Communication method and communication apparatus

By acquiring and verifying short-term trust credentials for user identifiers, the redundant authentication process for user identifiers in 5G communication systems is reduced, solving the problem of excessive signaling overhead and improving the flexibility and efficiency of user access to the network.

WO2026026544A1PCT designated stage Publication Date: 2026-02-05HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/108678
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-30
Filing Date
2025-07-15
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

In 5G communication systems, when a user accesses the network multiple times in a short period of time using the same user identifier, the network's authentication process for the user identifier is frequently triggered, resulting in excessive signaling overhead.

Method used

By acquiring and storing short-term trust certificates corresponding to user identifiers, the association between these certificates and received trust certificates is verified, and it is determined whether to trigger the authentication process for long-term trust certificates, thereby reducing duplicate authentication of user identifiers.

Benefits of technology

It reduces signaling overhead when users access the network, and improves the flexibility and efficiency of user network access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025108678_05022026_PF_FP_ABST
    Figure CN2025108678_05022026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a communication apparatus. The method comprises: acquiring and storing a first credential corresponding to a first user identifier, the first credential being a short-term credential corresponding to the first user identifier; when the first user identifier is used to log in to a same terminal device again, receiving a second credential corresponding to the first user identifier; verifying an association relationship between the first credential and the second credential; and on the basis of a verification result, determining whether to trigger an authentication process of authenticating the first user identifier on the basis of a third credential, the third credential being a long-term credential corresponding to the first user identifier. A first network element can verify a first user identifier by verifying a short-term credential corresponding to the first user identifier, so that an authentication process of authenticating the first user identifier by means of a long-term credential corresponding to the first user identifier can be omitted, thereby saving signaling overheads.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication apparatus

[0001] The present application claims priority from the Chinese patent application No. 202411038593.0 filed on July 30, 2024, and entitled "Communication method and communication apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication, and more particularly, to a communication method and a communication apparatus. BACKGROUND

[0003] In a communication system, such as a 5th generation (5G) communication system, a core network provides network services for a user equipment (UE) based on an identity of the UE, in which case an operator network can determine the UE by the identity of the UE and provide services for the UE based on subscription information corresponding to the identity of the UE. In order to be able to provide differentiated services for different users using the UE more flexibly, a user identity (user ID) is introduced. When different users access the network through different user identities, the core network can provide differentiated services for different users based on the user identities and the subscription information corresponding to the user identities.

[0004] In order to protect network security, when a user logs in a UE using a user identity and requests to access the network, the network side interacts with an authentication server / authentication network element to implement authentication of the user identity, that is, to determine whether the user corresponding to the user identity can access the network. In this case, if the user accesses the network through the same UE within a short time using the same user identity, the network will trigger the authentication process of the user identity multiple times, resulting in a large amount of signaling overhead. SUMMARY

[0005] The present application provides a communication method and a communication apparatus, which can improve the flexibility of user access to the network.

[0006] In a first aspect, a communication method is provided, which can be executed by a first network element, or can also be executed by a component (such as a chip or a circuit) of the first network element, and no limitation is made in this regard. For ease of description, the following is described by way of example with the first network element.

[0007] The method comprises: obtaining and storing a first trust record corresponding to a first user identifier, the first trust record being a short-term trust record corresponding to the first user identifier, and being used for verifying the first user identifier in a short term; receiving a second trust record corresponding to the first user identifier, the second trust record being received in a case where the first user identifier is used to log in a terminal device; verifying an association relationship between the first trust record and the second trust record; and determining, according to a verification result obtained by verifying the association relationship, whether to trigger an authentication process of authenticating the first user identifier according to a third trust record, the third trust record being a long-term trust record corresponding to the first user identifier.

[0008] Alternatively, the method comprises: obtaining and storing a first trust record corresponding to a first user identifier; receiving a second trust record corresponding to the first user identifier in a case where the first user identifier is used to log in a terminal device; verifying a short-term trust record corresponding to the first user identifier, the short-term trust record comprising the first trust record and / or the second trust record; and determining, according to a verification result obtained by verifying the short-term trust record, whether to trigger an authentication process of authenticating the first user identifier according to a third trust record, the third trust record being a long-term trust record corresponding to the first user identifier.

[0009] Based on the above scheme, the first network element obtains a short-term trust record corresponding to a first user identifier and receives a short-term trust record corresponding to the first user identifier from a terminal device, and verifies the first user identifier by verifying the short-term trust record corresponding to the first user identifier, so that an authentication process of authenticating the first user identifier by using a long-term trust record corresponding to the first user identifier can be omitted, and signaling overheads can be saved.

[0010] In some implementations of the first aspect, the first message is sent to the terminal device, the first message comprising a first authentication result, the first authentication result being obtained by triggering the authentication process of authenticating the first user identifier according to the third trust record, and the first authentication result indicating whether the network successfully authenticates the first user identifier.

[0011] In some implementations of the first aspect, the first message further comprises a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a time when the authentication result is generated, the first time length and the first timestamp being used to determine whether the authentication result is valid; and the second trust record corresponding to the first user identifier is received in a case where the first user identifier is used to log in the terminal device and the first authentication result is valid.

[0012] Based on the above scheme, by sending the first time length and the first timestamp to the terminal device, the terminal device can determine the validity of the authentication result corresponding to the first user identifier according to the first time length and the first timestamp, so that the terminal device can send the second credential corresponding to the first user identifier to the first network element within the validity period of the authentication result, so that the first network element verifies the first user identifier by verifying the short-term credential corresponding to the first user identifier.

[0013] In some implementations of the first aspect, before receiving the second credential corresponding to the first user identifier, it is determined whether the first authentication result is valid according to the first time length and the first timestamp, the first time length being the valid time length of the first authentication result, and the first timestamp indicating the generation time of the first authentication result; and in the case that the first authentication result is valid, a first request message is sent to the terminal device, the first request message being used to request the second credential.

[0014] Based on the above scheme, the validity of the authentication result corresponding to the first user identifier can be determined by the first time length and the first timestamp, so that the first user identifier can be verified by verifying the short-term credential corresponding to the first user identifier within the validity period of the authentication result, thereby saving signaling overhead.

[0015] In some implementations of the first aspect, the first credential is received from a second network element, the second network element being used to authenticate the first user identifier or being used to store subscription information corresponding to the first user identifier; or the first credential is generated.

[0016] Based on the above scheme, the first network element can flexibly obtain the first credential, so that the first user identifier can be verified by verifying the short-term credential corresponding to the first user identifier.

[0017] In some implementations of the first aspect, before receiving the second credential corresponding to the first user identifier, the terminal device notifies the first user of the first credential, wherein the first user is a user who logs in the terminal device using the first user identifier.

[0018] Based on the above scheme, the first user can hold the same short-term credential as the first network element, so that when the first user logs in the terminal device again, the first user can input the short-term credential, so that the first network element verifies the first user identifier according to the short-term credential corresponding to the first user identifier, avoiding the authentication process of the first user identifier, and saving signaling overhead.

[0019] In some implementations of the first aspect, the second credential is generated by the terminal device according to the third credential.

[0020] Based on the above scheme, the terminal device can generate the short-term trust record corresponding to the first user identifier, so that the first network element can verify the identifier of the first user based on the short-term trust record generated by the terminal device and the first trust record.

[0021] In a second aspect, a communication method is provided, which can be executed by a terminal device, or can also be executed by a component (such as a chip or circuit) of the terminal device, and the execution is not limited. For ease of description, the following is described by taking the execution by the terminal device as an example.

[0022] The method comprises: in a case where the terminal device is logged in using a first user identifier, sending a user authentication request message to a first network element, the user authentication request message being used to request authentication of the first user identifier; in a case where the terminal device is logged in again using the first user identifier, sending a second trust record to the first network element, the second trust record being used to verify a short-term trust record corresponding to the first user identifier, so that the first network element does not perform an authentication process of authenticating the first user identifier, wherein the short-term trust record comprises at least one of a first trust record and a second trust record, and the first trust record is a short-term trust record corresponding to the first user identifier and saved by the first network element.

[0023] Based on the above scheme, the terminal device can send the short-term trust record corresponding to the first user identifier generated by the terminal device to the first network element, so that the first network element can verify the first user identifier by verifying the short-term trust record corresponding to the first user identifier, that is, the first network element can skip the authentication process of authenticating the first user identifier by using the long-term trust record corresponding to the first user identifier, and can save signaling overhead.

[0024] In some implementations of the second aspect, the second trust record is generated before the second trust record is sent to the first network element.

[0025] In some implementations of the second aspect, in a case where the terminal device is logged in again using the first user identifier, the second trust record is generated according to the third trust record; wherein the first user is a user who logs in the terminal device using the first user identifier, and the third trust record is a long-term trust record corresponding to the first user identifier.

[0026] Based on the above scheme, in a case where the terminal device is logged in again using the first user identifier, the terminal device can generate the short-term trust record corresponding to the first user identifier, for example, the short-term trust record corresponding to the first user identifier can be generated based on the long-term trust record corresponding to the first user identifier input by the user.

[0027] In some implementations of the second aspect, the first credential is received from the first network element before the second credential is sent to the first network element; and the first credential is notified to the first user, so that when the first user logs in the terminal device again using the first user identifier, the second credential is input based on the first credential.

[0028] Based on the above scheme, the first user can hold the same short-term credential as the first network element, so that when the first user logs in the terminal device again, the verification of the first user identifier is realized by inputting the short-term credential corresponding to the first user identifier, which can avoid the first network element to perform the authentication process of the first user identifier, and save signaling overhead.

[0029] In some implementations of the second aspect, a first message is received from the first network element, the first message including a first authentication result, the first authentication result being obtained by triggering an authentication process of authenticating the first user identifier according to the third credential, and the first authentication result indicating whether the network authentication of the first user identifier is successful.

[0030] In some implementations of the second aspect, the first message further includes a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a generation time of the authentication result; whether the authentication result is valid is determined according to the first time length and the first timestamp; and the second credential is sent to the first network element in the case that the authentication result is valid.

[0031] Based on the above scheme, the terminal device can determine the validity of the authentication result corresponding to the first user identifier according to the first time length and the first timestamp, so that the second credential corresponding to the first user identifier can be sent to the first network element within the validity period of the authentication result, so that the first network element verifies the first user identifier by verifying the short-term credential corresponding to the first user identifier.

[0032] In a third aspect, a communication method is provided, which can be executed by a first network element, or can also be executed by a component (such as a chip or a circuit) of the first network element, which is not limited. For ease of description, the following is described by taking the execution of the first network element as an example.

[0033] The method comprises: sending a first message to a terminal device, the first message comprising a first authentication result and first information, the first authentication result indicating whether authentication of the first user identifier by the network is successful, the first information comprising a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, the first timestamp indicating a time of generation of the authentication result, the first time length and the first timestamp being used to determine whether the first authentication result is valid, so that the terminal device generates and saves a first trust record in a case where the first authentication result indicates that the authentication is successful, and verifies a second trust record input by a first user according to the saved first trust record in a case where the first user logs in the terminal device again using the first user identifier; receiving a second message from the terminal device, the second message indicating that short-term trust record verification of the terminal device is successful, the short-term trust record comprising the first trust record and / or a second trust record; determining not to perform an authentication procedure for authenticating the first user identifier according to the second message; wherein the first authentication result is determined according to a third trust record, the third trust record being a long-term trust record corresponding to the first user identifier.

[0034] In some implementations of the third aspect, the second message carries first indication information, the first indication information indicating that the authentication procedure for authenticating the first user identifier is not performed.

[0035] In some implementations of the third aspect, it is verified whether the terminal device is a trusted terminal device, and in a case where the terminal device is a trusted terminal device, it is determined that the authentication procedure for authenticating the first user identifier is not performed.

[0036] A fourth aspect provides a communication method, which can be executed by a terminal device or a component (for example, a chip or a circuit) of the terminal device, and is not limited in this regard. For ease of description, the method is described below by taking the terminal device as an example.

[0037] The method comprises: receiving a first message, the first message comprising a first authentication result, the first authentication result indicating whether authentication of the first user identifier by the network is successful; generating and saving a first trust record in a case where the first authentication result indicates that the authentication is successful; verifying a second trust record input by a first user according to the saved first trust record if the terminal device is logged in by the first user identifier; and determining that the first user identifier does not need to be authenticated in a case where short-term trust record verification of the first user identifier is successful; wherein the first authentication result is determined according to a third trust record, the third trust record being a long-term trust record corresponding to the first user identifier.

[0038] In some implementations of the fourth aspect, the first message further includes a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a time when the authentication result is generated, and the first time length and the first timestamp are saved; and whether the first authentication result is valid is determined according to the first time length and the first timestamp.

[0039] In some implementations of the fourth aspect, a second message is sent to the first network element, the second message carrying the first user identifier, and the second message being used to indicate that the terminal device successfully verifies the short-term credential corresponding to the first user identifier.

[0040] In some implementations of the fourth aspect, the second message further carries first indication information, and the first indication information indicates that the first user identifier does not need to be authenticated.

[0041] In a fifth aspect, a communication apparatus is provided, which includes a transceiver unit and a processing unit, the processing unit is configured to acquire and save a first credential corresponding to a first user identifier, the first credential being a short-term credential corresponding to the first user identifier, and the first credential being used to verify the first user identifier in a short term; the transceiver unit is configured to receive a second credential, the second credential being received in a case where the first user identifier is used to log in a terminal device; the processing unit is further configured to verify an association relationship between the first credential and the second credential; and the processing unit is further configured to determine, according to a verification result obtained by verifying the association relationship, whether to trigger an authentication process of authenticating the first user identifier according to a third credential, the third credential being a long-term credential corresponding to the first user identifier.

[0042] Alternatively, the apparatus includes a transceiver unit and a processing unit, the processing unit acquires and saves a first credential corresponding to a first user identifier; in a case where the first user identifier is used to log in a terminal device, the transceiver unit is configured to receive a second credential corresponding to the first user identifier; the processing unit is further configured to verify a short-term credential corresponding to the first user identifier, the short-term credential including the first credential and / or the second credential; and the processing unit is further configured to determine, according to a verification result obtained by verifying the short-term credential, whether to trigger an authentication process of authenticating the first user identifier according to a third credential, the third credential being a long-term credential corresponding to the first user identifier.

[0043] In some implementations of the fifth aspect, the transceiver unit is further configured to send a first message to the terminal device, the first message including a first authentication result, the first authentication result being obtained by triggering the authentication process of authenticating the first user identifier according to the third credential, and the first authentication result indicating whether the network successfully authenticates the first user identifier.

[0044] In some implementations of the fifth aspect, the first message further includes a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a time when the authentication result is generated, the first time length and the first timestamp being used to determine whether the authentication result is valid; and the transceiver is specifically configured to receive the second credential corresponding to the first user identifier, the second credential being received in a case that the first user identifier is used to log in the terminal device and the first authentication result is valid.

[0045] In some implementations of the fifth aspect, the processing unit is further configured to determine whether the first authentication result is valid according to a first time length and a first timestamp before receiving the second credential corresponding to the first user identifier, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a time when the first authentication result is generated; and the transceiver is further configured to send a first request message to the terminal device in a case that the first authentication result is valid, the first request message being used to request the second credential.

[0046] In some implementations of the fifth aspect, the transceiver is specifically configured to receive the first credential from a second network element, the second network element being used to authenticate the first user identifier or being used to store subscription information corresponding to the first user identifier; or generate the first credential.

[0047] In some implementations of the fifth aspect, the transceiver is further configured to notify the first user of the first credential through the terminal device before receiving the second credential corresponding to the first user identifier, the first user being a user who logs in the terminal device using the first user identifier.

