Mobile network registration method and apparatus

By generating and using keys for authentication of communication devices without a user identification module (VIM), the problem of these devices being unable to independently register to mobile networks is solved, enabling independent registration and secure authentication while protecting user privacy.

WO2026007965A1PCT designated stage Publication Date: 2026-01-08HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/106486
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-05
Filing Date
2025-07-01
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Devices without a user identification module cannot register to a mobile network independently, and when relying on a device with a user identification module, the device cannot register when it is powered off or has no network service.

Method used

The first network element generates and sends a first key to the communication device. The communication device uses this key for authentication during the registration process and interacts with the mobile network through the access gateway to exchange authentication information, thereby enabling independent registration of devices without a user identification module.

Benefits of technology

It enables independent registration of devices without user identification modules to the mobile network, avoiding dependence on terminal devices, ensuring the security and uniqueness of communication devices, and protecting user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025106486_08012026_PF_FP_ABST
    Figure CN2025106486_08012026_PF_FP_ABST
Patent Text Reader

Abstract

A mobile network registration method and apparatus, which relate to the technical field of communications. The method comprises: receiving a first request, which is used by a terminal device to request the issuance of a first key for a communication apparatus, wherein the communication apparatus does not have a subscriber identity module, and the terminal device has a subscriber identity module; in response to the first request, generating the first key for the communication apparatus; sending the first key to the communication apparatus; during a process of the communication apparatus requesting registration with a mobile network, receiving a request for authenticating the communication apparatus, wherein the request comprises a first identifier, which is used for uniquely identifying the communication apparatus in the mobile network, and a connection between the communication apparatus and the mobile network does not pass through the terminal device; generating first information on the basis of the first key corresponding to the communication apparatus that is identified by the first identifier; and receiving second information from the communication apparatus, and on the basis of whether the first information and the second information are consistent, determining whether the communication apparatus passes authentication, wherein a result of authenticating the communication apparatus is used for accepting or rejecting a request for registering the communication apparatus with the mobile network. The method enables a communication apparatus without a subscriber identity module to register with a mobile network.
Need to check novelty before this filing date? Find Prior Art

Description

Mobile network registration method and device

[0001] The present application claims priority from a Chinese patent application No. 202410918609.0 filed on July 5, 2024, and entitled "Mobile network registration method and device", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication technology, and in particular to a mobile network registration method and device. BACKGROUND

[0003] When a user subscribes to a network service, an operator needs to authenticate the real identity of the user, and after authentication, allocates a user number and a corresponding key to the user. The user number and the key are carried on a physical entity such as a subscriber identity module (SIM) card, and the user installs the SIM card on a terminal device, which can use the user number and the corresponding key to pass the operator's authentication and then register to the mobile network. For devices without a subscriber identity module, such as devices without a SIM card, the device also has the need to register to the mobile network, but cannot register to the mobile network independently. Currently, devices without a subscriber identity module can access the mobile network through the shared network of devices with a subscriber identity module (such as a mobile phone with a SIM card). For example, devices without a subscriber identity module can access the mobile network through the shared hotspot of devices with a subscriber identity module. However, this access method depends on devices with a subscriber identity module, and when the devices with a subscriber identity module are powered off or have no network service, the devices without a subscriber identity module cannot register to the mobile network through the devices with a subscriber identity module. SUMMARY

[0004] Embodiments of the present application provide a mobile network registration method and device.

[0005] In a first aspect, a method is provided, which can be performed by a first network element. The method comprises the following steps: receiving a first request, the first request being used by a terminal device to request a first key to be issued to a communication apparatus, wherein the communication apparatus does not have a subscriber identity module, and the terminal device has a subscriber identity module; in response to the first request, generating the first key for the communication apparatus; sending the first key to the communication apparatus; during a process in which the communication apparatus requests to register to a mobile network, receiving a request for authenticating the communication apparatus, the request including a first identity, the first identity being used to uniquely identify the communication apparatus in the mobile network, and the connection between the communication apparatus and the mobile network not passing through the terminal device; generating first information according to the first key corresponding to the communication apparatus identified by the first identity; receiving second information from the communication apparatus, and determining whether the communication apparatus passes the authentication according to whether the first information and the second information are consistent, and the authentication result of the communication apparatus being used to accept or reject the request of the communication apparatus to register to the mobile network.

[0006] For example, the connection between the communication apparatus and the mobile network not passing through the terminal device means that the communication apparatus does not register to the mobile network through a network shared by the terminal device. For example, the communication apparatus does not register to the mobile network through a hotspot opened by the terminal device, or the communication apparatus does not register to the mobile network through a network shared by the terminal device through a universal serial bus (USB), or the communication apparatus does not register to the mobile network through a network shared by the terminal device through other manners. For example, the communication apparatus can access the Internet, for example, the communication apparatus can access the Internet through wireless fidelity (WiFi). Or, the communication apparatus can access the Internet through fixed access (for example, through optical fiber or copper wire (for example, twisted pair or coaxial cable or network cable)). In addition, the connection between the communication apparatus and the mobile network not passing through the terminal device can also mean that data transmitted between the communication apparatus and the mobile network does not pass through the terminal device. For example, the data transmitted between the communication apparatus and the mobile network does not pass through the terminal device means that the data transmitted between the communication apparatus and the mobile network is not transparently transmitted by the terminal device, or the data transmitted between the communication apparatus and the mobile network is not processed by the terminal device.

[0007] For example, after the communication apparatus accesses the Internet, the communication apparatus can interact with the mobile network through an access gateway to exchange authentication related information, or the communication apparatus can receive the first key sent by the mobile network through the access gateway. For example, the manufacturer of the communication apparatus has signed a contract with an operator, and the communication apparatus can interact with the mobile network of the operator within a limited range through the access gateway (for example, the communication apparatus exchanges authentication related information with the mobile network, or the communication apparatus receives the first key from the mobile network).

[0008] It should be noted that the authentication of the communication device by the mobile network can also be referred to as the authentication of the communication device by the mobile network.

[0009] Through the method, the first network element generates the first key as a key for authentication for the communication device, and sends the first key to the communication device. The communication device can use the first key to complete the authentication of the communication device in the process of requesting registration to the mobile network. This embodiment realizes that the communication device can be independently registered to the mobile network, and further, the terminal device does not need to perform packet transmission with the mobile network.

[0010] In a possible implementation, the method further includes: generating the first identifier for the communication device; and sending the first identifier to the communication device. The first identifier can be a string capable of uniquely identifying the communication device in the mobile network. For example, the first identifier can have multiple fields, each field having a plurality of bytes, and each field representing a different meaning. For example, the fields can be used to represent the country, manufacturer, or operator to which the communication device belongs, respectively.

[0011] The first identifier can be used by the mobile network to manage the communication device. For example, the mobile network can uniquely determine the communication device corresponding to the first identifier through the first identifier. The mobile network can also obtain information of the communication device through the first identifier. For example, the mobile network can query the first key corresponding to the communication device according to the first identifier. For example, the mobile network can also obtain information such as the country, manufacturer, or operator to which the communication device belongs through the first identifier. The mobile network can also authenticate the communication device based on the identifier carried in the registration request. For example, the mobile network verifies whether the communication device is legal by verifying whether the value of each field of the identifier is legal. If the value of a field in the identifier carried in the registration request is illegal, the communication device is considered illegal, and the mobile network can reject the registration request. This manner can preliminarily filter illegal registration requests, and save network resources.

[0012] In a possible implementation, before the first identifier or the first key is generated, the first network element first determines whether to generate the first identifier or the first key.

[0013] Optionally, if the first signature from the terminal device is received before the first identifier is generated, the first network element verifies the first signature from the terminal device according to the shared key of the terminal device and the operator, and generates the first identifier or the first key for the communication device after the first signature verification is passed.

[0014] Optionally, the first identity or the first key is generated for the communication apparatus when the communication apparatus is not associated with any terminal device. For example, the first network element can query whether an association relationship between the identity of the communication apparatus and a certain terminal identity already exists according to the identity of the communication apparatus. If the query result indicates that the identity of the communication apparatus is already associated with a certain terminal identity, that is, the communication apparatus has already been associated with a terminal device (which can be any terminal device), the first network element refuses to generate the first identity or the first key.

[0015] Verifying that the communication apparatus is not associated with other terminal devices before generating the first key or the first identity can ensure that the communication apparatus is associated with only one terminal device. That is, the communication apparatus provides services for only one user, avoiding a communication apparatus serving multiple users, thereby avoiding user privacy leakage.

[0016] In a possible implementation, the first request is used to request the first identity for the communication apparatus. Optionally, the first request can also be used to request the first key for the communication apparatus.

[0017] In a possible implementation, the first key is sent to the communication apparatus in a secure transmission manner.

[0018] For example, the first network element obtains the second key; the first network element sends the first key and the second key to the access gateway, and the second key is used by the access gateway to encrypt the first key sent by the communication apparatus, or the first network element itself encrypts the first key sent to the communication apparatus using the second key.

[0019] By this method, the first key can be securely sent to the communication apparatus, avoiding the first key being acquired by an illegal user in the process in which the first network element sends the first key to the communication apparatus. Thus, the illegal user is avoided from registering to the mobile network using the first key.

[0020] For example, the first network element can obtain the second key in the following manners: the first network element generates the second key according to a preconfigured key for the communication apparatus; or the first network element generates the second key according to a shared key between the terminal device and the operator.

[0021] For example, the first network element receives the second key from the terminal device. For example, the second key is received by the first network element from the terminal device, and the first network element authenticates the second key. For example, the first network element verifies a first signature from the terminal device according to a shared key between the terminal device and the operator, and determines that the authentication of the second key is passed after the first signature verification is passed.

[0022] For example, the first network element authenticates the communication apparatus according to the second key.

[0023] In a possible implementation, the method further includes: receiving a second signature from the communication device, generating a third signature according to the second key, and determining whether the communication device passes the authentication according to whether the second signature is consistent with the third signature. For example, if the second signature is consistent with the third signature, it is determined that the communication device passes the authentication, otherwise, it is determined that the communication device fails the authentication.

[0024] In a possible implementation, the first key is sent to the communication device after the communication device passes the authentication.

[0025] For example, the first network element can authenticate the communication device by: querying an authentication server corresponding to the communication device, and establishing a connection between the communication device and the authentication server, the connection being used for the authentication server and the communication device to perform authentication. For example, the communication device and the authentication server interact authentication information through the connection.

[0026] For example, the first network element can also authenticate the communication device by: obtaining a fourth signature, generating a fifth signature according to a shared key between the terminal device and the operator, and determining whether the communication device passes the authentication according to whether the fourth signature is consistent with the fifth signature. For example, when the fourth signature is consistent with the fifth signature, the communication device passes the authentication.

[0027] Through the method, the first network element can send the first key to the legitimate communication device. This avoids an illegal user from obtaining the first key and then registering to the mobile network by using the first key.

[0028] In a possible implementation, the method further includes: storing an association between the identifier of the communication device and the terminal identifier.

[0029] Through the method, the mobile network stores the association between the identifier of the communication device and the terminal identifier. The first network element can determine whether the communication device has been associated with other terminal devices according to the association before generating the first identifier or the first key. The method can ensure that the communication device is associated with a unique terminal device, and avoid a communication device being associated with multiple terminal devices, thereby causing user privacy leakage.

[0030] In a possible implementation, the method further includes: generating a third key according to the first key, or generating a fast Internet Protocol security key as the third key, and sending the third key to an access gateway, the third key being used by the access gateway to encrypt or decrypt a packet transmitted between the communication device and the mobile network.

[0031] In a possible implementation, the method further includes: generating a fourth key according to the first key, and sending the fourth key to the access gateway, the fourth key being used to verify integrity of a packet transmitted between the communication device and the mobile network.

[0032] By the method, the messages transmitted between the communication device and the mobile network can be encrypted and integrity protected. The method can avoid the messages transmitted between the communication device and the mobile network being intercepted, and can avoid the messages transmitted between the communication device and the mobile network being tampered.

[0033] In a possible implementation, the method further includes: receiving a third request in a process in which the communication device requests to register to the IP multimedia subsystem network, the third request being used to request to authenticate the communication device, and the third request including the first identity; and authenticating the communication device according to the first key corresponding to the first identity.

[0034] By the method, the communication device can register to the IMS network, and it is realized that the communication device running independently of the terminal device can register to the IMS network to help a user to receive or make a call.

[0035] In a possible implementation, the communication device does not have a universal subscriber identity module (USIM), or an embedded subscriber identification module (eSIM), or an integrated subscriber identification module (iSIM).

[0036] In a possible implementation, the method further includes: generating the first information according to the first key, authentication information and the first function, the authentication information being a random number or a time stamp corresponding to a moment of generating the first information; and the second information being generated according to the first key, the authentication information and the first function. Exemplarily, the first information can be an authentication expected response (XRES), and the second information can be an authentication response (RES).

[0037] In a second aspect, a method is provided, which can be performed by a first network element, and the method comprises the following steps: receiving, from a terminal device, a first key generated by a communication apparatus, the communication apparatus being free of a subscriber identity module, and the terminal device having the subscriber identity module; receiving, in a process in which the communication apparatus requests to register to a mobile network, a request for authenticating the communication apparatus, the request including a first identity, the first identity being used to uniquely identify the communication apparatus in the mobile network, and a connection between the communication apparatus and the mobile network not passing through the terminal device; generating first information according to the first key corresponding to the communication apparatus identified by the first identity; receiving second information from the communication apparatus, and determining whether the communication apparatus passes the authentication according to whether the first information and the second information are consistent, and a result of the authentication of the communication apparatus being used to accept or reject the request of the communication apparatus to register to the mobile network.

[0038] By the method, the first network element receives the first key generated by the communication apparatus from the terminal device. The communication apparatus and the mobile network can use the first key to authenticate the communication apparatus. This embodiment enables the communication apparatus to register to the mobile network without passing through a device having a subscriber identity module, and further enables the communication apparatus to perform packet transmission with the mobile network.

[0039] In a possible implementation, the method further comprises: generating the first identity for the communication apparatus; and sending the first identity to the communication apparatus.

[0040] Optionally, the first identity is generated for the communication apparatus when the communication apparatus is not associated with any terminal device.

[0041] In a possible implementation, the method further comprises: authenticating the first key.

[0042] For example, the first key can be authenticated by verifying a signature of the first key according to a shared key between the terminal device and an operator, and determining that the first key passes the authentication when the signature of the first key is verified.

[0043] By the method, the first key generated by the communication apparatus passes the authentication of the mobile network, and the communication apparatus can use the key to register to the mobile network. The communication apparatus can more conveniently obtain the first key by the method.

[0044] In a possible implementation, the method further comprises: generating a third key according to the first key, or generating a fast Internet Protocol (IP) key as the third key; and sending the third key to an access gateway, the third key being used by the access gateway to encrypt or decrypt packets transmitted between the communication apparatus and the mobile network, and generating a fourth key according to the first key, the fourth key being used to perform integrity verification on the packets transmitted between the communication apparatus and the mobile network.

[0045] In a possible implementation, the method further includes: receiving a third request in a process in which the communication device requests to register to the IP multimedia subsystem network, the third request being used to request to authenticate the communication device, and the third request including the first identifier; and authenticating the communication device according to the first key corresponding to the first identifier.

[0046] It can be understood that features and advantages similar to those of the first aspect can be referred to the description of the first aspect, and will not be described here.

[0047] In a third aspect, a method is provided, which can be executed by a communication device, and includes the following steps: obtaining a first key; in a process in which the communication device requests to register to a mobile network, sending a request for registering to the mobile network, the request including a first identifier, the first identifier being used to uniquely identify the communication device in the mobile network, and the connection of the communication device to the mobile network not passing through a terminal device, wherein the communication device does not have a subscriber identity module, and the terminal device has the subscriber identity module; generating first information according to the first key, and sending the first information to the mobile network, the first information being used to authenticate the communication device.

[0048] By the method, the communication device registers to the mobile network using the first key generated by the mobile network for the communication device, or the first key authenticated by the mobile network. It is achieved that the communication device (a device without a subscriber identity module) can register to the mobile network without passing through the terminal device (a device with a subscriber identity module).

[0049] In a possible implementation, the method further includes: receiving the first identifier.

[0050] The communication device can use the first identifier to request to register to the mobile network. The first identifier can also be used by the mobile network to manage the communication device. For example, the mobile network can uniquely determine the communication device corresponding to the first identifier through the first identifier.

[0051] In a possible implementation, obtaining the first key includes: receiving the encrypted first key from the mobile network.

[0052] For example, the communication device receives the encrypted first key from the mobile network, and decrypts the encrypted first key using the second key or a private key corresponding to the second key.

[0053] For example, the communication device obtains the second key or the private key corresponding to the second key; and decrypts the encrypted first key received from the mobile network using the second key, or decrypts the encrypted first key received from the mobile network using the private key corresponding to the second key.

[0054] For example, the communication apparatus can obtain the second key or the private key corresponding to the second key by generating the second key according to a preconfigured key of the communication apparatus, or receiving the second key from the terminal device, or obtaining the private key corresponding to the preconfigured second key of the communication apparatus.

[0055] In a possible implementation, the obtaining the first key comprises generating the first key, and the method further comprises sending the first key to the mobile network.

[0056] For example, the communication apparatus generates the first key and the corresponding private key. For example, the communication apparatus generates a public key and the corresponding private key, wherein the public key is used as the first key. The first key can be used to authenticate the communication apparatus in a process of requesting registration to the mobile network, and the private key corresponding to the first key is held by the communication apparatus. After generating the first key, the communication apparatus sends the first key to the mobile network.

[0057] In a possible implementation, the method further comprises verifying the private key corresponding to the first key.

[0058] For example, the terminal device sends first authentication information to the communication apparatus, the communication apparatus signs the first authentication information using the private key corresponding to the first key, and the communication apparatus sends the signature of the first authentication information to the terminal device. The terminal device verifies the signature using the first key, and if the signature is verified, it can be determined that the communication apparatus holds the private key corresponding to the first key legally.

[0059] By the method, the communication apparatus can generate the first key and then send the first key to the mobile network. The mobile network and the communication apparatus use the first key to authenticate the communication apparatus. By the method, the communication apparatus can obtain the first key more conveniently.

[0060] In a possible implementation, the method further comprises generating a third key according to the first key, or receiving a fast Internet Protocol security key as the third key, when the authentication of the communication apparatus in the process of requesting registration to the mobile network is passed; the third key is used to encrypt or decrypt a packet; generating a fourth key according to the first key, the fourth key is used to verify the integrity of the packet.

[0061] By the method, the packet transmitted between the communication apparatus and the mobile network can be encrypted and integrity protected. The method can avoid the packet transmitted between the communication apparatus and the mobile network being intercepted, and can avoid the packet transmitted between the communication apparatus and the mobile network being tampered.

[0062] In a possible implementation, the method further comprises sending a second request, the second request is used to request registration to an IP multimedia subsystem network, and the second request comprises the first identifier.

[0063] In a fourth aspect, a method is provided, which can be performed by a terminal device, and the method comprises the following steps: sending a first request, the first request being used to request a first key for a communication device, the first key being used to authenticate the communication device in a process in which the communication device requests to register to a mobile network, a connection of the communication device to the mobile network not passing through the terminal device, wherein the communication device does not have a subscriber identity module, and the terminal device has the subscriber identity module.

[0064] Through the method, the terminal device requests the mobile network to issue the first key for the communication device. The communication device can obtain the first key issued by the mobile network and register to the mobile network using the first key. The method enables the device (the communication device) without the subscriber identity module to register to the mobile network without passing through the terminal device.

[0065] In a possible implementation, the first request is further used to request a first identity for the communication device, the first identity being used to uniquely identify the communication device in the mobile network; and the method further comprises: receiving the first identity.

[0066] The first identity can be used by the communication device to request to register to the mobile network, and the first identity can also be used by the mobile network to manage the communication device. For example, the mobile network can uniquely determine the communication device corresponding to the first identity through the first identity. The mobile network can also obtain information (for example, information about a country, a manufacturer, and an operator to which the communication device belongs) of the communication device through the first identity. The mobile network can also authenticate the communication device based on the identity carried in the registration request. For example, the mobile network verifies whether the value of each field of the identity is legal, and if the value of a certain field of the identity is illegal, the communication device is considered illegal. This way can preliminarily filter out illegal registration requests and save network resources.

[0067] In a possible implementation, the first request comprises an identity of the communication device and a terminal identity of the terminal device.

[0068] In a possible implementation, the first request further comprises a second key, the second key being used to encrypt the first key; and the first request further comprises a first signature of the second key, the first signature being used to verify the second key.

[0069] Through the method, the first key is securely sent to the communication device, avoiding that the first key is obtained by an illegal user in the process in which the first network element sends the first key to the communication device. Thus, the illegal user is avoided from registering to the mobile network using the first key.

[0070] In a fifth aspect, a method is provided, which can be performed by a terminal device, and the method comprises the following steps: sending a first request, the first request comprising a first key, the first request being used to request the authentication of the first key for a communication apparatus, the first key being used to authenticate the communication apparatus in a process in which the communication apparatus requests to register to a mobile network, a connection of the communication apparatus to the mobile network not passing through the terminal device, wherein the communication apparatus does not have a user identification module, and the terminal device has the user identification module.

[0071] For example, the communication apparatus generates the first key and a corresponding private key. For example, the communication apparatus generates a public key and a corresponding private key. The public key is used as the first key, which can be used to authenticate the communication apparatus in a process in which the communication apparatus requests to register to the mobile network, and the private key corresponding to the first key (the public key) is held by the communication apparatus.

