the terminal 101 is the same as the first personal password obtained by the first network element 1021, and in the case that the fifth information is not tampered, the second message authentication code and the third message authentication code can be consistent.

[0382] In some embodiments, the second message authentication code and the third message authentication code are consistent, which can also be considered that the second message authentication code and the third message authentication code match.

[0383] In some embodiments, the user authentication can include that the terminal 101 passes the user authentication. In some embodiments, the user authentication can include that the network side authenticates the terminal 101. In an example, the user authentication can include that the second network element 1022 authenticates the terminal 101. In some embodiments, in the case that the second message authentication code and the third message authentication code are consistent, the second network element 1022 can determine that the network side completes the authentication of the terminal 101. In some embodiments, the second network element 1022 can determine that the terminal 101 logged in by the first user passes the authentication of the network side.

[0384] In some embodiments, through steps S317 to S321, the user authentication can be implemented between the terminal 101 and the second network element 1022.

[0385] In step S322, the second network element 1022 sends twelfth information to the first network element 1021.

[0386] In some embodiments, the second network element 1022 can send the twelfth information. In some embodiments, the first network element 1021 can receive the twelfth information.

[0387] In some embodiments, after the user authentication between the terminal 101 and the second network element 1022 is completed, the second network element 1022 can notify other network elements of the authentication result of the user authentication.

[0388] In some embodiments, the twelfth information can be used by the first network element 1021 to obtain the authentication result.

[0389] In some embodiments, the twelfth information can be used to register the authentication result for the first user to the first network element 1021.

[0390] In some embodiments, the name of the twelfth information is not limited, which can be, for example, result registration information, result notification information, etc.

[0391] In some embodiments, the twelfth information can include at least one of the following: a user identifier of the first user, the authentication result.

[0392] In some embodiments, after the user authentication is completed, the authentication result can be that the first user passes the user authentication.

[0393] In some embodiments, the twelfth information can be sent through a user authentication result registration process.

[0394] In step S323, the first network element 1021 associates the authentication result with the user identifier.

[0395] In some embodiments, the first network element 1021 can associate the authentication result in the twelfth information with the user identification information of the first user.

[0396] In some embodiments, the first network element 1021 can save the authentication result corresponding to the user identification information of the first user locally. In an example, the first network element 1021 can save the authentication result in a user configuration related to the first user.

[0397] In some embodiments, the first network element 1021 can save the association between the user identification information of the first user and the corresponding authentication result locally. In an example, the first network element 1021 can save the association between the user identification information of the first user and the corresponding authentication result in a user configuration related to the first user.

[0398] In step S324, the first network element 1021 sends thirteenth information to the terminal 101.

[0399] In some embodiments, the first network element 1021 can send the thirteenth information. In some embodiments, the terminal 101 can receive the thirteenth information.

[0400] In some embodiments, the thirteenth information can be used by the terminal 101 to obtain the authentication result.

[0401] In some embodiments, the thirteenth information can be used to notify the terminal 101 of the authentication result for the first user.

[0402] In some embodiments, the name of the thirteenth information is not limited, which can be, for example, result notification information, and the like.

[0403] In some embodiments, the thirteenth information can include at least one of the following: a user identifier of the first user, an authentication result.

[0404] In some embodiments, the authentication result can be that the first user passes the user authentication.

[0405] In some embodiments, the thirteenth information can be transmitted through a control plane. In some embodiments, the second network element 1022 can send the thirteenth information to the terminal 101 via the fourth network element 1024.

[0406] In some embodiments, the thirteenth information can be transmitted through a user plane.

[0407] In some embodiments, the thirteenth information can be carried in a user authentication response message. In some embodiments, the second network element 1022 can send the user authentication response message to the terminal 101. The user authentication response message can include the thirteenth information.

[0408] Through the above steps S301 to S324, the user authentication method according to the embodiments of the present disclosure can be implemented.

[0409] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and the terms of “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “domain”, “field”, “symbol”, “symbol”, “codebook”, “codeword”, “code point”, “bit”, “data”, “program”, “chip”, and the like can be replaced with each other.

[0410] In some embodiments, the terms of “radio”, “wireless”, “radio access network (RAN)”, “access network (AN)”, “RAN-based”, and the like can be replaced with each other.

[0411] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectionally transmit", "send and / or receive" can be replaced by each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like.

[0412] In some embodiments, the terms "send", "transmit", "report", "issue", "transmit", "bidirectionally transmit", "send and / or receive", and the like can be replaced by each other.

[0413] In some embodiments, the terms "certain", "preset", "pre-set", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced by each other. "Certain A", "preset A", "pre-set A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, can be interpreted as A obtained by setting, configuring, or indicating, and the like, and can be interpreted as certain A, certain A, arbitrary A, or first A, but is not limited thereto.

[0414] In some embodiments, determination or judgment can be made by a value represented by 1 bit (0 or 1), by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.

[0415] The user authentication method related to the embodiments of the present disclosure can include at least one of steps S301 to S324. For example, step S306 can be implemented as an independent embodiment. For example, step S314 can be implemented as an independent embodiment. For example, step S315 can be implemented as an independent embodiment. For example, step S316 can be implemented as an independent embodiment. For example, step S317 can be implemented as an independent embodiment. For example, step S319 can be implemented as an independent embodiment. For example, step S320 can be implemented as an independent embodiment. For example, step S321 can be implemented as an independent embodiment. For example, the combination of steps S317 and S319 can be implemented as an independent embodiment. For example, the combination of steps S320 and S321 can be implemented as an independent embodiment. For example, the combination of steps S314, S315, and S316 can be implemented as an independent embodiment. It should be noted that the possible independent embodiments composed of one or more of steps S301 to S324 are not limited thereto.