[0048] In some implementations of the fifth aspect, the second credential is generated by the terminal device according to the third credential.

[0049] In a sixth aspect, a communication apparatus is provided, the apparatus including a transceiver and a processing unit, the transceiver being configured to send a user authentication request message to a first network element in a case that a first user identifier is used to log in the terminal device, the user authentication request message being used to request to authenticate the first user identifier; and the transceiver is further configured to send a second credential to the first network element in a case that the first user identifier is used to log in the terminal device again, the second credential being used to verify a short-term credential corresponding to the first user identifier, so that the first network element does not perform an authentication process of authenticating the first user identifier, wherein the short-term credential includes at least one of a first credential and a second credential, the first credential being a short-term credential corresponding to the first user identifier and saved by the first network element.

[0050] In some implementations of the sixth aspect, the processing unit is further configured to generate the second credential before sending the second credential to the first network element.

[0051] In some implementations of the sixth aspect, the processing unit is further configured to request a third credential from the first user if the first user logs in the terminal device again using the first user identity; the transceiver is configured to receive the third credential input by the first user; generate the second credential according to the third credential; wherein the first user is the user who logs in the terminal device using the first user identity, and the third credential is a long-term credential corresponding to the first user identity.

[0052] In some implementations of the sixth aspect, the transceiver is further configured to receive the first credential from the first network element before sending the second credential to the first network element; and notify the first user of the first credential, so that the first user inputs the second credential based on the first credential when logging in the terminal device again using the first user identity.

[0053] In some implementations of the sixth aspect, the transceiver receives a first message from the first network element, the first message including a first authentication result, the first authentication result being obtained by triggering an authentication procedure of authenticating the first user identity according to the third credential, and the first authentication result indicating whether the network successfully authenticates the first user identity.

[0054] In some implementations of the sixth aspect, the first message further includes a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a generation time of the authentication result; the processing unit is further configured to determine whether the authentication result is valid according to the first time length and the first timestamp; and the transceiver is further configured to send the second credential to the first network element if the authentication result is valid.

[0055] In a seventh aspect, a communication apparatus is provided, which comprises a transceiver and a processing unit. The transceiver is configured to send a first message to a terminal device, the first message comprising a first authentication result and first information, the first authentication result indicating whether an authentication of a first user identity by a network is successful, the first information comprising a first time length and a first time stamp, the first time length being a valid time length of the first authentication result, the first time stamp indicating a time when the authentication result is generated, the first time length and the first time stamp being used to determine whether the first authentication result is valid, so that the terminal device generates and saves a first trust record in a case that the first authentication result indicates that the authentication is successful, and verifies a second trust record input by a first user according to the saved first trust record in a case that the first user logs in the terminal device again using the first user identity; and receive a second message from the terminal device, the second message indicating that a short-term trust record verification of the terminal device is successful, the short-term trust record comprising the first trust record and / or a second trust record; and the processing unit is configured to determine not to perform an authentication procedure of authenticating the first user identity according to the second message; wherein the first authentication result is determined according to a third trust record, the third trust record being a long-term trust record corresponding to the first user identity.

[0056] In some implementations of the seventh aspect, the second message carries first indication information, the first indication information indicating not to perform the authentication procedure of authenticating the first user identity.

[0057] In some implementations of the seventh aspect, the processing unit is further configured to verify whether the terminal device is a trusted terminal device, and determine not to perform the authentication procedure of authenticating the first user identity in a case that the terminal device is the trusted terminal device.

[0058] In an eighth aspect, a communication apparatus is provided, which comprises a transceiver and a processing unit. The transceiver is configured to receive a first message, the first message comprising a first authentication result, the first authentication result indicating whether an authentication of a first user identity by a network is successful; and the processing unit is configured to generate and save a first trust record in a case that the first authentication result indicates that the authentication is successful; and verify a second trust record input by the first user according to the saved first trust record in a case that the terminal device is logged in by the first user identity; and determine not to authenticate the first user identity in a case that a short-term trust record verification of the first user identity is successful; wherein the first authentication result is determined according to a third trust record, the third trust record being a long-term trust record corresponding to the first user identity.

[0059] In some implementations of the eighth aspect, the first message further comprises a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a time when the authentication result is generated; and the processing unit is further configured to determine whether the first authentication result is valid according to the first time length and the first timestamp.

[0060] In some implementations of the eighth aspect, the transceiver is further configured to send a second message to the first network element, the second message carrying the first user identity, and the second message being used to indicate that the terminal device successfully verifies the short-term credential corresponding to the first user identity.

[0061] In some implementations of the eighth aspect, the second message further carries first indication information, the first indication information indicating that the first user identity does not need to be authenticated.

[0062] In a ninth aspect, a communication apparatus is provided, which comprises a processor configured to cause the apparatus to implement any one of the first aspect to the fourth aspect, and the method in any possible implementation of the first aspect to the fourth aspect, by executing a computer program (or computer executable instructions) stored in a memory and / or by a logic circuit.

[0063] Optionally, the apparatus further comprises a memory, which can be deployed separately from the processor or can be deployed centrally.

[0064] Optionally, the apparatus further comprises a communication interface, to which the processor is coupled. The communication interface can be a transceiver, or an input / output interface.

[0065] In one implementation, the apparatus is a verification network element, or a chip deployed in a verification network element, or a logic module or software capable of implementing all or part of the functions of a verification network element. When the apparatus is a chip, the communication interface can be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or related circuitry, etc. on the chip or chip system. The processor can also be embodied as a processing circuit or a logic circuit.

[0066] In another implementation, the apparatus is a terminal device, or a chip deployed in a terminal device, or a logic module or software capable of implementing all or part of the functions of a terminal device. When the apparatus is a chip, the communication interface can be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or related circuitry, etc. on the chip or chip system. The processor can also be embodied as a processing circuit or a logic circuit.

[0067] Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0068] In the implementation process, the processor can be one or more chips, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, a gate circuit, a flip-flop, and various logic circuits. The input signal received by the input circuit can be, but is not limited to, received and input by the receiver, the output signal output by the output circuit can be, but is not limited to, output to the transmitter and transmitted by the transmitter, and the input circuit and the output circuit can be the same circuit, which is used as the input circuit and the output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.

[0069] In a tenth aspect, a chip system is provided, and the processor is configured to execute a computer program or instructions in the memory, so that the chip system implements any one of the first aspect to the fourth aspect, and the method in any possible implementation manner of the first aspect to the fourth aspect.

[0070] In an eleventh aspect, a communication system is provided, and the communication system includes at least one of a first network element and a terminal device, the first network element is configured to execute the method in the first aspect and the second aspect, and any possible implementation manner of the first aspect and the second aspect; and the terminal device is configured to execute the method in the third aspect and the fourth aspect, and any possible implementation manner of the third aspect and the fourth aspect.

[0071] In a twelfth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program (also referred to as code or instructions), which, when executed on a computer, causes the computer to execute the method in any one of the first aspect to the fourth aspect, and any possible implementation manner of the first aspect to the fourth aspect.

[0072] In a thirteenth aspect, a computer program product is provided, and the computer program product includes a computer program (also referred to as code or instructions), which, when executed, causes a computer to execute the method in any one of the first aspect to the fourth aspect, and any possible implementation manner of the first aspect to the fourth aspect.

[0073] The beneficial effects brought by the above-mentioned fifth aspect to the thirteenth aspect can refer to the description of the beneficial effects of the first aspect to the fourth aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0074] FIG. 1 is a schematic diagram of a network architecture suitable for the present application.

[0075] FIG. 2 is a schematic diagram of a user equipment registering to a network.

[0076] FIG. 3 is a schematic diagram of an application scenario suitable for the present application.

[0077] FIG. 4 is a schematic flowchart of a user authentication method.

[0078] FIG. 5 is a schematic flowchart of a communication method 500 provided by the present application.

[0079] FIG. 6 is a schematic flowchart of a communication method 600 provided by the present application.

[0080] FIG. 7 is a schematic flowchart of a communication method 700 provided by the present application.

[0081] FIG. 8 is a schematic flowchart of a communication method 800 provided by the present application.

[0082] FIG. 9 is a schematic flowchart of a communication method 900 provided by the present application.

[0083] FIG. 10 is a schematic block diagram of a communication apparatus 1000 provided by the present application.

[0084] FIG. 11 is a schematic block diagram of a communication apparatus 1100 provided by the present application.

[0085] FIG. 12 is a schematic block diagram of a chip system 1200 provided by the present application. DETAILED DESCRIPTION

[0086] The technical solutions in the present application will be described below in conjunction with the accompanying drawings.

[0087] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), 5th generation (5G) system, future communication system, for example, 6th generation (6G) system.

[0088] FIG. 1 is a schematic diagram of an architecture of a communication system suitable for the present application. The various parts involved in the architecture will be described below respectively.

[0089] Terminal equipment 110: The terminal equipment in the embodiments of the present application can refer to a device that provides voice and / or data connectivity to a user, or a handheld device with wireless connection function, or other processing devices connected to a wireless modem.

[0090] The terminal device can also be referred to as a terminal, an access terminal, a user unit, a user equipment (UE), a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a wireless communication device, a user agent or a user apparatus. The terminal device is a device including a wireless communication function (providing voice / data connectivity to a user). For example, a handheld device with a wireless connection function, or a vehicle-mounted device, etc. The terminal in the embodiments of the present application can be a mobile phone, a pad, a computer with a wireless transceiver function, a train, an airplane, a mobile internet device (MID), a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (REDCAP UE), a wireless terminal in industrial control (such as a robot, etc.), a wireless terminal in vehicle networking (such as a vehicle-mounted device, a whole vehicle device, a vehicle-mounted module, a vehicle, a vehicle-mounted chip, an on board unit (OBU) or a telematics box (T-BOX), etc.), a wireless terminal in self driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart city, a wireless terminal in smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with a wireless communication function, a computing device or other processing device connected to a wireless modem, a wearable device, a terminal in a 5G network or a terminal in a future communication system, etc. It can be understood that all or part of the functions of the terminal device in the present application can also be realized by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform).

[0091] Among them, the wearable device can also be called a wearable smart device, which is a general term for devices that can be worn, such as glasses, gloves, watches, clothing, and shoes, which are designed and developed by applying wearable technology to daily wear. The wearable device is a portable device that can be worn directly on the body or integrated into the user's clothes or accessories. The wearable device is not only a hardware device, but also a powerful function achieved through software support and data interaction, cloud interaction. The broad sense of wearable smart devices includes devices with full functions, large sizes, and the ability to realize complete or partial functions without relying on smart phones, such as smart watches or smart glasses, and devices that focus on a specific application function and need to be used with other devices, such as smart phones, such as various smart wristbands, smart jewelry, and the like.

[0092] The terminal device of the present application can also be a module or unit for implementing terminal functions, for example, a universal integrated circuit card (UICC). It should be understood that the UICC card is only used as an example, and in actual implementation, the UICC card can also be replaced by a device similar to the function of the UICC card, such as an embedded universal integrated circuit card (eUICC). In addition, the UICC card can also be other names, such as a blockchain universal integrated circuit card (B-UICC), which is not limited in the present application.

[0093] (Radio) access network (radio access network, (R)AN) node 120: used to provide network access functions for terminal devices in a specific area, and can use different quality transmission tunnels according to the level of the terminal device, the demand of the service, etc. The RAN node can manage radio resources, provide access services for terminal devices, and then complete the forwarding of control signals and terminal device data between terminal devices and core networks.

[0094] In a possible scenario, the RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc. The RAN node can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a wireless controller in a cloud radio access network (CRAN) scenario. Alternatively, the RAN node can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in V2X technology can be a road side unit (RSU). All or part of the functions of the RAN node in this application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (for example, a cloud platform). The RAN node in this application can also be a logical node, a logical module or software that can implement all or part of the functions of the RAN node.

[0095] In another possible scenario, multiple RAN nodes cooperate to assist a terminal to implement wireless access, and different RAN nodes respectively implement part of the functions of a base station. For example, the RAN node can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna processing unit (AAU), or a remote radio head (RRH).

[0096] In different systems, the CU (or CU-CP and CU-UP), DU or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an open-radio access network (O-RAN) system, the CU can also be referred to as an open-central unit (O-CU) (open CU); the DU can also be referred to as an open-distributed unit (O-DU) (open DU); the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, CU-CP, CU-UP, DU and RU are taken as examples for description in this application. Any one of the CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0097] User plane network element 130: used for packet routing and forwarding, quality of service (QoS) processing of user plane data, etc.

[0098] In the 5G communication system, the user plane network element can be a user plane function (UPF) network element. In future communication systems, the user plane network element can still be a UPF network element, or it can also have other names, which are not limited in this application.

[0099] Data network (DN) 140: a data network that provides service to users, generally with the client located in the UE and the server located in the data network. The data network can be a private network such as a local area network, or an external network not under the control of the operator such as the Internet, or a dedicated network jointly deployed by operators such as a network providing internet protocol (IP) multimedia subsystem (IMS) services.

[0100] In future communication systems, the DN in the 5G communication system can be used, or entities with similar functions can be replaced by other names, which are not limited in this application.

[0101] Authentication server 150: performs authentication processes based on user identity to ensure that only legitimate users can access the network, and is used to generate and distribute keys to ensure data security and integrity. Supports a unified authentication framework.

[0102] In the 5G communication system, the authentication server can be an authentication server function (AUSF) network element. In future communication systems, the authentication server function network element can still be an AUSF network element, or can also have other names, which are not limited in the present application.

[0103] The access management (access management) network element 160 is mainly used for mobility management and access management, etc., such as access authorization and other functions.

[0104] In the 5G communication system, the access management network element can be an access and mobility management function (AMF) network element. In future communication systems, the access management network element can still be an AMF network element, or can also have other names, which are not limited in the present application.

[0105] The session management (session management) network element 170 is mainly used for session management, internet protocol (IP) address allocation and management of terminal devices, selection of manageable user plane functions, termination of policy control and charging function interfaces, and downlink data notification, etc.

[0106] In the 5G communication system, the session management network element can be a session management function (SMF) network element. In future communication systems, the session management network element can still be an SMF network element, or can also have other names, which are not limited in the present application.

[0107] The network exposure (network exposure) network element 180 is used to expose network capabilities to third-party applications, and can realize friendly connection of network capabilities and business needs.

[0108] In the 5G communication system, the network exposure network element can be a network exposure function (NEF) network element. In future communication systems, the network exposure network element can still be an NEF network element, or can also have other names, which are not limited in the present application.

[0109] The network repository (network repository) network element 190 is used to maintain real-time information of all network function services in the network.

[0110] In the 5G communication system, the network storage network element can be a network repository function (NRF) network element. In the future communication system, the network storage network element can still be an NRF network element, or can also have other names, which are not limited in the present application.

[0111] The policy control network element 1100 is a unified policy framework for guiding network behavior, and provides policy rule information and the like for control plane function network elements (such as AMF, SMF network elements, etc.).

[0112] In the 4G communication system, the policy control network element can be a policy and charging rules function (PCRF) network element. In the 5G communication system, the policy control network element can be a policy control function (PCF) network element. In the future communication system, the policy control network element can still be a PCF network element, or can also have other names, which are not limited in the present application.

[0113] The data management network element 1110 is used for processing terminal device identification, access authentication, registration, and mobility management, etc.

[0114] In the 5G communication system, the data management network element can be a unified data management (UDM) network element. In the future communication system, the unified data management can still be a UDM network element, or can also have other names, which are not limited in the present application.