[0072] By the method, the communication apparatus generates the first key and sends the first key to the mobile network through the terminal device. The mobile network uses the first key to authenticate the communication apparatus in a process in which the communication apparatus requests to register to the mobile network. The method enables the device without the user identification module (the communication apparatus) to register to the mobile network without passing through the terminal device.

[0073] In a possible implementation, the first request is also used to request a first identity for the communication apparatus, the first identity being used to uniquely identify the communication apparatus in the mobile network; and the method further comprises: receiving the first identity.

[0074] In a possible implementation, the method further comprises: verifying the private key corresponding to the first key.

[0075] For example, the terminal device verifies the private key corresponding to the first key generated by the communication apparatus. For example, the terminal device sends first authentication information to the communication apparatus, the communication apparatus signs the first authentication information using the private key corresponding to the first key, and the communication apparatus sends the signature of the first authentication information to the terminal device. The terminal device verifies the signature using the first key, and if the signature is verified, it can be determined that the communication apparatus holds the private key corresponding to the first key.

[0076] In a sixth aspect, a method is provided, which can be performed by an access gateway, and the method comprises the following steps: receiving a first key; sending the first key to a communication device, the first key being used for authenticating the communication device in a process of requesting registration to a mobile network, the connection of the communication device to the mobile network not passing through a terminal device, wherein the communication device has no subscriber identity module, and the terminal device has a subscriber identity module; receiving a request for registration to the mobile network from the communication device, the request comprising a first identity, the first identity being used for uniquely identifying the communication device in the mobile network; sending a request for authenticating the communication device, the request comprising the first identity; receiving first information from the communication device, the first information being used for authenticating the communication device by the mobile network; and sending the first information to the mobile network.

[0077] By the method, the communication device can receive the first key from the mobile network, and then use the first key to complete the authentication of the communication device by the mobile network. In addition, the communication device and the mobile network can interact authentication-related information through the method, for example, by forwarding the authentication request of the communication device and forwarding the authentication information of the communication device and the mobile network by the access gateway. By the method, the communication device can register to the mobile network without passing through the terminal device.

[0078] In a possible implementation, the sending of the first key to the communication device comprises: sending the first key to the communication device through a secure transmission.

[0079] By the method, the first key is securely sent to the communication device, avoiding the first key being acquired by an illegal user in the process of sending the first key to the communication device by the first network element. Thus, the illegal user is avoided from registering to the mobile network using the first key.

[0080] In a possible implementation, the sending of the first key to the communication device through a secure transmission comprises: receiving a second key; and encrypting the first key using the second key.

[0081] In a possible implementation, the method further comprises: receiving a first authentication request from the communication device, the first authentication request being used for requesting authentication of the communication device, the first authentication request comprising an identity of the communication device and first authentication information, the first authentication information corresponding to a time when the first authentication request is initiated by the communication device, or the first authentication information being a random number; and sending a second authentication request, the second authentication request being used for requesting authentication of the communication device, the second authentication request comprising the identity of the communication device and the first authentication information. Optionally, the first key is carried in the first authentication request.

[0082] In a possible implementation, the first authentication request further includes a first digital signature, the first digital signature is generated according to a shared key and the first authentication information, the first digital signature is used for authenticating the communication apparatus, and the shared key is shared by the terminal device and the operator; and the second authentication request further includes the first digital signature.

[0083] In a possible implementation, the method further includes: receiving a third response, the third response being used for indicating that the communication apparatus passes authentication, the third response including a third key, the third key being used for encrypting messages transmitted between the communication apparatus and the mobile network, the third key being generated according to the first key, or the third key being a fast Internet key exchange (IKE) key; and the third response including a fourth key, the fourth key being used for integrity verification of messages transmitted between the communication apparatus and the mobile network, the fourth key being generated according to the first key.

[0084] In a seventh aspect, a network element is provided, which includes units or modules for performing the method according to any one of the first aspect or the second aspect. The network element can provide the function of key generation, or key authentication, or authentication. Specifically, the network element can include a processing unit and a transceiver unit.

[0085] For example, corresponding to the first aspect, the transceiver unit receives a first request, the first request being used for a terminal device to request issuance of a first key for a communication apparatus, wherein the communication apparatus does not have a subscriber identity module, and the terminal device has a subscriber identity module; the processing unit generates the first key for the communication apparatus in response to the first request; the transceiver unit sends the first key to the communication apparatus; in a process in which the communication apparatus requests registration to a mobile network, a request for authenticating the communication apparatus is received, the request including a first identifier, the first identifier being used for uniquely identifying the communication apparatus in the mobile network, and connection of the communication apparatus to the mobile network not passing through the terminal device; the processing unit generates first information according to the first key corresponding to the communication apparatus identified by the first identifier; the transceiver unit receives second information from the communication apparatus, and the processing unit determines whether the communication apparatus passes authentication according to whether the first information and the second information are consistent, and an authentication result of the communication apparatus is used for accepting or rejecting a request of the communication apparatus to register to the mobile network.

[0086] For example, corresponding to the second aspect, the transceiver receives, from the terminal device, the first key from the communication apparatus, the communication apparatus does not have the user identification module, and the terminal device has the user identification module; receives a request for authentication of the communication apparatus in a process in which the communication apparatus requests to register to the mobile network, the request including the first identity, the first identity being used to uniquely identify the communication apparatus in the mobile network, and the connection of the communication apparatus to the mobile network not being through the terminal device; the processing unit generates the first information according to the first key corresponding to the communication apparatus identified by the first identity; the transceiver receives the second information from the communication apparatus, and the processing unit determines whether the communication apparatus is authenticated according to whether the first information and the second information are consistent, and the authentication result of the communication apparatus being used to accept or reject the request of the communication apparatus to register to the mobile network.

[0087] The specific implementation of the processing unit and the transceiver in processing each step can refer to the description in the first aspect or the second aspect above, and will not be described here again.

[0088] In an eighth aspect, a communication apparatus is provided, which includes units or modules for performing the method of any one of the third aspects above. The communication apparatus does not have the user identification module, and the communication apparatus does not register to the mobile network through the terminal device. Specifically, the communication apparatus can include a processing unit and a transceiver.

[0089] The processing unit acquires the first key; the transceiver sends a request for registration to the mobile network in a process in which the request for registration to the mobile network is requested, the request including the first identity, the first identity being used to uniquely identify the communication apparatus in the mobile network, and the connection of the communication apparatus to the mobile network not being through the terminal device, wherein the communication apparatus does not have the user identification module, and the terminal device has the user identification module; the processing unit generates the first information according to the first key, and the processing unit sends the first information to the mobile network through the transceiver, the first information being used to authenticate the communication apparatus.

[0090] The specific implementation of the processing unit and the transceiver in processing each step can refer to the description in the third aspect above, and will not be described here again.

[0091] In a ninth aspect, a device is provided, which includes units or modules for performing the method of any one of the fourth aspect or the fifth aspect above. Specifically, the device can include a processing unit and a transceiver.

[0092] For example, corresponding to the fourth aspect, the processing unit sends, through the transceiving unit, a first request for requesting a first key for the communication device, the first key being used for authenticating the communication device in a process of requesting registration to the mobile network, the connection of the communication device to the mobile network not being via the terminal device, wherein the communication device does not have a subscriber identity module, and the terminal device has the subscriber identity module.

[0093] For example, corresponding to the fifth aspect, the processing unit sends, through the transceiving unit, a first request including a first key, the first request being for requesting authentication of the first key for the communication device, the first key being used for authenticating the communication device in a process of requesting registration to the mobile network, the connection of the communication device to the mobile network not being via the terminal device, wherein the communication device does not have a subscriber identity module, and the terminal device has the subscriber identity module.

[0094] The specific implementation of the processing unit and the transceiving unit in processing each step can refer to the description in the fourth aspect or the fifth aspect above, and will not be repeated here.

[0095] In a tenth aspect, a network element is provided, which includes units or modules for performing the method of any one of the sixth aspects above. Specifically, the network element can include a processing unit and a transceiving unit.

[0096] The processing unit receives, through the transceiving unit, a first key; sends the first key to a communication device, the first key being used for authenticating the communication device in a process of requesting registration to the mobile network, the connection of the communication device to the mobile network not being via a terminal device, wherein the communication device does not have a subscriber identity module, and the terminal device has the subscriber identity module; receives a request for requesting registration to the mobile network from the communication device, the request including a first identity, the first identity being used for uniquely identifying the communication device in the mobile network; sends a request for requesting authentication of the communication device, the request including the first identity; receives first information from the communication device, the first information being generated according to the first key, the first information being used for authenticating the communication device by the mobile network; and sends the first information to the mobile network.

[0097] The specific implementation of the processing unit and the transceiving unit in processing each step can refer to the description in the sixth aspect above, and will not be repeated here.

[0098] In an eleventh aspect, a communication system is provided, comprising a device management function entity, a communication device, a terminal device and an access gateway. The device management function entity is configured to implement the method of any one of the first aspect, the device management function entity is configured to implement the method of any one of the second aspect, the terminal device is configured to implement the method of any one of the fourth aspect, the terminal device is configured to implement the method of any one of the fifth aspect, the access gateway is configured to implement the method of any one of the sixth aspect, or the device management function entity is configured to implement the method of any one of the first aspect, the communication device is configured to implement the method of any one of the third aspect, the terminal device is configured to implement the method of any one of the fifth aspect, and the access gateway is configured to implement the method of any one of the sixth aspect.

[0099] In a twelfth aspect, a readable storage medium is provided, wherein a program is stored in the readable storage medium, and when the program is executed by a communication device, the method of any one of the first aspect to the sixth aspect is implemented.

[0100] In a thirteenth aspect, a chip system is provided, comprising a memory configured to store a computer program, and a processor. When the processor invokes and runs the computer program from the memory, the communication device installed with the chip system is caused to execute the method of any one of the first aspect to the sixth aspect.

[0101] In a fourteenth aspect, a computer program product is provided, comprising instructions, and when the instructions are executed on a processor, the processor is caused to execute the method of any one of the first aspect to the sixth aspect. BRIEF DESCRIPTION OF DRAWINGS

[0102] FIG. 1 is a schematic diagram of an architecture of a communication system to which embodiments of the present application are applied;

[0103] FIG. 2(a) is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application;

[0104] FIG. 2(b) is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application;

[0105] FIG. 2(c) is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application;

[0106] FIG. 3 is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application;

[0107] FIG. 4 is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application;

[0108] FIG. 5 is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application;

[0109] Figure 6 is a signaling interaction diagram of a mobile network registration method according to an embodiment of the present application;

[0110] Figure 7 is a signaling interaction diagram of a mobile network registration method according to an embodiment of the present application;

[0111] Figure 8 is a possible exemplary block diagram of an apparatus according to an embodiment of the present application;

[0112] Figure 9 is a possible structural schematic diagram of an apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0113] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings. The specific operation methods in the method embodiments can also be applied to the apparatus embodiments or system embodiments. In the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise specified.

[0114] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be mutually referenced, unless otherwise specified and logically conflicted, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0115] It can be understood that the various numbers involved in the present application are only distinguished for the convenience of description, and are not used to limit the scope of the present application. The size of the serial number of the above processes does not mean the execution order, and the execution order of the processes should be determined according to its function and inherent logic.

[0116] The terms "first", "second", "third", "fourth" and other various terms labels in the specification and claims of the present application and the above-described drawings (if any) are used to distinguish similar objects, and do not necessarily mean a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0117] In the present application, “at least one” means one or more, and “multiple” means two or more. “And / or” describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. In the textual description of the present application, the character “ / ” generally represents that the front and rear associated objects are in an “or” relationship. “Including at least one of A, B and C” can represent: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0118] The technical solutions provided in the present application can be applied to various communication systems, such as a 5th generation (5G) communication system (or referred to as a new radio (NR) system), a 4th generation (4G) communication system (or referred to as a long term evolution (LTE) system), an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD) system, etc. The technical solutions provided in the present application can also be applied to future communication systems.

[0119] In order to enable a communication device without a user identification module to be registered to a mobile network independently of a device with a user identification module, the present application proposes a mobile network registration method, which can be applied to the communication system 100 introduced in FIG. 1.

[0120] The communication system shown in FIG. 1 includes the following network elements: a terminal device 101, an access network (for example, Access Network, AN) device 102, a session management function (SMF) network element 103, a subscription database 105, an access and mobility management function (AMF) network element 106, an access gateway 107, a Non-SIM device 108, a subscription server 109, an IP multimedia subsystem (IMS) network 110, a user plane function (UPF) network element 111, an authentication, authorization and accounting (AAA) server 112.

[0121] The above devices or network elements will be introduced respectively as follows.

[0122] Terminal device 101: The terminal device can be any device capable of accessing a network, and can also be referred to as a user equipment (UE), a terminal device, an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile station (MS), a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device, etc. The UE can be a device that provides voice / data connectivity to a user, such as a handheld device with wireless connectivity, a vehicle-mounted device, etc. Currently, some examples of the terminal can be: a mobile phone, a tablet computer, a computer with wireless transceiver function (such as a notebook computer, a palm computer, etc.), a mobile internet device (MID), a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical treatment, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a 4G / 5G network, or a terminal device in a future evolved public land mobile network (PLMN), etc. The embodiments of the present application do not limit the specific technology, device form, and name of the terminal device.It should be noted that the terminal device in the present application has a user identification module, and therefore the terminal device can be registered to a mobile network according to a SIM card or a universal subscriber identity module (USIM) card or a key in an embedded subscriber identification module (eSIM) through an existing process.

[0123] The access network device 102 may, for example, be a radio access network (RAN). The access network device is used to be responsible for the wireless side access of the terminal device, and possible deployment forms include a separation scenario of a centralized unit (CU) and a distributed unit (DU) and a single station scenario. In the separation scenario, the CU can support radio resource control (RRC), packet data convergence protocol (PDCP), service data adaptation protocol (SDAP), and other protocols; the DU can support a radio link control layer (RLC), a media access control layer (MAC), and a physical layer protocol. In the single station scenario, a single station can include a new radio node (gNB), an evolved node B (eNB), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station, a baseband unit (BBU), and the like.

[0124] The session management function network element 103 is mainly used for session management in a mobile network, such as session establishment, modification, and release. For example, the functions of the session management function network element include allocating an internet protocol (IP) address for a terminal device and selecting a user plane function network element that provides message forwarding functions. In a 5G communication system, the session management function network element can be a session management function (SMF).

[0125] Subscription database 105: stores and manages subscription data of users. In the 5G communication system, the user data management network element can be a unified data management (UDM) network element.

[0126] Access and mobility management function network element 106: mainly used for registration, mobility management, tracking area update process of terminal devices in the mobile network, and the access and mobility management function network element terminates non access stratum (NAS) messages, completes registration management, connection management and reachability management, allocates a tracking area list (TA list) and mobility management, and transparently routes session management (SM) messages to the session management function network element. In the 5G communication system, the access and mobility management function network element can be an access and mobility management function (AMF).

[0127] Non-SIM device 108: a device without a subscriber identity module (or, a user identity module), for example, a Non-SIM device is a device without a SIM card, or a USIM card, or an eSIM card, or an iSIM. For example, the device can be an artificial intelligence (AI) program running instance running on the Internet or a public cloud, or a virtual digital terminal such as a cloud phone running on a public cloud and installed with an AI application. For example, the device can be a communication assistant, which can help users handle various matters in work or life. The device can also be a hardware device without a SIM card, a USIM card, an eSIM card or an iSIM, such as a camera, a printer in an office, etc. The Non-SIM device in the form of hardware (for example, a camera or a printer) and the Non-SIM device in the form of a virtual digital terminal (for example, a communication assistant) are collectively referred to as a Non-SIM device, which will be referred to as a communication device hereinafter. The communication device is used by a user, for example, the user uses a communication assistant to handle matters, or the user uses a camera or a printer and the like to complete a specific application. The user can interact with the communication device through a terminal device. For example, the user can control the communication device through an application installed on the terminal device, for example, set the communication device through the application, or obtain information of the communication device. The Non-SIM device can also be referred to as a non-SIM device.

[0128] IMS network 110: IMS network is a network architecture that provides multimedia services based on Internet Protocol. Through the IMS network, users can use rich telecommunications-level multimedia services such as high-definition voice / video calls, video ring tones, and teleconferencing. The IMS network includes session border controllers (SBCs), serving-call session control functions (S-CSCFs), IMS application servers (IMS-ASs), and the like. The SBC is located at the edge of the IMS network, and the SBC can ensure voice service security and perform conversion between different protocols. The S-CSCF is the service switching center of the IMS network, and is mainly responsible for receiving and processing user registration requests, user management, session control, service switching, service control, SIP message processing, charging, and the like. The IMS-AS is an application layer device in the upper layer of the IMS system, which provides basic services and supplementary services, such as multimedia conferencing, converged communication, short message gateways, standard service desks, and the like.

[0129] User plane function network element 111: mainly responsible for processing user messages such as forwarding and charging. The user plane function (UPF) can also include a protocol data unit (PDU) session anchor (PSA).

[0130] Subscription server 109: The subscription server is a service management website or server established by the operator, and the terminal device can access the subscription server through the mobile network or the Internet. As shown in FIG. 1, there is an interface between the subscription server and the user plane function network element, and the subscription server and the user plane function network element can interact data.

[0131] AAA server 112: The AAA server is used to process user access requests, provide authentication and authorization, and account services. The AAA server is used to manage user access to the network and provide services to users with access rights. As shown in FIG. 1, there is an interface between the AAA server and the user plane function network element, and the AAA server and the user plane function network element can interact data.

[0132] In the prior art, a device without a user identification module (or referred to as a Non-SIM device, referred to as a communication apparatus in the present application) cannot pass the authentication of the mobile network and thus cannot be independently registered to the mobile network because the device cannot obtain the key required for authentication.

[0133] In order to enable the communication device to register to the mobile network independently of the terminal device with the user identification module, the present application defines a new network function for issuing a key (referred to as a first key in the present application) for the communication device, and in the process of the communication device requesting to register to the mobile network, the function network element uses the first key to authenticate the communication device, thereby solving the problem that the communication device cannot register to the mobile network, so that the communication device can register to the mobile network independently of the terminal device. In addition, the network function can also issue an identity (referred to as a first identity in the present application) for the communication device, which can uniquely identify the communication device in the mobile network and can be used by the communication device to request to register to the mobile network, thereby facilitating the unified management of the communication device by the mobile network. The network function can be carried by an independent network element, for example, by a newly defined network element such as the device management network element 104 shown in FIG. 1, or the network function can also be carried by a unified data management network element. In addition, the device management network element 104 can also be referred to as a Non-SIM device management network element, or the device management network element 104 can also be referred to as an Identifier Management (IdM) network element, or have other names. The present application does not limit the network element carrying the network function. For example, the device management network element 104 interacts with the session management function network element 103, or the access and mobility management function network element 106, or the subscription database, etc. network elements in FIG. 1 through a service interface.

[0134] The application also defines another new network function, which can be used to connect or control the communication device (Non-SIM device) to access the mobile network. This network function can be carried by the access gateway 107 shown in Figure 1. Alternatively, this network function can also be carried by the non-3GPP interworking function (non-3GPP interworking function, N3IWF) network element. The communication device can authenticate with the mobile network through the access gateway. After authentication, the communication device registers with the mobile network through the access gateway, or establishes a session connection with the mobile network through the access gateway. For example, before the communication device authenticates with the mobile network, the communication device can interact with the mobile network through the access gateway to exchange authentication-related information, or the communication device can receive a first key sent by the mobile network through the access gateway. For example, the communication device can access the Internet, for example, the communication device can access the Internet through WiFi, or the communication device can access the Internet through fixed access (for example, through optical fiber or copper wire (for example, twisted pair or coaxial cable or network cable)). After the communication device accesses the Internet, it can interact with the mobile network through the access gateway. For example, the manufacturer of the communication device has signed a contract with the operator, and the communication device can interact with the mobile network of the operator through the access gateway before authentication, for example, the communication device exchanges authentication-related information with the mobile network, or the communication device receives a first key from the mobile network. After authentication, the communication device can register with the mobile network through the access gateway, or establish a session connection with the mobile network through the access gateway. For example, there is an interface between the access gateway and the user plane function network element, and the user plane connection can be established between the access gateway and the user plane function network element, and the access gateway interacts with the session management function network element 103, or the access and mobile management function network element 106, or the device management network element 104, or the subscription database, etc. in Figure 1 through the service interface.

[0135] Figures 2(a)-2(c) are signaling interaction diagrams of a mobile network registration method provided by an embodiment of the application.

[0136] Figure 2(a) describes the process of issuing a key by the mobile network for the communication device, and Figures 2(b) and 2(c) describe two ways of registering the communication device to the mobile network using the key issued by the mobile network.

[0137] The signaling interaction diagram shown in FIG. 2(a) involves the interaction between the terminal device, the communication apparatus, the access gateway, the access and mobility management function network element, the first network element, etc. For example, the terminal device, the communication apparatus, the access gateway, the access and mobility management function network element, the first network element, and the AAA server can be the terminal device 101, the SIM-free device 108, the access gateway 107, the access and mobility management function network element 106, the device management network element 104, and the AAA server 112 in FIG. 1, respectively.

[0138] For example, a mobile network registration method includes the following steps:

[0139] S200: The terminal device sends a request 2a to the access and mobility management function network element.