[0416] In some embodiments, the steps in S301-S324 can be exchanged in order or performed simultaneously. In an example, S317 and S318 can be exchanged in order or performed simultaneously. In an example, S322 and S324 can be exchanged in order or performed simultaneously.

[0417] In some embodiments, S301-S313 and S317-S324 are optional, and one or more of them can be omitted or replaced in different embodiments.

[0418] In some embodiments, S301-S316 and S318-S324 are optional, and one or more of them can be omitted or replaced in different embodiments.

[0419] In some embodiments, S301-S305 and S307-S324 are optional, and one or more of them can be omitted or replaced in different embodiments.

[0420] In some embodiments, S301-S316, S318, and S320-S324 are optional, and one or more of them can be omitted or replaced in different embodiments.

[0421] In some embodiments, other optional implementations can be described before or after the description of Figure 3.

[0422] Figure 4 is a flow diagram of a user authentication method according to an embodiment of the present disclosure. The present embodiment relates to a user authentication method. The user authentication method is performed by a first network element 1021. As shown in Figure 4, the above method includes steps S401-S407.

[0423] In step S401, third information is obtained.

[0424] Optional implementations of S401 can refer to optional implementations of S308 of Figure 3 and other related parts in the embodiments related to Figure 3, which will not be repeated here.

[0425] In some embodiments, the first network element 1021 can receive the third information sent by the third network element 1023, but is not limited thereto, and can also receive the third information sent by other subjects.

[0426] In step S402, the second key and the first identification information are associated.

[0427] The optional implementation of step S402 can refer to the optional implementation of step S309 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0428] In some embodiments, the first network element 1021 can associate the first identification information with the second key in the third information.

[0429] In step S403, the first information is acquired.

[0430] The optional implementation of step S403 can refer to the optional implementation of step S314 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0431] In some embodiments, the first network element 1021 can receive the first information sent by the second network element 1022, but is not limited thereto, and can also receive the first information sent by other subjects.

[0432] In step S404, the first key is determined.

[0433] The optional implementation of step S404 can refer to the optional implementation of step S315 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0434] In step S405, the second information is sent.

[0435] The optional implementation of step S405 can refer to the optional implementation of step S316 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0436] In some embodiments, the first network element 1021 can send the second information to the second network element 1022, but is not limited thereto, and can also send the second information to other subjects.

[0437] In step S406, the twelfth information is acquired.

[0438] The optional implementation of step S406 can refer to the optional implementation of step S322 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0439] In some embodiments, the first network element 1021 can receive the twelfth information sent by the second network element 1022, but is not limited thereto, and can also receive the twelfth information sent by other subjects.

[0440] In step S407, the user identifier and the authentication result are associated.

[0441] The optional implementation of step S407 can refer to the optional implementation of step S323 in FIG. 3, and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0442] The user authentication method involved in the embodiments of the present disclosure can include at least one of steps S401 to S407. For example, step S403 can be implemented as an independent embodiment. For example, step S404 can be implemented as an independent embodiment. For example, step S405 can be implemented as an independent embodiment. For example, the combination of steps S403, S404, and S405 can be implemented as an independent embodiment. It should be noted that the possible independent embodiments composed of one or more of steps S401 to S407 are not limited to this.

[0443] In some embodiments, steps S401, S402, S404, S405, S406, and S407 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0444] In some embodiments, steps S401, S402, S403, S405, S406, and S407 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0445] In some embodiments, steps S401, S402, S403, S404, S406, and S407 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0446] FIG. 5 is a flow diagram of a user authentication method according to an embodiment of the present disclosure. The embodiments of the present disclosure relate to a user authentication method. The user authentication method is performed by a second network element 1022. As shown in FIG. 5, the above method includes steps S501 to S508.

[0447] In step S501, the eleventh information is obtained.

[0448] The optional implementation of step S501 can refer to the optional implementation of step S313 in FIG. 3, and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0449] In some embodiments, the second network element 1022 can receive the eleventh information sent by the terminal 101, but is not limited thereto, and can also receive the eleventh information sent by other subjects.

[0450] In step S502, the first information is sent.

[0451] The optional implementation of step S502 can refer to the optional implementation of step S314 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0452] In some embodiments, the second network element 1022 can send the first information to the first network element 1021, but is not limited thereto, and can also send the first information to other subjects.

[0453] In step S503, the second information is acquired.

[0454] The optional implementation of step S503 can refer to the optional implementation of step S316 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0455] In some embodiments, the second network element 1022 can receive the second information sent by the first network element 1021, but is not limited thereto, and can also receive the second information sent by other subjects.

[0456] In step S504, the fourth information is sent.

[0457] The optional implementation of step S504 can refer to the optional implementation of step S317 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0458] In some embodiments, the second network element 1022 can send the fourth information to the terminal 101, but is not limited thereto, and can also send the fourth information to other subjects.

[0459] In step S505, the fifth information is acquired.

[0460] The optional implementation of step S505 can refer to the optional implementation of step S320 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0461] In some embodiments, the second network element 1022 can receive the fifth information sent by the terminal 101, but is not limited thereto, and can also receive the fifth information sent by other subjects.

[0462] In step S506, user verification is performed.

[0463] The optional implementation of step S506 can refer to the optional implementation of step S321 in FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0464] In step S507, the twelfth information is sent.

[0465] The optional implementation of step S507 can refer to the optional implementation of step S322 of FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0466] In some embodiments, the second network element 1022 can send the twelfth information to the first network element 1021, but is not limited thereto, and can also send the twelfth information to other subjects.

[0467] In step S508, the thirteenth information is sent.

[0468] The optional implementation of step S508 can refer to the optional implementation of step S324 of FIG. 3 and other associated parts in the embodiments related by FIG. 3, which will not be repeated here.

[0469] In some embodiments, the second network element 1022 can send the thirteenth information to the terminal 101, but is not limited thereto, and can also send the thirteenth information to other subjects.