[0115] The application network element 1120 is used for data routing for application influence, access to the network, interaction with the policy framework for policy control, etc.

[0116] In the 5G communication system, the application network element can be an application function (AF) network element. In the future communication system, the application network element can still be an AF network element, or can also have other names, which are not limited in the present application.

[0117] In the above network architecture, a network slice-specific authentication and authorization function (NSSAAF), an authentication credential repository and processing function (ARPF) network element, a security anchor function (SEAF) network element, etc. (not shown in the figure) can also be included. Among them, the NSSAAF can be responsible for authenticating network slices that require specific authentication, ensuring that users have access to specific network slice services; the ARPF is mainly used to store the root key of the user and the relevant subscription data of the authentication, and to calculate the authentication and authorization vector; the SEAF is mainly used to derive the non-access layer (NAS) and access layer (AS) keys of the lower layer according to the anchor key, and to compare the authentication results.

[0118] In the above network architecture, N1, N2, N3, N4, N6, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are interface sequence numbers. The meanings of the above interface sequence numbers can be referred to the meanings defined in the 3GPP standard protocol, and the present application does not limit the meanings of the above interface sequence numbers.

[0119] Exemplarily, the N2 interface is the interface between the RAN and the access management network element, used for sending wireless parameters, NAS signaling, etc.; the N3 interface is the interface between the RAN and the user plane function network element, used for transmitting user plane data, etc.; the N4 interface is the interface between the session management function network element and the user plane function network element, used for transmitting information such as service policy, N3 connection tunnel identification information, data caching indication information, and downlink data notification message, etc. The N6 interface is the interface between the DN and the user plane function network element, used for transmitting user plane data, etc.

[0120] Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are service interfaces, and the network elements can exchange information through the service interfaces.

[0121] It should be understood that the interface names between the various network functions in the figure are only an example, and in specific implementation, the interface names of the system architecture can also be other names, which are not limited by the present application. In addition, the names of the messages (or signaling) transmitted between the above various network elements are also only an example, and do not constitute any limitation on the functions of the messages themselves.

[0122] It should also be understood that the network architecture described above for the embodiments of the present application is only an example of the network architecture from the perspective of the traditional point-to-point architecture and the service-oriented architecture, and the network architecture applicable to the embodiments of the present application is not limited thereto, and any network architecture capable of realizing the functions of the above-mentioned network elements is applicable to the embodiments of the present application.

[0123] It should also be understood that the names of the various network elements and interfaces in the present application are only examples, and the present application does not exclude the case where the various network elements are given other names in the future, and the case where the functions of the various network elements are merged. With the evolution of communication systems, any device or network element capable of realizing the functions of the above-mentioned network elements is within the scope of protection of the present application.

[0124] It can be understood that the above-mentioned network elements or functions can be network elements in a hardware device, or software functions running on a dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The above-mentioned network elements or functions can be divided into one or more services, and further, services independent of network functions can also exist.

[0125] In order to facilitate understanding of the technical solutions of the embodiments of the present application, first, some terms or concepts that may be involved in the embodiments of the present application are simply described.

[0126] FIG. 2 is a schematic flowchart of a UE registration process. The registration process can include the following steps.

[0127] S201, the UE sends a registration request message to the RAN. Accordingly, the RAN receives the registration request message.

[0128] The registration request message carries the identity of the UE and the registration type.

[0129] The registration type includes but is not limited to the following:

[0130] 1) Initial registration: the registration process initiated by the UE in the deregistered state (deregistered state: i.e. connection management (CM) idle (CM-IDLE) state, at this time, there is no connection established between the UE and the RAN and between the RAN and the 5GC.

[0131] 2) mobility registration update: the UE needs to initiate a re-registration procedure due to mobility (at this time, the UE is in a registration management (RM)-REGISTERED state), and the location of the UE is updated through the mobility registration update.

[0132] 3) periodic registration update: the UE is in the RM-REGISTERED state, and initiates a registration procedure due to a periodic registration update timer timeout;

[0133] 4) emergency registration: a registration procedure initiated when the UE is in a service-restricted state;

[0134] In the 5G registration procedure, the identity information of the UE carried by the registration request message includes the following cases:

[0135] 1) when the UE has a valid 5G globally unique temporary identifier (5G-GUTI) (for example, allocated by the AMF serving the UE), the 5G-GUTI is carried in the registration request; if the UE does not have a valid 5G-GUTI, the SUCI is carried.

[0136] 2) in the emergency registration, if the UE does not have a valid 5G-GUTI and does not have a subscription permanent identifier (SUPI) (that is, does not have a subscription concealed identifier (SUCI), and the SUCI is an encrypted SUPI), a permanent equipment identifier (PEI) is carried.

[0137] S202, the RAN selects an AMF.

[0138] That is, the RAN selects an AMF that can properly serve the UE. For example, the RAN can select the AMF according to local pre-configuration information or information in the 5G-GUTI.

[0139] S203, the RAN sends a registration request to the AMF. Correspondingly, the AMF receives the registration request.

[0140] S204, the AMF selects an AUSF.

[0141] That is, the AMF selects a suitable AUSF to perform authentication and other security procedures. For example, the AMF can discover the AUSF through local configuration or NRF based on SUPI or based on the home public land mobile network (HPLMN ID) and / or router-identity (RID) in SUCI.

[0142] S205, interaction between the UE, AMF, AUSF, and UDM to complete authentication and other security procedures.

[0143] For example, the security procedures include the EAP-AKA' authentication procedure.

[0144] It should be understood that the authentication methods currently supported by the 5G network are the 5G-AKA authentication method and the EAP-AKA' authentication method, respectively. The present application does not limit the authentication method, for example, the operator can configure the authentication method in the subscription data, and the UDM can determine the authentication method after obtaining the SUPI of the UE; or the UDM can select according to the SUPI type in the SUPI, for example, if the SUPI type is IMSI, select 5G-AKA; if the SUPI type is NAI, select EAP-AKA'.

[0145] S206, the AMF interacts with the UDM to obtain the subscription data of the UE.

[0146] For example, after the UE and the network side authenticate each other successfully, the AMF interacts with the UDM to obtain the subscription data of the UE.

[0147] S207, the AMF sends an N2 message to the RAN. Correspondingly, the RAN receives the N2 message.

[0148] The N2 message carries a NAS message that needs to be forwarded to the UE by the RAN. The NAS message includes a registration accept message sent by the AMF to the UE.

[0149] S208, the RAN sends the NAS message to the UE.

[0150] That is, after receiving the N2 message, the NAS message included in the N2 message is forwarded to the UE.

[0151] In the current network architecture, the core network provides network services based on the SUPI. When the UE requests a certain service from the network, the core network identifies the SUPI, and then provides the corresponding network service for the UE based on the subscription data of the SUPI. That is, in this case, the operator network can determine the UE through the SUPI, but cannot determine the user of the terminal device. That is, the operator only knows the SUPI of the UE, and assumes that the user using the subscription data corresponding to the SUPI is the user of the UE. In order to be able to provide more flexible services, a user identifier can be introduced, that is, when different users of the UE access the network, the core network can provide responsive services for different users based on different user identifiers and corresponding subscription information.

[0152] FIG. 3 is a schematic diagram of an application scenario suitable for the present application. As shown in FIG. 3, a shared car is configured with a SUPI when it is shipped, that is, the shared car is a terminal device. After the user ID is introduced, the core network can know whether user A is driving the car or user B is using it. Thus, different services can be provided for different users. For example, some users have assisted driving appeals and need large bandwidth and low latency services, and the subscription data of the user will reflect these appeals; other users do not have this appeal and can use the minimum guaranteed communication capability.

[0153] It should be understood that in the present application, the user identifier corresponds to the subscription information (data), which can be used to provide differentiated services for different users logged into the UE. For example, the quality of service (Qos) parameters corresponding to the subscription information of different user identifiers are different, and the subscribed services are different.

[0154] After the user (user) logs in to the UE using the user identifier (user ID), the network side authenticates the legality of the user ID (that is, the network side determines whether the user corresponding to the user ID can access the network).

[0155] FIG. 4 is a schematic diagram of an authentication process based on a user identifier (user ID). The method includes the following steps.

[0156] S401, the user holds a long-term credential.

[0157] In the present application, the long-term credential can be used for network user identifier authentication / authorization or establishing a secure connection, which can be a set of strings or a certificate, and the specific format of the long-term credential is not limited.

[0158] The user holding the long-term credential can be understood as: the long-term credential is stored on the user device (such as the memory of the user device), or can be stored elsewhere (such as a USIM card, a user's personal notebook, or the user's memory, etc.).

[0159] It should be understood that the long-term credential of the user can be used on the external device or the UE. The external device can be a terminal device (such as a mobile phone without a SIM card) or a device used by the user to establish a connection with the UE (such as a tablet computer without 3GPP wireless function).

[0160] S402, the UDM stores the long-term credential of the user.

[0161] For example, the long-term credential of the user is stored in the credential storage function. The long-term credential of the user is stored in the credential storage function, which means that the long-term credential is stored in the user identifier. If the user identifier is represented by the user ID (or user ID), the long-term credential of the user ID is unique. On the terminal side, the user can use the long-term credential to log in to different external devices or different UEs.

[0162] Optionally, S403, the UE registers to the network.

[0163] For details, refer to the description of the method 200.

[0164] S404, the external device or the user triggers login.

[0165] For example, the user logs in to the external device or the user equipment using the user ID (or user ID). If the user logs in to the external device, the external device establishes a connection with the UE, and the UE determines that the user logs in. The UE determines the user login in multiple ways, which are not limited, for example, by establishing a connection with the external device or by being logged in by the user. The external device and the user equipment establish a connection in multiple ways, such as through Bluetooth technology, wi-fi technology, etc.

[0166] S405, the UE sends a first NAS message to the AMF. Correspondingly, the AMF receives the first NAS message.

[0167] For example, the first NAS message carries at least one of the following: UE identity information, user ID, or at least one of the first indication information.

[0168] For example, the user ID is protected by security, for example, including integrity security protection and / or confidentiality security protection. For example, the user ID is protected by confidentiality.

[0169] Optionally, the first NAS message has security protection, including: integrity security protection and / or confidentiality security protection. The application does not limit the protection manner of the user ID, for example, it can be security protection for the user ID alone, or security protection for the first NAS message carrying the user ID.

[0170] In an implementation manner, the first NAS message is a registration request message.

[0171] The registration request message carries at least two of the UE identity information, the user ID and the first indication information. Optionally, the registration request message can only carry the user ID.

[0172] (1) UE identity information;

[0173] For example, the UE identity information can also be described as UE identity (such as UE ID), for example, it can be SUCI or 5G-GUTI.

[0174] (2) user ID;

[0175] For example, the user ID can include an information part for uniquely identifying a user and a routing information part for determining a credential storage function. The credential storage function can determine a long-term credential corresponding to the user according to the information part for uniquely identifying the user.

[0176] In an example, the user ID is expressed in the NAI format: username@realm. The username part carries information for uniquely identifying a user, such as a 64-bit string, which can be information convenient for a user to remember. The realm part carries routing information for determining the credential storage function.

[0177] In another example, the user ID is expressed in the fully qualified domain name (FQDN) format. The form of the user ID is not limited.

[0178] (3) first indication information;

[0179] The first indication information can indicate user login, for example, it indicates that a user logs in a user device, or it indicates that the UE receives a message (or a pop-up window) sent by an external device, which indicates that a user logs in the external device.

[0180] The first indication information can be a registration type, such as the registration type indicating that the registration request message is used to request registration for a user; or the first indication information can also be a user ID; or the first indication information can also be bit indication information, such as when the bit indication information is set to 1, it indicates that the registration request message is not used for UE registration, or indicates that the registration request message is sent because the user logs in or receives a message of an external device; or the first indication information can also be user ID authentication capability information (for example, capability of User-Id based authentication) of the UE, such as when the UE has user authentication capability, it indicates that the registration request message is used to request registration for a user or for an external device, at this time the network can perform user authentication.

[0181] It should be noted that when the UE identity information is 5G-GUTI, the user ID is protected by confidentiality; when the UE identity information is 5G-SUCI, the user ID can be placed in the confidentiality protection part.

[0182] Specifically, the first NAS message carries UE identity information, and when the UE identity information is 5G-GUTI, the user ID is protected by confidentiality and / or integrity security protection; in the case of carrying UE identity information in the first NAS message and the UE identity information being SUCI, the user ID can be placed in the confidentiality protection part.

[0183] It should be understood that if the UE identity information and the user ID are carried in the first NAS message at the same time, the network side can first perform primary authentication on the UE, and then trigger the NAS SMC process to activate the NAS security context, for example, the AMF sends the NAS SMC message to the UE, and the AMF receives the NAS SMP message from the UE. Further, after the primary authentication of the UE is successful, the authentication process for the user ID is initiated.

[0184] In another implementation manner, the first NAS message is a user authentication request message.

[0185] The user authentication request message can be regarded as a new type of NAS message. The user authentication request message can carry at least one of the UE identity information, the user ID and the first indication information.

[0186] (1) the UE identity information is SUCI or 5G-GUTI;

[0187] (2) the user ID;

[0188] (3) the first indication information;

[0189] The above information can be referred to the description above.

[0190] In yet another implementation, the first NAS message is a NAS security mode complete (SMP) message.

[0191] The NAS SMP message carries the user ID, and the specific implementation can be referred to the description above.

[0192] Optionally, before performing the step S405, the method further includes: receiving, by the AMF, a registration request message from the UE, the registration request message comprising UE identity information (e.g., 5G-SUCI or 5G-GUTI); determining, by the AMF, to initiate a primary authentication procedure for the UE according to the registration request message; and sending, by the AMF to the UE, a NAS SMC message after the primary authentication procedure for the user equipment, the NAS SMC message being used to activate a NAS security context. That is, in the NAS SMC procedure, the UE can carry the user ID with security protection in the NAS SMP message, which reduces the signaling overhead while ensuring the security of the network session.

[0193] Optionally, before the UE sends the first NAS message to the AMF, the method further includes: obtaining, by the UE, a user ID (user ID).

[0194] Exemplarily, the UE can obtain the user ID in one or more of the following manners.

[0195] In a first implementation, the UE obtains the user ID through a connection with the user equipment.

[0196] For example, the user ID is carried in a message (or a pop-up window) sent by the external device to the UE. It should be understood that in this implementation, a communication connection is established between the external device and the UE.

[0197] In a second implementation, the UE obtains the user ID through user input.

[0198] For example, when the user logs in to the UE using a username (e.g., the user's mobile phone number or WeChat ID), the UE can determine the username as the user ID.

[0199] In a third implementation, the UE obtains part of the user ID according to the message sent by the external device or through user input, and then determines the user ID.

[0200] For example, the UE first acquires the information part uniquely identifying the user in the user ID, and then determines the user ID. For example, after the user inputs an account number with a username of 123456, the UE acquires 123456 and determines it as the information part uniquely identifying the user. The UE further determines the HPLMN ID and / or RID of the UE as the routing information for determining the credential storage function, for example, 5gc.RID.HPLMN ID, and then combines to obtain the user ID in the NAI format of 123456@5gc.RID.HPLMN ID.

[0201] In a fourth implementation manner, the information part uniquely identifying the user in the user ID contains information uniquely identifying the user that is protected by confidentiality.

[0202] That is, the information part uniquely identifying the user in the user ID in this implementation manner can be regarded as the information uniquely identifying the user that is protected by confidentiality (obtained by establishing a communication connection with an external device or obtained by user input).

[0203] S406, the AMF determines to perform the user authentication procedure.