[0140] For example, the request 2a is used to request issuance of a first key for the communication apparatus. The first key can be used by the mobile network to authenticate the communication apparatus, for example, the mobile network uses the first key to authenticate the communication apparatus in the process in which the communication apparatus requests to register to the mobile network. It should be noted that authentication in this application can also be referred to as authentication. For example, in the process in which the communication apparatus subsequently requests to register to the mobile network, the communication apparatus uses the first key to respond to the authentication information from the first network element, and sends the response information to the first network element. If the mobile network can verify the response information from the communication apparatus using the first key, it is considered that the communication apparatus passes the authentication of the mobile network, or it is considered that the communication apparatus legally holds the first key, or it is considered that the communication apparatus is legal, or the mobile network accepts the registration request of the communication apparatus, and the communication apparatus can register to the mobile network.

[0141] The first key can be used for the communication device to register to the mobile network without the terminal device, or in other words, the connection between the communication device and the mobile network is not through the terminal device. For example, the communication device registers to the mobile network through a network shared by the terminal device. Illustratively, the communication device registers to the mobile network through a hotspot network shared by the terminal device, or the communication device registers to the mobile network through a network shared by the terminal device via USB, or the communication device registers to the mobile network through a network shared by the terminal device via other means. In addition, the connection between the communication device and the mobile network not through the terminal device can also mean that the data transmitted between the communication device and the mobile network is not through the terminal device. For example, the data transmitted between the communication device and the mobile network is not through the terminal device means that the data transmitted between the communication device and the mobile network is not transparently transmitted by the terminal device, or the data transmitted between the communication device and the mobile network is not processed by the terminal device. Conversely, the connection between the communication device and the mobile network through the terminal device means that the communication device accesses the mobile network through a network shared by the terminal device. Or, the data transmitted between the communication device and the mobile network is transparently transmitted by the terminal device, or the data transmitted between the communication device and the mobile network is processed by the terminal device.

[0142] Since the terminal device and the communication device have an association relationship, for example, a user can interact with the communication device through the terminal device. Therefore, the request for issuing the first key to the communication device before the communication device registers to the mobile network can be initiated by the terminal device which can interact with the mobile network (for example, with the access and mobility management function network element in the mobile network). For example, the terminal device has registered to the mobile network through prior art before performing step S200 (for example, the terminal device registers to the mobile network means that the terminal device has completed the authentication of the mobile network according to the key in the user identification module, and can access the services provided by the mobile network, such as data services).

[0143] It should be noted that the present application does not limit the device or method for initiating the request for issuing the first key, for example, the device can be the terminal device, or other devices that can register to the mobile network. Or, the request for issuing the first key can also be initiated by other methods. For example, the user requests the mobile network to issue the first key or the first identifier for the communication device through the operator portal website. Illustratively, the user logs in to the operator portal website and requests the mobile network to issue the first key or the first identifier for the communication device. When the user requests the mobile network to issue the first key or the first identifier for the communication device through the operator portal website, the mobile network can obtain the identifier of the communication device through the identifier of the communication device input by the user on the operator portal website.

[0144] For example, the first key can be a sequence of several bytes, e.g., the first key can be a long-term key shared by the user identity module and the authentication center of the mobile network. Alternatively, the first key can be a long-term key shared by the communication device and the mobile network. For example, the long-term key is constant in different secondary authentication processes.

[0145] Optionally, the first key can also be used to generate other keys. For example, the first network element or the communication device can generate a key (e.g., can be referred to as an encryption key) for encrypting or decrypting messages transmitted between the communication device and the access gateway according to the first key. For example, the first network element or the communication device can generate a key (e.g., can be referred to as an integrity protection key) for verifying the integrity of messages transmitted between the communication device and the access gateway according to the first key.

[0146] Optionally, the request 2a can also be used to request the first identity to be issued to the communication device. The first identity is used to uniquely identify the communication device in the mobile network. For example, the first identity can be a string capable of uniquely identifying the communication device. For example, the string can have multiple fields, each field having several bytes, and each field representing a different meaning. For example, the first identity is represented by field #1, field #2, field #3, …, and field #N. Field #1 represents a country code, which represents the country to which the terminal device associated with the communication device belongs, or the country to which the manufacturer of the communication device belongs; field #2 represents the code of the operator issuing the first identity; field #3 represents the manufacturer code of the communication device; and field #N is the number of the communication device, which can uniquely identify the communication device in the mobile network. The above fields and their order in the string are only for example, and the first identity can have other fields, which are not limited by the present application.

[0147] Optionally, since the first identity uniquely identifies the communication device, the mobile network can use the first identity to manage the communication device. For example, the mobile network can obtain information of the communication device through the first identity, such as the country where the communication device belongs, the manufacturer where the communication device belongs, the operator where the communication device belongs, and the like. In the process of the communication device initiating a request to register to the mobile network, the mobile network can also verify the identity carried by the communication device. For example, the identity can be a tampered first identity issued by the mobile network, or the identity can be any identity obtained by the communication device. In the process of the communication device requesting to register to the mobile network, the mobile network can verify whether the identity carried by the communication device satisfies the generation rule of the first identity. For example, the mobile network verifies whether the value of each field of the identity carried by the communication device is legal, where the value is legal means that the value of the field is within the value range of the field. For example, the value of field #1 is {a, b, c}, if the value of field #1 of the identity carried by the communication device is d, then the identity carried by the communication device is considered illegal. If the value of a certain field of the identity carried by the communication device is illegal, then the communication device is considered illegal, or the identity held by the communication device is considered illegal. In this way, the network resource can be saved by preliminarily identifying the illegal registration request.

[0148] In one implementation, the request 2a sent by the terminal device to the access and mobility management function network element can carry the identity of the communication device. The identity of the communication device can be used to determine the authentication server serving the communication device, for example, the authentication server can be the authentication server of the manufacturer of the communication device. For example, the identity of the communication device can be in the format of network access identifier (NAI), where the identity contains the domain name of the manufacturer, and the domain name can be used to query the authentication server of the manufacturer. The authentication server can be the AAA server 112 in FIG. 1.

[0149] Optionally, before the terminal device sends the request 2a containing the identity of the communication device to the access and mobility management function network element, the terminal device first obtains the identity of the communication device. For example, a two-dimensional code of a communication device (for example, a communication assistant) provided by a public cloud service provider is displayed on the remote access interface of the terminal device, and the terminal device can obtain the identity of the communication device by scanning the code. For another example, the identity of the communication device is displayed on the factory plate of the communication device (for example, a camera and a printer), and the user inputs the identity of the factory plate of the communication device on the terminal device, so that the terminal device obtains the identity of the communication device.

[0150] Optionally, the request 2a can also carry the terminal identity. For example, the terminal identity can be a concealed identity of the terminal device, such as a subscription concealed identifier (SUCI), or when the terminal device has registered to the mobile network and obtained a globally unique temporary identity (GUTI), the terminal identity can also be the GUTI.

[0151] For example, the request 2a contains a non-access stratum signaling container (NAS Container), wherein the identity of the communication device and the terminal identity are carried in the NAS container. Optionally, the identity of the communication device and the terminal identity can be carried in the same NAS container, or can be carried in different NAS containers.

[0152] S201: The access and mobility management function network element sends a first request to the first network element.

[0153] For example, the first network element can be the device management network element 104 in FIG. 1.

[0154] For example, the first request is used to request the mobile network to issue a first key for the communication device. Optionally, the first request is also used to request the mobile network to issue a first identity for the communication device.

[0155] Optionally, the first request includes at least one of the identity of the communication device and the terminal identity. For example, the terminal identity can be a subscription permanent identifier (SUPI) or a user number. For example, the user number is a mobile station international integrated services digital network number (MSISDN). For example, the access and mobility management function network element decrypts the SUCI received in S200 to obtain the SUPI, or the access and mobility management function network element obtains the SUPI according to the GUTI received in S200. For another example, the access and mobility management function network element uses the SUPI to obtain the user number from a subscription database.

[0156] S202: The first network element generates the first key.

[0157] Optionally, the first network element can also generate the first identity.

[0158] The first key and the first identity can refer to the foregoing description.

[0159] Optionally, before generating the first identity or the first key, the first network element first judges whether to generate the first identity or the first key. For example, the first network element first judges whether the communication apparatus has associated with other terminal devices. When the communication apparatus has not associated with other terminal devices, the first network element generates the first identity or the first key for the communication apparatus. The verification of the association relationship between the communication apparatus and the terminal device is used to confirm that the communication apparatus is associated with a unique terminal device, that is, the communication apparatus only provides services for a specific user, thereby avoiding that one communication apparatus provides services for multiple users, and thus avoiding leakage of user privacy. For example, the communication apparatus #1 (for example, a communication assistant) is associated with the terminal device #1. The communication assistant only answers or makes a call for the terminal device #1, thereby avoiding that the communication assistant obtains the call record of other terminal devices, or avoiding that the communication assistant leaks the call record of the terminal device #1 to other terminal devices.

[0160] For example, the first network element can query whether the association relationship between the identity of the communication apparatus and a certain terminal identity (for example, a user number / SUPI) exists according to the identity of the communication apparatus received in S201. If the query result indicates that the association relationship between the identity of the communication apparatus and a certain terminal identity already exists, that is, the communication apparatus has already associated with a terminal device (which can be any terminal device), the first network element refuses to generate the first identity or the first key, and indicates in the first response in S204 that the issuance of the first identity or the first key fails. If the first network element does not query the association relationship between the identity of the communication apparatus and any terminal identity, it is determined to generate the first identity or the first key, and the subsequent steps of S202 and the following are continued.

[0161] It should be noted that the association relationship between the identity of the communication apparatus and the terminal identity can be stored in the first network element, or can also be stored in a subscription database, for example, the subscription database 105 in FIG. 1. If the association relationship between the identity of the communication apparatus and the terminal identity is stored in the subscription database, the first network element sends the identity of the communication apparatus to the subscription database to query whether the association relationship between the identity of the communication apparatus and a certain terminal identity already exists. For example, if the subscription database stores the association relationship between the identity of the communication apparatus and the terminal identity, the subscription database returns the association relationship, or returns the indication information (for example, bit 1) that the association relationship is queried. Otherwise, no value is returned, or only the identity of the communication apparatus is returned, or the indication information (for example, bit 0) that the association relationship is not queried is returned.

[0162] Optionally, the first network element can also use the identity of the communication apparatus as the first identity. That is, the first network element can not generate the first identity, and use the identity of the communication apparatus received in S201 as the first identity. Directly using the identity of the communication apparatus to identify the communication apparatus in the mobile network can reduce the number of various identities used to identify the communication apparatus managed by the mobile network.

[0163] Using the first identity issued by the mobile network unification in the mobile network to identify the communication device is beneficial to the management of the communication device. For example, the mobile network can obtain the information of the country, the manufacturer, the operator, etc. of the communication device through the first identity. The mobile network can also verify whether the registration request is issued by a legal communication device based on the identity carried in the registration request. For example, the mobile network verifies whether the value of each field of the identity is legal. If the value of a field in the identity is illegal, it is considered that the registration request is not issued by a legal communication device, or in other words, the communication device is illegal, and the network can reject the registration request. In this way, the network resource can be saved by preliminarily filtering illegal registration requests.

[0164] S203: The first network element stores the first key.

[0165] For example, the first network element can store the first key in the first network element. Alternatively, the first network element can send the first key to the subscription database, and the subscription database stores the first key. The first network element or the subscription database can also store the first identity. In the process of subsequent registration of the communication device to the mobile network, the first network element can obtain the stored first key according to the first identity, and use the first key to authenticate the communication device.

[0166] For example, the first network element can also store the association relationship between the communication device and the terminal device. It should be noted that the terminal device is the terminal device that sends the request 2a in S200. For example, the first network element stores the association relationship between the terminal identity (for example, the user number or SUPI) of the terminal device and the identity of the communication device received in S201. Alternatively, the association relationship between the communication device and the terminal device can also be stored in the subscription database, for example, the first network element sends the identity of the communication device and the terminal identity of the terminal device to the subscription database, and the subscription database stores the association relationship. The association relationship between the communication device and the terminal device is used for the first network element to determine that the communication device (denoted as communication device #1) has been associated with the terminal device (denoted as terminal device #1) in the subsequent first key or first identity issuing process, and cannot be associated with other terminal devices, that is, the first network element cannot issue the first key or the first identity for the communication device. For example, when the terminal device #2 requests the first network element to issue the first key or the first identity for the communication device #1, the first network element can query that the communication device #1 has been associated with the terminal device #1 according to the identity of the communication device #1, and therefore, the first network element rejects the request of the terminal device #2.

[0167] Optionally, the first identity and the first key and the association between the terminal identity and the identity of the communication device can be saved as a four-tuple. For example, the first identity and the first key and the association between the terminal identity and the identity of the communication device can be saved as: {first identity, first key, terminal identity, identity of the communication device}, or in other words, the first identity and the first key and the association between the terminal identity and the identity of the communication device can be saved as a whole.

[0168] Optionally, the first network element or the subscription database can further save the association between the first identity and the identity of the communication device, or save the association between the first key and the identity of the communication device, or save the association between the first key and the first identity and the identity of the communication device. The first identity or the first key can be queried by the identity of the communication device.

[0169] S204: The first network element sends a first response to the access and mobility management function network element.

[0170] For example, the first response can carry the terminal identity, for example, the terminal identity can be a user number or a SUPI. Optionally, the response can further include an indication of whether the first key or the first identity is successfully issued.

[0171] S205: The access and mobility management function network element sends a response to request 2a to the terminal device.

[0172] For example, the access and mobility management function network element determines the terminal device to be received according to the terminal identity received in step S204, and then sends the response to request 2a to the terminal device through the wireless access network. Optionally, the response carries an indication of whether the first key is successfully issued, and the response can further carry an indication of whether the first identity is successfully issued. For example, the response can be a NAS message, wherein the indication of whether the first key is successfully issued and / or the indication of whether the first identity is successfully issued can be carried in a NAS container.

[0173] It should be noted that if the response in S205 indicates that the first key is not issued, the following steps do not need to be performed.

[0174] In addition, the above steps S204 and S205 are optional steps.

[0175] For example, in an implementation manner, only in the case that the first key is successfully issued, steps S204 and S205 are performed, and if the first key is not issued, steps S204 and S205 are not performed. Optionally, if the terminal device does not receive any response after a specified time, it can be considered that the key is not issued, so that the following steps do not need to be performed.

[0176] Through the above steps, the first network element generates the first key for the communication device, and then the first network element sends the first key to the communication device.

[0177] Optionally, before the first network element sends the first key to the communication device, the mobile network authenticates the communication device. For example, in the example of FIG. 2(a), the first network element introduces the AAA server of the manufacturer of the communication device to authenticate the communication device. For example, the manufacturer of the communication device has signed a contract with the operator, and the operator recognizes the authentication result of the AAA server of the manufacturer of the communication device. Illustratively, the first network element establishes a connection between the first network element and the communication device and a connection between the first network element and the AAA server, so as to realize the authentication of the communication device through the connection. For example, the mobile network can authenticate the communication device through the Extensible Authentication Protocol (EAP). As described above, the manufacturer of the communication device has signed a contract with the operator, and therefore, the communication device can interact with the authentication information of the mobile network of the operator through the access gateway before the authentication is passed. For example, the communication device can receive or send the EAP authentication information through the access gateway. Illustratively, the authentication process includes the following steps:

[0178] S206a: The communication device sends an internet key exchange (IKE) security association (SA) initialization message IKE_SA_INIT to the access gateway. Correspondingly, the access gateway sends an IKE_SA_INIT response to the communication device. Optionally, the exchange process is completed to negotiate the IKE SA parameters, for example, including negotiating encryption and authentication algorithms. Illustratively, the communication device sends the security association initialization message to the access gateway after being powered on. Alternatively, the communication device sends the security association initialization message to the access gateway triggered by the user, for example, the user triggers the communication device to send the security association initialization message through the APP controlling the communication device.

[0179] S206b: The communication device sends an IKE authentication request, for example, IKE_AUTH_Req, to the access gateway, wherein the IKE authentication request carries the identity of the communication device, and optionally, the IKE authentication request can also carry the first authentication information, wherein the first authentication information can be a timestamp corresponding to a certain moment before the communication device sends the authentication request, or the first authentication information can also be a random number. For example, the moment can be any moment within a specified time before the communication device sends the authentication request (for example, the moment can be any moment within 10 minutes before the communication device sends the IKE authentication request).

[0180] Optionally, the communication device saves the first authentication information.

[0181] S206c: After receiving the IKE authentication request, the access gateway sends an EAP request to the first network element, wherein the EAP request carries the identity of the communication device and the first authentication information received in step S206b. The first network element receives the identity of the communication device and the first authentication information. Optionally, the first network element saves the identity of the communication device and the first authentication information.

[0182] S206d: After receiving the EAP request, the first network element performs EAP authentication on the communication device.

[0183] The first network element establishes a connection between the first network element and the communication device and a connection between the first network element and the AAA server. For example, the first network element determines the AAA server according to the identity of the communication device, and then the first network element establishes a connection between the first network element and the AAA server. The first network element can establish the connection with the AAA server directly, or the first network element establishes the connection with the AAA server through a proxy. In addition, the first network element establishes a connection with the communication device through an access gateway. After the first network element establishes the connections with the communication device and the AAA server respectively, the communication device and the AAA server can interact authentication information through the connections established with the first network element. For example, the communication device and the AAA server can perform EAP authentication through the connections. For example, the AAA server initiates a challenge authentication to the communication device. The AAA server can send challenge information to the communication device through the connection, for example, the challenge information can be a random number, or the challenge information can also be a timestamp corresponding to a time point before the AAA server sends the challenge information. For example, the time point can be any time point within a specified time before the AAA server sends the challenge information (for example, the time point can be any time point within 10 minutes before the AAA server sends the challenge information). After receiving the challenge information, the communication device uses a pre-configured key (for example, a pre-configured vendor key) to respond to the challenge information of the AAA server, and returns the challenge response information to the AAA server through the connection. For example, the challenge response information of the communication device can be calculated by the communication device using the pre-configured vendor key and the challenge information through a pre-configured algorithm (denoted as algorithm #1). That is, the communication device takes the pre-configured vendor key and the challenge information as the input of the algorithm #1, and takes the output of the algorithm #1 as the challenge response information. After receiving the challenge response information, the AAA server uses the same pre-configured key as the communication device to verify the challenge response information of the communication device. If the verification is passed, it is determined that the EAP authentication is passed, or the communication device passes the authentication. For example, the AAA server calculates the expected challenge response information using the same pre-configured vendor key as the communication device, the challenge information, and the pre-configured algorithm (algorithm #1). For example, the AAA server takes the pre-configured vendor key and the challenge information as the input of the algorithm #1, and takes the output of the algorithm #1 as the expected challenge response information. The AAA server compares the challenge response information received from the communication device with the expected challenge response information calculated by the AAA server. If they are the same, it is considered that the communication device passes the authentication. It should be pointed out that the application does not limit the timing of the AAA server calculating the expected challenge response information. For example, the AAA server can calculate the expected challenge response information when sending the challenge information.

[0184] Optionally, the communication device can also initiate a challenge authentication with the AAA server, wherein the communication device sends a challenge information to the AAA server, the AAA server uses a pre-configured key (e.g., a vendor key configured by a vendor of the communication device) to generate a response to the challenge information of the communication device, and returns the response information to the communication device. The communication device uses the same pre-configured key as the AAA server to verify the challenge response information of the AAA server, and determines that the EAP authentication is passed if the verification is passed.

[0185] Optionally, when the communication device and the AAA server perform the mutual authentication, the communication device can send the challenge information to the AAA server at the same time when sending the response message to the AAA server, and the AAA server can send the challenge information to the communication device at the same time when sending the response message to the communication device, which will not be described herein.

[0186] S206e: The first network element generates a second key.

[0187] For example, the first network element uses the pre-configured key and the first authentication information and a pre-configured algorithm (e.g., algorithm #2) to generate the second key. Optionally, the first network element generates the second key after the authentication is passed. The second key is used to encrypt the first key sent to the communication device, for example, the second key is used by the access gateway to encrypt the first key sent to the communication device. Alternatively, the second key is used to negotiate an internet protocol security (IPsec) tunnel between the access gateway and the communication device, and the IPsec tunnel is used to transmit the first key. Optionally, the IPsec tunnel between the access gateway and the communication device is considered to be negotiated when the access gateway and the communication device obtain the second key.

[0188] Optionally, the first network element uses the pre-configured key and the first authentication information and algorithm #3 to generate a key (e.g., referred to as a first integrity protection key) for verifying the integrity of the first key after the authentication is passed, and the key is used to verify whether the first key is tampered during transmission. Algorithm #3 can be a pre-configured algorithm for generating an integrity protection key.

[0189] Optionally, the IPsec tunnel can also be used to transmit the first identity. Alternatively, the second key can also be used by the access gateway to encrypt the first identity sent to the communication device. Optionally, the first integrity protection key can also be used to verify the integrity of the first identity.

[0190] S206f: The first network element sends a communication device authentication response to the access gateway.

[0191] Optionally, the communication device authentication response carries the second key generated in S206e. Optionally, the communication device authentication response carries the first integrity protection key generated in S206e. Optionally, the communication device authentication response indicates whether the communication device authentication is successful.

[0192] S206g: The access gateway sends a communication device authentication response to the communication device.

[0193] For example, the communication device authentication response indicates whether the communication device authentication is successful. For example, the response can be an IKE_AUTH_Resp message.

[0194] It is noted that steps S206f and S206g are optional steps.

[0195] It is noted that if the response in S206g indicates that the communication device authentication fails, then the following steps do not need to be performed.

[0196] S207: The communication device generates a second key.