[0470] The user authentication method related by the embodiments of the present disclosure can include at least one of steps S501 to S508. For example, step S502 can be implemented as an independent embodiment. For example, step S503 can be implemented as an independent embodiment. For example, step S504 can be implemented as an independent embodiment. For example, step S505 can be implemented as an independent embodiment. For example, the combination of steps S502 and S503 can be implemented as an independent embodiment. For example, the combination of steps S504 and S505 can be implemented as an independent embodiment. It should be noted that the possible independent embodiments composed of one or more of steps S501 to S508 are not limited thereto.

[0471] In some embodiments, multiple steps in steps S501 to S508 can be exchanged in order or executed simultaneously. In an example, step S507 and step S508 can be exchanged in order or executed simultaneously.

[0472] In some embodiments, steps S501, S503, S504, S505, S506, S507, S508 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0473] In some embodiments, steps S501, S502, S504, S505, S506, S507, S508 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0474] In some embodiments, steps S501, S502, S503, S505, S506, S507, and S508 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0475] In some embodiments, steps S501, S502, S503, S504, S506, S507, and S508 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0476] Figure 6 is a flowchart illustrating a user authentication method according to an embodiment of this disclosure. This disclosure relates to a user authentication method. This user authentication method is executed by a fourth network element 1024. As shown in Figure 6, the method includes steps S601 to S607.

[0477] In step S601, the tenth information is obtained.

[0478] The optional implementation of step S601 can be found in the optional implementation of step S302 in Figure 3, as well as other related parts in the embodiments involved in Figure 3, which will not be repeated here.

[0479] In some embodiments, the fourth network element 1024 may receive the tenth information sent by the terminal 101, but is not limited thereto, and may also receive the tenth information sent by other entities.

[0480] In step S602, the main authentication process is executed.

[0481] The optional implementation of step S602 can be found in the optional implementation of step S303 in Figure 3, as well as other related parts in the embodiments involved in Figure 3, which will not be repeated here.

[0482] In step S603, the seventh information is obtained.

[0483] The optional implementation of step S603 can be found in the optional implementation of step S304 in Figure 3, as well as other related parts in the embodiments involved in Figure 3, which will not be repeated here.

[0484] In some embodiments, the fourth network element 1024 may receive the seventh information sent by the fifth network element 1025, but is not limited thereto, and may also receive the seventh information sent by other entities.

[0485] In step S604, it is determined that user authentication is triggered.

[0486] The optional implementation of step S604 can be found in the optional implementation of step S305 in Figure 3, as well as other related parts in the embodiments involved in Figure 3, which will not be repeated here.

[0487] In step S605, sixth information is sent.

[0488] Optional implementation of step S605 can refer to optional implementation of step S306 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0489] In some embodiments, the fourth network element 1024 can send the sixth information to the third network element 1023, but is not limited thereto, and can send the sixth information to other subjects.

[0490] In step S606, eighth information is acquired.

[0491] Optional implementation of step S606 can refer to optional implementation of step S310 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0492] In some embodiments, the fourth network element 1024 can receive the eighth information sent by the third network element 1023, but is not limited thereto, and can receive the eighth information sent by other subjects.

[0493] In step S607, ninth information is sent.

[0494] Optional implementation of step S607 can refer to optional implementation of step S311 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0495] In some embodiments, the fourth network element 1024 can send the ninth information to the terminal 101, but is not limited thereto, and can send the ninth information to other subjects.

[0496] The user authentication method involved in the embodiments of the present disclosure can include at least one of steps S601 to S607. For example, step S605 can be implemented as an independent embodiment. It should be noted that the possible independent embodiments composed of one or more of steps S601 to S607 are not limited thereto.

[0497] In some embodiments, steps S601, S602, S603, S604, S606, and S607 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0498] FIG. 7 is a flow diagram of a user authentication method according to an embodiment of the present disclosure. The embodiments of the present disclosure relate to a user authentication method. The user authentication method is performed by the terminal 101. As shown in FIG. 7, the above method includes steps S701 to S708.

[0499] In step S701, a user identifier and a first personal password are obtained.

[0500] Optional implementation of step S701 can refer to optional implementation of step S301 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0501] In step S702, the tenth information is sent.

[0502] Optional implementation of step S702 can refer to optional implementation of step S302 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0503] In some embodiments, the terminal 101 can send the tenth information to the fourth network element 1024, but is not limited to this, and can also send the tenth information to other subjects.

[0504] In step S703, a main authentication process is performed.

[0505] Optional implementation of step S703 can refer to optional implementation of step S303 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0506] In step S704, the ninth information is obtained.

[0507] Optional implementation of step S704 can refer to optional implementation of step S311 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0508] In some embodiments, the terminal 101 can receive the ninth information sent by the fourth network element 1024, but is not limited to this, and can also receive the ninth information sent by other subjects.

[0509] In step S705, a second key is determined.

[0510] Optional implementation of step S705 can refer to optional implementation of step S312 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0511] In step S706, the eleventh information is sent.

[0512] Optional implementation of step S706 can refer to optional implementation of step S313 of FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0513] In some embodiments, the terminal 101 can send the eleventh information to the second network element 1022, but is not limited to this, and can also send the eleventh information to other subjects.

[0514] In step S707, fourth information is acquired.

[0515] Optional implementation of step S707 can refer to optional implementation of step S317 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0516] In some embodiments, the terminal 101 can receive the fourth information sent by the second network element 1022, but is not limited thereto, and can also receive the fourth information sent by other subjects.

[0517] In step S708, a first key is determined.

[0518] Optional implementation of step S708 can refer to optional implementation of step S318 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0519] In step S709, user authentication is performed.

[0520] Optional implementation of step S709 can refer to optional implementation of step S319 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0521] In step S710, fifth information is sent.