[0204] Specifically, the AMF determines to perform the user authentication procedure according to the information carried in the first NAS message or the information associated with the first NAS message.

[0205] For example, the AMF determines to perform the user authentication procedure according to the user ID in the first NAS message.

[0206] For another example, the AMF determines to perform the user authentication procedure according to the first indication information in the first NAS message.

[0207] For example, the first indication information can be a registration type (indicating that the first NAS message can be a registration request message for the user), a specific field or user ID (user ID) associated with the user, or user ID authentication capability information of the UE.

[0208] For another example, the AMF determines to perform the user authentication procedure according to the name of the first NAS message.

[0209] For example, the name of the first NAS message is a user authentication request message (such as Namf_UserAuthentication_Authenticate Request).

[0210] Optionally, the AMF can determine to perform the user authentication procedure according to local configuration information. The determination manner of the AMF determining to perform the user authentication procedure is not limited.

[0211] Optionally, the AMF confirms the occasion to perform the user authentication.

[0212] In one example, the AMF confirms the occasion to perform the user authentication after receiving the first NAS message, but performs the user authentication after the specific procedure is finished.

[0213] Here, the specific procedure can be a primary authentication procedure for the UE, or a registration procedure for the UE, i.e., the user authentication is performed after the UE is successfully registered. That is, the AMF performs the authentication for the UE first, and then performs the authentication for the user after the authentication for the UE is successful. Specifically, when the first NAS message carries UE identity information, if the UE identity information is SUCI, the AMF performs the primary authentication procedure first, and then performs the user authentication procedure.

[0214] In another example, the AMF confirms the occasion to perform the user authentication in the NAS SMC procedure.

[0215] For example, the AMF triggers the authentication for the user after receiving the NAS SMP message sent by the UE; or the occasion for the AMF to confirm the user authentication can also be that the AMF can perform the action of determining the user authentication after obtaining the subscription data of the UE. For example, the AMF determines that the UE can be used for user login or can perform the user authentication procedure instead of an external device, and then performs the action of determining the user authentication, such as the subscription data of the UE indicating that the user ID can be bound to the UE, and then determining to perform the user authentication.

[0216] In another example, the AMF performs the action of determining after obtaining the subscription data of the user ID currently logged in the UE. For example, the AMF determines that the user ID of the UE can log in the UE or an external device, and then performs the action of determining the user authentication.

[0217] S407, the AMF performs an AUSF discovery procedure.

[0218] For example, the AMF performs the AUSF discovery procedure when the AMF determines to perform the user authentication.

[0219] For example, the AMF discovers the AUSF that can perform the user authentication based on local configuration.

[0220] For another example, the AMF determines the AUSF that can perform the user authentication based on the user id.

[0221] It can be understood that if the first NAS message is a registration request message, the step can be performed before the registration accept message or after the registration accept message. That is, the AMF sends the registration accept message to the UE before S406 is performed, or the AMF sends the registration accept message to the UE after S415 is performed. The present application does not limit the order of the registration process and the user authentication process.

[0222] The specific implementation of the AMF discovering (or determining) the AUSF will be described in detail below.

[0223] For example, the AMF can discover the AUSF based on the user ID of the UE, including the following ways:

[0224] Firstly, the AUSF is discovered based on the home network identifier (home network identifier), routing indicator (routing indicator) and local configuration in the user ID.

[0225] Secondly, the AUSF is discovered through the NRF based on the AUSF group identifier (AUSF Group ID) in the user ID context in the AMF.

[0226] When the AMF discovers the AUSF through the NRF, the NRF can send the AUSF group identifier to the AMF; the AMF sends the group identifier to other AMFs, so that other AMFs can select the AUSF according to the AUSF group identifier.

[0227] Thirdly, the AUSF is discovered through the NRF based on the user ID.

[0228] When the AMF discovers the AUSF through the NRF, the AMF can send the user ID of the UE to the NRF, and then the NRF performs AUSF discovery according to the user ID of the UE.

[0229] S408, the AMF sends a user authentication request message to the AUSF. Correspondingly, the AUSF receives the user authentication request message from the AMF.

[0230] For example, the user ID is carried in the user authentication request message. That is, the user authentication request message is used to request to authenticate the user corresponding to the user ID.

[0231] Optionally, the user authentication request message also carries second indication information.

[0232] The second indication information is used for indicating the user authentication. The second indication information is used for indicating a user authentication request message, or the second indication information can be a user authentication request message, or is used for indicating that the current is a user authentication process. Specifically, the second indication information is used for indicating that the user authentication request message is sent for the user authentication process.

[0233] The second indication information can have various forms, which are not limited.

[0234] For example, the second indication information is the message itself, i.e., the user authentication request message.

[0235] For another example, the second indication information is a new service operation, such as the second indication information indicating a user authentication type. When the authentication type is user authentication, it is indicated that the user authentication request message is for user authentication, not for UE authentication.

[0236] For another example, the second indication information is a bit indication information used for indicating the authentication type. When the bit is "1", it is indicated that the user authentication request message is not for UE authentication, or is for user authentication requested by the user or external equipment.

[0237] Optionally, the user authentication request message also carries an SN Name.

[0238] The SN Name can be a PLMN ID of the AMF, which is a fixed string, such as "user authentication".

[0239] S409, the AUSF performs a UDM discovery process.

[0240] For example, the AUSF determines to perform the user authentication process according to the user authentication request message of S408, and further triggers the discovery process of the UDM.

[0241] For example, the AUSF determines to perform the user authentication process according to the second indication information, or the user ID carried in the user authentication request message, or the user ID and the second indication information carried in the user authentication request message, and further triggers the discovery process of the UDM.

[0242] For another example, if the user authentication request message in S408 does not carry the SN Name, the AUSF determines to perform the user authentication process, and further triggers the discovery process of the UDM. The SN name is a service network name associated with the UE. If the user authentication request message does not carry the SN Name, the AUSF can understand that the user authentication request message is not for UE authentication, but for user authentication.

[0243] Exemplarily, the AUSF can discover the UDM in the following ways:

[0244] discovering the UDM based on a home network identifier and a routing indication in the user ID;

[0245] discovering the UDM based on a UDM Group ID in the user ID context in the AMF through the NRF;

[0246] discovering the UDM based on the user ID through the NRF.

[0247] S410, the AUSF sends a user authentication vector request message to the UDM. Correspondingly, the UDM receives the user authentication vector request message.

[0248] For example, the user authentication vector request message is Nudm_UEAuthentication_Request.

[0249] Exemplarily, the user ID is carried in the user authentication vector request message.

[0250] Optionally, the user authentication vector request message also carries third indication information. The third indication information is used to indicate that it is a user authentication vector request message, or is used to indicate that it is a user authentication process, specifically, is used to indicate that the current user authentication vector request message is sent for the user authentication process.

[0251] The form of the third indication information is not limited.

[0252] For example, the third indication information is the message itself.

[0253] For another example, the third indication information is a new service operation, such as the third indication information can be a user authentication type. When the authentication type is user authentication, it indicates that the user authentication vector request message is used to request the authentication vector of the user, rather than the authentication vector of the UE, or indicates that the user authentication vector request message is sent for the user or external device requested user authentication.

[0254] For another example, the third indication information can be a bit indication information representing the authentication type. When the bit is “1”, it indicates that the user authentication vector request message is not used to request the authentication vector of the UE, or indicates that the authentication vector request message is the authentication vector requested by the user or external device.

[0255] Optionally, if the AUSF in S408 receives the SN Name in the user authentication request message, the SN Name is also carried in S410.

[0256] S411, the UDM generates an authentication vector according to the long-term credential corresponding to the user ID.

[0257] Illustratively, the UDM selects an authentication mode (EAP-AKA) according to the subscription information of the user and generates a corresponding authentication vector AV.

[0258] S412, the UDM sends a user authentication vector response message to the AUSF. Correspondingly, the AUSF receives the user authentication vector response message.

[0259] The user authentication vector response message carries a user authentication vector.

[0260] Illustratively, the UDM sends the authentication vector to the AUSF through the user authentication vector response message (e.g., Nudm_UEAuthentication_Response).

[0261] Optionally, the user authentication vector response message carries the user ID (if the user authentication vector request message sent by the AUSF to the UDM carries the user ID, the user authentication vector response message can carry the user ID).

[0262] S413, a user authentication procedure is performed.

[0263] Illustratively, the AUSF performs a user authentication procedure with an external device or a user logged on the UE. The user authentication procedure can be an EAP-AKA authentication procedure or a 5G-AKA authentication procedure.

[0264] S414, the AUSF sends a user authentication response message to the AMF. Correspondingly, the AMF receives the user authentication response message from the AUSF.

[0265] Illustratively, the user authentication response message carries indication information #1 indicating a user authentication result and a user ID.

[0266] The indication information #1 is used to indicate a user authentication success or a user authentication failure. The indication information #1 can be bit indication information, or enumeration type indication information, or a message.

[0267] For example, when the indication information #1 is bit indication information, a bit of “0” indicates authentication failure, and a bit of “1” indicates authentication success.

[0268] For another example, when the indication information #1 is enumeration type indication information, a string of “failure” represents authentication failure, and a string of “success” represents authentication success.

[0269] For example, when the indication information #1 is a message, the EAP-Failure indicates that the authentication fails, and the EAP-Success indicates that the authentication succeeds.

[0270] Optionally, the AMF locally creates the context information of the user ID in the case that the indication information #1 indicates that the user authentication succeeds.

[0271] Optionally, the AMF can save at least one of the correspondence between the user ID and the SUPI and the authentication success time information, or in other words, the AMF saves the correspondence between the user ID and the SUPI and / or the authentication success time.

[0272] The S414a, the AMF saves the authentication result of the user.

[0273] The S415, the AMF sends a second NAS message to the UE. Correspondingly, the UE receives the second NAS message from the AMF.

[0274] The second NAS message carries indication information #2 indicating the authentication result of the user, for example, the indication information #2 indicates that the user authentication succeeds or the user authentication fails.

[0275] In an implementation manner, the indication information #2 is the same as the indication information #1.

[0276] For example, in the case that the indication information #2 indicates that the user authentication succeeds, the UE allows the user or the external device to continue to use the UE to provide services for the UE. In the case that the indication information #2 indicates that the user authentication fails, the UE allows the user or the external device to continue to attempt the authentication again, or the UE logs off the user from the UE, or releases the connection between the UE and the external device. In the case that the UE allows the user or the external device to continue to attempt the authentication again, the UE re-sends the first NAS message to the AMF.

[0277] The S416, the UE sends indication information #3 to the user or the external device. Correspondingly, the external device receives the indication information #3 from the UE.

[0278] The indication information #3 is used to indicate the authentication result of the user, for example, the indication information #3 indicates that the user authentication succeeds or the user authentication fails.

[0279] In an implementation manner, the indication information #3, the indication information #2 and the indication information #1 are the same.

[0280] The UE can send the indication information #3 to the external device in multiple ways. For example, the UE can display notification information, and the notification information displays “login succeeds”. In the case that the UE sends the indication information #3 to the external device, the transmission of the indication information #3 adapts to the protocol between the UE and the external device.

[0281] In this application, the AUSF can also be replaced by NSSAAF, AAA-Proxy, or NSSAAF and AAA-Proxy (AAA-P); the UDM can be replaced by an AAA server. When the UDM is replaced by an AAA server and the AUSF is replaced by an AAA-P, the AAA-P is an optional network element. In the case where the AAA-P is not needed, S408 and S409 can not be performed; S410 is sent by the AMF, and S412 is sent to the AMF; the endpoint of S413 is in the AAA server; the sender of S414 is the AAA server. The description of the same or similar cases is omitted below.

[0282] Based on the above user authentication process, each time the user logs in the UE using the user ID, the network will interact with the authentication server / authentication network element to achieve the authentication of the user (user ID), which brings multiple redundant authentication processes and increases the signaling overhead for repeated login of the same user ID in a short time.

[0283] Therefore, the present application provides a communication method which can reduce the signaling interaction in the authentication process of the same user ID authentication and save the signaling overhead.

[0284] In order to facilitate the understanding of the embodiments of the present application, the following points are explained.

[0285] Firstly, in the present application, "for indicating" can include direct indication and indirect indication. When describing that certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and it does not mean that A must be included in the indication information.

[0286] The information indicated by the indication information is called to-be-indicated information, and there are many ways to indicate the to-be-indicated information in the specific implementation process. The to-be-indicated information can be sent as a whole, or can be sent separately in multiple sub-information, and the sending period and / or sending occasion of these sub-information can be the same or different. The specific sending method is not limited in the present application. Among them, the sending period and / or sending occasion of these sub-information can be pre-defined, for example, pre-defined according to the protocol, or configured by the transmitting end device through sending configuration information to the receiving end device.

[0287] Secondly, in the present application, "at least one" means one or more, and "multiple" means two or more.

[0288] In addition, in the embodiments of the present application, "first", "second", and various numbers (for example, "#1", "#2", etc.) are only for the convenience of description and do not limit the scope of the embodiments of the present application.

[0289] Thirdly, the "storing" in the embodiments of the present application can refer to storing in one or more memories. The one or more memories can be separately arranged or integrated in the encoder or decoder, processor, or communication device. The one or more memories can be partially separately arranged and partially integrated in the decoder, processor, or communication device. The memory can be any form of storage medium, which is not limited in the present application.

[0290] It should be understood that the following embodiments do not limit the specific structure of the subject performing the method, as long as the subject can execute the method provided in the present application by running the code recording the method. For example, the subject performing the method provided in the present application can be a first network element, or a functional module or unit in the first network element capable of calling and executing a program.

[0291] Hereinafter, the communication method provided in the present application will be described in detail by way of example of the interaction between network elements without loss of generality.

[0292] FIG. 5 is a schematic flowchart of a communication method 500 provided in the present application. The method can include the following steps.

[0293] S510, the first network element obtains and stores a first credential corresponding to the first user identifier.

[0294] Exemplarily, the first network element can be a network element in a core network for processing user authentication. For example, the first network element can be a mobility management network element or a session management network element.

[0295] The first credential can be understood as a short-term credential corresponding to the first user identifier, which is used to verify the first user identifier in a short term. Specifically, verifying the first user identifier can refer to verifying whether the first user identifier is allowed to log in the terminal device, or verifying whether the first user identifier is allowed to access the network through the terminal device, or verifying the legality of the first user identifier, or verifying the binding relationship between the first user identifier and the terminal device.

[0296] In one example, the first network element obtains the first credential from a second network element.

[0297] The second network element can be used for authenticating the first user identifier or storing the subscription information corresponding to the first user identifier. For example, the second network element is an authentication function network element or an authentication server, such as AAA-S or AUSF; or the second network element is a data storage function network element, such as UDM.

[0298] Exemplarily, when the second network element is an authentication function network element or an authentication server, the first network element can acquire the first credential in an authentication procedure in which the authentication function network element or the authentication server authenticates the first user identifier.

[0299] It should be understood that, unless otherwise specified, "authenticating the first user identifier" in the present application refers to that the authentication function network element or the authentication server authenticates a long-term credential (an example of the third credential) corresponding to the first user identifier. The authentication procedure can refer to S401 to S414 in the method 400, and the same or similar cases are omitted below.

[0300] Specifically, before S510, the network side authenticates the first user identifier. For example, in the case that the external device or the first user triggers the first login of the terminal device, such as that the user logs in to the external device or logs in to the terminal device using the user ID #1 (an example of the first user identifier), the network side performs an authentication procedure of authenticating the user ID #1. The authentication procedure can refer to S401 to S414 in the method 400. In the authentication procedure or after the authentication procedure, the first network element receives a short-term credential #1 (an example of the first credential) corresponding to the user ID #1 from the authentication network element or the authentication server. For example, the authentication network element or the authentication server sends the authentication result corresponding to the user ID #1 and the short-term credential #1 to the first network element through an authentication response message.