[0197] For example, the communication device uses the preconfigured key (e.g., vendor key) and the first authentication information to generate the second key after receiving the response that the communication device authentication is successful. The preconfigured key and the first authentication information are the same as those used in step S206e. It is noted that the algorithm used by the communication device to generate the second key is the same as the algorithm used by the first network element to generate the second key in step S206e (e.g., algorithm #2 is used to generate the second key). That is, the first network element and the communication device use the same preconfigured key, the same first authentication information, and the same algorithm to generate the same second key.

[0198] Optionally, the communication device uses the preconfigured key and the first authentication information and algorithm #3 to generate a first integrity protection key after receiving the response that the communication device authentication is successful. The first integrity protection key is used to verify whether the first key is tampered during transmission.

[0199] For example, the communication device can use the second key to decrypt the encrypted transmission of the first key from the access gateway. Optionally, the second key can also be used to decrypt the encrypted transmission of the first identity from the access gateway. Optionally, the communication device can use the first integrity protection key to verify whether the transmitted first key is tampered.

[0200] S208: The communication device sends a request 2b to the first network element through the access gateway.

[0201] For example, the request 2b is used to request the mobile network to send the first key to the communication device. Optionally, the request 2b is also used to request the mobile network to send the first identity to the communication device.

[0202] Optionally, the request 2b carries the identity of the communication device. The mobile network can determine the communication device by the identity of the communication device, and further determine the first key of the communication device. For example, the first network element or the subscription database stores the association between the identity of the communication device and the first key, and the mobile network can query the first key of the communication device by the identity of the communication device. Optionally, the first network element or the subscription database stores the association between the identity of the communication device and the first identity, and the mobile network can determine the first identity of the communication device by the identity of the communication device.

[0203] It is noted that this step is optional, that is, the first network element can send the first key to the communication device after the authentication of the communication device is completed, for example, after the completion of S206f. For example, the first network element starts a timer with a specified time length after the execution of step 206e or 206f, and sends the first key to the communication device by step S209 when the timer is expired.

[0204] Similarly, the request 2b can also be used to request the first network element to send the first identity to the communication device. Alternatively, the first network element can send the first identity to the communication device after the authentication of the communication device is completed, for example, after the completion of S206f.

[0205] S209: The first network element sends the first key. Correspondingly, the communication device receives the first key.

[0206] For example, the first network element sends the first key to the access gateway, and the access gateway sends the first key to the communication device. Optionally, the first network element sends the second key to the access gateway. Optionally, the first network element sends the first integrity protection key to the access gateway. It is noted that if the first network element sends the second key (or the first integrity protection key) to the access gateway in this step, the second key (or the first integrity protection key) generated in S206e is not carried in the response of the authentication of the communication device in step S206f.

[0207] In one implementation, the access gateway sends the first key to the communication device through a secure transmission. For example, the access gateway establishes an IPsec tunnel with the communication device, and transmits the first key through the IPsec tunnel. Alternatively, the access gateway encrypts the first key using the second key, and sends the encrypted first key to the communication device. Optionally, the access gateway generates a message authentication code for integrity (MAC-I) of the first key using the first integrity protection key, the first key, and an algorithm #4, where the algorithm #4 is used to calculate the message authentication code for integrity. The authentication code is used to verify whether the first key is tampered during the transmission. The access gateway sends the message authentication code for integrity of the first key to the communication device.

[0208] For example, the first network element stores the first key, and the first network element can query the stored first key using the identity of the communication device received in S208. For example, if the first identity and the first key, and the association between the terminal identity and the identity of the communication device are stored in the first network element or the subscription database in a four-tuple, the first network element can query the first key according to the identity of the communication device. If the first network element or the subscription database also stores the association between the first key and the identity of the communication device, the first network element can also query the first key according to the identity of the communication device, or if the first network element or the subscription database also stores the association between the first identity and the identity of the communication device, the first network element queries the first identity according to the identity of the communication device, and then queries the first key according to the first identity.

[0209] Encrypting the first key using the second key can avoid the first key being intercepted by an illegal user during the transmission. For example, encrypting the first key using the second key by the mobile network can avoid the first key being intercepted by an illegal user during the transmission, and thus avoid the illegal user registering to the mobile network using the first key.

[0210] Optionally, if the first network element does not query the first key or the first identity, the first network element sends indication information to the communication device through the access gateway, indicating that the first network element does not query the first key or the first identity, or in other words, the first network element fails to issue the first key or the first identity.

[0211] Optionally, if the first identity is generated by the first network element, the first network element can send the first identity to the access gateway, and the access gateway sends the first identity to the communication device. Optionally, the access gateway can also transmit the first identity through an IPsec tunnel, or in other words, the access gateway can also encrypt the first identity using the second key, and then send the encrypted first identity to the communication device. Optionally, the access gateway can also calculate an integrity message authentication code of the first identity using the first integrity protection key, and send the integrity message authentication code of the first identity to the communication device. Optionally, the access gateway can not transmit the first identity through an IPsec tunnel, or in other words, the access gateway does not encrypt the first identity using the second key.

[0212] Optionally, the first network element can also encrypt the first key (or the first identity) using the second key. The first network element sends the encrypted first key (or the first identity) to the access gateway. The access gateway sends the encrypted first key (or the first identity) to the communication device. If the first network element encrypts the first key (or the first identity) using the second key, the first network element does not need to send the second key to the access gateway, for example, in step S206f or step S209, the first network element does not need to send the second key to the access gateway.

[0213] Optionally, the first network element can also calculate an integrity message authentication code of the first key (or the first identity) using the first integrity protection key, and send the integrity message authentication code of the first key (or the first identity) to the access gateway. If the first network element calculates the integrity message authentication code of the first key (or the first identity) using the first integrity protection key, the first network element does not need to send the first integrity protection key to the access gateway, for example, in step S206f or step S209, the first network element does not need to send the first integrity protection key to the access gateway.

[0214] Optionally, the first network element can also calculate an integrity message authentication code of the first key (or the first identity) using the first integrity protection key, and send the integrity message authentication code of the first key (or the first identity) to the access gateway. If the first network element calculates the integrity message authentication code of the first key (or the first identity) using the first integrity protection key, the first network element does not need to send the first integrity protection key to the access gateway, for example, in step S206f or step S209, the first network element does not need to send the first integrity protection key to the access gateway.

[0215] For example, the communication device writes the first identity and the first key into a Trusted Execution Environment (TEE) of the communication device. Alternatively, if the communication device does not have a hardware TEE, the communication device writes the first identity and the first key into a software form of TEE of the communication device, for example, the communication device writes the first identity and the first key into a software security hardening unit of the communication device. If the first identity is not generated by the first network element or the first identity is not sent in S209, only the first key is saved.

[0216] The above steps describe a process in which the terminal device requests the first key for the communication device. The first network element generates the first key for the communication device and then sends the first key to the communication device. The communication device can use the first key to register to the mobile network. The process in which the communication device uses the first key to register to the mobile network is described below. The process is shown in FIG. 2(b).

[0217] S2013: The communication device sends a first registration request to the access gateway.

[0218] As described above, the vendor of the communication device has signed a contract with the operator, therefore, the communication device can initiate a registration request to the mobile network through the access gateway before the authentication is passed, and can also interact with the mobile network through the access gateway to exchange authentication information.

[0219] For example, the first registration request is used for the communication device to request registration to the mobile network.

[0220] For example, the first registration request carries the first identity.

[0221] Optionally, the first registration request can also carry second authentication information, the second authentication information being the time at which the communication device initiates the request to register to the mobile network, or the second authentication information being a random number.

[0222] S2014: The access gateway sends a first authentication request to the first network element.

[0223] For example, the first authentication request is used for requesting the first network element to authenticate the communication device.

[0224] For example, the first authentication request carries the first identity. Optionally, the first authentication request can also carry the second authentication information received by the access gateway in S2013.

[0225] S2015: The first network element authenticates the communication device.

[0226] For example, the first network element obtains the first key corresponding to the first identity. For example, the first identity and the first key are stored in the first network element. The first network element obtains the first key according to the first identity received in S2014. Alternatively, the first identity and the first key are stored in a subscription database, and the first network element obtains the first key according to the first identity in the subscription database.

[0227] For example, the first network element authenticates the communication device after obtaining the first key.

[0228] For example, the first network element performs EAP authentication with the communication device through the access gateway. For example, the first network element performs challenge authentication with the communication device, the first network element sends challenge information to the communication device, the communication device uses the first key to respond to the challenge information from the first network element, and returns the challenge response information to the first network element. After receiving the challenge response information, the first network element verifies the challenge response information of the communication device using the first key, and determines that the communication device passes the authentication if the verification is correct. If the authentication is passed, it is determined that the communication device is a legal holder of the first key, or in other words, it is determined that the communication device is legal, or in other words, the communication device is allowed to register to the mobile network.

[0229] For example, the challenge information sent by the first network element to the communication device can be a random number, or the challenge information can also be a timestamp corresponding to a certain moment before the first network element initiates challenge authentication. For example, the moment can be any moment within a specified time before the first network element sends the challenge information to the communication device (for example, the moment can be any moment within 10 minutes before the first network element sends the challenge information to the communication device). After receiving the challenge information, the communication device uses the first key to respond to the challenge information from the first network element, generates challenge response information (or second information), and returns the second information to the first network element through the access gateway. For example, the second information of the communication device can be calculated by the communication device using the first key and the challenge information through a preconfigured algorithm (denoted as algorithm #5). After receiving the second information, the first network element verifies the second information of the communication device using the first key. For example, the first network element calculates the expected challenge response information (or first information) using the first key, the challenge information, and the algorithm #5. The first network element compares the second information received from the communication device with the first information calculated by the first network element, and if they are the same, it is considered that the communication device passes the authentication. It should be noted that the application does not limit the timing of the first network element calculating the first information, for example, the first network element can calculate the first information when sending the challenge information.

[0230] Optionally, the challenge information sent by the first network element to the communication device can be an indication that the communication device performs EAP authentication with the first network element. Optionally, the challenge information can indicate that the communication device reports second authentication information and challenge response information (or second information) calculated based on the second authentication information. For example, after receiving the indication information from the first network element, the communication device reports the second authentication information and the second information calculated based on the second authentication information to the first network element. The first network element receives the second authentication information and calculates the first information based on the first key and the second authentication information. If the second information received from the communication device is the same as the first information calculated by the first network element, the communication device is considered to pass the authentication.

[0231] Optionally, the communication device can also initiate the challenge authentication to the first network element using the same method, for example, the communication device sends challenge information to the first network element, the first network element responds to the challenge information using the first key and sends the challenge response information to the communication device, and the communication device verifies the challenge response information.

[0232] Optionally, when the communication device and the first network element perform bidirectional authentication, the communication device can send challenge information to the first network element while sending challenge response information to the first network element, and similarly, the first network element can send challenge information to the communication device while sending challenge response information to the communication device.

[0233] S2016: The first network element generates a third key.

[0234] For example, the third key is used to encrypt or decrypt the message transmitted between the communication device and the access gateway.

[0235] For example, after the authentication in step S2015 is passed, the first network element generates the third key using the first key. Alternatively, the first network element generates the third key using the first key and the second authentication information received in step S2014. For example, the first network element generates the third key using the first key, the second authentication information, and a preconfigured algorithm (for example, algorithm #6).

[0236] Optionally, the first network element generates a fourth key using the first key and the second authentication information and a preconfigured algorithm (e.g., algorithm #7), and the fourth key is used to verify the integrity of the messages transmitted between the communication device and the access gateway, or in other words, the fourth key is used to verify whether the messages transmitted between the communication device and the access gateway are tampered during the transmission. Optionally, the first network element can also generate the third key (or the fourth key) using other keys, wherein the key used to generate the third key (or the fourth key) is trusted, that is, the key used to generate the third key (or the fourth key) can be generated by the mobile network or the key used to generate the third key (or the fourth key) passes the authentication of the mobile network.

[0237] S2017: The first network element sends a first authentication request response to the access gateway.

[0238] For example, the first network element sends the third key (or the fourth key) to the access gateway through the first authentication request response. For example, the first authentication request response sent by the first network element to the access gateway includes the third key (or the fourth key) generated in S2016. Optionally, the first authentication request response also includes an indication of whether the authentication of the communication device in the process of the communication device requesting to register to the mobile network is passed.

[0239] S2018: The access gateway sends a first registration request response to the communication device.

[0240] For example, the first registration request response is used to indicate whether the communication device is allowed to register to the mobile network. For example, the first registration request response includes an indication of whether the communication device is allowed to register to the mobile network. If the first network element indicates in S2017 that the authentication of the communication device is passed, the access gateway indicates in the first registration request response that the first registration request of the communication device is accepted. If the authentication fails, the access gateway indicates in the first registration request response in S2018 that the first registration request of the communication device is rejected.

[0241] It should be noted that if the first registration request response in S2018 indicates that the first registration request of the communication device is rejected, the execution of S2019 and the subsequent steps is terminated, otherwise, S2019 and the subsequent steps are executed.

[0242] S2019: The communication device generates a third key.

[0243] Optionally, the communication device generates a third key according to the first key and the second authentication information, and the communication device generates the third key in the same way as the first network element generates the third key in S2016. For example, the communication device generates the third key using the first key and the second authentication information and algorithm #6. The application does not limit the way of generating the third key, but no matter which way is used to generate the third key, the third key generated by the first network element and the communication device is the same, and the third key is used to encrypt or decrypt the message between the communication device and the access gateway. Optionally, the communication device generates a fourth key using the first key and the second authentication information and algorithm #7, and the fourth key is used to verify the integrity of the message transmitted between the communication device and the access gateway, or in other words, the fourth key is used to verify whether the message transmitted between the communication device and the access gateway is tampered during transmission.

[0244] Optionally, the communication device establishes an IPsec tunnel with the access gateway using the third key and the fourth key, and the IPsec tunnel is used to transmit the message between the communication device and the access gateway.

[0245] In addition, if the communication device still needs to access the IMS network, the following steps can be performed:

[0246] S2020: The communication device initiates a second registration request to the IMS network.

[0247] For example, the access gateway enables NAT for the message received from the communication device or sent to the communication device. For example, the access gateway converts the message received from the IPsec tunnel in the uplink direction to the destination network corresponding to the session (for example, the IMS network), and correspondingly, converts the message received from the session in the downlink direction to be sent to the communication device to the IPsec tunnel corresponding to the session.

[0248] For example, the communication device sends a second registration request to the SBC of the IMS network through the access gateway, and requests to register to the IMS network. For example, the communication device sends the second registration request to the access gateway, and the access gateway forwards the second registration request to the SBC of the IMS network through NAT.

[0249] For example, the second registration request carries the first identity, and optionally, the second registration request carries authentication information. For example, the authentication information can be third authentication information, which can be a timestamp corresponding to a certain moment before the communication device sends the second registration request, or the third authentication information can also be a random number. For example, the moment can be any moment within a specified time before the communication device sends the second registration request (for example, the moment can be any moment within 10 minutes before the communication device sends the second registration request). Optionally, the authentication information can be generated by the communication device using the first key corresponding to the first identity according to the third authentication information, for example, the communication device calculates the authentication information according to the first key and the third authentication information through algorithm #8, wherein algorithm #8 is a function configured by the communication device to calculate the authentication information.

[0250] Optionally, the second registration request carries the third authentication information.

[0251] For example, the SBC forwards the second registration request to the S-CSCF.

[0252] S2021: The S-CSCF sends a multimedia authentication request (MAR) to the subscription database.

[0253] For example, the MAR is used to request authentication of the communication device in the process of requesting the communication device to register to the IMS network, and the MAR carries the first identity. Optionally, the MAR carries authentication information.

[0254] Optionally, the MAR carries the third authentication information.

[0255] S2022: The subscription database initiates an authentication request to the first network element and receives an authentication response.

[0256] For example, the subscription database sends an authentication request to the first network element to request the first network element to authenticate the communication device. For example, the subscription database obtains the corresponding first key according to the first identity received in S2021, and then sends the first key and the authentication information to the first network element. After the first network element verifies that the authentication information is correct using the first key, it determines that the authentication of the communication device is passed. For example, the first network element calculates the authentication information a according to the first key and the third authentication information and algorithm #8, and when the authentication information a calculated by the first network element is the same as the authentication information received from the subscription database, it determines that the authentication of the communication device is passed. The first network element sends an authentication response to the subscription server, which indicates that the authentication of the communication device is passed if the authentication of the communication device is passed, or indicates that the authentication of the communication device is not passed.

[0257] S2023: The subscription database sends a multimedia authentication answer (MAA) to the S-CSCF.

[0258] For example, the MAA indicates that the communication apparatus passes the authentication of the IMS network, that is, the communication apparatus is allowed to register to the IMS network.

[0259] S2024: After determining that the communication apparatus obtains the access authorization of the IMS network, the S-CSCF forwards the second registration request in step S2020 to the IMS-AS.

[0260] S2025: The IMS-AS sends a second registration request response to the communication apparatus.

[0261] For example, after successfully processing the second registration request of the communication apparatus, the IMS-AS sends the second registration request response to the communication apparatus through the S-CSCF, the SBC and the access gateway. Thereafter, the communication apparatus can initiate or accept an IMS call.

[0262] Through the above-mentioned embodiments of FIG. 2(a) and FIG. 2(b), the first network element generates the first key for the communication apparatus and sends the first key to the communication apparatus. The communication apparatus can use the first key to pass the authentication of the mobile network. The device without the user identification module is implemented to register to the mobile network independently of the terminal device (the device with the user identification module). In the process of registering to the mobile network, the first network element and the communication apparatus generate the same third key, and the secure transmission of the message is implemented using the third key. In addition, the communication apparatus can further access the IMS network, and help the user to answer or make a call independently of the terminal device. The method does not limit the state of the terminal device, for example, in the case that the terminal device is powered off, or the terminal device is out of credit, or the terminal device does not access the network, the communication apparatus can still register to the mobile network and the IMS network. For example, in the case that the terminal device is powered off or the terminal device does not access the network, the communication apparatus can still help the user to answer or make a call.

[0263] As another implementation, in the process that the communication device requests to register to the mobile network, the first network element and the communication device encrypt messages transmitted between the access gateway and the communication device using a third key generated by the first network element. For example, the first network element generates the third key and sends the third key to the communication device. For example, the first network element can generate a Quick User Datagram Protocol Internet Connections (QUIC) key and send the QUIC key to the communication device, and messages between the communication device and the mobile network can be encrypted or decrypted using the QUIC key, and specific steps are shown in FIG. 2(c). FIG. 2(c) will be described in combination with FIG. 2(b). The process that the communication device registers to the mobile network according to the steps of FIG. 2(c) will be described below.

[0264] S2030-S2032: S2030-S2032 are the process that the communication device initiates a registration request to the mobile network and the mobile network authenticates the communication device, which is the same as steps S2013-S2015 of FIG. 2(b), and will not be described herein again.

[0265] S2033: The first network element generates a third key.

[0266] For example, after the mobile network authenticates the communication device, the first network element generates the third key, and the third key is used to encrypt or decrypt messages between the communication device and the access gateway. The first network element sends the generated third key to the communication device.

[0267] For example, the third key is a QUIC key generated by the first network element. For example, after the communication device is authenticated, the first network element generates the QUIC key. The first network element sends the QUIC key to the communication device, and the communication device uses the QUIC key to encrypt or decrypt messages transmitted between the communication device and the mobile network (or the communication device and the access gateway).

[0268] Optionally, the first network element also generates a fourth key, and the manner of generating the fourth key can refer to step S2016 of FIG. 2(b).

[0269] S2034: The first network element sends a first authentication response to the access gateway.

[0270] For example, the first network element sends the third key (or the fourth key) to the access gateway through the first authentication request response. That is, the first authentication request response can include the third key (or the fourth key). Optionally, the first authentication request response also includes an indication of whether the authentication of the communication device in the process that the communication device requests to register to the mobile network is passed. The specific implementation steps are the same as step S2017 of FIG. 2(b).

[0271] S2035: The access gateway sends a first registration request response to the communication device.

[0272] For example, the first registration request response comprises the third key (or the fourth key). Optionally, the access gateway can encrypt the third key (or the fourth key) using the first key, and then send the encrypted third key (or the fourth key) to the communication device. Optionally, the first registration request response can further comprise an indication of whether the authentication of the communication device in the process of the communication device requesting to register to the mobile network is passed.

[0273] It is noted that if the first registration request response in S2035 indicates that the authentication of the communication device is not passed, the execution of S2036 and the following steps is terminated.

[0274] S2036: The communication device decrypts the third key.

[0275] Optionally, the communication device decrypts the information received in S2035 according to the first key to obtain the decrypted third key (or the fourth key).

[0276] Optionally, the communication device can further generate the fourth key. The communication device can generate the fourth key in the manner as described in S2019 of FIG. 2(b). If the communication device generates the fourth key, the fourth key can not be carried in the first registration request response in S2035.

[0277] S2037: The access gateway triggers the establishment of a PDU session.

[0278] Optionally, the communication device has an uplink packet to be sent. The communication device sends the uplink packet to the access gateway, and the access gateway triggers the establishment of the PDU session. Optionally, the uplink packet is encrypted using the third key. Optionally, the communication device calculates an integrity message authentication code of the uplink packet using the fourth key. The method of calculating the integrity message authentication code can refer to S209 of FIG. 2(a). Optionally, the integrity message authentication code is sent to the access gateway together with the uplink packet.

[0279] Optionally, the mobile network has a downlink packet to be sent. The mobile network instructs the access gateway to trigger the establishment of the PDU session.

[0280] For example, the message triggering the establishment of the PDU session carries the third key (or the fourth key) obtained in S2034.