[0522] Optional implementation of step S710 can refer to optional implementation of step S320 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0523] In some embodiments, the terminal 101 can send the fifth information to the second network element 1022, but is not limited thereto, and can also send the fifth information to other subjects.

[0524] In step S711, thirteenth information is acquired.

[0525] Optional implementation of step S711 can refer to optional implementation of step S324 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0526] In some embodiments, the terminal 101 can receive the thirteenth information sent by the second network element 1022, but is not limited thereto, and can also receive the thirteenth information sent by other subjects.

[0527] The user authentication method related to the embodiments of the present disclosure can comprise at least one of steps S701 to S711. For example, step S707 can be implemented as an independent embodiment. For example, step S710 can be implemented as an independent embodiment. It should be noted that the possible independent embodiments composed of one or more of steps S701 to S711 are not limited thereto.

[0528] In some embodiments, the steps in steps S701 to S711 can be exchanged in order or executed simultaneously. In an example, step S707 and step S708 can be exchanged in order or executed simultaneously.

[0529] In some embodiments, steps S701 to S706, and S708 to S711 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0530] In some embodiments, steps S701 to S709, S711 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0531] FIG. 8A is an interaction diagram of a user authentication method according to an embodiment of the present disclosure. The embodiments of the present disclosure relate to a user authentication method. As shown in FIG. 8A, the above method comprises steps S8101 to S8103.

[0532] In step S8101, the second network element 1022 sends first information to the first network element 1021.

[0533] The optional implementation of step S8101 can refer to the optional implementation of step S314 of FIG. 3 and other associated parts in the embodiments related to FIG. 3, which will not be repeated here.

[0534] In step S8102, the first network element 1021 determines a first key.

[0535] The optional implementation of step S8102 can refer to the optional implementation of step S315 of FIG. 3 and other associated parts in the embodiments related to FIG. 3, which will not be repeated here.

[0536] In step S8103, the first network element 1021 sends second information to the second network element 1022.

[0537] The optional implementation of step S8103 can refer to the optional implementation of step S316 of FIG. 3 and other associated parts in the embodiments related to FIG. 3, which will not be repeated here.

[0538] FIG. 8B is an interaction schematic diagram of a user authentication method according to an embodiment of the present disclosure. The embodiment of the present disclosure relates to a user authentication method. As shown in FIG. 8B, the above method comprises steps S8201 to S8202.

[0539] In step S8201, the second network element 1022 sends fourth information to the terminal 101.

[0540] The optional implementation of step S8201 can refer to the optional implementation of step S317 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0541] In step S8202, the terminal 101 performs user authentication.

[0542] The optional implementation of step S8202 can refer to the optional implementation of step S319 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0543] FIG. 8C is an interaction schematic diagram of a user authentication method according to an embodiment of the present disclosure. The embodiment of the present disclosure relates to a user authentication method. As shown in FIG. 8C, the above method comprises step S8301.

[0544] In step S8301, the fourth network element 1024 sends sixth information to the third network element 1023.

[0545] The optional implementation of step S8301 can refer to the optional implementation of step S306 in FIG. 3 and other associated parts in the embodiments involved in FIG. 3, which will not be repeated here.

[0546] In the following, the technical solutions of the embodiments of the present disclosure are exemplarily described through specific embodiments.

[0547] FIG. 9 is a schematic diagram of a key hierarchy in a user authentication method according to an embodiment of the present disclosure. As shown in FIG. 9, K AUSF (i.e., the third key) is an intermediate key derived by the UE and the network (i.e., the AUSF) for UE primary authentication, and is used as a root key in the key hierarchy of user authentication. Based on the root key K AUSF , the UE and the AUSF derive K UIA (i.e., the second key) to be used as an intermediate key for all users on the terminal. In some embodiments, the AUSF can send a {SUPI, K UIA} pair to the UPS. The UPS can associate K UIA to the GPSI (i.e., the first identification information) mapped by the SUPI (i.e., the second identification information). Based on the intermediate key K UIA, the UE / ME and the UPS can derive K USER (i.e., the first key) from the user identity (i.e., user ID, user identifier) and the corresponding PIN (i.e., the first personal password). USER K UIA may be used as a user authentication credential for each specific user on the UE.

[0548] FIG. 10A is an interaction schematic diagram of an exemplary implementation of a user authentication method according to an embodiment of the present disclosure. In the registration procedure shown in FIG. 10A, the AUSF and the UE can generate K AUSF . As shown in FIG. 10A, the registration procedure includes steps S10101 to S10111.

[0549] In some embodiments, it is assumed that the user identity and the corresponding PIN are provided to each user in advance by the network through, for example, an operator portal website.

[0550] In step S10101, the UE sends a registration request. The registration request at least contains the SUCI or GUTI of the UE (i.e., the third identification information), and the UE capability of supporting user authentication.

[0551] In step S10102, in the process of successfully performing the primary authentication between the UE and the network, the AUSF derives K AUSF .

[0552] In step S10103, in the case where the UE capability supports the user authentication derived by the key K UIA , the AMF can send an Nudm_SDM_Get request message to the UDM to retrieve the UE subscription from the UDM.

[0553] In step S10104, in the case where the UE does not subscribe to the user authentication feature, the AMF can continue to perform step S10109 and does not indicate the user authentication method.

[0554] In some embodiments, in the case where the UE subscribes to the user authentication feature and the user authentication policy indicates the derivation of the credential (K UIA ), the AMF determines to interact with the AUSF to trigger the derivation of the user authentication credential.

[0555] In step S10105, the AMF sends an Nausf_UserAuthentication_Authenticate request message to the AUSF of the UE, which includes the SUPI of the UE, etc.

[0556] In step S10106, upon receiving a Nausf_UserAuthentication_Authenticate request message from the AMF, the AMF determines that user authentication requires the UE's K... AUSF Derivation of K UIA In some embodiments, AUSF can derive K. UIA And K UIA Associated with UE's SUPI.