[0301] When the second network element is a storage function network element, after the above authentication procedure, the authentication function network element or the authentication server can save the authentication result corresponding to the user ID #1 to the storage function network element, for example, by sending the authentication result to the storage function network element through an authentication notification message; after receiving the authentication result, the storage function network element stores the authentication result corresponding to the user ID #1 and generates a short-term credential #1 corresponding to the user ID #1; and the storage function network element notifies the first network element of the short-term credential #1.

[0302] The short-term credential #1 described above can be generated by the second network element, and the specific way of generating the short-term credential #1 by the second network element is not limited. For example, the second network element can generate the short-term credential #1 according to a long-term credential (such as a user password) corresponding to the user ID #1, such as generating the short-term credential #1 according to the long-term credential and a short-term credential generation algorithm signed by the terminal device, or generating the short-term credential #1 according to at least one of the identity of the terminal device (such as SUPI) and the long-term credential. The short-term credential can be of user identifier granularity.

[0303] In another example, the first network element generates the first credential.

[0304] Exemplarily, in the above authentication procedure, the first network element receives an authentication result corresponding to the user ID #1 from the authentication function network element or the authentication server, and after receiving the authentication result corresponding to the user ID #1, the first network element generates a short-term credential #1 (an example of the first credential) corresponding to the user ID #1. The specific generation manner can refer to the manner in which the second network element generates the short-term credential #1.

[0305] Optionally, the method further includes that the first network element notifies the first user of the first credential.

[0306] The first user can include a user (for example, user #1) who logs in the terminal device using the user ID #1. That is, after obtaining the short-term credential #1 (obtained from the second network element or generated as the first credential), the first network element notifies the user #1 of the short-term credential corresponding to the user ID #1.

[0307] The application does not limit the specific manner in which the first network element notifies the user #1 of the short-term credential corresponding to the user ID #1. For example, the first network element can send the short-term credential #1 to the terminal device, and the terminal device notifies the first user in the form of a short message or a pop-up window. Optionally, the first user memorizes the short-term credential corresponding to the user ID #1 for subsequent use of the user ID #1 and the short-term credential corresponding to the user ID #1 to log in the terminal device again.

[0308] In another example, the first network element requests the first credential from the first user, or in other words, the first network element negotiates with the first user to determine the first credential.

[0309] For example, after receiving the above authentication result, the first network element sends a NAS message to the terminal device to request negotiation of the short-term credential #1 (an example of the first credential) corresponding to the user ID #1 with the first user. After receiving the NAS message, the terminal device requests the first user to input the short-term credential corresponding to the user ID #1 in the form of a pop-up window or the like. The terminal device feeds back the short-term credential corresponding to the user ID #1 input by the first user to the first network element.

[0310] After obtaining the first credential through the above example, the first network element can save the first credential. For example, the first network element saves the first credential in the context information (UE context) corresponding to the terminal device or the context information (user context) corresponding to the user ID #1.

[0311] Optionally, the method further includes S520:

[0312] S520, the first network element sends an authentication result obtained by authenticating the first user identifier to the terminal device. Correspondingly, the terminal device receives the authentication result.

[0313] wherein the authentication result indicates whether the authentication of the first user identity is successful.

[0314] That is, after performing the authentication procedure of the first user identity at the network side, the first network element notifies the terminal device of the authentication result.

[0315] Exemplarily, the first network element sends the authentication result to the terminal device through a NAS message. The NAS message can refer to the description of the second NAS message in S415. For example, the NAS message carries indication information (refer to indication information #2 in S415) indicating that the authentication is successful or the authentication fails.

[0316] Further, the method further comprises: the user logs out or enters an inactive state (the first user identity logs out or enters an inactive state).

[0317] For example, the user is inactive within a preconfigured inactivity time, and the network changes the state of the first user identity to a deregistered state or an inactive state (inactive state) or a suspend state. In the case that the authentication result corresponding to the user ID #1 is not expired, the AMF can not delete the saved short-term credential corresponding to the user ID #1.

[0318] It should be understood that in this application, the long-term credential and the short-term credential are both a kind of credential, and the long-term and the short-term refer to the validity period of the credential. The validity period of the short-term credential is shorter than that of the long-term credential. For example, the validity period of the short-term credential is similar to that of the authentication result obtained by authenticating the user ID #1.

[0319] Optionally, the complexity of the composition of the long-term credential and the short-term credential can also be different. For example, the long-term credential is more complex, such as a long password composed of uppercase and lowercase letters and numbers, and the short-term credential is simpler, such as a short numeric password.

[0320] In this application, "authentication" and "certification" can be replaced, for example, "authentication procedure" can be replaced by "certification procedure", and "authenticating the user ID #1" can be replaced by "certifying the user ID #1". For ease of description, "authentication" is used uniformly below.

[0321] S530, in the case of logging into the terminal device again using the first user identity, the terminal device sends a second credential corresponding to the first user identity to the first network element. Correspondingly, the first network element receives the second credential.

[0322] The second credential is a short-term credential (denoted as short-term credential #2) corresponding to the first user identifier. The second credential can be generated by the terminal device or input by the user, as described below. The second credential can be used to verify the first user identifier, i.e., to verify whether the first user identifier is allowed to log in the terminal device, or to verify whether the first user identifier is allowed to access the network through the terminal device, or to verify the legitimacy of the first user identifier, or to verify the binding relationship between the first user identifier and the terminal device.

[0323] That is, in the case where the user logs in the terminal device using the first user identifier for the first time, the terminal device sends a request message (e.g., the first NAS message in S405) to the first network element to request the network side to authenticate the first user identifier. In the case where the user logs out and logs in the terminal device using the first user identifier again, the terminal device can send a short-term credential corresponding to the first user identifier to the first network element to verify the binding relationship between the first user identifier and the terminal device.

[0324] The second credential can be generated by the terminal device or can come from the user (e.g., user #1 or user #2, an example of the first user) who logs in the terminal device using the first user identifier, i.e., the second credential is input by the user who logs in the terminal device using the first user identifier.

[0325] In the first possible case, the short-term credential #2 is generated by the terminal device.

[0326] The specific way in which the terminal device generates the short-term credential is not limited.

[0327] For example, the terminal device can generate the short-term credential #2 by at least one of the long-term credential corresponding to the user ID #1 and the identifier of the terminal device, or generate the short-term credential #2 by a short-term credential generation algorithm to which the terminal device subscribes, such as generating the short-term credential #2 by the long-term credential corresponding to the user ID #1 and the short-term credential generation algorithm. The long-term credential corresponding to the user ID #1 can be input by the first user, and the first user holds the long-term credential corresponding to the user ID #1, as described in S410.

[0328] In the second possible case, the short-term credential #2 is input by the first user.

[0329] The short-term credential #2 input by the first user has an association relationship with the short-term credential #1 on the network side, e.g., the short-term credential #2 is the same as or has a corresponding relationship with the short-term credential #1.

[0330] For example, if the first network element informs the first user of the short-term credential #1 in S510, the short-term credential #2 can be the short-term credential #1 remembered by the user. If the first network element and the first user negotiate to determine the short-term credential #1 in S510, the short-term credential #2 can be the short-term credential #1 held by the first user.

[0331] For example, the terminal device can trigger the first user to input the short-term credential #2, or the first user can actively input the short-term credential.

[0332] For example, in the process in which the first user logs in the terminal device using the first user identifier, the terminal device triggers the short-term credential verification process and requests the user to input the short-term credential. For example, after the first user inputs the user ID #1, the terminal device requests the first user to input the short-term credential #2 in the form of a pop-up window. The first user can input the short-term credential #2 through an application (APP) interface installed in the operating system of the terminal device.

[0333] For another example, the interface in which the first user inputs the user ID #1 has an interface for selecting to input the long-term credential or the short-term credential. The first user can select to use the short-term credential to complete the login, that is, the first user inputs the short-term credential #2 to log in the terminal device at the same time of inputting the first user identifier.

[0334] Optionally, before S530, the method further includes: determining whether the authentication result corresponding to the user ID #1 is valid.

[0335] The terminal device sends the second credential corresponding to the first user identifier to the first network element (S530) can be: in the case where the authentication result corresponding to the user ID #1 is valid, the terminal device sends the second credential corresponding to the first user identifier to the first network element.

[0336] In a possible implementation manner, the terminal device determines whether the authentication result corresponding to the user ID #1 is valid.

[0337] For example, when the user ID #1 is used to log in the terminal device for the first time, the terminal device triggers the authentication process of the user ID #1. The terminal device receives and saves the authentication result obtained by authenticating the user ID #1. For details, refer to the description of the method 400. When the user ID #1 is used to log in the terminal device subsequently, the terminal device can determine whether the authentication result is valid.

[0338] The specific manner in which the terminal device determines whether the authentication result is valid is not limited in the application.

[0339] For example, the terminal device can determine whether the authentication result is valid according to a configured authentication result validity duration.

[0340] Alternatively, the terminal device determines whether the authentication result is valid according to information (denoted as first information) sent by the network side for determining whether the authentication result is valid.

[0341] For example, the terminal device receives the first time length and the first timestamp (an example of the first information) from the first network element, and determines whether the authentication result is valid based on the first time length and the first timestamp. The first time length is the valid time length of the authentication result, and the first timestamp can indicate the generation time of the authentication result.

[0342] For example, after receiving the first time length and the first timestamp, the terminal device sets the timing length of the timer according to the first timestamp and the first time length, and starts the timer. During the counting of the timer, the authentication result is valid. After the counting of the timer ends, the authentication result is invalid, and the terminal device can delete the authentication result corresponding to the user ID#1 or mark the authentication result as expired.

[0343] The application does not limit the sending time and sending mode of the first information.

[0344] For example, after the authentication process for the user ID#1 is completed, the first network element sends the first time length and the first timestamp to the terminal device. The first time length, the first timestamp and the authentication result of the user ID#1 can be sent simultaneously, such as being carried in the same message, i.e., S520, or can be sent separately.

[0345] In another possible implementation, the first network element determines whether the authentication result corresponding to the user ID#1 is valid.

[0346] For example, the first network element can determine whether the authentication result corresponding to the user ID#1 is valid according to the first user identifier and the valid time length of the authentication result corresponding to the first user identifier. The valid time length of the authentication result corresponding to the first user identifier can be obtained based on pre-configuration, or the subscription information of the user, or obtained from other network elements, which is not limited in the application.

[0347] The first user identifier can be included in a request message sent by the terminal device. The request message can be used to request authentication of the user ID#1. For example, when the user ID#1 logs in the terminal device again, the terminal device sends a NAS message (an example of the request message) to the first network element to request authentication of the user ID#1. The NAS message is similar to the first NAS message in S405, and the user ID#1 is included in the NAS message. After receiving the NAS message, the first network element determines whether the authentication result is valid if the authentication result corresponding to the user ID#1 is stored.

[0348] Optionally, the request message can also be a request message specially used for requesting the first network element to judge whether the authentication result corresponding to the user ID #1 is expired, and the type and name of the request message are not limited.

[0349] Further, if it is judged that the authentication result corresponding to the user ID #1 is not expired, the first network element can send a short-term credential request message to the terminal device, for requesting the terminal device to send the short-term credential corresponding to the user ID #1, that is, the first network element triggers S530, or in other words, the first network element triggers the authentication process of the trusted user (i.e., the first user) and the binding relationship of the trusted user on the terminal device.

[0350] The judgment manner of the first network element judging whether the authentication result corresponding to the user ID #1 is valid is similar to that of the terminal device, for example, the first network element can judge whether the authentication result is expired according to the first time stamp and the first time length.

[0351] S540, the first network element verifies the short-term credential corresponding to the first user identifier.

[0352] The "verifying the short-term credential corresponding to the first user identifier" can mean verifying the first credential or the second credential, or can mean verifying the association relationship of the first credential and the second credential. That is, the first network element can verify whether the other one is valid through one of the first credential and the second credential, or verify whether the first credential and / or the second credential is valid through verifying the association relationship of the first credential and the second credential. Verifying the short-term credential of the first user identifier can also be understood as verifying the first user identifier through the short-term credential of the first user identifier.

[0353] For example, if the second credential is the same as or has a corresponding relationship with the first credential, the first network element verifies the short-term credential corresponding to the first user identifier successfully; otherwise, the verification of the short-term credential fails.

[0354] It should be understood that the specific verification manner of the first network element verifying the short-term credential is not limited in the present application, for example, if the first network element can derive one of the first credential and the second credential based on the other one, the verification of the short-term credential is successful; otherwise, the verification fails.

[0355] S550, the first network element determines whether to trigger the authentication process of authenticating the first user identifier according to the third credential according to the verification result of verifying the short-term credential corresponding to the first user identifier.

[0356] The third credential is a long-term credential corresponding to the user ID #1. An authentication procedure for authenticating the first user identifier according to the third credential can be understood as follows: the third credential is used in the authentication procedure, for example, an authentication vector is generated according to the long-term credential corresponding to the user ID #1. For details, reference can be made to the description in the method 400.

[0357] Exemplarily, if the short-term credential corresponding to the first user identifier is verified successfully, the first network element can not trigger / skip the authentication procedure for the user ID #1, for example, it is determined that all or part of the steps in S406 to S415 are not performed. In other words, if the short-term credential corresponding to the first user identifier is verified successfully, it means that the user ID #1 is real and legal, and the first network element can omit the authentication of the user ID #1 and continue to perform the subsequent procedure.

[0358] If the short-term credential corresponding to the first user identifier fails to be verified, the first network element can trigger the authentication procedure for the user ID #1. That is, the first network element can trigger the authentication procedure for authenticating the first user identifier on the network side again, for example, re-perform all or part of the steps in S406 to S415.

[0359] Optionally, the first network element sends a verification result obtained by verifying the short-term credential corresponding to the first user identifier to the terminal device, and the verification result indicates whether the first network element successfully verifies the short-term credential corresponding to the first user identifier. The verification result can be used to determine whether to allow the user ID #1 to log in to the terminal device. For example, if the verification result indicates that the first network element successfully verifies the short-term credential corresponding to the first user identifier, the terminal device determines to allow the user ID #1 to log in to the terminal device and continues to perform the subsequent procedure for the first user; if the verification result indicates that the first network element fails to verify the short-term credential corresponding to the first user identifier, the terminal device can determine not to allow the user ID #1 to log in to the terminal device, for example, forcibly log the user out of the user device, and the like.

[0360] Based on the above scheme, when a user identifier logs in to a terminal device, the network side can determine not to initiate an authentication procedure for the user identifier by verifying the short-term credential corresponding to the user identifier reported by the terminal device and the short-term credential corresponding to the user identifier saved by the network side, and then provide services for the user using the user identifier, which can reduce signaling overhead and improve user service experience.

[0361] FIG. 6 is a schematic flowchart of a communication method 600 provided by the present application. The method can include the following steps.

[0362] S610, the first network element sends a first message to the terminal device. Correspondingly, the terminal device receives the first message.

[0363] The first network element can refer to the description in S510; and the first message includes an authentication result (i.e., a first authentication result) obtained by authenticating the first user identifier.