[0281] S2038: The session management function network element controls the access gateway and the user plane function network element to establish a PDU session, and the session management function network element sends the third key (or the fourth key) to the user plane function network element through the PDU session.

[0282] For example, the session management function network element determines a data network (DN) according to a destination address of the uplink message, for example, determines that the IMS network is the destination DN, and then selects the user plane function network element. The session management function network element controls the access gateway and the user plane function network element to establish a PDU Session, and sends the third key (or the fourth key) to the user plane function network element.

[0283] S2039: The communication device transmits an uplink message or a downlink message with the data network.

[0284] For example, the communication device encrypts the message to be sent using the third key, and then the uplink message is forwarded to the user plane function network element through the access gateway, the user plane function network element decrypts the uplink message using the third key, and then forwards it to the DN. Optionally, the communication device calculates the integrity message authentication code of the uplink message using the fourth key. Optionally, the integrity message authentication code and the uplink message are sent to the access gateway and then sent to the user plane function network element through the access gateway. Optionally, the user plane function network element calculates the expected integrity message authentication code of the uplink message using the fourth key. The user plane function network element compares the expected integrity message authentication code calculated by the user plane function network element with the integrity message authentication code received by the user plane function network element. If they are the same, it is considered that the integrity verification of the uplink message is passed, or in other words, the uplink message has not been tampered with.

[0285] Correspondingly, the user plane function network element encrypts the downlink message sent by the DN to the communication device using the third key, and the encrypted downlink message is sent to the communication device through the access gateway. The communication device decrypts the encrypted downlink message using the third key. Optionally, the user plane function network element calculates the integrity message authentication code of the downlink message using the fourth key, and sends the integrity message authentication code of the downlink message to the communication device. The communication device verifies the integrity message authentication code of the downlink message using the fourth key to determine whether the downlink message has been tampered with.

[0286] Similarly, if the communication device has the need to access the IMS network, the following steps can also be performed:

[0287] S2040-S2045: The communication device registers to the IMS network, the specific steps are the same as S2020-S2025 in FIG. 2(b), which will not be repeated here. Through the above embodiments of FIG. 2(a) and FIG. 2(c), the first network element generates the first key for the communication device and sends the first key to the communication device. The communication device can use the first key to complete the authentication of the communication device in the process of requesting to register to the mobile network. In the process of registering to the mobile network, the first network element generates the third key and sends the third key to the communication device, and the mobile network and the communication device use the third key to realize the secure transmission of messages. In addition, the communication device can further access the IMS network to realize the independent terminal device to help the user to answer or dial the phone. The method does not limit the state of the terminal device, for example, in the case of terminal device power off, or terminal device undercharge, or terminal device not accessing the network, the communication device can still register to the mobile network. For example, in the case of terminal device power off, or terminal device not accessing the network, the communication device can still help the user to answer or dial the phone.

[0288] It should be noted that in the steps shown in FIG. 2(b), the access gateway realizes the establishment of a transmission channel between the communication device and the target network through NAT. For example, the access gateway realizes that the access gateway converts the message received from the IPsec tunnel in the uplink direction to the destination network (for example, the IMS network) corresponding to the session through NAT, and correspondingly, converts the message to be sent to the communication device received from the session in the downlink direction to the IPsec tunnel corresponding to the session. In addition to realizing the establishment of a transmission channel between the communication device and the target network through NAT, a transmission channel can also be established by establishing a PDU session between the access gateway and the user plane function network element. For example, the method described in steps S2037-S2038 in FIG. 2(c) is used to establish a PDU session (for example, a GPT-U tunnel) between the access gateway and the user plane function network element. The messages between the communication device and the access gateway are transmitted through the IPsec tunnel, and the messages between the access gateway and the user plane function network element are transmitted through the GPT-U tunnel. The user plane function network element performs NAT, for example, the user plane function network element converts the uplink message transmitted through the IPsec tunnel and the GTP-U tunnel to the destination network (such as the IMS network) corresponding to the session, and correspondingly, converts the downlink message to be sent to the communication device to the GPT-U tunnel corresponding to the session.

[0289] In step shown in FIG. 2(c), the access gateway establishes a transmission channel by establishing a PDU session with the user plane function network element. Alternatively, FIG. 2(c) can also use the step S2020 in FIG. 2(b) to establish a transmission channel between the access gateway and the target network. For example, the access gateway implements the transmission channel between the communication apparatus and the target network through NAT. That is, the access gateway implements the transmission channel between the access gateway and the target network through NAT, in which the access gateway transfers the message received from the IPsec tunnel in the uplink direction to the destination network (for example, the IMS network) corresponding to the session, and correspondingly, transfers the message to be sent to the communication apparatus in the downlink direction to the IPsec tunnel corresponding to the session.

[0290] FIG. 3 is another signaling interaction diagram of a mobile network registration method provided by an embodiment of the present application. FIG. 3 will be described in combination with FIG. 2(a). In FIG. 3, the process that the terminal device requests the first key for the communication apparatus is the same as that in FIG. 2(a), and the difference is that in FIG. 3, the authentication manner of the communication apparatus by the mobile network (or the first network element) is different in the process that the mobile network (or the first network element) sends the first key to the communication apparatus. In the example of FIG. 3, the terminal device generates a first signature for the communication apparatus, and the communication apparatus sends the first signature to the first network element, and the first network element verifies the first signature. If the first signature verification is passed, it is determined that the communication apparatus is authenticated by the mobile network, and thus the first key is sent to the communication apparatus after the authentication. The implementation process of this embodiment will be described in combination with FIG. 3.

[0291] S300-S305: The process that the terminal device requests the first key for the communication apparatus, for example, the terminal device sends a request for requesting the access and mobility management function network element to issue the first key for the communication apparatus. Optionally, the request carries the identifier of the communication apparatus. For the description of the request and the process that the first network element issues the first key, reference can be made to S200-S205 in FIG. 2(a), which will not be described herein again.

[0292] Before sending the first key, the first network element authenticates the communication apparatus. Optionally, the authentication of the communication apparatus by the first network element is initiated by the communication apparatus. For example, the communication apparatus initiates the authentication and sends the parameters required in the authentication process to the first network element, and correspondingly, the first network element authenticates the communication apparatus according to the parameters.

[0293] Optionally, before the authentication process, the communication apparatus can first acquire the parameters to be used in the authentication process. For example:

[0294] S306: The communication apparatus acquires the first signature and the first authentication information.

[0295] For example, the first signature and the first authentication information are used for the first network element to authenticate the communication apparatus. Optionally, the communication apparatus can acquire the first signature and the first authentication information from the terminal device.

[0296] For example, the first authentication information can be a time stamp corresponding to the time when the terminal device generates the first signature, or the first authentication information can be a random number.

[0297] For example, the terminal device generates the first signature by using a shared key between the terminal device and the operator. For example, the terminal device signs the first authentication information by using the shared key between the terminal device and the operator to obtain the first signature. Or, the terminal device signs the first authentication information and the identifier of the communication device by using the shared key between the terminal device and the operator to obtain the first signature.

[0298] Thus, the communication device obtains the first signature and the first authentication information.

[0299] Optionally, the terminal device can also generate the second key by using the shared key between the operator. For example, the terminal device calculates the second key by using the shared key between the operator and the first authentication information according to the algorithm pre-set by the first network element. Optionally, the method for calculating the second key can refer to step S206e or step S207 of FIG. 2(a), which will not be described herein again.

[0300] Thus, the communication device also obtains the second key.

[0301] For example, the authentication process in FIG. 3 can include the following steps:

[0302] S307a: The communication device sends an Internet Key Exchange Security Association Initialization message IKE_SA_INIT to the access gateway. Correspondingly, the access gateway sends an IKE_SA_INIT response to the communication device. Optionally, the exchange process is completed to negotiate the IKE SA parameters, including negotiating the encryption and authentication algorithms. The process can refer to step S206a of FIG. 2(a).

[0303] S307b: The communication device sends an IKE authentication request, for example, IKE_AUTH_Req, to the access gateway, wherein the IKE authentication request carries the first authentication information and the first signature, and optionally, the IKE authentication request can also carry the identifier of the communication device.

[0304] S307c: After receiving the IKE authentication request, the access gateway sends an EAP request to the first network element, wherein the EAP request carries the first authentication information and the first signature received in step S307b, and optionally, the EAP request can also carry the identifier of the communication device received in step S307b. Correspondingly, the first network element receives the first authentication information and the first signature, and optionally, if the identifier of the communication device is carried in the EAP request, the first network element can also receive the identifier of the communication device.

[0305] S307d: After receiving the EAP request, the first network element performs the EAP authentication with the communication apparatus.

[0306] For example, the first network element obtains the terminal identity (e.g., user number or SUPI) associated with the identity of the communication apparatus according to the identity of the communication apparatus. For example, if the first network element stores the association between the identity of the communication apparatus and the terminal identity, the first network element can obtain the terminal identity from the first network element. Alternatively, if the subscription database stores the association between the identity of the communication apparatus and the terminal identity, the first network element can also obtain the terminal identity from the subscription database, for example, the first network element first queries the terminal identity from the subscription database according to the identity of the communication apparatus. After obtaining the terminal identity, the first network element can obtain the shared key between the terminal device and the operator from the subscription database according to the terminal identity (user number or SUPI).

[0307] In a possible implementation, after obtaining the shared key between the terminal device and the operator, the first network element generates a second signature using the shared key, for example, the first network element calculates the second signature using the shared key and the first authentication information received in S307c. The first network element compares the calculated second signature with the first signature received in S307c. If the second signature is consistent with the first signature, it can be determined that the first signature sent by the communication apparatus in S307b is calculated by the terminal device associated with the first identity, that is, it can be determined that the communication apparatus passes the authentication. Otherwise, it is determined that the communication apparatus fails the authentication, and the process of S307d and the following processes are terminated after the authentication fails. Alternatively, if the first signature is generated by the terminal device using the shared key between the terminal device and the operator to sign the first authentication information and the identity of the communication apparatus, the first network element calculates the second signature using the shared key between the terminal device and the operator and the first authentication information and the identity of the communication apparatus received in S307c. If the second signature is consistent with the first signature, it can be determined that the first signature is verified, or in other words, the communication apparatus passes the authentication. Otherwise, it is determined that the communication apparatus fails the authentication.

[0308] In another possible implementation, after the first network element obtains the shared key between the terminal device and the operator, the first network element uses the shared key to decrypt the first signature. For example, the first network element uses the shared key to decrypt the first signature received in S307c to obtain the first authentication information (or the first authentication information and the identifier of the communication apparatus). The first network element compares the first authentication information (or the first authentication information and the identifier of the communication apparatus) obtained by decrypting the first signature with the first authentication information (or the first authentication information and the identifier of the communication apparatus) received in S307c. If the first authentication information (or the first authentication information and the identifier of the communication apparatus) obtained by decrypting the first signature is the same as the first authentication information (or the first authentication information and the identifier of the communication apparatus) received from S307c, it is determined that the first signature is verified, or in other words, the communication apparatus passes the authentication. Otherwise, it is determined that the communication apparatus fails the authentication, and the process after S307d is terminated.

[0309] S307e: The first network element generates a second key.

[0310] For example, after the authentication passes as described in S307d, the first network element uses the shared key between the terminal device and the operator and the first authentication information used in S307d to generate a second key. The method for generating the second key can refer to S206e in FIG. 2(a), which will not be described herein. The algorithm used by the first network element to calculate the second key according to the shared key between the terminal device and the operator and the first authentication information is the same as the algorithm used by the terminal device to calculate the second key. Because the terminal device uses the same parameters and algorithm to generate the second key as the first network element uses to calculate the second key, the communication apparatus receiving the second key from the terminal device and the first network element hold the same second key. The second key is used for encrypted transmission between the access gateway and the communication apparatus. For example, the second key is used to encrypt the first key transmitted between the access gateway and the communication apparatus.

[0311] Optionally, the first network element can use the shared key between the terminal device and the operator, the first authentication information, and a preconfigured algorithm to generate a first integrity protection key, which is used to verify whether the first key is tampered in the transmission process. The method for generating the first integrity protection key can refer to S206e in FIG. 2(a), which will not be described herein.

[0312] S307f: The first network element sends a communication apparatus authentication response to the access gateway.

[0313] For example, the communication apparatus authentication response indicates whether the communication apparatus authentication is successful. Optionally, the communication apparatus authentication response carries the second key (or the first integrity protection key) generated by the first network element.

[0314] S307g: The access gateway sends a communication device authentication response to the communication device.

[0315] For example, the communication device authentication response indicates whether the communication device authentication is successful or not. For example, the response can be an IKE_AUTH_Resp message.

[0316] It is noted that if the communication device authentication response in S307g indicates that the communication device authentication fails, S308 and the following steps are not needed to be performed.

[0317] S308: The communication device sends a request 3b to the access gateway.

[0318] For example, the function and content of the request 3b can refer to the request 2b in S208 of FIG. 2(a).

[0319] It is noted that this step is an optional step. That is, the first network element can send the first key / first identity to the communication device actively after the communication device authentication is completed, for example, after S307f is completed. The implementation of this step can refer to S208 of FIG. 2(a).

[0320] S309: The first network element sends the first key. Correspondingly, the communication device receives the first key.

[0321] For example, the first network element sends the first key to the communication device through the access gateway. Optionally, if the first network element generates the first identity, the first network element can also send the first identity to the communication device through the access gateway.

[0322] Optionally, the first network element can send the first key to the communication device through a secure transmission. For example, the first network element encrypts the first key using the second key, sends the encrypted first key to the access gateway, and then the access gateway forwards the encrypted first key to the communication device. It is noted that if the first network element encrypts the first key using the second key, the first network element does not need to send the second key to the access gateway. Optionally, the first network element can generate an integrity message authentication code of the first key using the first integrity protection key, the first key, and algorithm #4. The first network element sends the integrity message authentication code of the first key to the communication device, which is used by the communication device to verify whether the first key is tampered or not according to the integrity message authentication code. Optionally, the first network element can send the first identity to the communication device through a secure transmission. The specific method can refer to the method of sending the first key to the communication device through a secure transmission by the first network element, which is not described herein again.

[0323] Optionally, in another possible implementation, the first network element sends the first key to the access gateway, the access gateway encrypts the first key using the second key, and the access gateway sends the encrypted first key to the communication apparatus. Similarly, the access gateway can also generate an integrity message authentication code for the first key using the first integrity protection key. It should be noted that the second key (or the first integrity protection key) can also be sent by the first network element to the access gateway at S309. If the first network element sends the second key (or the first integrity protection key) to the access gateway at S309, the authentication response message in S307f does not need to carry the second key (or the first integrity protection key). Optionally, the first network element can send the first identifier to the communication apparatus by the above method, and the specific steps are not described here.

[0324] Optionally, the first network element sends the first key by referring to step S209 of FIG. 2(a), and correspondingly, the communication apparatus receives the first key or the first identifier by referring to step S209 of FIG. 2(a), and the details are not described here.

[0325] After receiving the first key or the first identifier, the communication apparatus stores the received first key or first identifier. For example, the communication apparatus writes the first identifier and the first key into the TEE of the communication apparatus. Alternatively, if the communication apparatus does not have a hardware TEE, the communication apparatus writes the first identifier and the first key into a software form of TEE of the communication apparatus, for example, the communication apparatus writes the first identifier and the first key into a software security reinforcement unit of the communication apparatus.

[0326] Sending the first key to the communication apparatus through the secure channel can avoid the first key being intercepted by an illegal user during transmission. For example, encrypting the first key using the second key by the mobile network can avoid the first key being intercepted by an illegal user during transmission, thereby avoiding the illegal user completing the authentication of the mobile network using the first key. In addition, performing integrity verification on the first key using the first integrity protection key can ensure that the first key has not been tampered with during transmission.

[0327] Optionally, in another implementation, the terminal device generates information required for authenticating the communication apparatus before sending the request 3a. For example, the terminal device generates information required for authenticating the communication apparatus before sending the request 3a in step S300.

[0328] For example, the terminal device generates the first signature according to the first authentication information before sending the request 3a in step S300, or generates the first signature according to the first authentication information and the identifier of the communication device, and the way of generating the first signature is the same as that described in S306. The first authentication information can be a time stamp corresponding to the moment of generating the first signature, or the first authentication information can be a random number. After generating the first signature, the terminal device sends the first authentication information and the first signature to the access and mobility management function network element in S300, and the access and mobility management function network element sends the first authentication information and the first signature to the first network element. Optionally, if the first signature is generated by the terminal device according to the identifier of the communication device and the first authentication information, the terminal device sends the first authentication information, the identifier of the communication device and the first signature to the first network element via the access and mobility management function network element in S300. Optionally, the first network element stores the first authentication information and the first signature.

[0329] Optionally, if the terminal device sends the first authentication information and the first signature (or also includes the identifier of the communication device) to the first network element via the access and mobility management function network element in S300, the communication device in step S306 can not obtain the first authentication information and the first signature (or also does not obtain the identifier of the communication device). Correspondingly, the IKE authentication request sent by the communication device to the access gateway in S307b does not carry the first authentication information and the first signature (or also does not carry the identifier of the communication device). That is, the IKE authentication request sent by the communication device to the access gateway in S307b is used to request authentication of the communication device, and does not carry the information required for authentication. The first network element uses the information required for authentication (for example, the first authentication information and the first signature (or also includes the identifier of the communication device)) received in S300 to authenticate the communication device after receiving the authentication request in S307c.

[0330] Optionally, in another implementation, the terminal device generates the information required for authenticating the communication device in any step before step S306, and then sends the information required for authenticating the communication device to the communication device in S306. For example, the terminal device generates the information required for authenticating the communication device (for example, the first authentication information and the first signature (or also includes the identifier of the communication device)) in S300, and then sends the information required for authenticating the communication device to the communication device in S306. Optionally, the IKE authentication request sent by the communication device to the access gateway in S307b carries the first authentication information and the first signature (or also carries the identifier of the communication device). Then, the access gateway sends the first authentication information and the first signature (or also includes the identifier of the communication device) to the first network element in S307c. The terminal device generates the information required for authenticating the communication device in the same way as described in S306, which is not described here.

[0331] The above two implementation manners describe the method that the terminal device generates the information required by the authentication communication device and sends the information to the first network element. Optionally, in addition to generating the information required by the authentication communication device, the terminal device also generates a second key (or a first integrity protection key) and sends the second key (or the first integrity protection key) to the communication device. The following describes the process that the communication device generates the second key (or the first integrity protection key) and sends the second key (or the first integrity protection key) to the communication device.

[0332] Optionally, the terminal device can generate the second key (or the first integrity protection key) according to the method described in step S206e or step S207 of FIG. 2(a) before sending the second key (or the first integrity protection key) to the communication device. For example, the terminal device can send the second key (or the first integrity protection key) to the communication device before step S309. That is, the terminal device can generate the second key (or the first integrity protection key) before step S309. The terminal device sends the second key (or the first integrity protection key) to the communication device before the communication device receives the first key, so that the communication device can use the second key to decrypt the received first key, or so that the communication device can use the first integrity protection key to verify the integrity of the received first key. For example, the terminal device can send the second key (or the first integrity protection key) generated according to the above method to the communication device at step S306. That is, the terminal device can generate the second key (or the first integrity protection key) at step S306 or any step before step S306, and then send the second key (or the first integrity protection key) to the communication device at step S306.

[0333] The steps in the above FIG. 3 describe the process that the terminal device requests the first key for the communication device. The first network element generates the first key for the communication device, and then the first network element sends the first key to the communication device. The communication device can use the first key to perform the authentication of the communication device by the mobile network in the process of registering to the mobile network. The process that the communication device registers to the mobile network using the first key and the first identity can refer to the steps described in FIG. 2(b) or FIG. 2(c). In combination with the steps in FIG. 3 and FIG. 2(b), or FIG. 3 and FIG. 2(c), the communication device can independently register to the mobile network using the first key issued by the first network element for the communication device, and further can access the IMS network. This method realizes that the device without the user identification module does not depend on the terminal device to register to the mobile network and the IMS network.

[0334] Figure 4 is another signaling interaction diagram of a method for mobile network registration according to an embodiment of the present application. Figure 4 will be described in combination with Figure 2(a) and Figure 3. In the process described in Figure 2(a) and Figure 3, the first network element and the communication device hold the same second key. The difference between the process described in Figure 4 and the process described in Figure 2(a) and Figure 3 is that in the process described in Figure 4, the first network element and the communication device hold a pair of public key and private key to encrypt and decrypt the first key. For example, the manufacturer of the communication device generates the public key and the private key, the communication device holds the private key, and the first network element holds the public key corresponding to the private key as the second key. In the transmission of the first key, the authentication of the communication device by the mobile network, and the encryption and decryption of the first key by the mobile network and the communication device can be performed using the second key (public key) and the private key. The implementation process of this embodiment will be described in combination with Figure 4.

[0335] S400: The terminal device sends a request 4a to the access and mobility management function network element.

[0336] For example, the request 4a is used to request the issuance of the first key for the communication device. Alternatively, the request 4a can also be used to request the issuance of the first identity for the communication device. Alternatively, the request 4a carries the identity of the communication device and the terminal identity. The description of the identity of the communication device and the terminal identity is referred to step S200 of Figure 2(a).

[0337] Alternatively, the request 4a can also carry the second key. For example, the second key is a pre-configured key for the communication device, for example, the second key can be the public key configured by the manufacturer of the communication device for the communication device.

