WO2014113920A1 - Method and network device for security authentication of mobile communication system - Google Patents

Method and network device for security authentication of mobile communication system Download PDF

Info

Publication number
WO2014113920A1
WO2014113920A1 PCT/CN2013/070839 CN2013070839W WO2014113920A1 WO 2014113920 A1 WO2014113920 A1 WO 2014113920A1 CN 2013070839 W CN2013070839 W CN 2013070839W WO 2014113920 A1 WO2014113920 A1 WO 2014113920A1
Authority
WO
WIPO (PCT)
Prior art keywords
lte
hss
network element
access network
sgsn
Prior art date
Application number
PCT/CN2013/070839
Other languages
French (fr)
Chinese (zh)
Inventor
陈璟
靳维生
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2013/070839 priority Critical patent/WO2014113920A1/en
Priority to CN201380070864.4A priority patent/CN104937990B/en
Publication of WO2014113920A1 publication Critical patent/WO2014113920A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery

Definitions

  • Embodiments of the present invention relate to the field of communications, and in particular, to a method and a network device for secure authentication of a mobile communication system.
  • Long Term Evolution Long Term Evolution
  • SAE System Architecture Evolution
  • 3rd Generation Partnership Project 3rd Generation Partnership Project
  • WCDMA Wideband Code Division Multiple Access
  • TD-SCDMA Time Division-Synchronous Code Division Multiple Access
  • CDMA Division Code Division Multiple Access 2000
  • the Universal Mobile Telecommunication System (UMTS) network and the LTE/SAE network have developed an Authentication and Key Agreement ("AKA") mechanism to perform UE and network. Two-way authentication.
  • the two-way authentication mechanism of the UMTS network is called UMTS AKA
  • the two-way authentication mechanism of the LTE/SAE network is called an Evolved Packet System (“EPS”) AKA.
  • UE User Equipment
  • UE accesses a 2G/3G core network through an LTE access network. Since the 2G/3G core network can only obtain UMTS AV from the HSS, the LTE UE refuses to use the UMTS AV for authentication when accessing through the LTE network. Therefore, the LTE UE cannot access the 2G/3G core network through the LTE access network.
  • the embodiments of the present invention provide a method and a network device for secure authentication of a mobile communication system, which enable the LTE UE to complete the secure authentication and access the 2G/3G network.
  • the first aspect provides a security authentication method for a mobile communication system, including: after the home subscriber server HSS receives the request for the authentication vector sent by the GPRS service support node SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, The request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request attach request message sent by the access network element;
  • the HSS recognizes that after the LTE UE accesses the 2G or 3G network, the HSS generates a special authentication vector
  • the HSS sends the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the UMTS attach request message is obtained by the access network element converting the attach request attach message, and the attach request message is sent by the LTE UE.
  • the SGSN, the access network element, and the LTE UE completing the security authentication include: sending, by the SGSN The UMTS AKA authentication challenge is performed to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge, and then sends the LTE UE to the LTE UE, and the LTE UE performs verification and generates according to the LTE AKA authentication challenge.
  • the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access.
  • the network element, the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
  • the HSS identifies that the LTE UE accesses the 2G or 3G network, and the HSS includes: a list including identification information of an LTE UE that accesses a 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating, by the HSS, the special authentication vector includes:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converting the EPS AV into the UMTS AV format includes:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • a method for secure authentication of a mobile communication system including:
  • the SGSN receives the UMTS attach request message, and the UMTS attach request message is obtained by the access network element converting the attach request message sent by the LTE UE; the SGSN receives the sent by the access network element After the UMTS attach request message, the SGSN sends a request for the authentication vector to the HSS, so that the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G or 3G network, so that the HSS generates the special authentication vector;
  • the SGSN After receiving the special authentication vector from the HSS, the SGSN sends a UMTS AKA authentication challenge to the access network element, so that the SGSN, the access network element, and the LTE UE complete security authentication.