[0364] For example, in a case where the external device or the first user triggers the first login to the terminal device, such as the user logs in to the external device or logs in to the terminal device using a user ID #1 (an example of the first user identifier), the network side performs an authentication process on the user ID #1. The authentication process can refer to S401 to S414 in the method 400. After obtaining the authentication result, the first network element sends the authentication result corresponding to the user ID #1 to the terminal device through the first message. The first message can refer to the second NAS message in S415.

[0365] The above authentication process can be understood as an authentication process in which the network side authenticates the user ID #1 according to a long-term credential (an example of a third credential) corresponding to the user ID #1, or an authentication process in which the first user identifier is authenticated using the long-term credential. The long-term credential can refer to the description in S401.

[0366] Alternatively, the first message carries a first time length and a first timestamp, which are used by the terminal device to determine whether the authentication result is valid. The first time length is the valid time length of the authentication result; and the first timestamp can indicate the generation time of the authentication result.

[0367] For example, after receiving the first time length and the first timestamp, the terminal device sets the timing time length of the timer according to the first timestamp and the first time length, and starts the timer. During the counting of the timer, the authentication result is valid. After the timer counting ends, the authentication result is invalid, and the terminal device can delete the authentication result corresponding to the user ID #1 or mark the authentication result as expired, which is not limited in the present application.

[0368] Further, the method further includes that the user logs out or enters an inactive state (the first user identifier logs out or enters an inactive state). The specific description can refer to the related description in the method 500.

[0369] S620, in a case where the first authentication result indicates that the authentication on the first user identifier is successful, the terminal device acquires and saves a first credential.

[0370] The first credential is a short-term credential (denoted as short-term credential #1) corresponding to the first user identifier.

[0371] The present application does not limit the specific way in which the terminal device acquires the short-term credential #1.

[0372] Exemplarily, the terminal device negotiates with the first user to determine the short-term credential #1, for example, the terminal device can trigger the first user to input the short-term credential in the form of a pop-up window or the like (i.e., taking the short-term credential input by the first user as the short-term credential #1); the terminal device saves the short-term credential #1; and the first user holds the short-term credential #1. Wherein, the first user refers to the user who logs in the terminal device using the first user identifier. Alternatively, the terminal device generates the short-term credential #1 by itself and notifies the first user of the short-term credential #1; the terminal device saves the short-term credential #1; and the first user holds the short-term credential #1. Alternatively, the terminal device receives the short-term credential #1 generated from the network side or the authentication server and notifies the first user of the short-term credential #1.

[0373] It should be understood that this step can be performed before logging in the terminal device using the first user identifier, for example, after receiving the authentication result corresponding to the user ID #1 or after the terminal device receives the user registration success message, which is not limited in the present application.

[0374] Further, the method further includes: if the user logs out or is inactive for a long time, the state of the first user identifier enters an inactive state. For details, refer to the related description in method 500.

[0375] S630, in the case of logging in the terminal device using the first user identifier again, the terminal device verifies the short-term credential corresponding to the first user identifier.

[0376] Wherein, "verifying the short-term credential corresponding to the first user identifier" can refer to verifying the short-term credential #1 saved by the terminal device or the short-term credential #2 (an example of the second credential) input by the first user, or can refer to verifying the correspondence between the short-term credential #1 and the short-term credential #2. That is, the terminal device can verify whether the other one is valid through one of the short-term credential #1 and the short-term credential #2, or verify whether the short-term credential #1 and / or the short-term credential #2 is valid by verifying the correspondence between the short-term credential #1 and the short-term credential #2.

[0377] Wherein, the short-term credential #2 is the short-term credential corresponding to the first user identifier held (e.g., memorized) by the first user, for example, the short-term credential #2 is the short-term credential corresponding to the user ID #1 determined by the terminal device and the first user in negotiation (for details, refer to the description in S620) or the short-term credential generated by the terminal device and notified to the first user. The short-term credential #2 can be used to verify the first user identifier, for details, refer to the description above.

[0378] Exemplarily, if the short-term credential #1 and the short-term credential #2 are the same or have a correlation relationship, the terminal device verifies that the short-term credential corresponding to the first user identity is successful; otherwise, the verification of the short-term credential fails.

[0379] It should be understood that the present application does not limit the specific verification manner of the terminal device verifying the short-term credential, for example, if the terminal device can derive one of the short-term credential #1 and the short-term credential #2 based on the other, the verification of the short-term credential is successful; otherwise, the verification fails.

[0380] Before S630, the method can further include: determining whether the authentication result corresponding to the user ID #1 is valid.

[0381] The terminal device verifies the short-term credential corresponding to the first user identity (S630) can be: in a case where the authentication result corresponding to the user ID #1 is valid, the terminal device verifies the short-term credential corresponding to the first user identity.

[0382] In a possible implementation manner, whether the authentication result corresponding to the user ID #1 is valid is determined by the terminal device. The specific manner in which the terminal device determines whether the authentication result is valid is described with reference to S530.

[0383] In another possible implementation manner, if the first network element saves the authentication result corresponding to the user ID #1, whether the authentication result corresponding to the user ID #1 is valid can be determined by the first network element. The specific manner is described with reference to S530.

[0384] S640, in a case where the verification of the short-term credential corresponding to the first user identity is successful, the terminal device determines that the first user identity does not need to be authenticated.

[0385] That is, in a case where the verification of the short-term credential corresponding to the first user identity is successful, the terminal device determines not to perform the authentication process of authenticating the first user identity, for example, the terminal device can not send a request message (for example, the first NAS message in S405) to the first network element to request the network side to authenticate the first user identity.

[0386] S650, the terminal device sends a second message to the first network element. Correspondingly, the first network element receives the second message.

[0387] The second message is used to indicate that the terminal device successfully verifies the short-term credential corresponding to the first user identifier, and the second message can carry the first user identifier, so that the first network element can determine not to perform the authentication process of the first user identifier according to the second message. In other words, if the terminal device successfully verifies the short-term credential corresponding to the first user identifier, it means that user ID #1 is real and legal, and the first network element can omit the authentication of user ID #1 and continue to perform the subsequent process.

[0388] Optionally, if the terminal device fails to verify the short-term credential corresponding to the first user identifier, the terminal device can initiate the authentication process of user ID #1, for example, perform all or part of the steps in S405 to S415.

[0389] Optionally, after receiving the second message, the first network element can determine whether the verification result of the terminal device is reliable, that is, whether the terminal device is reliable, or whether to perform the subsequent step according to the verification result of the terminal device, for example, omit the authentication process of the first user identifier.

[0390] For example, the first network element determines whether the verification result of the terminal device is reliable according to the configured trusted terminal list. That is, if the terminal device belongs to the trusted terminal list, it can be determined that the verification result of the terminal device is reliable, otherwise, it is determined to be unreliable. For another example, the first network element determines whether the terminal device is reliable according to the location information of the terminal device, and the specific way in which the first network element determines whether the verification result of the terminal device is reliable is not limited.

[0391] If the first network element determines that the verification result of the terminal device is reliable, it means that user ID #1 is real and legal, and the first network element can omit the authentication of user ID #1 and continue to perform the subsequent process.

[0392] If the first network element determines that the verification result of the terminal device is not reliable, the first network element can trigger the authentication process of the first user identifier. That is, the authentication process of the first user identifier using the long-term credential. For example, the first network element sends a re-authentication request message to the terminal device, which can include user ID #1. After receiving the re-authentication request message, the terminal device can send an authentication request response to the first network element, which includes the long-term credential corresponding to user ID #1, so that the first network element triggers the authentication process of user ID #1. For details, refer to the description in method 400.

[0393] Based on the above scheme, when a user identifier is used to log in to a terminal device, the terminal device can determine not to initiate an authentication process for the user identifier by verifying the short-term credential corresponding to the user identifier input by the user and the short-term credential corresponding to the user identifier stored by the terminal device, thereby providing services for the user using the user identifier, reducing signaling overhead, and improving user service experience.

[0394] The method 500 and the method 600 will be described in detail below in combination with specific network elements.

[0395] FIG. 7 is a flow diagram of a communication method 700 provided by the present application. The method 700 is a detailed description of the method 500, and the method includes the following steps.

[0396] S701, a UE (an example of a terminal device) accesses a network, and the network authenticates the legality of the UE.

[0397] The UE registers to the network, and the network authenticates the UE. For a specific implementation manner, reference can be made to the related description of the method 200.

[0398] It should be understood that the present application does not limit the initiation time of this step. The UE can be registered to the network before the user logs in or connects with an external device, such as the UE being used. The UE can also be triggered to initiate registration, such as the UE being used before, but the UE also presents a deregistered state as the user is offline. At this time, the condition for triggering the UE is that the UE is logged in by the user or the UE is connected with an external device.

[0399] S702, an external device or a user triggers login.

[0400] For example, a user logs in to an external device using a user identifier (user ID) (for example, user ID#1) or logs in to a UE. If the user logs in to the external device, the external device establishes a connection with the UE, and the UE determines that the user logs in. The way in which the external device establishes a connection with the UE includes, for example, establishing a connection through Bluetooth technology, wifi technology, etc., without limitation.

[0401] S703, the UE sends a first NAS message to an AMF (an example of a first network element). Correspondingly, the AMF receives the first NAS message from the UE.

[0402] For example, in the case where the external device or the user triggers login, the UE sends the first NAS message to the AMF.

[0403] The user ID#1 is carried in the first NAS message. Optionally, the first NAS message carries at least one of the following: identification information of the UE, or first indication information. The user ID#1, the identification information of the UE, and the first indication information can be referred to the description in S405.

[0404] For example, the user ID#1 can include an information part uniquely identifying the user and a routing information part used to determine a credential storage function, the credential storage function can be used to determine the credential corresponding to the user according to the information part uniquely identifying the user; the identification information of the UE can be SUCI or 5G-GUTI; the first indication information can indicate that the user logs in, for example, indicating that the user logs in the user equipment, or indicating that the UE receives a message (or a pop-up window) sent by the external device, the message (or the pop-up window) indicating that the user logs in the external device.

[0405] Optionally, the user ID#1 has security protection, for example, integrity security protection and / or confidentiality security protection.

[0406] Optionally, the first NAS message has security protection.

[0407] That is, the security protection can be performed on the user ID#1 alone, or the security protection can be performed on the first NAS message carrying the user ID#1.

[0408] For example, the first NAS message is any one of a registration request message, a user authentication request message, and a NAS SMP message. For details, refer to the description in S405.

[0409] S704, the AMF determines to perform a user authentication procedure.

[0410] Specifically, the AMF determines to perform the user authentication procedure according to the information carried in the first NAS message or the information associated with the first NAS message.

[0411] For example, the AMF determines to perform the user authentication procedure according to the user ID#1 in the first NAS message.

[0412] For another example, the AMF determines to perform the user authentication procedure according to the first indication information in the first NAS message, for example, the first indication information can be a registration type (indicating that the first NAS message can be a registration request message for the user), a specific field or user ID (user ID#1) associated with the user, or user identification authentication capability information of the UE.

[0413] For another example, the AMF determines to perform the user authentication procedure according to the name of the first NAS message, for example, the name of the first NAS message is a user authentication request (for example, Namf_UserAuthentication_Authenticate Request) message.

[0414] Optionally, the AMF can determine to perform the user authentication procedure according to the local configuration information. For details, refer to the related description of the method 400.

[0415] S705, the AMF performs an AAA-S (an example of a second network element) discovery procedure.

[0416] For example, when the AMF determines to perform the user authentication, the AMF performs the AAA-S discovery procedure.

[0417] The AMF can determine the AAA-S that can perform the user authentication according to the user ID#1.

[0418] For example, the AMF finds the AAA-S address corresponding to the authentication of the user ID#1 from the user profile or the user subscription information of the user stored in the UDM or the UDR according to the user ID#1. The AMF can send a user profile query request message, for example, a Nudm_SDM_query Request message, to the UDM, and the message carries the user ID#1. The UDM sends a Nudm_SDM_query Response message to the AMF, and the message carries the address of the AAA-S.

[0419] S706, the AMF sends a user authentication request message to the AAA-S. Correspondingly, the AAA-S receives the user authentication request message from the AMF.

[0420] The user authentication request message can carry the user ID#1 and the identification information of the UE, that is,

[0421] The user authentication request message is used to request the authentication of the user ID#1 of the logged-in UE.

[0422] For example, the user authentication request message is an Authentication / Authorization Request message.

[0423] S707, the user authentication procedure is performed.

[0424] For example, the AAA-S interacts with the UE to perform the user authentication procedure.

[0425] The AAA-S holds the long-term credential corresponding to the user ID#1. For example, the long-term credential corresponding to the user ID#1 is stored in a credential storage function or an authentication server, that is, the credential is stored in the user granularity on the credential storage function. On the terminal side, the user can use the long-term credential to log in to different external devices or different UEs.

[0426] The authentication procedure can be an authentication procedure in an existing protocol. For example, the authentication procedure can be an EAP-AKA authentication procedure or a 5G-AKA authentication procedure.

[0427] In the authentication procedure, the AAA-S completes authentication and verification of the user based on the user ID#1 and the long-term credential corresponding to the user ID#1 (such as a user password). For a specific implementation, reference can be made to an existing protocol. If the authentication is successful, the AAA-S generates a short-term credential corresponding to the user ID#1. The short-term credential is in the granularity of a UE and in the granularity of a user ID corresponding to the UE.

[0428] For example, the AAA-S can generate a short-term credential corresponding to the user ID#1 based on the long-term credential of the user ID#1 and the identification information of the UE. The AAA-S can also generate the short-term credential from the long-term credential based on an algorithm for generating a short-term credential in the subscription information of the UE.

[0429] S708, the AAA-S sends a user authentication response message to the AMF. Correspondingly, the AMF receives the user authentication response message.

[0430] The user authentication response message can be a response to the user authentication request message. For example, the user authentication response message is an Authentication / Authorization Response message.

[0431] The response message carries an authentication result indication#1 and information#1. The authentication result indication#1 indicates whether the authentication of the user ID#1 is successful. The authentication result indication#1 can refer to the related description in S414.

[0432] The information#1 includes one or more of the following:

[0433] (1) a user identity, such as the user ID#1.

[0434] (2) a validity period of the authentication result and a timestamp#1 (an example of a first timestamp).

[0435] If the authentication response message does not carry the validity period of the authentication result, the AMF can determine the validity period of the authentication result according to network configuration. For example, the network configures a validity period of the authentication result obtained by one authentication of the user ID#1, or configures a validity period of the authentication result obtained by the first authentication of the user ID#1.

[0436] (3) a short-term credential, such as a short-term credential corresponding to the user ID#1.

[0437] If the AMF or UDM does not generate the short-term credential, the information #1 is mandatory.

[0438] In the case that the authentication result indication #1 indicates that the user authentication is successful, the AMF stores the authentication result indication #1 and the information #1, and the storage location is not limited in the present application, for example, the storage is into the context information of the user ID #1.

[0439] Optionally, the AMF generates and stores the short-term credential.

[0440] Optionally, the AMF sends a user authentication response message to the UE at S709. Correspondingly, the UE receives the user authentication response message from the AMF.

[0441] Exemplarily, the user authentication response message can be a Namf_UserAuthentication_Response message.

[0442] The user authentication response message includes the user ID #1 and an authentication result indication #2. The authentication result indication #2 is used to indicate the authentication result of the user ID #1. In one implementation, the authentication result indication #2 is the same as the authentication result indication #1.

[0443] Optionally, the response message carries the validity period of the authentication result and the timestamp #1, which is described in S708.

[0444] Optionally, the UE stores the user ID #1, the authentication result, the validity period of the authentication result, and the timestamp #1 after receiving the response message. Optionally, the UE starts a timer, which is used to determine whether the authentication result is expired.