[0338] Alternatively, before sending the request 4a to the access and mobility management function network element, the terminal device obtains the second key. For example, the terminal device obtains the second key from the public key certificate of the communication device. For example, the terminal device first obtains the identity of the communication device, obtains the public key certificate of the communication device through the identity of the communication device, for example, the terminal device obtains the public key certificate of the communication device from the server of the manufacturer. After obtaining the public key certificate, the terminal device verifies the signature generated by the manufacturer of the communication device corresponding to the public key certificate, and the verification method of the signature can be referred to step S307d of Figure 3. After verifying that the signature is correct, the terminal device obtains the public key of the communication device from the public key certificate. The terminal device takes the public key as the second key.

[0339] Optionally, the request 4a can also carry a first signature generated by the terminal device according to a shared key between the terminal device and the operator. For example, the terminal device signs the second key according to the shared key between the terminal device and the operator to obtain the first signature, or the terminal device signs the identity of the communication apparatus and the second key according to the shared key between the terminal device and the operator to obtain the first signature. Optionally, the first signature can be used by the mobile network to verify whether the second key is authentic. When the first signature is verified, the mobile network determines that the second key is authentic. When the mobile network verifies that the second key is authentic, the mobile network can use the second key to authenticate the communication apparatus, or the mobile network uses the second key to encrypt the first key.

[0340] S401: The access and mobility management function network element sends a first request to the first network element.

[0341] For example, the first request is used to request to issue a first key for the communication apparatus. Optionally, the first request is used to request to issue a first identity corresponding to the first key for the communication apparatus.

[0342] Optionally, the first request includes the identity of the communication apparatus, and optionally, the first request includes the terminal identity. Optionally, the first request further includes the second key and the first signature obtained in S400.

[0343] S402: The first network element generates the first key.

[0344] Optionally, the first network element can also generate the first identity.

[0345] The first key and the first identity can refer to the description of step S200 of FIG. 2(a).

[0346] Optionally, in response to the first request, the first network element generates the first key or the first identity.

[0347] Optionally, the first request received by the first network element contains the first signature, and the first network element verifies the first signature before generating the first key or the first identity. After the first signature is verified, the first network element generates the first key or the first identity. If the verification fails, the process of S402 and the following steps is terminated. For example, the first network element obtains the shared key between the terminal device and the operator according to the user number or the SUPI. For example, the shared key between the terminal device and the operator is stored in the subscription database, and the first network element can query the shared key from the subscription database according to the user number or the SUPI. Then, the first network element verifies the first signature received in step S401 using the shared key between the terminal device and the operator. If the verification is passed, the step S402 and the following steps are continued to be executed; otherwise, the step S402 and the following steps are terminated to be executed.

[0348] For example, the first network element can verify the first signature in the following manner.

[0349] In one implementation, the first network element uses the shared key between the terminal device and the operator to decrypt the first signature received in step S401 to obtain the second key; if the first signature is generated by the terminal device based on the second key and the identity of the communication apparatus, the first network element uses the shared key between the terminal device and the operator to decrypt the first signature received in step S401 to obtain the second key and the identity of the communication apparatus. The first network element compares the decrypted second key (or the second key and the identity of the communication apparatus) with the second key (or the second key and the identity of the communication apparatus) received in step S401. If the second key (or the second key and the identity of the communication apparatus) obtained by decrypting the first signature is the same as the second key (or the second key and the identity of the communication apparatus) received in step S401, it is determined that the first signature is verified; otherwise, it is determined that the first signature is not verified.

[0350] In another implementation, the first network element uses the shared key between the terminal device and the operator to sign the second key (or sign the second key and the identity of the communication apparatus) to obtain a second signature. The first network element compares the calculated second signature with the first signature received in step S401. If the second signature is consistent with the first signature, it is determined that the first signature is verified; otherwise, it is determined that the first signature is not verified.

[0351] For example, after the first signature is verified, the first network element generates the first key or the first identity. That is, after the first signature is verified, the first network element generates the first key or the first identity.

[0352] Optionally, the first network element verifies the association relationship between the communication apparatus and the terminal device. When the communication apparatus is not associated with any terminal device, the first network element generates the first key or the first identity, otherwise, the execution of step S402 and the following steps is terminated. The step of the first network element generating the first key or the first identity and the step of the first network element verifying the association relationship between the communication apparatus and the terminal device are referred to step S202 of FIG. 2(a).

[0353] Optionally, the first network element verifies both the association relationship between the communication apparatus and the terminal device and the first signature. When the association relationship between the communication apparatus and the terminal device and the first signature are verified, the first network element generates the first key or the first identity, otherwise, the execution of step S402 and the following steps is terminated.

[0354] Optionally, the first network element can directly execute the step of generating the first key or the first identity in step S202 of FIG. 2(a) without verifying the first signature.

[0355] Optionally, the first network element can take the identity of the communication apparatus as the first identity.

[0356] S403: The first network element stores the first key. The implementation of this step is referred to step S203 of FIG. 2(a), and thus is not described here.

[0357] S404: The first network element sends a first response to the access and mobility management function network element. The implementation of this step is referred to step S204 of FIG. 2(a), and thus is not described here.

[0358] S405: The access and mobility management function network element sends a response of the request 4a to the terminal device. The implementation of this step is referred to step S205 of FIG. 2(a), and thus is not described here.

[0359] S406: The communication apparatus sends a request 4b to the first network element.

[0360] For example, the request 4b is used to request the mobile network to send the first key to the communication apparatus. Optionally, the request 4b carries an identity of the communication apparatus.

[0361] For example, the communication apparatus sends the request 4b to the access gateway, and the access gateway forwards the request 4b to the first network element.

[0362] S407: The first network element authenticates the communication apparatus.

[0363] Optionally, the first network element performs EAP authentication on the communication apparatus through the access gateway. For example, the first network element sends challenge information to the communication apparatus, wherein the challenge information comprises first authentication information. The first authentication information can be a time stamp corresponding to a certain moment before the challenge authentication is initiated, or the first authentication information can be a random number. For example, the moment can be any moment within a specified time before the first network element sends the challenge information (for example, the moment can be any moment within 10 minutes before the first network element sends the challenge information). The communication apparatus generates challenge response information by using a private key corresponding to the second key and the received first authentication information, and then sends the challenge response information to the first network element. The first network element verifies the challenge response information received from the communication apparatus using the second key received from step S401, and if the verification is passed, it confirms that the communication apparatus is legal and continues the process of S407 and the following steps, otherwise, it terminates the subsequent process. The process of the EAP authentication performed by the first network element and the communication apparatus can be referred to step S206d of FIG. 2(a), and thus is not described here.

[0364] Optionally, the first network element can also authenticate the communication device by the following method. For example, the first network element sends challenge information to the communication device, wherein the challenge information comprises the first authentication information. The communication device signs the received first authentication information using the private key corresponding to the second key to obtain a second signature. Then, the communication device sends the second signature to the first network element. The first network element verifies the second signature received from the communication device using the second key received from step S401. For example, the first network element verifies the second signature using the second key in two ways as described in step S307d of FIG. 3, which will not be described herein again. If the second signature is verified, it is confirmed that the communication device is legal, and the process continues from step S407 and the following steps. Otherwise, the subsequent process is terminated.

[0365] Optionally, the first network element obtains the first key or the first identifier according to the identifier of the communication device received in step S406. For example, the first network element queries a subscription database according to the identifier of the communication device to obtain the first identifier or the first key, or the first network element stores the first identifier or the first key, and the first network element obtains the first identifier or the first key stored in the first network element according to the identifier of the communication device. Optionally, if the first identifier or the first key is successfully obtained, the process continues from step S407 and the following steps. Otherwise, the subsequent process is terminated.

[0366] By this method, the first network element can perform authentication of the communication device on the premise that the first key is determined to be stored. If the first key does not exist, the first network element does not need to authenticate the communication device, and thus network resources can be saved.

[0367] S408: The first network element encrypts the first key using the second key.

[0368] For example, the first network element encrypts the first key using the second key. Optionally, the first network element can also encrypt the first identifier using the second key.

[0369] Optionally, the first network element can also obtain the first key or the first identifier according to the identifier of the communication device received in step S406 at this step, that is, the first network element does not obtain the first key or the first identifier in step S407, and the method of obtaining the first key or the first identifier according to the identifier of the communication device by the first network element is as described in step S407.

[0370] Optionally, the first network element can not encrypt the first key using the second key in step S408. For example, the first network element can also send the unencrypted first key or first identifier and the second key to the access gateway, and the access gateway encrypts the first key or the first identifier using the second key.

[0371] S409: The first network element sends a response to the request 4b to the access gateway.

[0372] For example, the response to the request 4b carries the encrypted first identity and the first key, or the response to the request 4b carries the encrypted first key and the unencrypted first identity, or if the first identity is not generated by the first network element, the response to the request 4b carries the encrypted first key.

[0373] Optionally, if the first key or the first identity is not encrypted by the first network element, the first network element can send the unencrypted first key or the first identity and the second key to the access gateway.

[0374] S4010: The access gateway forwards the response to the request 4b received in S409 to the communication device.

[0375] For example, the access gateway forwards the encrypted first identity and the first key, or forwards the encrypted first key and the unencrypted first identity. Or if the first identity is not generated by the first network element, the access gateway forwards only the encrypted first key.

[0376] Optionally, if the first key or the first identity is not encrypted by the first network element, the access gateway receives the second key and the first key or the first identity from the first network element, and the access gateway encrypts the first key or the first identity using the second key. The access gateway sends the encrypted first key or the first identity to the communication device.

[0377] S4011: The communication device decrypts the first key.

[0378] For example, the communication device decrypts the information received in S4010 using the private key corresponding to the second key to obtain the first key or the first identity.

[0379] For example, the communication device saves the decrypted first key, and optionally, the communication device saves the first identity. For example, the communication device writes the first key or the first identity into the TEE. Or if the communication device does not have a hardware TEE, the communication device writes the first identity and the first key into a software form of TEE (for example, a software security reinforcement unit).

[0380] The above steps describe the process of the terminal device requesting the first key for the communication device. The first network element generates the first key for the communication device, and then transmits the first key to the communication device. The communication device can register to the mobile network using the first identity and the first key. The process of the communication device registering to the mobile network using the first identity and the first key can refer to the steps described in FIG. 2(b) or FIG. 2(c). In combination with FIG. 4 and FIG. 2(b), or FIG. 4 and FIG. 2(c), the communication device can register to the mobile network independently of the terminal device using the first identity and the first key.

[0381] FIG. 5 is another signaling interaction diagram of a method of mobile network registration according to an embodiment of the present application. The method shown in FIG. 5 also involves a subscription server, for example, the subscription server 109 in FIG. 1. The implementation process of this embodiment will be described below in conjunction with FIG. 2(a), FIG. 3 and FIG. 4. Different from the schemes described in FIG. 2(a), FIG. 3 and FIG. 4, in the scheme described in FIG. 5, the first key is generated by the communication apparatus and sent to the first network element. The first network element can use the first key to authenticate the communication apparatus in the process of the communication apparatus requesting to register to the mobile network.

[0382] S500: The terminal device sends a request 5a to the subscription server.

[0383] For example, before sending the request 5a, the communication apparatus generates the first key and the corresponding private key. For example, the communication apparatus generates a public key and the corresponding private key. The public key is used as the first key, which can be used to authenticate the communication apparatus in the process of the communication apparatus requesting to register to the mobile network, and the private key corresponding to the first key (the public key) is held by the communication apparatus. Optionally, the terminal device authenticates the private key corresponding to the first key. For example, the terminal device obtains the identity of the communication apparatus and the first key generated by the communication apparatus. After obtaining the first key, the terminal device verifies the private key corresponding to the first key according to the first key. For example, the terminal device sends first authentication information to the communication apparatus, the communication apparatus signs the first authentication information using the private key corresponding to the first key, and the communication apparatus sends the signature of the first authentication information and the first authentication information to the terminal device. The first authentication information can be a timestamp corresponding to a certain time before sending the request 5a, or the first authentication information can be a random number. For example, the time can be any time within a specified time before the communication apparatus sends the request 5a (for example, the time can be any time within 10 minutes before the communication apparatus sends the request 5a). The terminal device verifies the signature using the first key, and if the signature is verified, it can be determined that the communication apparatus holds the private key corresponding to the first key. The terminal device can refer to FIG. 3 step S307d or FIG. 4 step S402 for the way of verifying the signature using the first key, which will not be described here.

[0384] For example, the first request is used to request the mobile network to authenticate the first key. Optionally, the request 5a is used to request to issue a first identity for the communication apparatus.

[0385] For example, the first signature is obtained by the terminal device signing the first key using the shared key with the operator. Alternatively, the first signature can also be obtained by the terminal device signing the first key and the identity of the communication apparatus using the shared key with the operator. If the first signature is obtained by the terminal device signing the first key and the identity of the communication apparatus, the request 5a further carries the identity of the communication apparatus. Alternatively, the request 5a can further carry the terminal identity.

[0386] For example, the terminal device sends the request 5a to the subscription server through a user plane connection. For example, the terminal device registers to the mobile network, establishes a PDU session with a user plane function network element, and accesses the subscription server of the operator through the user plane connection.

[0387] S501: The subscription server sends a first request to the first network element.

[0388] Alternatively, the first request is used to request the mobile network to authenticate the first key. The first request carries the first key carried by the request 5a in S500. Alternatively, the first request further carries the first signature carried by the request 5a in S500. Alternatively, if the first signature is obtained by the terminal device signing the first key and the identity of the communication apparatus, the first request further carries the identity of the communication apparatus. Alternatively, the first request can further carry the terminal identity.

[0389] Alternatively, the first request is further used to request to issue the first identity for the communication apparatus.

[0390] S502: The first network element authenticates the first key.

[0391] For example, in response to the first request, the first network element authenticates the first key. For example, after receiving the first request, the first network element verifies the first signature of the first key, and determines that the first key is trusted after the first signature verification passes. If the first signature verification fails, it is determined that the first key is untrusted, and the process of S502 and the following processes is terminated. For example, the first network element obtains the shared key of the terminal device with the operator from a subscription database according to the terminal identity (e.g., user number or SUPI). Then, the first network element verifies the first signature received in step S500 using the shared key of the terminal device with the operator, and if the verification passes, it continues to execute the steps of S502 and the following steps, otherwise it stops the execution of the subsequent steps. For example, the method of verifying the first signature can refer to step S307d of FIG. 3 or step S402 of FIG. 4, which will not be described here.

[0392] Alternatively, the first network element can directly use the first key to authenticate the communication apparatus in the process of requesting the communication apparatus to register to the mobile network, that is, the first network element does not need to authenticate whether the first key is trusted.

[0393] Optionally, the first network element generates the first identity. For example, the first network element generates the first identity in response to the first request. Optionally, the first network element generates the first identity after the first signature verification is passed. For example, the first network element performs the step of generating the first identity in step S202 of FIG. 2(a) after the first signature verification is passed. That is, the first network element generates the first identity after the first signature verification is passed. Alternatively, the first network element continues to verify the association between the communication apparatus and the terminal device after the first signature verification is passed. When the communication apparatus is not associated with any terminal device, the first network element generates the first identity. Otherwise, the first network element terminates the execution of step S502 and the following steps. The step of generating the first identity by the first network element and the step of verifying the association between the communication apparatus and the terminal device by the first network element are described in step S202 of FIG. 2(a) and will not be repeated here.

[0394] Optionally, the first network element can directly perform the step of generating the first identity in step S202 of FIG. 2(a) without verifying the first signature.

[0395] Optionally, the first network element can also use the identity of the communication apparatus as the first identity.

[0396] S503: The first network element stores the first key. The same as step S203 of FIG. 2(a) and will not be repeated here.

[0397] S504: The first network element sends a first response to the subscription server.

[0398] Optionally, the first response is used to indicate whether the first key is authenticated. Optionally, the first response is used to indicate whether the first identity is issued successfully. If the first identity is issued successfully, the first response carries the first identity.

[0399] S505: The subscription server sends a response to request 5a to the terminal device.

[0400] Optionally, the response to request 5a is used to indicate whether the first key is authenticated by the mobile network. After the first key is authenticated by the mobile network, the first network element and the communication apparatus can use the first key to authenticate the communication apparatus in the process of registering the communication apparatus to the mobile network. If the first key is not authenticated, the first key is considered untrusted, and the first network element and the communication apparatus cannot use the first key to authenticate the communication apparatus in the process of registering the communication apparatus to the mobile network.

[0401] Optionally, the response to request 5a is also used to indicate whether the first identity is issued successfully. If the first identity is issued successfully, the response to request 5a carries the first identity.

[0402] S506: The terminal device imports the first identity into the communication apparatus.

[0403] For example, if the response of the request 5a carries the first identity, the terminal device sends the first identity to the communication device. Specifically, the first identity can be imported to the communication device (e.g., a camera, a printer, etc.) through a near field communication method such as Bluetooth, or the user logs in the communication device (e.g., a communication assistant) through a mobile phone using a public cloud account and password to import the first identity to the communication device.

[0404] The steps of the above Fig. 5 describe the process of the communication device obtaining the first key. The communication device generates the first key and sends the first key to the first network element through the terminal device. The communication device and the first network element can use the first key to authenticate the communication device in the process of the communication device requesting to register to the mobile network. The process of the communication device registering to the mobile network using the first identity and the first key can refer to the steps described in Fig. 2(b) or Fig. 2(c). Since the communication device and the first network element hold asymmetric keys in the flow described in Fig. 5, i.e., the first network element holds the first key and the communication device holds the private key corresponding to the first key, the EAP authentication process between the communication device and the first network element in the registration process is different from the steps described in Fig. 2(b) or Fig. 2(c). For example, the first network element sends challenge information to the communication device, the communication device uses the private key corresponding to the first key to respond to the challenge information of the first network element, and the first network element verifies the response information from the terminal device using the first key. For example, for the EAP authentication process in S2015 in Fig. 2(b), the first network element sends challenge information to the communication device, the communication device uses the private key corresponding to the first key to respond to the challenge information of the first network element, and returns the response information to the first network element. Similarly, for the EAP authentication process in Fig. 2(c), the communication device uses the private key corresponding to the first key to respond to the challenge information of the first network element, and returns the response information to the first network element.

[0405] The method described in Fig. 5 in combination with Fig. 2(b), or Fig. 2(c) realizes that the communication device registers to the mobile network using the first key independently of the terminal device. In the method described in Fig. 5, the first key is generated by the communication device and sent to the first network element. The process of the mobile network issuing the first key to the communication device is simplified, and network resources are saved.

[0406] It can be understood that although Fig. 2(a), Fig. 3, Fig. 4, and Fig. 5 introduce several different methods for registering to the mobile network, different permutations and combinations can be made for a specific step in the method, which is not limited herein.

[0407] FIG. 6 is a signaling interaction diagram of a method of mobile network registration according to an embodiment of the present application. FIG. 6 describes a process of revoking the first key by the terminal device. For example, the terminal device determines that it is no longer associated with the communication apparatus, and the terminal device can request the mobile network to revoke the first key. For example, the user determines to stop using the service of the communication assistant, and the user can request the mobile network to revoke the first key issued for the communication assistant through the terminal device. For another example, the user determines that the camera or the printer is not needed to be registered to the mobile network, and the user can also request the mobile network to revoke the first key issued for the camera or the printer through the terminal device. It should be noted that the first key issued through the processes shown in FIG. 2(a), FIG. 3, FIG. 4, and FIG. 5 can be revoked through the process shown in FIG. 6.

[0408] The process of revoking the first key is described below.

[0409] S600: The terminal device sends a request 6a to the second network element.

[0410] For example, the request 6a is used to request the mobile network to revoke the first key of the communication apparatus. For example, the second network element can be the access and mobility management function network element 106 in FIG. 1. For example, the first key can be issued by the first network element for the communication apparatus, for example, the first key can be issued by the first network element for the communication apparatus through the method described in FIG. 2(a), FIG. 3, and FIG. 4.

[0411] Optionally, the request 6a carries the identifier of the communication apparatus and the terminal identifier, for example, the terminal identifier can be the SUCI or the GUTI of the terminal device. Optionally, the method of obtaining the identifier of the communication apparatus by the terminal device is described in step S200 of FIG. 2(a).

[0412] Optionally, if the mobile network has issued the first identifier for the communication apparatus, the request 6a is also used to request the mobile network to revoke the first identifier of the communication apparatus.

[0413] S601: The second network element sends a request 6b to the first network element.

[0414] For example, the request 6b is used to request to revoke the first key of the communication apparatus. Optionally, the request 6b carries the identifier of the communication apparatus and the terminal identifier (for example, the user number or the SUPI). For example, the second network element decrypts the SUCI received in S600 to obtain the SUPI of the terminal device. Alternatively, the second network element obtains the SUPI of the terminal device according to the GUTI. Optionally, the second network element can also obtain the user number from the subscription database using the SUPI.

[0415] S602: The first network element verifies the association relationship between the identifier of the communication apparatus and the terminal identifier.

[0416] For example, the first network element queries the association between the identifier of the communication apparatus and the user number / SUPI according to the identifier of the communication apparatus received in S601. If the query result indicates that the identifier of the communication apparatus and the user number / SUPI received in S601 have already been associated, that is, the communication apparatus has been associated with the terminal device, the first network element continues the subsequent first key revocation process, otherwise, the first network element stops S602 and the subsequent steps.

[0417] S603: The first network element deletes the first key.

[0418] Optionally, the first network element also deletes the first identifier. Optionally, the first network element deletes the first identifier from the subscription database.

[0419] Optionally, the first network element deletes the first key from the subscription database. Optionally, the first network element also deletes the association between the identifier of the communication apparatus and the terminal identifier (for example, the user number or the SUPI) from the subscription database.