  • the SGSN, the access network element, and the LTE UE complete the security authentication, including:
  • the access network element is sent to the LTE UE, and after the LTE UE performs verification according to the LTE AKA authentication challenge and generates a RES and a key K ASME , the LTE UE will The LTE AKA authentication response including the RES is sent to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access network element, and the access network element generates according to the CK and or IK. K ASME , the access network element and the The LTE UE shares the K ASME .
  • the second possible implementation manner of the second aspect further includes: when the comparison result is different, suspending the security authentication.
  • the HSS receives the request of the SGSN and identifies the LTE UE.
  • Access to 2G or 3G networks includes:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating, by the HSS, the special authentication vector after receiving the request of the SGSN includes:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into the UMTS AV format including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • a method for secure authentication of a mobile communication system including:
  • the access network element converts the attach request message from the LTE UE into a UMTS attach request message
  • the access network element sends the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN to identify that the LTE UE accesses the 2G or 3G network.
  • the HSS In order for the HSS to generate a special authentication vector;
  • the access network element receives the UMTS AKA authentication challenge sent by the SGSN, and the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
  • the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the challenge to the LTE UE, so that the access network element, the SGSN, and the LTE UE complete the security authentication.
  • the accessing the network element, the SGSN, and the LTE UE to complete the security authentication includes:
  • the LTE UE After the LTE UE verifies the LTE AKA authentication challenge, the RES and the key K ASME are generated;
  • the access network element receives the LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the LTE AKA authentication response including the RES is converted into a UMTS AKA authentication response including the RES, where the access network element, the SGSN, and the LTE UE further perform security authentication, the access network element:
  • the network element sends the UMTS AKA authentication response including the RES to the SGSN, so that the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the SGSN.
  • Network access network element
  • the access network element generates K ASME according to the CK and or IK, the access network element and the LTE UE A total of KASME °
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
  • the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G.
  • 3G networks include:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating, by the HSS, the special authentication vector includes:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to instruct the HSS to generate the special authentication vector; the HSS generates EPS AV for the LTE UE;
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converting the EPS AV into the UMTS AV format includes:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the access network element generating the K ASME according to the CK and or the ⁇ includes:
  • an HSS including: a receiving module, an identifying module, a processing module, and a sending module;
  • the receiving module is configured to receive a request for an authentication vector sent by the SGSN, where the request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request message sent by the access network element, where the identifying module is used to Receiving the request for the authentication vector, the receiving module identifies that the LTE UE accesses the 2G or 3G network;
  • the processing module is configured to generate a special authentication vector after the identification module identifies that the LTE UE accesses the 2G or 3G network;
  • the sending module is configured to send the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
  • the SGSN, the access network element, and the LTE UE completing the security authentication include: sending, by the SGSN The UMTS AKA authentication challenge is performed to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge, and then sends the LTE UE to the LTE UE, and the LTE UE performs verification and generates according to the LTE AKA authentication challenge.
  • the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access.
  • the network element, the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
  • the SGSN comparing whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the HSS further includes a storage module, where the storage module is configured to store a list, the list Including identification information of an LTE UE that accesses a 2G/3G network;
  • the identification module knows that the identifier information of the LTE UE is included in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the processing module is configured to identify, by the identification module, that the LTE UE accesses the 2G or the fourth aspect, or the first to the fifth possible implementation manner of the fourth aspect, Generating special authentication vectors after the 3G network includes:
  • the processing module is configured to add indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector; the processing module is configured to generate an EPS AV for the LTE UE;
  • the processing module is configured to convert the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the processing module is configured to convert the EPS AV into the UMTS AV format, including:
  • the processing module is configured to use RAND in the EPS AV as the RAND of the UMTS AV, and the processing module is configured to use the AUTN in the EPS AV as the AUTN of the UMTS AV, and the processing module is used to use the XRES in the EPS AV As the XRES of the UMTS AV, the processing module is configured to split the K ASME in the EPS AV into two parts, respectively, as the CK and the IK of the UMTS AV.