[0557] In step S10107, AUSF sends {SUPI,K} to UPS. UIA Yes. In some embodiments, the UPS can be a standalone network function or paired with a UDM. In some embodiments, the UPS can connect to K... UIA It is associated with the GPSI mapped from SUPI. In some embodiments, the mapping between GPSI and SUPI may be stored in UPS or retrieved from UDM or UDR.

[0558] In step S10108, AUSF may return a Nausf_UserAuthentication_Authenticate response message to AMF, which indicates the derivation of K. UIA .

[0559] In step S10109, the AMF sends a registration acceptance to the UE, optionally carrying a user authentication method.

[0560] In step S10110, upon receiving an indication that K needs to be deduced... UIA In the case of user authentication methods, the UE can adopt the same approach as AUSF based on K. AUSF Derivation of K UIA In some embodiments, the UE can transmit K UIA Associated with the UE's GPSI.

[0561] In step S10111, user authentication is performed between the UE and the UAAF. In some embodiments, the UAAF may be an AUSF, or it may be a separate network function different from the AUSF.

[0562] Figure 10B is an interactive schematic diagram of an exemplary implementation of the user authentication method provided according to embodiments of the present disclosure. In the user authentication process shown in Figure 10B, the UPS and UE can generate K. USER As shown in Figure 10B, the user authentication process includes steps S10201 to S10208.

[0563] In some embodiments, in UE derivation K UIAAfterwards, whenever a user logs in the UE, the UE can initiate a user authentication procedure to the network.

[0564] In step S10201, the UE sends a user authentication request message to the UAAF. The message indicates at least the user identifier and the GPSI. In some embodiments, the message can be sent over the control plane via the AMF, or can be sent over the user plane.

[0565] In step S10202, after receiving the user authentication request, the UAAF can send an authentication key request to the UPS. In some embodiments, the authentication key request can contain the user identifier and the GPSI.

[0566] In step S10203, the UPS can retrieve the K UIA based on the received GPSI. Afterwards, the UPS can retrieve the PIN of the user based on the received user identifier. Based on the retrieved K UIA and PIN, the UPS can generate the K USER .

[0567] In step S10204, the UPS can return the derived K USER to the UAAF.

[0568] In some embodiments, the UAAF and the UPS can be used in conjunction. In this case, step S10202 and step S10204 can be omitted.

[0569] In step S10205, the UE and the UAAF can perform user authentication based on the user identifier and the K USER (see the embodiment of FIG. 10C).

[0570] In step S10206, the UAAF registers the user authentication result obtained by the K USER to the UPS.

[0571] In step S10207, the UPS stores the user authentication result associated with the user identifier.

[0572] In step S10208, the UAAF sends a user authentication response message carrying the authentication result to the UE.

[0573] FIG. 10C is an interaction schematic diagram of an exemplary embodiment of a user authentication method according to an embodiment of the present disclosure. The user authentication procedure shown in FIG. 10C involves the UE and the UAAF. As shown in FIG. 10C, the user authentication procedure includes steps S10301 to S10305.

[0574] In step S10301, the UAAF receives the K USERThereafter, the UAAF sends an EAP challenge to the UE. In some embodiments, the EAP challenge contains the UAAF ID (i.e. the identifier of the second network element), a random number RAND-N (i.e. the first random number), and a MAC_N (i.e. the first message authentication code). In some embodiments, the MAC_N is a message authentication code of the UAAF ID and the RAND-N, and is computed by K USER .

[0575] In step S10302, upon receiving the EAP challenge from the UAAF, the UE computes K UIA . USER .

[0576] In step S10303, the UE computes a message authentication code XMAC_N (i.e. the fourth message authentication code) for the received UAAF ID and RAND-N using K USER , and compares XMAC_N with the received MAC_N. In case XMAC_N matches MAC_N, the network gets authenticated by the terminal used by the user.

[0577] In step S10304, in response, the UE sends an EAP challenge. In some embodiments, the EAP challenge contains a RAND-U (the second random number) and a user identifier, RAND-N (optional), and a MAC_U (i.e. the second message authentication code). In some embodiments, the MAC_U is a message authentication code of the UAAF ID, the user identifier, the RAND-U, and the RAN-N, and is computed by K USER .

[0578] In step S10305, the UAAF computes a message authentication code XMAC_U for the received user identifier and RAND-U, and the UAAF's own UAAF ID, RAND-N, using K USER , and compares XMAC_U with the received MAC_U. In some embodiments, in case XMAC_U matches MAC_U, the UE gets authenticated by the network.

[0579] In some embodiments, the following parameters can be used as inputs of the KDF in the process of deriving K UIA . USER from K

[0580] - FC = to be determined (i.e. the first numerical value);

[0581] - P0 = the user identifier;

[0582] - L0 = the length of the user identifier;

[0583] - P1 = PIN;

[0584] - L1 = length of PIN;

[0585] - P2 = network function identifier (e.g., identifier of UPS);

[0586] - L2 = length of network function identifier.

[0587] In some embodiments, the input key is K UIA .

[0588] In the embodiments of the present disclosure, part or all of the steps, the optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with the optional implementation manners of other embodiments.

[0589] The embodiments of the present disclosure also provide a user authentication apparatus for implementing any of the above methods. For example, the embodiments of the present disclosure provide a user authentication apparatus comprising units or modules for implementing the steps performed by the network element in any of the above methods. For example, the embodiments of the present disclosure provide a user authentication apparatus comprising units or modules for implementing the steps performed by the terminal in any of the above methods.

[0590] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the above units or modules are realized by the design of the logical relationship of the elements in the circuit; for example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0591] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit, a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by a special-purpose integrated circuit or a programmable logic device, such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads an instruction to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0592] FIG. 11 is a structural schematic diagram of a user authentication apparatus provided by the embodiments of the present disclosure. As shown in FIG. 11, the user authentication apparatus 1100 can include at least one of a transceiver module 1101 and a processing module 1102.