[0420] If the first network element stores the association between the identifier of the communication apparatus and the terminal identifier (for example, the user number or the SUPI), the first network element deletes the above association.

[0421] S604: The first network element sends a response to the request 6b to the second network element.

[0422] For example, the response to the request 6b carries the SUPI. The response to the request 6b is also used to indicate that the revocation of the first key is successful.

[0423] S605: The second network element sends a response to the request 6a to the terminal device.

[0424] For example, the response to the request 6a is used to indicate that the revocation of the first key is successful.

[0425] S606: The communication apparatus sends a first registration request to the access gateway.

[0426] For example, the first registration request is used for the communication apparatus to request registration to the mobile network. Optionally, the first registration request carries the first identifier.

[0427] S607: The access gateway sends a first authentication request to the first network element.

[0428] For example, the first authentication request is used to request the mobile network to authenticate the communication apparatus, and the first authentication request carries the first identifier.

[0429] S608: The first network element queries the first identifier.

[0430] For example, the first network element receives the first authentication request, and queries whether the first network element or the subscription database stores the first identifier according to the first identifier carried in S607. If the first identifier is not queried, it is determined that the first key corresponding to the first identifier has been revoked, or it is determined that the first key corresponding to the first identifier has been deleted from the first network element or the subscription database.

[0431] S609: The first network element sends a first authentication request response to the access gateway.

[0432] For example, the first authentication request response is used to indicate that the first identifier is invalid, or the first identifier has been revoked, or the first key corresponding to the first identifier is invalid.

[0433] S6010: The access gateway sends a first registration request response to the communication device.

[0434] For example, the first registration request response is used to indicate that the registration to the mobile network fails, or the first key or the first identifier is invalid, or the first key or the first identifier has been revoked.

[0435] In another implementation, the second network element receiving the request 6a in step S600 is the subscription server 109 in FIG. 1. For example, the first key can be generated by the communication device and then sent to the first network element, for example, the communication device generates the first key through the process described in FIG. 5 and sends the first key to the first network element.

[0436] For example, the request 6a is used to request the mobile network to revoke the first key of the communication device. Optionally, if the mobile network issues the first identifier to the communication device, the request 6a is also used to request the mobile network to revoke the first identifier of the communication device.

[0437] For example, the mobile network revokes the first key or the first identifier of the communication device according to the steps described in S601-S6010.

[0438] Through the method, the terminal device can control the revocation of the first key or the first identifier of the communication device, thereby supporting the user to flexibly control the communication device (such as the communication assistant and the camera and the printer) to enter and exit the network.

[0439] It should be noted that the application does not limit the device or method for initiating the request for revoking the first key, for example, the device can be a terminal device, or other devices that can be registered to a mobile network. Alternatively, the request for revoking the first key can also be initiated by other methods. For example, a user requests to revoke the first key of the communication device through an operator portal, or requests to revoke the first identity of the communication device. Illustratively, the user logs in to the operator portal and requests to revoke the first key or the first identity of the communication device. When the user requests the mobile network to revoke the first key or the first identity of the communication device through the operator portal, the mobile network can obtain the identity of the communication device by the user inputting the identity of the communication device on the operator portal.

[0440] FIG. 7 is a signaling interaction diagram of a mobile network registration method provided by an embodiment of the application. The implementation process of the embodiment shown in FIG. 7 is described below in combination with FIGS. 2(a) to 4.

[0441] S700: The first network element receives a first request.

[0442] For example, the first request is used by a terminal device to request the mobile network to issue a first key for a communication device, wherein the communication device does not have a user identification module, and the terminal device has a user identification module. The first key is used for the mobile network and the communication device to authenticate the communication device in a process in which the communication device requests to register to the mobile network. For example, the first network element can be the device management network element 104 in FIG. 1. For example, the first request can be the first request in step S201 in FIG. 2(a), or the first request in step S301 in FIG. 3, or the first request in step S401 in FIG. 4. For example, the first network element receives the first request from the terminal device through an access and mobility management function network element.

[0443] S701a: In response to the first request, the first network element generates a first key for the communication device.

[0444] For example, the process in which the first network element generates the first key can refer to step S202 in FIG. 2(a), or step S402 in FIG. 4, which is not described herein again.

[0445] S702: The first network element sends the first key to the communication device.

[0446] For example, the first network element sends the first key to the communication device through an access gateway. For example, the first network element sends the first key to the access gateway, and the access gateway sends the first key to the communication device. Correspondingly, the communication device receives the first key. For example, the process can refer to step S209 in FIG. 2(a), or step S309 in FIG. 3, or steps S409-S4011 in FIG. 4.

[0447] S703b: The first network element receives a request for authenticating the communication device.

[0448] For example, in the process of the communication device requesting to register to the mobile network, the first network element receives a request for authenticating the communication device, the request including a first identity, the first identity being used to uniquely identify the communication device in the mobile network, and the connection between the communication device and the mobile network not passing through the terminal device. The connection between the communication device and the mobile network not passing through the terminal device means that the communication device accesses the mobile network through a network shared by the terminal device, or in other words, the data exchanged between the communication device and the mobile network does not pass through the terminal device.

[0449] For example, as shown in step S703a, the communication device sends a request for registering to the mobile network to the access gateway, and correspondingly, the access gateway receives the request for registering to the mobile network, wherein the request for registering to the mobile network carries the first identity. This implementation can refer to step S2013 of FIG. 2(b) or step S2030 of FIG. 2(c). After receiving the request for registering to the mobile network from the communication device, the access gateway sends a request for authenticating the communication device to the first network element, and correspondingly, the first network element receives the request for authenticating the communication device from the access gateway. For example, the request for authenticating the communication device is used to request the first network element to authenticate the communication device. Optionally, the request for authenticating the communication device carries the first identity. This implementation can refer to step S2014 of FIG. 2(b) or step S2031 of FIG. 2(c).

[0450] S704: The first network element generates first information.

[0451] For example, the first network element generates the first information according to the first key of the communication device corresponding to the first identity. The first information is used to authenticate the communication device. For example, the first network element obtains the first key of the communication device corresponding to the first identity according to the first identity received in step S703, for example, the first network element queries the first key stored in the first network element or the subscription database according to the first identity. After obtaining the first key, the first network element generates the first information. For example, the first network element generates the first information according to the first key, authentication information and a first algorithm, wherein the authentication information is a random number or a time stamp corresponding to the time when the first information is generated. The first algorithm is an algorithm pre-configured for the first network element to generate the first information. For example, the first information can be an authentication expected response. The implementation method of this step can refer to step S2015 of FIG. 2(b) or step S2032 of FIG. 2(c).

[0452] S705b: The first network element receives second information from the communication device.

[0453] For example, the first network element receives second information from the communication device. For example, the second information is used to authenticate the communication device. For example, as shown in S705a, the communication device generates the second information according to the first key. For example, the communication device generates the second information according to the first key, the authentication information received from S704 and a first function, wherein the first function is a function pre-configured for the communication device to generate the second information. The first function is the same as the first function in S704. The communication device sends the second information to the first network element, and correspondingly, the first network element receives the second information.

[0454] The implementation manner of the process of authenticating the communication device by the first network element and the communication device using the first key can refer to S2015 in FIG. 2(b) or S2032 in FIG. 2(c), which will not be repeated here.

[0455] S705c: The first network element authenticates the communication device according to the first information and the second information.

[0456] For example, the first network element determines whether the communication device passes the authentication according to whether the first information and the second information are consistent, and the authentication result of the communication device is used to accept or reject the request of the communication device to register to the mobile network. For example, the first network element authenticates the communication device according to the second information after receiving the second information. For example, the first network element compares whether the first information and the second information are consistent, and if the first information and the second information are consistent, it is determined that the communication device passes the authentication, otherwise, it is determined that the communication device does not pass the authentication. The authentication result of the communication device by the mobile network is used for the mobile network to decide to accept or reject the request of the communication device to register to the mobile network. For example, if the communication device passes the authentication, the request of the communication device to register to the mobile network is accepted, otherwise, the request of the communication device to register to the mobile network is rejected. The implementation manner of the process of authenticating the communication device by the first network element and the communication device using the first key can refer to S2015 in FIG. 2(b) or S2032 in FIG. 2(c), which will not be repeated here.

[0457] Through the above implementation manner of FIG. 7, the first network element generates the first key for the communication device and sends the first key to the communication device. The communication device can use the first key to pass the authentication of the mobile network. The device without the user identification module is realized to register to the mobile network independently of the terminal device (the device with the user identification module).

[0458] In one implementation manner, the first network element generates the first key for the communication device when the communication device is not associated with any terminal device. For example, the first network element determines whether the communication device has been associated with other terminal devices before generating the first key, and generates the first key for the communication device when the communication device is not associated with other terminal devices.

[0459] For example, the first request can carry the identity of the communication apparatus, and optionally, the first request can also carry the identity of the terminal. For example, the first network element queries whether the identity of the communication apparatus is associated with the identity of the terminal according to the identity of the communication apparatus. If the first network element does not query that the identity of the communication apparatus is associated with the identity of the terminal, it is considered that the communication apparatus is not associated with other terminal devices, and the first network element generates the first key for the communication apparatus. Otherwise, the first key is not generated. This implementation manner can refer to step S202 in FIG. 2(a).

[0460] The verification of the communication apparatus not being associated with other terminal devices before the first network element generates the first key can ensure that the communication apparatus is only associated with one terminal device. That is, the communication apparatus only provides services for a unique user, avoiding a communication apparatus serving multiple users, thereby avoiding user privacy leakage.

[0461] In an implementation manner, the first network element verifies the first signature from the terminal device according to the shared key of the terminal device and the operator, and generates the first key for the communication apparatus after the first signature verification is passed. For example, the first network element verifies the first signature carried in the first request before generating the first key. For example, the first signature can be generated by the terminal device according to the shared key of the terminal device and the operator. Optionally, if the first network element receives the first signature from the terminal device, the first network element verifies the first signature according to the shared key of the terminal device and the operator before generating the first key, and generates the first key after the first signature verification is passed. The implementation manners of verifying the first signature and generating the first key can refer to step S402 in FIG. 4.

[0462] In an implementation manner, the first request is also used to request the mobile network to issue a first identity for the communication apparatus, and the first identity is used to uniquely identify the communication apparatus in the mobile network.

[0463] Optionally, as shown in step S701b, the first network element also generates a first identity capable of uniquely identifying the communication apparatus, and the description of the first identity can refer to step S200 in FIG. 2(a).

[0464] Optionally, in response to the first request, the first network element generates a first identity for the communication apparatus, and the first network element sends the first identity to the communication apparatus.

[0465] Optionally, when the communication apparatus is not associated with any terminal device, the first network element generates a first identity for the communication apparatus, and the first network element sends the first identity to the communication apparatus. This implementation manner can refer to step S202 in FIG. 2(a).

[0466] Optionally, the first network element verifies the first signature from the terminal device according to the shared key between the terminal device and the operator, and generates the first identity for the communication apparatus after the first signature verification is passed. The first network element sends the first identity to the communication apparatus. This implementation manner can refer to step S402 in FIG. 4.

[0467] The first identity can be used for managing the communication apparatus by the mobile network. For example, the mobile network can uniquely determine the communication apparatus corresponding to the first identity through the first identity. The mobile network can also obtain information of the communication apparatus through the first identity, for example, the first key can be queried according to the first identity. For example, the mobile network can also obtain information such as the country, the manufacturer or the operator to which the communication apparatus belongs through the first identity. The mobile network can also verify whether the registration request is issued by a legitimate communication apparatus based on the identity carried in the registration request. For example, the mobile network verifies whether the value of each field of the identity is legal. If the value of a field in the first identity is illegal, it is determined that the communication apparatus is illegal, and the mobile network can reject the registration request. This manner can preliminarily filter the illegal registration request, and save network resources.

[0468] Optionally, the first network element can take the identity of the communication apparatus as the first identity, wherein the identity of the communication apparatus refers to the identity of the communication apparatus assigned by the manufacturer.

[0469] In one implementation manner, the first network element stores the first key. Optionally, if the first network element generates the first identity, the first network element stores the first identity. The first network element can also store the association relationship between the communication apparatus and the terminal device. For example, the first network element can store the first identity or the first key in the first network element, and optionally, the first network element can also store the association relationship between the identity of the communication apparatus and the terminal identity in the first network element. Alternatively, the first network element can send the first identity or the first key to the subscription database, which is stored by the subscription database. Similarly, the first network element can also send the association relationship between the identity of the communication apparatus and the terminal device to the subscription database, which is stored by the subscription database. This implementation manner can refer to step S203 in FIG. 2(a) or step S403 in FIG. 4.

[0470] The mobile network stores the association relationship between the identity of the communication apparatus and the terminal identity, and the first network element can determine whether the communication apparatus has been associated with other terminal devices according to the association relationship before generating the first identity or the first key. This method can ensure that the communication apparatus is associated with a unique terminal device, and avoid user privacy leakage. In addition, the first network element (or the subscription database) stores the first identity and the first key, and in the process of requesting the registration to the mobile network by the communication apparatus, the first network element can query the first key through the first identity, so as to complete the authentication of the communication apparatus by the mobile network by using the first key.

[0471] In one implementation, the first key is sent to the communication device via a secure transmission. For example, the first network element sends the first key to the communication device via a secure transmission channel.

[0472] Optionally, before sending the first key to the communication device via the secure transmission channel, the first network element obtains a second key, which is used to encrypt the first key. Correspondingly, the communication device obtains the second key or a private key corresponding to the second key, which is used to decrypt the first key encrypted by the mobile network. For example, the first network element and the communication device can obtain the second key in the following manner.

[0473] In one implementation, the first network element generates the second key according to a key pre-configured for the communication device. For example, the first network element generates the second key according to a key pre-configured by a vendor of the communication device. The implementation of generating the second key can refer to step S206e of FIG. 2(a). Optionally, after generating the second key, the first network element sends the second key to the access gateway. The implementation of the first network element sending the second key to the access gateway can refer to step S206f of FIG. 2(a). Optionally, the communication device generates the second key according to a key pre-configured for the communication device. For example, the communication device generates the second key according to a key pre-configured by a vendor of the communication device. The implementation of generating the second key can refer to step S207 of FIG. 2(a). Optionally, the first network element and the communication device can generate the first integrity protection key using a key pre-configured by a vendor of the communication device. The implementation of generating the first integrity protection key can refer to step S206e or step S207 of FIG. 2(a). Optionally, after generating the first integrity protection key, the first network element sends the first integrity protection key to the access gateway. The implementation of the first network element sending the first integrity protection key to the access gateway can refer to step S206f of FIG. 2(a), which is not described herein again.

[0474] Optionally, the first network element and the communication device can also generate the second key (or the first integrity protection key) using other keys, that is, it is not limited that the first network element and the communication device generate the second key (or the first integrity protection key) using a key pre-configured for the communication device. The first network element and the communication device generate the second key (or the first integrity protection key) using the same key and algorithm.

[0475] In an implementation, the first network element generates the second key according to the shared key between the terminal device and the operator. The implementation of generating the second key can refer to step S307e in FIG. 3. Optionally, after generating the second key, the first network element sends the second key to the access gateway. The implementation of the first network element sending the second key to the access gateway can refer to step S307f in FIG. 3. Optionally, the communication apparatus receives the second key from the terminal device, which is generated by the terminal device according to the shared key between the terminal device and the operator. For example, the implementation of the terminal device generating the second key can refer to step S306 or S300 in FIG. 3. Optionally, the first network element or the terminal device can generate the first integrity protection key using the shared key. The implementation of the process can refer to step S307e in FIG. 3, or step S306 or S300, which will not be described herein. Optionally, the first network element sends the generated first integrity protection key to the access gateway, and the implementation of the process can refer to step S307f in FIG. 3.

[0476] Optionally, the first network element and the terminal device can also generate the second key (or the first integrity protection key) using other keys, that is, the first network element and the terminal device are not limited to generating the second key (or the first integrity protection key) using the shared key between the terminal device and the operator. The first network element and the terminal device generate the second key (or the first integrity protection key) using the same key and algorithm.

[0477] In an implementation, the first network element receives the second key from the terminal device. For example, the first network element receives the second key from the first request. For example, the second key is a key pre-configured for the communication apparatus by the manufacturer of the communication apparatus, for example, the second key can be a public key configured for the communication apparatus by the manufacturer of the communication apparatus. Optionally, the first network element authenticates the second key from the terminal device, for example, the first network element receives a signature corresponding to the second key from the terminal device. For example, the signature corresponding to the second key can be the first signature carried in the first request. The first network element verifies the first signature from the terminal device according to the shared key between the terminal device and the operator, and determines that the second key passes the authentication after the first signature verification. The implementation of the first network element receiving the second key and verifying the second key can refer to steps S401 and S402 in FIG. 4. Optionally, the communication apparatus obtains a private key corresponding to the second key. For example, the second key is a public key configured for the communication apparatus by the manufacturer of the communication apparatus, the first network element holds the public key as the second key, and the communication apparatus holds a private key corresponding to the public key (the second key). The second key is used to encrypt the first key, and the private key corresponding to the second key is used to decrypt the first key encrypted using the second key.

[0478] After obtaining the second key, the first network element sends the first key to the communication apparatus through a secure transmission channel.

[0479] In one implementation, the first network element sends the first key to the access gateway. The access gateway encrypts the first key using the second key, and then sends the encrypted first key to the communication device, where the second key can be obtained by any of the above-mentioned ways. Correspondingly, the communication device receives the encrypted first key. The communication device decrypts the encrypted first key using the second key. This implementation can refer to step S209 of FIG. 2. Optionally, the communication device can also decrypt the encrypted first key using the private key corresponding to the second key.

[0480] Optionally, the access gateway and the communication device can also verify the integrity of the first key using the first integrity protection key. The process of verifying the integrity of the first key by the access gateway and the communication device using the first integrity protection key can refer to step S209 of FIG. 2, which will not be described herein.

[0481] In one implementation, the first network element encrypts the first key using the second key, and sends the encrypted first key to the access gateway. The second key can be obtained by any of the above-mentioned ways. The access gateway sends the encrypted first key to the communication device. Correspondingly, the communication device receives the encrypted first key. The communication device decrypts the encrypted first key using the second key. Optionally, the first network element and the communication device can also verify the integrity of the first key using the first integrity protection key. The process of verifying the integrity of the first key by the first network element and the communication device can refer to step S209 of FIG. 2, which will not be described herein. Optionally, the communication device can also decrypt the encrypted first key using the private key corresponding to the second key. This implementation can refer to steps S408-S4011 of FIG. 4.

[0482] This method can ensure that the first key is securely sent to the communication device, avoiding the first key being obtained by an illegal user in the process of the first network element sending the first key to the communication device. Thus, the illegal user is avoided from registering to the mobile network using the first key.

[0483] In one implementation, if the first network element also generates the first identifier, the first network element sends the first identifier to the communication device. For example, the first network element sends the first identifier to the communication device through the access gateway. Optionally, the first network element can also send the first identifier to the communication device through secure transmission. This implementation can refer to step S209 of FIG. 2, or refer to steps S408-S4011 of FIG. 4, which will not be described herein.

[0484] In one implementation, the first network element can also authenticate the communication device before sending the first key to the communication device. That is, the first network element sends the first key to the communication device after the communication device is authenticated. The authentication of the communication device ensures that the first network element sends the first key to a legitimate communication device. For example, the first network element can authenticate the communication device in the following manner.

[0485] In one implementation, the first network element authenticates the communication device via an authentication server. For example, the first network element queries the authentication server corresponding to the communication device, and the first network element establishes a connection between the communication device and the authentication server, which is used for the authentication server to authenticate the communication device. For example, the communication device initiates an authentication request, and the authentication request is sent to the first network element via the access gateway. The authentication request can carry the identity of the communication device. Upon receiving the authentication request, the first network element queries the authentication server corresponding to the communication device, for example, via the identity of the communication device carried in the authentication request. Upon querying the authentication server, the first network element establishes a connection between the first network element and the authentication server. The first network element also establishes a connection between the first network element and the communication device. The communication device and the authentication server establish a connection via the first network element, which is used for the authentication server to authenticate the communication device. For example, the connection is used for the communication device and the authentication server to exchange challenge information and response information. The implementation of the authentication can refer to step S206 of FIG. 2(a).

[0486] In one implementation, the first network element authenticates the communication device using the second key. For example, the first network element receives a second signature from the communication device, the first network element generates a third signature according to the second key, and determines whether the communication device passes the authentication according to whether the second signature and the third signature are consistent. For example, the first network element receives the second key from the terminal device. For example, the second key is a key pre-configured for the communication device, for example, the second key is a public key pre-configured for the communication device by the manufacturer of the communication device, and the private key corresponding to the public key is held by the communication device. The second signature is generated by the communication device using the private key corresponding to the second key. For example, the communication device signs the first authentication information, or the first authentication information and the identity of the communication device, using the private key corresponding to the second key to obtain the second signature, where the first authentication information can be a timestamp corresponding to the time when the communication device signs, or the first authentication information can be a random number. The first network element generates a third signature according to the second key, and determines that the communication device passes the authentication if the second signature and the third signature are consistent, and otherwise, determines that the communication device fails the authentication. For example, the implementation of the authentication can refer to step S407 of FIG. 4.