  • the access network element generates a K ASME according to the CK and or IK, including:
  • an SGSN including: a receiving module; a sending module;
  • the receiving module is configured to receive a UMTS attach request message sent by an access network element, where the
  • the UMTS attach request is obtained by converting, by the access network element, the attach request message sent by the LTE UE;
  • the sending module is configured to send a request for an authentication vector to the HSS after the receiving module receives the UMTS attach request message, so that the HSS receives the request and identifies that the LTE UE accesses the 2G or 3G network, and thus The HSS generates the special authentication vector;
  • the receiving module is further configured to receive the special authentication vector from the HSS, where the sending module is further configured to send a UMTS AKA authentication challenge to the access network element after the receiving module receives the special authentication vector, so that the SGSN The access network element and the LTE UE complete the security authentication.
  • the SGSN, the access network element, and the LTE UE complete the security authentication, including:
  • the access network element is sent to the LTE UE, and after the LTE UE performs verification according to the LTE AKA authentication challenge and generates a RES and a key K ASME , the LTE UE will The LTE AKA authentication response including the RES is sent to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the SGSN further includes a processing module
  • the special authentication vector contains XRES, CK, IK;
  • the further completing the security authentication for the access network element, the SGSN, and the LTE UE includes: the access network element converting the LTE AKA authentication response into a UMTS AKA authentication response and transmitting the UMTS AKA authentication response to the receiving Module, the processing module is used to compare the RES and Whether the XRES is the same. When the comparison result is the same, the sending module sends the CK and or IK to the access network element, and the access network element generates the K ASME according to the CK and or IK. CK and or IK are sent by the sending module, and the access network element and the LTE UE share the K ASME .
  • the processing module is configured to compare whether the RES and the XRES are the same, and further includes: when the comparison result is different, the suspension is performed. safety certificate.
  • the HSS is configured to identify that the LTE UE accesses the 2G after receiving the request.
  • 3G networks include:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating, by the HSS, the special authentication vector includes:
  • the HSS adds indication information to the request for the authentication vector, the indication information is used to indicate that the HSS generates the special authentication vector; the HSS generates EPS AV for the LTE UE;
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into the UMTS AV format including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • a sixth aspect provides an access network element, including: a receiving module, a processing module, and a sending module;
  • the receiving module is configured to receive an attach request message from an LTE UE; the processing module is configured to convert the attach request message into a UMTS attach request message;
  • the sending module is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and after receiving the request of the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, and further
  • the receiving module is further configured to receive a UMTS AKA authentication challenge sent by the SGSN, where the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
  • the processing module is further configured to convert the UMTS AKA authentication challenge into an LTE AKA authentication challenge, where the sending module is further configured to send the LTE AKA authentication challenge to the LTE UE, so that the access network element, the SGSN, and the LTE are The UE completes the security certification.
  • the security authentication of the access network element, the SGSN, and the LTE UE is performed by:
  • the LTE UE After the LTE UE verifies the LTE AKA authentication challenge, the RES and the key K ASME are generated;
  • the receiving module is configured to receive an LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the processing module is further configured to convert the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, where the sending module further comprises: the processing module further configured to: Also used to send the UMTS AKA authentication response containing the RES to the SGSN, so that the SGSN compares the RES and the XRES Similarly, when the comparison result is the same, the SGSN sends the CK and or IK to the access network element;
  • the processing module is further configured to generate a K ASME according to the CK and or IK, the access network element and the LTE UE being the KASME.
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
  • the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G.
  • 3G networks include:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating, by the HSS, the special authentication vector includes:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converting the EPS AV into the UMTS AV format includes:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS K ASME in the EPS AV (256bits) Split into two parts, respectively as the CK and the IK of the UMTS AV.
  • the HSS identifies that the LTE UE accesses the 2G/3G network, and the HSS generates a special authentication vector, and the LTE UE accesses the 2G/3G network to complete the security authentication through the SGSN and the access network element, so that the LTE UE can use the 2G. /3G core network resources.