[0593] In some embodiments, the user authentication apparatus 1100 can be the first network element 1021. In some embodiments, the transceiver module 1101 can be configured to receive first information sent by the second network element, wherein the first information is used by the first network element to determine the terminal and the first user of the terminal; and send second information to the second network element, wherein the second information is used to implement user authentication for the first user, and the second information at least includes the first key. In some embodiments, the processing module 1102 can be configured to determine the first key based on the first information and the first password. Optionally, the transceiver module 1101 can be configured to perform at least one of the communication steps (for example, steps S308, S314, S316, S322, but not limited thereto) of the sending and / or receiving performed by the first network element 1021 in any of the above methods, and details are not described herein again. Optionally, the processing module 1102 can be configured to perform at least one of the steps (for example, steps S309, S315, S323, but not limited thereto) other than the sending and / or receiving communication steps performed by the first network element 1021 in any of the above methods, and details are not described herein again.

[0594] In some embodiments, the user authentication apparatus 1100 can be the second network element 1022. In some embodiments, the transceiver module 1101 can be configured to send fourth information to the terminal, where the fourth information is used by the terminal to perform the user authentication for the first user of the terminal; where the user authentication is implemented based on the first key, which is derived based on at least the first password. Optionally, the transceiver module 1101 can be configured to perform at least one of the communication steps (e.g., steps S313, S314, S316, S317, S320, S322, S324, but not limited to) of sending and / or receiving performed by the second network element 1022 in any of the above methods, which are not described herein again. Optionally, the processing module 1102 can be configured to perform at least one of the steps (e.g., step S321, but not limited to) other than the communication steps of sending and / or receiving performed by the second network element 1022 in any of the above methods, which are not described herein again.

[0595] In some embodiments, the user authentication apparatus 1100 can be the fourth network element 1024. In some embodiments, the transceiver module 1101 can be configured to send sixth information to the third network element, where the sixth information is used to trigger the third network element to generate a second key; where the second key is used to determine the first key together with the first identification code, and the first key is used to implement the user authentication for the first user of the terminal. Optionally, the transceiver module 1101 can be configured to perform at least one of the communication steps (e.g., steps S302, S303, S304, S306, S310, S311, but not limited to) of sending and / or receiving performed by the fourth network element 1024 in any of the above methods, which are not described herein again. Optionally, the processing module 1102 can be configured to perform at least one of the steps (e.g., step S305, but not limited to) other than the communication steps of sending and / or receiving performed by the fourth network element 1024 in any of the above methods, which are not described herein again.

[0596] In some embodiments, the user authentication apparatus 1100 can be the terminal 101. In some embodiments, the transceiver module 1101 can be configured to receive fourth information sent by the second network element, where the fourth information is used for the terminal to perform user authentication for the first user of the terminal. In some embodiments, the processing module 1102 can be configured to perform the user authentication according to the fourth information. The user authentication is implemented based on the first key. The first key is derived based on at least the first password. Optionally, the transceiver module 1101 can be configured to perform at least one of the communication steps (for example, steps S302, S303, S311, S313, but are not limited thereto) of the sending and / or receiving performed by the terminal 101 in any of the above methods, which are not described herein again. Optionally, the processing module 1102 can be configured to perform at least one of the steps (for example, steps S301, S312, S318, S319, but are not limited thereto) of the terminal in any of the above methods, except for the communication steps such as sending and / or receiving, which are not described herein again.

[0597] In some embodiments, the transceiver module can include a sending module and / or a receiving module. The sending module and the receiving module can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with the transceiver.

[0598] In some embodiments, the processing module can be one module or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module respectively. Optionally, the processing module can be mutually replaced with the processor.

[0599] FIG. 12A is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. The communication device 12100 can be a network device (for example, an access network device, a core network device, etc.), a terminal (for example, a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 12100 can be used to implement the methods described in the above method embodiments, and specific reference can be made to the descriptions in the above method embodiments.

[0600] As shown in FIG. 12A, the communication device 12100 includes one or more processors 12101. The processor 12101 can be a general processor or a special-purpose processor, etc., such as a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control a communication device apparatus (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 12100 is configured to perform any of the above methods. Optionally, the one or more processors 12101 are configured to invoke instructions to cause the communication device 12100 to perform any of the above methods.

[0601] In some embodiments, the communication device 12100 further includes one or more transceivers 12102. When the communication device 12100 includes one or more transceivers 12102, the transceiver 12102 performs at least one of the communication steps (e.g., steps S302, S303, S304, S306, S308, S310, S311, S313, S314, S316, S317, S320, S322, S324, but not limited to this) in the above methods, and the processor 12101 performs other steps (e.g., steps S301, S305, S307, S309, S312, S315, S318, S319, S321, S323, but not limited to this). In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced with each other, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.

[0602] In some embodiments, the communication device 12100 further includes one or more memories 12103 for storing data. Optionally, all or part of the memory 12103 can also be outside the communication device 12100. In optional embodiments, the communication device 12100 can include one or more interface circuits 12104. Optionally, the interface circuit 12104 is connected to the memory 12103, and the interface circuit 12104 can be configured to receive data from the memory 12103 or other apparatuses, and can be configured to send data to the memory 12103 or other apparatuses. For example, the interface circuit 12104 can read data stored in the memory 12103 and send the data to the processor 12101.

[0603] The communication device 12100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 12100 described in the present disclosure is not limited thereto, and the structure of the communication device 12100 can not be limited by FIG. 12A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0604] FIG. 12B is a structural diagram of a chip according to an embodiment of the present disclosure. For the case where the communication device 12100 can be a chip or a chip system, the structural diagram of the chip 12200 shown in FIG. 12B can be referred to, but is not limited thereto.