[0487] In an implementation, the first network element obtains a fourth signature, generates a fifth signature according to the shared key between the terminal device and the operator, and determines whether the communication apparatus passes the authentication according to whether the fourth signature and the fifth signature are consistent. For example, the fourth signature is generated by the terminal device using the shared key between the terminal device and the operator. For example, the terminal device signs the first authentication information, or the first authentication information and the identifier of the communication apparatus, using the shared key between the terminal device and the operator, to obtain the fourth signature, where the first authentication information can be a timestamp corresponding to the time when the terminal device signs, or the first authentication information can be a random number. The manner of generating the fourth signature can refer to step S300 or S306 in FIG. 3. The first network element generates the fifth signature according to the shared key between the terminal device and the operator, and determines that the communication apparatus passes the authentication if the fourth signature and the fifth signature are consistent, or determines that the communication apparatus does not pass the authentication otherwise. For example, the implementation of the authentication can refer to step S307d in FIG. 3.

[0488] The first network element sends the first key to the communication apparatus after the authentication of the communication apparatus passes, which can ensure that the first network element sends the first key to the legitimate communication apparatus, thereby avoiding that an illegal user obtains the first key and registers to the mobile network using the first key.

[0489] It should be noted that the embodiments of the present application do not limit the order of authenticating the communication apparatus and generating the second key. In addition, the method of authenticating the communication apparatus and the manner of generating the second key of the first network element can be combined in any manner.

[0490] Optionally, in an implementation, the first network element sends the authentication information to the communication apparatus.

[0491] In an implementation, the first network element generates a third key using the first key. For example, after the authentication in step S705c passes, the first network element generates the third key using the first key. Correspondingly, the communication apparatus also generates the third key using the first key. The third key is used to encrypt or decrypt the message transmitted between the communication apparatus and the access gateway. This implementation can refer to step S2016 in FIG. 2(b), which will not be described herein again.

[0492] In an implementation, the first network element generates a third key and sends the third key to the communication apparatus. For example, after the authentication in step S705c passes, the first network element generates a QUIC key, and the third key is the QUIC key. The first network element encrypts the third key using the first key, and sends the encrypted third key to the communication apparatus through the access gateway. After receiving the third key, the communication apparatus decrypts the third key using the first key to obtain the decrypted third key. This implementation can refer to step S2033 in FIG. 2(c), which will not be described herein again.

[0493] Optionally, the first network element can also generate a fourth key using the first key, and the fourth key is used to verify the integrity of the message transmitted between the communication device and the access gateway. Optionally, the first network element can send the fourth key to the communication device, or the communication device can generate the fourth key using the same method as the first network element. The method of generating the fourth key can refer to step S2016 in FIG. 2(b), or step S2033 in FIG. 2(c).

[0494] In one implementation, if the communication device still needs to access the IMS network, the method described in steps S2020-S2025 in FIG. 2(b) can also be performed to access the IMS network.

[0495] Through the method, the communication device can also register to the IMS network, and realize that the communication device helps the user to answer or dial a call independently of the terminal device.

[0496] FIG. 8 and FIG. 9 are structural schematic diagrams of possible communication devices provided by embodiments of the present application. These communication devices can be used to implement the functions of the device management network element, or the terminal device, or the access gateway, or the user identification module-free device in the method embodiments described above, and thus can also achieve the beneficial effects of the method embodiments described above. In embodiments of the present application, the communication device can be the device described above or a module (such as a chip) in the device.

[0497] As shown in FIG. 8, the communication device 800 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the functions of the device management network element, or the terminal device, or the access gateway, or the user identification module-free device in the method embodiments described above in any of FIG. 2(a)-(c), FIG. 3, FIG. 4, FIG. 5, FIG. 6, and FIG. 7.

[0498] When the communication device 800 is used to implement the functions of the device management network element in the method embodiments described above in the above-mentioned drawings:

[0499] The transceiver 820 is configured to receive a first request, the first request being used by a terminal device to request issuance of a first key for a user identification module-free device, wherein the user identification module-free device does not have a user identification module, and the terminal device has a user identification module; the processing unit 810 is configured to generate the first key for the user identification module-free device in response to the first request; the transceiver 820 is configured to send the first key to the user identification module-free device; in a process in which the user identification module-free device requests to register to a mobile network, receive a request for authentication of the user identification module-free device, the request including a first identifier, the first identifier being used to uniquely identify the user identification module-free device in the mobile network, and connection of the user identification module-free device to the mobile network does not pass through the terminal device; the processing unit 810 is configured to generate first information according to the first key corresponding to the user identification module-free device identified by the first identifier; the transceiver 820 is configured to receive second information from the user identification module-free device; the processing unit 810 is configured to determine whether the user identification module-free device passes the authentication according to whether the first information and the second information are consistent, and an authentication result of the user identification module-free device is used to accept or reject a request of the user identification module-free device to register to the mobile network.

[0500] When the communication apparatus 800 is configured to implement the function of the device management network element in the method embodiments shown in the above figures:

[0501] The transceiver 820 is configured to receive the first key from the user identification module-free device from a terminal device, wherein the user identification module-free device does not have a user identification module, and the terminal device has a user identification module; in a process in which the user identification module-free device requests to register to a mobile network, receive a request for authentication of the user identification module-free device, the request including a first identifier, the first identifier being used to uniquely identify the user identification module-free device in the mobile network, and connection of the user identification module-free device to the mobile network does not pass through the terminal device; the processing unit 810 is configured to generate first information according to the first key corresponding to the user identification module-free device identified by the first identifier; the transceiver 820 is configured to receive second information from the user identification module-free device; the processing unit 810 is configured to determine whether the user identification module-free device passes the authentication according to whether the first information and the second information are consistent, and an authentication result of the user identification module-free device is used to accept or reject a request of the user identification module-free device to register to the mobile network.

[0502] When the communication apparatus 800 is configured to implement the function of the user identification module-free device in the method embodiments shown in the above figures:

[0503] The processing unit 810 obtains a first key; the transceiver unit 820 sends a request for registration to a mobile network in a process of requesting registration to the mobile network, the request including a first identifier, the first identifier being used to uniquely identify a user identification module-free device in the mobile network, the user identification module-free device being connected to the mobile network without passing through a terminal device, wherein the user identification module-free device does not have a user identification module, and the terminal device has the user identification module; the processing unit 810 generates first information according to the first key, and the transceiver unit 820 sends the first information to the mobile network, the first information being used to authenticate the user identification module-free device.

[0504] When the communication apparatus 800 is used to implement the function of the terminal device in the method embodiments shown in the above figures:

[0505] The processing unit 810 is configured to control the transceiver unit 810 to send a first request, the first request being used to request a first key for a user identification module-free device, the first key being used to authenticate the user identification module-free device in a process of requesting registration to a mobile network by the user identification module-free device, the user identification module-free device being connected to the mobile network without passing through a terminal device, wherein the user identification module-free device does not have a user identification module, and the terminal device has the user identification module.

[0506] When the communication apparatus 800 is used to implement the function of the terminal device in the method embodiments shown in the above figures:

[0507] The processing unit 810 is configured to control the transceiver unit 810 to send a first request, the first request including a first key, the first request being used to request authentication of the first key for a user identification module-free device, the first key being used to authenticate the user identification module-free device in a process of requesting registration to a mobile network by the user identification module-free device, the user identification module-free device being connected to the mobile network without passing through a terminal device, wherein the user identification module-free device does not have a user identification module, and the terminal device has the user identification module.

[0508] When the communication apparatus 800 is used to implement the function of the access gateway in the method embodiments shown in the above figures:

[0509] The processing unit 810 is configured to receive, through the transceiver unit 820, a first key, send the first key to a user identification module free device, the first key being used for authenticating the user identification module free device in a process in which the user identification module free device requests to register to a mobile network, a connection of the user identification module free device to the mobile network not passing through a terminal device, the user identification module free device being free of a user identification module, the terminal device having the user identification module; receive a request for registering to the mobile network from the user identification module free device, the request including a first identifier, the first identifier being used for uniquely identifying the user identification module free device in the mobile network; send a request for requesting to authenticate the user identification module free device, the request including the first identifier; receive first information from the user identification module free device, the first information being generated according to the first key, the first information being used for authenticating the user identification module free device by the mobile network; and send the first information to the mobile network.

[0510] More detailed description of the processing unit 810 and the transceiver unit 820 can be directly obtained by referring to the related description in the method embodiments shown in the above figures, and will not be repeated here.

[0511] As shown in FIG. 9, the communication apparatus 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It can be understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the communication apparatus 900 can further include a memory 930, used for storing instructions executed by the processor 910 or storing input data required by the processor 910 for running instructions or storing data generated by the processor 910 after running instructions.

[0512] When the communication apparatus 900 is used to implement the methods shown in the above figures, the processor 910 is configured to implement the functions of the processing unit 910, and the interface circuit 920 is configured to implement the functions of the transceiver unit 920.

[0513] When the above communication apparatus is a chip applied to the above device, the chip implements the functions of the corresponding device in the above method embodiments. The chip receives information from other modules (such as a radio frequency module or an antenna) in the device, and the information is sent by other devices to the device; or the chip sends information to other modules (such as a radio frequency module or an antenna) in the device.

[0514] When the communication apparatus is a module applied to a mobile node, the module implements the functions of the mobile node in the method embodiments. The module receives information from other modules (such as a radio frequency module or an antenna), and the information is sent by the terminal to the device; or the module sends information to other modules (such as a radio frequency module or an antenna) in the device, and the information is sent by the device to the terminal. The module can be a baseband chip of the device, or a DU or other module, and the DU can be a DU under the open radio access network (O-RAN) architecture.

[0515] It can be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor, or any conventional processor.

[0516] In the present application, another example of a communication apparatus is provided, which includes at least one processor and at least one memory coupled to the at least one processor, the at least one memory configured to store instructions that, when executed by the at least one processor, cause the communication apparatus to perform the method in the above embodiments. Taking the communication apparatus including one processor and one memory as an example, as shown in FIG. 9, the communication apparatus 900 includes one processor 910 and one memory 930. The processor 910 and the memory 930 are coupled, and the memory 930 stores instructions, when the instructions stored in the memory 930 are executed by the processor 910, the communication apparatus 900 performs the method executed by the terminal device or the network device (for example, a device management network element, an access gateway) or a user identification module-free device in the above embodiments.

[0517] It should be understood that the processor 910 and the memory 930 can also be integrated together, such as integrated in one chip.

[0518] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions executable by a processor. The software instructions can be composed of corresponding software modules, which can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal. The processor and the storage medium can also exist as discrete components in the network device or the terminal.

[0519] In the above embodiments, the implementation can be entirely or partially achieved by software, hardware, firmware, or any combination thereof. When implemented by software, the implementation can be entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer programs or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are entirely or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable devices. The computer programs or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer programs or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through a wired or wireless manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape; an optical medium, such as a digital video disc; or a semiconductor medium, such as a solid-state disk. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile storage media.

[0520] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be mutually referred to if there is no special description and no logical conflict. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0521] It can be understood that various digital numbers involved in the embodiments of the present application are only distinguished for convenience of description, and are not used to limit the scope of the embodiments of the present application. The size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic.

Claims

A mobile network registration method, characterized in that, The method is applied to a first network element, and the method comprises: receiving a first request for a terminal device to request a first key to be issued to a communication apparatus, wherein the communication apparatus has no user identification module, and the terminal device has a user identification module; generating the first key for the communication apparatus in response to the first request; sending the first key to the communication apparatus; in a process in which the communication apparatus requests to register to the mobile network, receiving a request to authenticate the communication apparatus, the request comprising a first identity for uniquely identifying the communication apparatus in the mobile network, and the connection of the communication apparatus to the mobile network not passing through the terminal device; generating first information according to the first key corresponding to the communication apparatus identified by the first identity; receiving second information from the communication apparatus, determining whether the communication apparatus passes the authentication according to whether the first information and the second information are consistent, and the authentication result of the communication apparatus being used to accept or reject the request of the communication apparatus to register to the mobile network. The method of claim 1, wherein The method further comprises: generating the first identity for the communication apparatus in response to the first request; sending the first identity to the communication apparatus. The method according to claim 2, characterized in that The generating of the first identity for the communication apparatus comprises: verifying a first signature from the terminal device according to a shared key between the terminal device and an operator, and generating the first identity for the communication apparatus after the first signature verification is passed. The method according to claim 2 or 3, characterized in that The generating of the first identity for the communication apparatus comprises: generating the first identity for the communication apparatus when the communication apparatus is not associated with any terminal device. The method according to any one of claims 1 to 4, characterized in that The first key is sent to the communication apparatus in a secure transmission manner. The method according to any one of claims 1 to 5, characterized in that The sending of the first key to the communication apparatus comprises: obtaining a second key; sending the first key and the second key to an access gateway, the second key being used by the access gateway to encrypt the first key sent to the communication apparatus, or the first key sent to the communication apparatus being encrypted by using the second key. The method according to claim 6, characterized in that The obtaining of the second key comprises: generating the second key according to a preconfigured key for the communication apparatus; or generating the second key according to a shared key between the terminal device and an operator. The method according to claim 6, characterized in that The obtaining of the second key comprises: receiving the second key from the terminal device. The method according to claim 7 or 8, characterized in that The method further comprises: authenticating the communication apparatus according to the second key. The method of claim 9, wherein The authenticating of the communication apparatus according to the second key comprises: receiving a second signature from the communication apparatus; generating a third signature according to the second key, and determining whether the communication apparatus passes the authentication according to whether the second signature and the third signature are consistent. The method according to any one of claims 1 to 10, characterized in that The sending of the first key to the communication apparatus comprises: sending the first key to the communication apparatus after the authentication of the communication apparatus is passed. The method according to any one of claims 1 to 11, characterized in that The method further comprises: inquiring an authentication server corresponding to the communication apparatus; establishing a connection between the communication apparatus and the authentication server, the connection being used for the authentication server and the communication apparatus to perform authentication. The method according to any one of claims 1 to 12, characterized in that The method further comprises: obtaining a fourth signature; determining whether the communication apparatus passes authentication according to whether the fourth signature and a fifth signature are consistent, the fifth signature being generated according to a shared key between the terminal device and an operator. The method according to any one of claims 1 to 13, characterized in that The communication apparatus does not have a global user identity module, or an embedded user identification module, or an integrated user identification module. The method according to any one of claims 1 to 14, characterized in that The first key is a long-term key shared by the communication apparatus and the mobile network. A mobile network registration method, characterized in that, The method is applied to a first network element, and the method comprises: receiving, from a terminal device, a first key from a communication apparatus, the communication apparatus not having a user identification module, the terminal device having a user identification module; in a process in which the communication apparatus requests to register to the mobile network, receiving a request for authentication of the communication apparatus, the request comprising a first identity, the first identity being used to uniquely identify the communication apparatus in the mobile network, a connection between the communication apparatus and the mobile network not passing through the terminal device; generating first information according to the first key corresponding to the communication apparatus identified by the first identity; receiving second information from the communication apparatus, and determining whether the communication apparatus passes authentication according to whether the first information and the second information are consistent, a result of the authentication of the communication apparatus being used to accept or reject a request of the communication apparatus to register to the mobile network. The method of claim 16, wherein The method further comprises: generating the first identity for the communication apparatus; sending the first identity to the communication apparatus. The method according to claim 16 or 17, characterized in that The method further comprises: verifying a signature of the first key according to a shared key between the terminal device and an operator, and determining that the first key passes authentication after the signature verification of the first key passes. A mobile network registration method, characterized in that, The method is applied to a communication apparatus, and the method comprises: obtaining a first key; in a process in which the communication apparatus requests to register to a mobile network, sending a request for registration to the mobile network, the request comprising a first identity, the first identity being used to uniquely identify the communication apparatus in the mobile network, a connection between the communication apparatus and the mobile network not passing through a terminal device, wherein the communication apparatus does not have a user identification module, and the terminal device has a user identification module; generating first information according to the first key, and sending the first information to the mobile network, the first information being used to authenticate the communication apparatus. The method of claim 19, wherein The method further comprises: receiving the first identity. The method according to claim 19 or 20, characterized in that The obtaining of the first key comprises: receiving, from the mobile network, the first key encrypted. The method of claim 21, wherein The obtaining of the first key further comprises: obtaining a second key or a private key corresponding to the second key; decrypting, using the second key, the first key received from the mobile network and encrypted, or decrypting, using the private key corresponding to the second key, the first key received from the mobile network and encrypted. The method of claim 22, wherein The obtaining of the second key or the private key corresponding to the second key comprises: generating the second key according to a key pre-configured for the communication apparatus; or, receiving the second key from the terminal device; or obtaining a private key corresponding to the second key preconfigured for the communication apparatus. The method according to claim 19 or 20, characterized in that The obtaining the first key comprises: generating the first key; The method further comprises: sending the first key to the mobile network. The method according to any of claims 19-24, characterized in that The method further comprises: generating a third key according to the first key, or receiving a quick user datagram protocol internet key as the third key after the authentication of the communication apparatus is passed in the process of requesting registration to the mobile network, the third key being used for encrypting or decrypting a packet; generating a fourth key according to the first key, the fourth key being used for integrity verification of the packet. A mobile network registration method, characterized in that, The method comprises: sending a first request, the first request being used for requesting a first key for a communication apparatus, the first key being used for authenticating the communication apparatus in a process of requesting registration to a mobile network, connection of the communication apparatus to the mobile network not passing through a terminal device, wherein the communication apparatus has no subscriber identity module, and the terminal device has a subscriber identity module. The method of claim 26, wherein The first request is further used for requesting a first identity for the communication apparatus, the first identity being used for uniquely identifying the communication apparatus in the mobile network. The method further comprises: receiving the first identity. The method according to claim 26 or 27, characterized in that The first request comprises an identity of the communication apparatus and a terminal identity of the terminal device. The method according to any one of claims 26-28, characterized in that The first request further comprises a second key, the second key being used for encrypting transmission of the first key; and the first request further comprises a first signature of the second key, the first signature being used for verifying the second key. A mobile network registration method, characterized in that, The method comprises: sending a first request, the first request comprising a first key, the first request being used for requesting authentication of the first key for a communication apparatus, the first key being used for authenticating the communication apparatus in a process of requesting registration to a mobile network, connection of the communication apparatus to the mobile network not passing through a terminal device, wherein the communication apparatus has no subscriber identity module, and the terminal device has a subscriber identity module. The method of claim 30, wherein The first request is further used for requesting a first identity for the communication apparatus, the first identity being used for uniquely identifying the communication apparatus in the mobile network; and the method further comprises: receiving the first identity. The method according to claim 30 or 31, characterized in that The method further comprises: verifying a private key corresponding to the first key. A mobile network registration method, characterized in that, The method comprises: receiving a first key; sending the first key to a communication apparatus, the first key being used for authenticating the communication apparatus in a process of requesting registration to a mobile network, connection of the communication apparatus to the mobile network not passing through a terminal device, wherein the communication apparatus has no subscriber identity module, and the terminal device has a subscriber identity module; receiving a request of requesting registration to the mobile network from the communication apparatus, the request comprising a first identity, the first identity being used for uniquely identifying the communication apparatus in the mobile network; sending a request of requesting authentication of the communication apparatus, the request comprising the first identity; receiving first information from the communication device, the first information being used for authentication of the communication device by the mobile network; sending the first information to the mobile network. The method of claim 33, wherein The sending of the first key to the communication device comprises sending the first key to the communication device over a secure transmission. The method according to claim 33 or 34, characterized in that The sending of the first key to the communication device over a secure transmission comprises: receiving a second key; encrypting the first key using the second key. The method according to any of claims 33-35, characterized in that The method further comprises: receiving a first authentication request from the communication device, the first authentication request being used for requesting authentication of the communication device, the first authentication request comprising an identity of the communication device and first authentication information, the first authentication information corresponding to a time instant at which the first authentication request is initiated by the communication device, or the first authentication information being a random number; sending a second authentication request, the second authentication request being used for requesting authentication of the communication device, the second authentication request comprising the identity of the communication device and the first authentication information. The method according to any one of claims 33-36, characterized in that The first authentication request further comprises a first digital signature, the first digital signature being generated according to a shared key and the first authentication information, the first digital signature being used for authenticating the communication device, the shared key being shared by the terminal device and an operator; the second authentication request further comprises the first digital signature. The method according to any one of claims 33-37, characterized in that The method further comprises: receiving a third response, the third response being used for indicating that the authentication of the communication device is passed, the third response comprising a third key, the third key being used for encrypting messages transmitted between the communication device and the mobile network, the third key being generated according to the first key, or the third key being a fast internet key exchange key; the third response comprising a fourth key, the fourth key being used for integrity verification of messages transmitted between the communication device and the mobile network, the fourth key being generated according to the first key. A communication system characterized by comprising a first network element configured to implement the method according to any one of claims 1-18, and a communication device configured to implement the method according to any one of claims 19-25. A network element, characterized by comprising means or modules for performing the method according to any one of claims 1-18, comprising means or modules for performing the method according to any one of claims 33-38. A communication device characterized by comprising: comprising means or modules for performing the method according to any one of claims 19-25, or comprising means or modules for performing the method according to any one of claims 26-29, or comprising means or modules for performing the method according to any one of claims 30-32. A readable storage medium characterized in that, The readable storage medium has a program stored therein, when the program is executed by a communication device, the method according to any one of claims 1-38 is implemented. A computer program product, characterized in that The computer program product comprises instructions, when the instructions are run on a processor, the processor is caused to perform the method according to any one of claims 1-38.

Citation Information

Patent Citations

  • Method and system of card-free terminal registration to mobile network, and equipment

    CN105554751A

  • 5G communication card-free access method and equipment, and storage medium

    CN111083695A

  • Method and device for allowing a user equipment without sim card to take advantage of a mobile data subscription of its user to access a wireless network

    EP2741459A1

  • Agent-based authentication and key agreement method for devices without SIM card

    US20190021002A1

  • Connection between SIM-less device and cellular network

    US20220256330A1