[0445] S710, the user logs out or enters an inactive state.

[0446] For example, the user is inactive within the pre-configured inactivity time, and the network changes the state of the user ID #1 to a deregistered state or an inactive state (inactive state) or a suspended state (suspend state).

[0447] For another example, the user ID #1 logs out by deregistration.

[0448] Optionally, in the case that the authentication result is not expired, the UE and the AMF do not delete the stored authentication result, the validity period of the authentication result, the timestamp #1, and the short-term credential corresponding to the user ID #1.

[0449] S711, an external device or the user triggers to log in again.

[0450] That is, the user logs in the UE again using the user ID #1. This step refers to the relevant description of S702.

[0451] The method further includes determining whether short-term credential authentication is required. Refer to S712a or S712b for details.

[0452] S712a, the UE determines whether short-term credential authentication is required for the user ID #1.

[0453] For example, if the authentication response message sent by the AMF to the UE in S709 carries the validity period of the authentication result and the timestamp #1, the UE can determine whether the authentication result is expired based on the authentication result, the timestamp #1, and the validity period of the authentication result. For example, after receiving the authentication result, the UE sets the timer duration according to the timestamp #1 and the validity period of the authentication result, and starts the timer. When the timer ends, the UE deletes the authentication result corresponding to the user ID #1, or marks the authentication result as expired.

[0454] If it is determined that the authentication result corresponding to the user ID #1 is not expired, the UE determines to perform short-term credential authentication for the user ID #1.

[0455] S712b, the AMF determines whether short-term credential authentication is required for the user ID #1.

[0456] For example, in the case that the user logs in the UE again using the user ID #1, the UE sends a NAS message to the AMF, which is used to request authentication for the user ID #1. The NAS message can refer to the first NAS message in S703. After receiving the NAS message, the AMF determines whether the authentication result is expired based on the stored authentication result corresponding to the user ID #1, the timestamp #1, and the validity period of the authentication result. The determination method can refer to the determination method of the UE in S712a.

[0457] If it is determined that the authentication result is not expired, the AMF sends a short-term credential request message to the UE to trigger the short-term credential authentication process. The request message carries the user ID #1.

[0458] S713, the UE requests the user to input the long-term credential.

[0459] For example, the user can be requested to input the long-term credential through a native application (APP) installed in the operating system. This step can occur simultaneously with S711, or can occur after S711 through a pop-up window or the like.

[0460] S714, the UE generates a short-term credential.

[0461] Exemplarily, the UE can generate the short-term credential by the long-term credential and the identification information of the UE; or the UE can generate the short-term credential by the long-term credential and the short-term credential generation algorithm signed by the UE, which is not limited in the present application.

[0462] S715, the UE sends a short-term credential verification request message to the AMF. Correspondingly, the AMF receives the short-term credential verification request message.

[0463] The message is used to request the AMF to verify the short-term credential corresponding to the user ID#1. The message can carry the user ID#1 and the short-term credential generated in S714.

[0464] S716, the AMF verifies the short-term credential corresponding to the user ID#1.

[0465] Exemplarily, the AMF can verify the short-term credential corresponding to the user ID#1 by comparing the short-term credential in S715 with the saved short-term credential of the user ID#1. For example, if the short-term credential of the user ID#1 in S715 is consistent with or has a corresponding relationship with the short-term credential of the user ID#1 received by the AMF from the AAA-S, the AMF verifies the short-term credential corresponding to the user ID#1 successfully, that is, the authentication of the user ID#1 is successful. Otherwise, the authentication is not successful.

[0466] In other words, if the verification is successful, the authentication of the user ID#1 is skipped, that is, the authentication process similar to S707 is skipped.

[0467] If the verification fails, S717 is performed to authenticate the user ID#1, or in other words, the authentication process similar to S707 is performed.

[0468] FIG. 8 is a flow diagram of a communication method 800 provided by the present application. The method 800 is a detailed description of the method 500, and the method includes the following steps.

[0469] S801, the UE accesses the network, and the network side authenticates the legality of the UE.

[0470] The step can be specifically described with reference to S701.

[0471] S802, an external device or a user triggers login.

[0472] The step can be specifically described with reference to S702.

[0473] S803, the UE sends a first NAS message to the AMF. Correspondingly, the AMF receives the first NAS message from the UE.

[0474] This step can be described with reference to S703.

[0475] For example, the first NAS message carries the user ID #1. Optionally, the first NAS message carries at least one of the following: identification information of the UE, or the first indication information. The user ID #1, the identification information of the UE, and the first indication information can be described with reference to S405.

[0476] S804, the network side authenticates the user ID #1, and sends an authentication result to the AMF.

[0477] This step can be described with reference to S704 to S708.

[0478] S805, the AMF sends a user authentication response message to the UE. Correspondingly, the UE receives the user authentication response message from the AMF.

[0479] For example, the user authentication response message can be a Namf_UserAuthentication_Response message.

[0480] The user authentication response message includes the user ID #1 and the authentication result indication #2. The authentication result indication #2 is used to indicate the authentication result of the user ID #1. In one implementation, the authentication result indication #2 is the same as the authentication result indication #1.

[0481] Optionally, the response message carries the validity period of the authentication result and the timestamp #1, which can be described with reference to S708.

[0482] Optionally, after receiving the response message, the UE saves the user ID #1, the authentication result, the validity period of the authentication result, and the timestamp #1. Optionally, the UE starts a timer, which is used to determine whether the authentication result is expired.

[0483] S806, obtain and save the short-term credential.

[0484] For example, the short-term credential can be a password, a verification code, a combination of short numbers, etc.

[0485] For example, the short-term credential can be agreed by the UE and the user, or generated by the network side (e.g., AMF, UDM) or an authentication server. The short-term credential generated by the network side or the authentication server can be sent to the UE by the AMF, such as sending the short-term credential to the UE through S708 and S709 messages.

[0486] The application does not limit the specific way of the UE and the user agreeing on the short-term credential. For example, the short-term credential can be set by the user (e.g., the user inputs the short-term credential in an interface to complete the setting). Alternatively, the short-term credential can be generated by the network or the authentication entity (e.g., after the user ID #1 is successfully authenticated, the network side can send the generated short-term credential to the UE and inform the user through a pop-up display or the like).

[0487] S807, the user memorizes the short-term credential (S807a), and the UE stores the short-term credential (S807b).

[0488] That is, the UE stores the short-term credential agreed in S806, and the user memorizes the short-term credential.

[0489] S808, the user logs out or enters an inactive state.

[0490] This step can refer to the description of S710.

[0491] S809, the external device or the user triggers to log in again.

[0492] That is, the user uses the user ID #1 to log in to the UE again. This step refers to the related description of S702.

[0493] S810, the UE requests the user to input the short-term credential.

[0494] Optionally, before S810, the UE can determine whether the authentication result corresponding to the user ID #1 is expired, and if not, S810 is performed. The specific way of the UE determining whether the authentication result corresponding to the user ID #1 is expired can refer to S712a.

[0495] The application does not limit the execution order of S809 and S710. For example, the UE can request the user to input the short-term credential through a pop-up window after the user inputs the user ID #1, or there is an interface for inputting the long-term credential or the short-term credential in the interface for inputting the user ID, and the short-term credential can be input at the same time as the user logs in.

[0496] S811, the UE verifies the short-term credential input by the user.

[0497] For example, the UE can verify the short-term credential input by the user through the short-term credential saved in S807. For example, if the two are consistent or have a corresponding relationship, the verification of the short-term credential input by the user is successful, otherwise, it is not successful. The specific verification method can refer to the related description in S630.

[0498] S812, the UE sends a verification result notification to the AMF.

[0499] For example, if the UE successfully verifies the short-term credential input by the user, the UE sends a short-term credential verification result notification / verification result success message to the AMF. Exemplarily, the message can be a NAS message in S803. The message can also be a new message, i.e., a message specially used to notify the AMF of the verification result of the short-term credential corresponding to the userID#1 by the UE.

[0500] The message carries the user ID#1. Optionally, the message carries indication information indicating that no authentication is required for the user ID#1. That is, the indication information indicates that the UE passes the verification of the short-term credential corresponding to the userID#1. The AMF can determine that the authentication process of the user ID can be skipped through the indication information or through the message name.

[0501] Optionally, the method further comprises:

[0502] S813, the AMF confirms whether the verification result of the UE is credible.

[0503] Exemplarily, the AMF can verify whether the verification result of the UE on the short-term credential of the user is credible by verifying whether the UE is a credible UE and / or whether the user is a credible user. For example, the AMF learns the identification information of the UE through an (NG application protocol, NGAP) header, determines whether the UE is a credible UE according to the identification information of the UE, and selects whether to trust the verification result of the UE, such as that the AMF can be configured with a whitelist of trusted UEs, and if the identification information of the UE is in the whitelist, it is determined that the verification result of the UE is credible.

[0504] Alternatively, only the network side trusted UE can send the verification result notification in S812 to the AMF, at which time the network side trusts the verification result of the UE, and S813 can not be executed.

[0505] If the AMF trusts the verification result of the UE on the short-term credential corresponding to the user ID#1, the network side can not perform the authentication process of the user ID#1, i.e., S704 to S709 are not performed; otherwise, S814 is performed to authenticate the user ID#1, or in other words, an authentication process similar to S807 is performed.

[0506] For example, the AMF can send a re-authentication request message to the UE to request to perform the authentication process of the user ID#1 again, which can carry the user ID#1 and the network side and the UE interact to perform the authentication process of the user ID#1.

[0507] FIG. 9 is a flowchart of a communication method 900 provided by the present application. The method comprises the following steps.

[0508] S901. The UE accesses the network, and the network side authenticates the legality of the UE.

[0509] This step can be specifically described with reference to S701.

[0510] S902. The external device or the user triggers login.

[0511] This step can be specifically described with reference to S702.

[0512] S903. The UE sends a first NAS message to the AMF. Accordingly, the AMF receives the first NAS message from the UE.

[0513] The first NAS message carries the user ID #1. Optionally, the first NAS message carries at least one of the following: identification information of the UE, or first indication information. The user ID #1, the identification information of the UE, and the first indication information can be described with reference to S405.

[0514] This step can be specifically described with reference to S703.

[0515] S904. The network side authenticates the user ID #1, and sends an authentication result to the AMF.

[0516] This step can be specifically described with reference to S704.

[0517] The method further includes: generating and saving a short-term passport corresponding to the user ID #1.

[0518] The short-term passport corresponding to the user ID #1 can be generated by the network side, or can be generated by interaction between the network side and the UE. The network side generates the short-term passport corresponding to the user ID #1 in the following manner:

[0519] In one example, the UDM generates the short-term passport corresponding to the user ID #1.

[0520] Specifically, after the AMF receives the first NAS message from the UE, it is determined to perform a user identity authentication procedure; the network side and the UE interact to perform an authentication procedure for user ID#1, and after the authentication is completed, the AAA-S sends an authentication notification message (S905a) to the UDM, for example, the message is a Nudm_UserAuthenrication_Response message. The message carries an authentication result indication #1 and information #1, the authentication result indication #1 indicates the authentication result obtained by authenticating user ID#1; the information #1 can include at least one of the user identity, such as user ID#1, the validity period of the authentication result, and a timestamp #1 (an example of the first timestamp); after receiving the authentication notification message, the UDM generates a short-term credential corresponding to user ID#1 (S905b); optionally, the UDM saves the short-term credential corresponding to user ID#1 in the subscription information or the user profile of the UE.

[0521] The UDM sends the short-term credential corresponding to user ID#1 to the AMF (S905c), and correspondingly, the AMF stores the short-term credential.

[0522] In another example, the AMF generates a short-term credential corresponding to user ID#1 (S906a).

[0523] Optionally, if the network side determines the short-term credential corresponding to user ID#1 through the above two examples, the method further includes:

[0524] S906b, the AMF sends the short-term credential to the UE.

[0525] For example, the AMF can send the short-term credential to the UE through a NAS message.

[0526] Further, after the UE receives the short-term credential corresponding to user ID#1 from the AMF, the UE notifies the user of the short-term credential, for example, by the way of a pop-up window.

[0527] The network side and the UE interact to generate the short-term credential in the following manner:

[0528] In another example, the AMF requests the short-term credential corresponding to user ID#1 from the user (S907).

[0529] For example, the AMF sends a NAS message to the UE after receiving the authentication result, the message being used to request the short-term credential negotiated with the user; the UE receives the NAS message and requests the user to input the short-term credential, for example, the UE requests the user to input the short-term credential in the form of a pop-up window.

[0530] Optionally, the method further comprises:

[0531] S908, the AMF stores the short-term credential corresponding to the user ID#1.

[0532] For example, the AMF stores the short-term credential corresponding to the user ID#1 in the UE context or the user context.

[0533] S909, the user logs out or enters the inactive state.

[0534] This step can refer to the related description of S710.

[0535] S910, the external device or the user triggers to log in again.

[0536] That is, the user logs in the UE again using the user ID#1. This step can refer to the related description of S702.

[0537] Optionally, the method further comprises S911a-S913a:

[0538] S911a, the UE determines whether the authentication result corresponding to the user ID#1 is expired.

[0539] For example, after S904, the AMF sends an authentication response message to the UE, which carries the validity period of the authentication result and the timestamp#1. The UE can determine whether the authentication result is expired based on the authentication result, the timestamp#1, and the validity period of the authentication result. The specific determination method can refer to the determination method of the UE in S712a.

[0540] In the case where it is determined that the authentication result corresponding to the user ID#1 is not expired, the method further comprises:

[0541] S912a, the UE requests the user to input the short-term credential.

[0542] S913a, the UE sends the short-term credential input by the user to the AMF.

[0543] Alternatively, the method can further comprise S911b-S913b:

[0544] S911b, the UE sends a first NAS message to the AMF. Correspondingly, the AMF receives the first NAS message from the UE.

[0545] For example, in the case where the external device or the user triggers to log in, the UE sends a first NAS message to the AMF. The first NAS message carries the user ID#1. Optionally, the first NAS message carries at least one of the following: the identification information of the UE, or the first indication information. The user ID#1, the identification information of the UE, and the first indication information can refer to the description in S405.

[0546] S912b, the AMF determines whether the authentication result corresponding to the user ID #1 is expired.

[0547] The specific determination manner refers to the determination manner of the UE in S712a.

[0548] S913b, the AMF requests the user to input the short-term credential.

[0549] If the AMF determines that the authentication result is not expired, the AMF sends a short-term credential request message to the UE, triggering a short-term credential authentication process. The request message carries the user ID #1.

[0550] The method further includes: verifying the short-term credential.

[0551] In one example, the AMF verifies the short-term credential input by the user.

[0552] As in S914a, the AMF can verify the short-term credential corresponding to the user ID #1 by comparing the short-term credential corresponding to the user ID #1 with the saved short-term credential.

[0553] In another example, the UDM verifies the short-term credential input by the user.

[0554] S915a, the AMF sends a short-term credential verification request message to the UDM, which can carry the identification information of the UE, the user ID #1, and the short-term credential corresponding to the user ID #1 input by the user.

[0555] S915b, the UDM verifies the short-term credential and sends a short-term credential verification result to the AMF.

[0556] If the verification result is successful, the authentication of the user ID #1 is skipped, that is, the authentication process similar to S907 is skipped.

[0557] If the verification result is failed, S916 is performed to authenticate the user ID #1, or in other words, the authentication process similar to S907 is performed.