[0605] The chip 12200 includes one or more processors 12201. The chip 12200 is configured to perform any of the above methods.

[0606] In some embodiments, the chip 12200 further includes one or more interface circuits 12202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 12200 further includes one or more memories 12203 for storing data. Optionally, all or part of the memory 12203 can be outside the chip 12200. Optionally, the interface circuit 12202 is connected to the memory 12203, and the interface circuit 12202 can be configured to receive data from the memory 12203 or other devices, and the interface circuit 12202 can be configured to send data to the memory 12203 or other devices. For example, the interface circuit 12202 can read data stored in the memory 12203 and send the data to the processor 12201.

[0607] In some embodiments, the interface circuit 12202 performs at least one of the communication steps (for example, steps S302, S303, S304, S306, S308, S310, S311, S313, S314, S316, S317, S320, S322, S324, but are not limited thereto) of transmitting and / or receiving in the above-described methods. The interface circuit 12202 performing the communication steps such as transmitting and / or receiving in the above-described methods refers to, for example, the interface circuit 12202 performing data interaction between the processor 12201, the chip 12200, the memory 12203, or the transceiver device. In some embodiments, the processor 12201 performs at least one of the other steps (for example, steps S301, S305, S307, S309, S312, S315, S318, S319, S321, S323, but are not limited thereto).

[0608] The various modules and / or devices described in each of the embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated according to circumstances. Alternatively, part or all of the steps can also be performed by a plurality of modules and / or devices in cooperation, which is not limited here.

[0609] The embodiments of the present disclosure also propose a storage medium, and the storage medium stores instructions. When the instructions run on the communication device 12100, the communication device 12100 performs any one of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer readable storage medium, but is not limited thereto, and it can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but is not limited thereto, and it can also be a transitory storage medium.

[0610] The embodiments of the present disclosure also propose a program product, and the program product is executed by the communication device 12100, so that the communication device 12100 performs any one of the above methods. Alternatively, the program product is a computer program product.

[0611] The embodiments of the present disclosure also propose a computer program, which makes the computer execute any one of the above methods when it runs on the computer.

[0612] Other embodiments of the present application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The present disclosure is intended to cover any and all variations of the present application comprising adaptations, modifications, equivalents, and alternatives falling within the scope of the present application. It is intended that the specification and examples be considered exemplary only, with the true scope and spirit of the application being indicated by the following claims.

[0613] It should be understood that the application is not limited to the precise construction which has been described above and which shown in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application should be limited only by the appended claims.