[0558] The above describes the communication method provided by the embodiments of the present application in combination with FIG. 1 to FIG. 9. It should be understood that the size of the serial number of each process described above does not mean the execution order, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0559] It should also be understood that, in various embodiments of the present application, the terms and / or descriptions between different embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0560] It can be understood that, in each of the above method embodiments, the methods and operations implemented by the devices (such as the first network element and the terminal device described above) can also be implemented by components (such as chips or circuits) of the devices.

[0561] The above communication method is mainly introduced from the perspective of interaction between various network elements. It can be understood that each network element includes a corresponding hardware structure and / or software module for performing each function in order to implement the above functions.

[0562] In the following, the communication apparatus provided by the embodiments of the present application will be described in detail in combination with FIGS. 10 to 12. It should be understood that the description of the apparatus embodiments corresponds to the description of the method embodiments, and therefore, the content not described in detail can be referred to the above method embodiments, and will not be described here again for the sake of brevity.

[0563] FIG. 10 shows a schematic diagram of a communication apparatus 1000 provided by an embodiment of the present application.

[0564] The apparatus 1000 includes an interface unit 1010, which can be used to implement corresponding communication functions. The interface unit 1010 can also be referred to as a communication interface, a communication unit, or a transceiver unit.

[0565] Optionally, the apparatus 1000 can also include a processing unit 1020, which can be used for data processing.

[0566] Optionally, the apparatus 1000 also includes a storage unit, which can be used to store instructions and / or data. The processing unit 1020 can read the instructions and / or data in the storage unit, so that the apparatus implements the actions of different devices in the above various method embodiments.

[0567] In a possible design, the apparatus 1000 can be the first network element (for example, the AMF) in the above embodiments, or can be a component (such as a chip) of the first network element. The apparatus 1000 can implement the steps or processes corresponding to the steps performed by the first network element in the above method embodiments. Among them, the interface unit 1010 can be used to perform the transceiving-related operations of the first network element in the above method embodiments; the processing unit 1020 can be used to perform the processing-related operations of the first network element in the above method embodiments.

[0568] In another possible design, the apparatus 1000 can be a second network element (e.g., AAA-S, UDM) in the foregoing embodiments, or a component (e.g., a chip) of the second network element. The apparatus 1000 can implement steps or procedures corresponding to those performed by the second network element in the foregoing method embodiments. The interface unit 1010 can be configured to perform operations related to receiving and transmitting of the second network element in the foregoing method embodiments, and the processing unit 1020 can be configured to perform operations related to processing of the second network element in the foregoing method embodiments.

[0569] In another possible design, the apparatus 1000 can be a terminal device in the foregoing embodiments, or a component (e.g., a chip) of the terminal device. The apparatus 1000 can implement steps or procedures corresponding to those performed by the terminal device in the foregoing method embodiments. The interface unit 1010 can be configured to perform operations related to receiving and transmitting of the terminal device in the foregoing method embodiments, and the processing unit 1020 can be configured to perform operations related to processing of the terminal device in the foregoing method embodiments.

[0570] FIG. 11 is a schematic block diagram of a communication apparatus 1100 according to an embodiment of the present application.

[0571] The apparatus 1100 includes a processor 1110 and a memory 1120 coupled to the processor 1110. Optionally, the apparatus 1100 further includes the memory 1120. The memory 1120 is configured to store computer programs or instructions and / or data, and the processor 1110 is configured to execute the computer programs or instructions stored in the memory 1120 or read the data stored in the memory 1120, to perform the methods in the foregoing method embodiments.

[0572] Optionally, the processor 1110 is one or more.

[0573] Optionally, the memory 1120 is one or more.

[0574] Optionally, the memory 1120 is integrated with the processor 1110, or is separately arranged.

[0575] Optionally, as shown in FIG. 11, the apparatus 1100 further includes a communication interface 1130 configured to receive and / or send signals. For example, the processor 1110 is configured to control the communication interface 1130 to receive and / or send signals.

[0576] For example, the communication interface 1130 can be a transceiver, a circuit, a bus, a module, or another type of communication interface. The communication interface 1130 can also be referred to as an interface.

[0577] As an example, the apparatus 1100 is configured to implement operations performed by a first network element in the foregoing method embodiments.

[0578] For example, the processor 1110 is configured to execute the computer programs or instructions stored in the memory 1120 to implement the operations of the first network element in the various method embodiments.

[0579] As another option, the apparatus 1100 is configured to implement the operations performed by the second network element in the various method embodiments.

[0580] For example, the processor 1110 is configured to execute the computer programs or instructions stored in the memory 1120 to implement the operations of the first network element in the various method embodiments.

[0581] As another option, the apparatus 1100 is configured to implement the operations performed by the terminal device in the various method embodiments.

[0582] For example, the processor 1110 is configured to execute the computer programs or instructions stored in the memory 1120 to implement the operations of the terminal device in the various method embodiments.

[0583] In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the processor 1110 or the instructions in the form of software. The method disclosed in the embodiments of the present application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor. The software module can be located in the random access memory, the flash memory, the read-only memory, the programmable read-only memory, the electrically erasable programmable memory, the register, and other mature storage mediums in the art. The storage medium is located in the memory 1120, and the processor 1110 reads the information in the memory 1120 and combines the hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0584] It should be understood that in the embodiments of the present application, the processor can be one or more integrated circuits for executing related programs to perform the method embodiments of the present application.

[0585] The processor (e.g., the processor 1110) can include one or more processors and be implemented as a combination of computing devices. The processor can include one or more of a microprocessor, a microcontroller, a digital signal processor (DSP), a digital signal processing device (DSPD), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a programmable logic device (PLD), a gated logic, transistor logic, discrete hardware circuits, processing circuitry, or other suitable hardware, firmware, and / or hardware and software in combination, for performing the various functions described in the present disclosure. The processor can be a general purpose processor or a special purpose processor. For example, the processor 1110 can be a baseband processor or a central processor. The baseband processor can be used to process communication protocols and communication data. The central processor can be used to make the device execute a software program and process data in the software program. In addition, a part of the processor can also include a non-volatile random access memory. For example, the processor can also store device type information.

[0586] The programs in the present application are used in a broad sense to represent software. Non-limiting examples of software include program code, programs, subprograms, instructions, instruction sets, codes, code segments, software modules, applications, or software applications, etc. The programs can be run in the processor and / or computer. So that the device performs various functions and / or processes described in the present application.

[0587] The memory (e.g., the memory 1120) can store data required by the processor (e.g., the processor 1110) when executing software. The memory can be implemented using any suitable storage technology. For example, the memory can be any available storage media that can be accessed by the processor and / or computer. Non-limiting examples of storage media include random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), Compact Disc Read-Only Memory (CD-ROM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM), flash memory, registers, state machines, remotely mounted memory, locally mounted memory, or any other storage medium that can be used to carry or store software, data, or information in the memory that is accessible to the processor / computer. It is understood that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0588] The memory (e.g., the memory 1120) and the processor (e.g., the processor 1110) can be disposed separately or integrated together. The memory can be used to connect with the processor, so that the processor can read information from the memory, store and / or write information in the memory. The memory can be integrated in the processor. The memory and the processor can be disposed in an integrated circuit (for example, the integrated circuit can be disposed in the UE or other network node).

[0589] FIG. 12 is a schematic block diagram of a chip system 1200 provided by an embodiment of the present application. The chip system 1200 (or also can be referred to as a processing system) includes a logic circuit 1210 and an input / output interface 1220.

[0590] The logic circuit 1210 can be a processing circuit in the chip system 1200. The logic circuit 1210 can be coupled to a storage unit, and invoke instructions in the storage unit, so that the chip system 1200 can implement the methods and functions of the embodiments of the present application. The input / output interface 1220 can be an input / output circuit in the chip system 1200, and output the processed information of the chip system 1200, or input the data or signaling information to be processed into the chip system 1200 for processing.

[0591] As an option, the chip system 1200 is configured to implement the operations performed by the first network element in the above method embodiments.

[0592] For example, the logic circuit 1210 is configured to implement the processing-related operations performed by the first network element in the above method embodiments; and the input / output interface 1220 is configured to implement the sending and / or receiving-related operations performed by the first network element in the above method embodiments.

[0593] As another option, the chip system 1200 is configured to implement the operations performed by the terminal device in the above method embodiments.

[0594] For example, the logic circuit 1210 is configured to implement the processing-related operations performed by the terminal device in the above method embodiments; and the input / output interface 1220 is configured to implement the sending and / or receiving-related operations performed by the terminal device in the above method embodiments.

[0595] The embodiments of the present application also provide a computer readable storage medium, which stores computer instructions for implementing the method performed by the communication device (such as the first network element, the second network element, and the terminal device) in the above method embodiments.

[0596] The embodiments of the present application also provide a computer program product, which contains instructions executed by a computer to implement the method performed by the communication device (such as the first network element, the second network element, and the terminal device) in the above method embodiments.

[0597] The embodiments of the present application also provide a communication system, which includes at least one of the first network element, the second network element, and the terminal device in the above embodiments.

[0598] The explanations and beneficial effects of the related contents in any of the above devices can refer to the corresponding method embodiments provided above, and will not be repeated here.

[0599] In the above embodiments, the terms and / or descriptions of different embodiments are consistent and can be mutually referred to if there is no special description and no logical conflict. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0600] In the present application, the words "exemplary," "for example," and the like are used solely to

[0601] It should be understood that any reference to an "embodiment" or "example" means that a particular feature, structure, or characteristic corresponding to the embodiment or example is included in at least one embodiment or example of the application. The appearances of the

[0602] It should be understood that the size of the serial number of the above-mentioned processes does not mean the order of execution in various embodiments of the present application, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The names of all nodes and messages in the present application are only the names set by the present application for convenience of description, and the names in the actual network may be different, and the present application should not be understood as limiting the names of various nodes and messages. On the contrary, any name with the same or similar function as the nodes or messages used in the present application is regarded as the method or equivalent replacement of the present application, and is within the protection scope of the present application.

[0603] It should also be understood that in the present application, "when", "if" and "when" refer to the corresponding processing of the network element under certain objective circumstances, not the time limit, and the network element does not require judgment action when it is implemented, nor does it mean that there are other limitations.

[0604] It should be noted that in the embodiments of the present application, "pre-setting", "pre-configuration" and the like can be realized by pre-saving corresponding codes, tables or other means for indicating related information in the device (for example, terminal device), and the specific implementation manner is not limited in the present application, for example, the rules and preset constants in the embodiments of the present application.

[0605] In addition, the terms "system" and "network" are often used interchangeably in the present application.

[0606] The term "at least one of" or "at least one of the following" in the present application means all or any combination of the listed items, for example, "at least one of A, B and C" can mean six cases of A alone, B alone, C alone, A and B together, B and C together, and A, B and C together. The "at least one" in the present application means one or more. "Multiple" means two or more.

[0607] It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0608] In addition, "of", "corresponding", "corresponding" and "associated" can be mixed sometimes, and it should be pointed out that when the distinction is not emphasized, the meaning expressed is consistent. The terms "include", "contain", "have" and their variants mean "include but not limited to", unless otherwise specifically emphasized.

[0609] Those skilled in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0610] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0611] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be realized by other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0612] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0613] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0614] The functions, if implemented in the form of software functional units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application or the parts of the technical solutions that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and various media that can store program codes.

[0615] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

A communication method characterized by comprising: The method applied to a first network element comprises: obtaining and saving a first credential corresponding to a first user identifier, the first credential being a short-term credential corresponding to the first user identifier, and being used for verifying the first user identifier in a short term; receiving a second credential corresponding to the first user identifier, the second credential being received in a case where the first user identifier is used to log in a terminal device; verifying an association relationship between the first credential and the second credential; determining whether to trigger an authentication process of authenticating the first user identifier according to a third credential according to a verification result obtained by verifying the association relationship, the third credential being a long-term credential corresponding to the first user identifier. The method of claim 1, wherein The method further comprises: sending a first message to the terminal device, the first message comprising a first authentication result, the first authentication result being obtained by triggering the authentication process of authenticating the first user identifier according to the third credential, and the first authentication result indicating whether the authentication of the first user identifier by the network is successful. The method according to claim 2, characterized in that The first message further comprises a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a generation time of the first authentication result, the first time length and the first timestamp being used to determine whether the first authentication result is valid; The receiving of the second credential corresponding to the first user identifier comprises: receiving the second credential corresponding to the first user identifier, the second credential being received in a case where the first user identifier is used to log in the terminal device and the first authentication result is valid. The method according to claim 1 or 2, characterized in that Before receiving the second credential corresponding to the first user identifier, the method further comprises: determining whether the first authentication result is valid according to a first time length and a first timestamp, the first time length being a valid time length of the first authentication result, and the first timestamp indicating a generation time of the first authentication result; in a case where the first authentication result is valid, sending a first request message to the terminal device, the first request message being used to request the second credential. The method according to any one of claims 1 to 4, characterized in that The obtaining and saving of the first credential corresponding to the first user identifier comprises: receiving the first credential from a second network element, the second network element being used to authenticate the first user identifier or being used to store subscription information corresponding to the first user identifier; or generating the first credential. The method according to claim 5, characterized in that Before receiving the second credential corresponding to the first user identifier, the method further comprises: informing the first user of the first credential through the terminal device, the first user being a user who logs in the terminal device using the first user identifier. The method according to any one of claims 1 to 4, characterized in that The second credential is generated by the terminal device according to the third credential. A communication method characterized by comprising: The method applied to a terminal device comprises: receiving a first message, the first message comprising a first authentication result, the first authentication result indicating whether the authentication of a first user identifier by a network is successful; in a case where the first authentication result indicates that the authentication is successful, obtaining and saving a first credential; If the terminal device is logged in through the first user identifier, a second trust letter input by the first user is verified according to the saved first trust letter; In a case where the second trust letter is verified successfully, it is determined that the first user identifier does not need to be authenticated; The first authentication result is determined according to a third trust letter, and the third trust letter is a long-term trust letter corresponding to the first user identifier. The method of claim 8, wherein The first message further includes a first time length and a first timestamp, the first time length is a valid time length of the first authentication result, and the first timestamp indicates a generation time of the authentication result, and the method further includes: Saving the first time length and the first timestamp; Determining whether the first authentication result is valid according to the first time length and the first timestamp; The first trust letter includes: In a case where the first authentication result is valid, the first trust letter is acquired and saved. The method according to claim 8 or 9, characterized in that The method further includes: A second message is sent to a first network element, the second message carries the first user identifier, and the second message is used to indicate that the terminal device successfully verifies a second trust letter corresponding to the first user identifier. The method of claim 10, wherein The second message further carries first indication information, and the first indication information indicates that the first user identifier does not need to be authenticated. A communication device characterized by comprising: The apparatus includes units or modules for performing the method of any of claims 1 to 11. A communication device, characterized by includes: The processor is configured to cause the apparatus to perform the method of any of claims 1 to 11 by executing a computer program stored in the memory and / or by a logic circuit. A computer-readable storage medium, characterized by, The computer-readable storage medium includes a computer program or instructions, which, when executed on a computer, cause the computer to perform the method of any of claims 1 to 11. A computer program product, characterized in that The computer program product includes a computer program or instructions, which, when executed on a computer, cause the computer to perform the method of any of claims 1 to 11.

Citation Information

Patent Citations

  • Authentication method, method for generating credential and correlative apparatus

    CN104348801A

  • Authentication method, authentication network element and security anchor entity

    CN114727285A

  • User authentication data switching processing method, communication equipment and readable storage medium

    CN115866581A

  • Communication method, device and system

    CN116074822A

  • Method and system for carrying out personalized authorization use by utilizing public UE based on 5GC

    CN116806022A