Claims

A user authentication method, performed by a first network element, wherein The method comprises: receiving first information sent by a second network element, wherein the first information is used for the first network element to determine a terminal and a first user of the terminal; determining a first key based on the first information and a first personal password; sending second information to the second network element, wherein the second information is used for implementing user authentication for the first user, and the second information comprises at least the first key. The method of claim 1, wherein, The first personal password is a personal password assigned to the first user. The method according to claim 1 or 2, wherein The determining of the first key based on the first information and the first personal password comprises: obtaining first identification information from the first information, wherein the first identification information is used for identifying the terminal; determining a second key associated with the first identification information; determining the first key according to the second key and the first personal password. The method of claim 3, wherein, The first key is determined according to at least one of the following parameters: a first numerical value used for identifying a key derivation function; a user identifier of the first user; a length of the user identifier; the first personal password; a length of the first personal password; an identifier of the first network element; a length of the identifier of the first network element. The method of any one of claims 1 to 4, wherein, The method further comprises: receiving third information sent by a third network element, wherein the third information is used for providing a second key to the first network element; associating the second key with the first identification information. The method of claim 5, wherein, The third information comprises at least one of the following: the second key; second identification information associated with the first identification information. A user authentication method, performed by a second network element, wherein The method comprises: sending fourth information to a terminal, wherein the fourth information is used for the terminal to perform user authentication for a first user of the terminal; wherein the user authentication is implemented based on a first key, and the first key is obtained based on at least a first personal password. The method of claim 7, wherein, The first personal password is a personal password assigned to the first user. The method according to claim 7 or 8, wherein The fourth information comprises at least one of the following: an identifier of the second network element; a first random number generated by the second network element; a first message authentication code. The method of claim 9, wherein, The first message authentication code is associated with the identifier of the second network element and the first random number, and the first message authentication code is calculated using the first key. The method of any one of claims 7 to 10, wherein, The method further comprises: receiving fifth information sent by the terminal, wherein the fifth information is used for a second network element to perform user authentication for the first user; performing the user authentication according to the fifth information. The method of claim 11, wherein, The fifth information comprises at least one of the following: a user identifier of the first user; a first random number obtained by the terminal from the fourth information; a second random number generated by the terminal; a second message authentication code. The method of claim 12, wherein, The second message authentication code is associated with the user identifier of the first user, an identifier of the second network element, the first random number and the second random number, and the second message authentication code is calculated using the first key. The performing of the user authentication according to the fifth information comprises: The method according to claim 12 or 13, wherein ​ calculating, based on the first random number and the identifier of the second network element stored locally by the second network element and the second random number and the user identifier of the first user in the fifth information, and using the first key, a third message authentication code; comparing the second message authentication code with the third message authentication code; in a case where the second message authentication code is consistent with the third message authentication code, determining that the terminal passes the user authentication. The method of any one of claims 7 to 14, wherein, The method further comprises: sending first information to a first network element, wherein the first information is used by the first network element to determine the terminal and the first user; receiving second information sent by the first network element, wherein the second information is used to implement the user authentication, and the second information at least comprises the first key. The method of claim 15, wherein, The first key is determined according to at least one of the following parameters: a first numerical value, used to identify a key derivation function; a user identifier of the first user; a length of the user identifier; the first personal password; a length of the first personal password; an identifier of the first network element; a length of the identifier of the first network element. A user authentication method, performed by a fourth network element, wherein The method comprises: sending sixth information to a third network element, wherein the sixth information is used to trigger the third network element to generate a second key; wherein the second key is used to determine a first key together with a first identification code, and the first key is used to implement user authentication for a first user of a terminal. The method of claim 17, wherein, The first personal password is a personal password assigned to the first user. The method according to claim 17 or 18, wherein The sixth information comprises: second identification information, used to identify a terminal corresponding to the first user. The method of any one of claims 17 to 19, wherein, The method further comprises: receiving seventh information sent by a fifth network element, wherein the seventh information is used by the fourth network element to determine that the terminal supports the second key; determining, according to the seventh information, to trigger generation of the second key. The method of claim 20, wherein, The seventh information comprises at least one of the following: a user authentication characteristic related to the second key; a user authentication policy related to the second key; second identification information, used to identify the terminal. The method of any one of claims 17-21, wherein The method further comprises: receiving eighth information sent by the third network element, wherein the eighth information is used by the fourth network element to determine that the second key is successfully obtained. The method of any one of claims 17 to 22, wherein, The method further comprises: sending ninth information to a terminal, wherein the ninth information is used by the terminal to determine the user authentication based on the first key. A user authentication method, performed by a terminal, wherein, The method comprises: receiving fourth information sent by a second network element, wherein the fourth information is used by the terminal to perform user authentication for a first user of the terminal; performing the user authentication according to the fourth information; wherein the user authentication is implemented based on a first key, and the first key is obtained based on at least a first personal password. The method of claim 24, wherein, The first personal password is a personal password assigned to the first user. The method of claim 24 or 25, wherein, The fourth information comprises at least one of the following: an identifier of the second network element; a first random number generated by the second network element; a first message authentication code. The method of claim 26, wherein, The first message authentication code is associated with an identifier of the second network element and the first random number, and is calculated by using the first key. The method of claim 26 or 27, wherein, The performing of the user authentication according to the fourth information comprises: calculating a fourth message authentication code based on the identifier of the second network element and the first random number in the fourth information and by using the first key; comparing the first message authentication code with the fourth message authentication code; and determining that the network side passes the authentication of the first user in a case where the first message authentication code is consistent with the fourth message authentication code. The method of any one of claims 24 to 28, wherein, The method further comprises: sending fifth information to the second network element, wherein the fifth information is used for the second network element to perform the user authentication for the first user. The method of claim 29, wherein, The fifth information comprises at least one of: a user identifier of the first user; a first random number, which is obtained from the fourth information; a second random number, which is generated by the terminal; a second message authentication code. The method of claim 30, wherein, The second message authentication code is associated with the user identifier of the first user, the identifier of the second network element, the first random number and the second random number, and is calculated by using the first key. The method of any one of claims 24-31, wherein The method further comprises: receiving ninth information, wherein the ninth information is used for the terminal to determine the user authentication based on the first key. The method of any one of claims 24-32, wherein The method further comprises: determining a second key associated with the first user; determining the first key according to the second key and the first personal password. The method of claim 33, wherein, The method further comprises: associating the second key with first identification information, wherein the first identification information is used for identifying the terminal. A user authentication apparatus is arranged in a first network element, wherein, The apparatus comprises: a transceiver module, configured to: receive first information sent by a second network element, wherein the first information is used for the first network element to determine a terminal and a first user of the terminal; send second information to the second network element, wherein the second information is used for implementing the user authentication for the first user, and the second information at least comprises a first key; a processing module, configured to: determine the first key based on the first information and a first personal password. A user authentication apparatus is arranged in a second network element, wherein The apparatus comprises: a transceiver module, configured to send fourth information to a terminal, wherein the fourth information is used for the terminal to perform the user authentication for a first user of the terminal; wherein the user authentication is implemented based on a first key, and the first key is obtained based on at least a first personal password. A user authentication apparatus is arranged in a fourth network element, wherein, The apparatus comprises: a transceiver module, configured to send sixth information to a third network element, wherein the sixth information is used for triggering the third network element to generate a second key; wherein the second key is used for jointly determining a first key with a first identification code, and the first key is used for implementing the user authentication for a first user of a terminal. A user authentication apparatus is provided in a terminal, wherein The apparatus comprises: a transceiver module, configured to receive fourth information sent by a second network element, wherein the fourth information is used for the terminal to perform the user authentication for a first user of the terminal; a processing module, configured to perform the user authentication according to the fourth information. The user authentication is implemented based on a first key, which is derived based on at least a first password. A communication device comprising: one or more processors; memory storing instructions; wherein the instructions, when executed by the communication device, cause the communication device to implement at least one of: the method of any of claims 1-6; the method of any of claims 7-16; the method of any of claims 17-23; the method of any of claims 24-34. A communication system comprising at least one of: a first network element, a second network element, a fourth network element, and a terminal; wherein the first network element is configured to implement the method of any of claims 1-6; wherein the second network element is configured to implement the method of any of claims 7-16; wherein the fourth network element is configured to implement the method of any of claims 17-23; wherein the terminal is configured to implement the method of any of claims 24-34. A storage medium storing instructions, wherein, when the instructions are run on a communication device, cause the communication device to implement at least one of: the method of any of claims 1-6; the method of any of claims 7-16; the method of any of claims 17-23; the method of any of claims 24-34. A computer program product comprising instructions, wherein, when the instructions are run on a communication device, cause the communication device to implement at least one of: the method of any of claims 1-6; the method of any of claims 7-16; the method of any of claims 17-23; the method of any of claims 24-34.

Citation Information

Patent Citations

  • User authentication method and device and electronic device

    CN109977643A

  • Network verification method, device and system

    CN111669276A

  • User identity authentication method, device and equipment and storage medium

    CN112637131A

  • Identity authentication method, system and device, electronic equipment and readable medium

    CN114124513A

  • Secure communication method and apparatus

    US20230188997A1