  • FIG. 1 is a schematic flowchart of an authentication method of a mobile communication system according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of an authentication method of a mobile communication system according to another embodiment of the present invention
  • FIG. 3 is a schematic flow chart of an authentication method of a mobile communication system according to another embodiment of the present invention.
  • FIG. 4 is a schematic flow chart of an authentication method of a mobile communication system according to another embodiment of the present invention.
  • FIG. 5 is a schematic block diagram of a home subscriber server according to an embodiment of the present invention.
  • FIG. 6 is a schematic block diagram of a GPRS service support node according to an embodiment of the present invention.
  • FIG. 7 is a schematic block diagram of an access network element according to an embodiment of the present invention.
  • FIG. 8 is a schematic block diagram of a home subscriber server according to another embodiment of the present invention.
  • FIG. 9 is a schematic block diagram of a GPRS service support node according to another embodiment of the present invention.
  • FIG. 10 is a schematic block diagram of an access network element according to another embodiment of the present invention. detailed description
  • GSM Global System of Mobile communication
  • CDMA code division multiple access
  • WCDMA Wideband Code Division Multiple Access
  • GSM General Packet Radio Service
  • UMT Universal Mobile Telecommunication System
  • Wi-Fi Worldwide Interoperability for Microwave Access
  • the access network element in the embodiment of the present invention is an enhanced access network element for supporting the LTE UE to access the 2G/3G core network.
  • the access network element may have the following functions: The function of the LTE eNB, the LTE UE may access the 2G/3G core network through the access network element without modification, and the LTE UE considers that The LTE network is being accessed, instead of the 2G/3G core network; the access network element in the embodiment of the present invention can also implement the function of a Mobility Management Entity (called " ⁇ "). Such as the security protection function of the non-access stratum (“Non-Access Stratum").
  • FIG. 1 shows a schematic flow diagram of a method 100 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention. As shown in FIG. 1, the method 100 includes:
  • the HSS After receiving the request for the authentication vector sent by the SGSN, the HSS identifies that the HSS is
  • the LTE UE accesses the 2G or 3G network, and the request for the authentication vector is received by the SGSN. Sending the UMTS attach request message sent by the network element to the SGSN;
  • the HSS recognizes that after the LTE UE accesses the 2G or 3G network, the HSS generates a special authentication vector
  • the HSS sends the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the HSS in order to enable the LTE UE to use the 2G or 3G core network, after the HSS recognizes that the LTE UE accesses the 2G/3G core network, the HSS generates a special authentication vector for the LTE UE, so that the SGSN, the SGSN, The access network element and the LTE UE complete the security authentication to enable the LTE UE to access the 2G or 3G network, so that the LTE UE can use the 2G or 3G core network resources.
  • the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
  • the SGSN, the access network element, and the LTE UE complete the security authentication, where the SGSN sends a UMTS AKA authentication challenge to the access network element, and the access network element authenticates the UMTS AKA.
  • the challenge is converted into an LTE AKA authentication challenge, and sent to the LTE UE, after the LTE UE performs verification according to the LTE AKA authentication challenge and generates a RES and a key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the LTE AKA authentication challenge.
  • Accessing the network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
  • the access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, and the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the The SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, the access network element and the
  • the LTE UE shares the K ASME .
  • the SGSN compares whether the RES and the XRES are the same, and includes, when the comparison is If the results are different, the safety certification is suspended.
  • the HSS identification is that the LTE UE accesses the 2G or 3G network, including:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the HSS generates a special authentication vector including:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format, including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the access network element generates the K ASME according to the CK and or the ⁇ :
  • the message sent by the LTE UE is converted into a message applicable to the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G core through the access network element.
  • the HSS After the scenario of the network, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • FIG. 2 shows an illustration of a method 200 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention.
  • Intentional flow chart. 2 and its description of the disclosed method may be based on the embodiment of the present invention and the method disclosed in FIG. 1 based on an embodiment of the present invention.
  • the method 200 includes:
  • the SGSN receives the UMTS attach request message, where the UMTS attach request is that the access network element converts the attach request message sent by the LTE UE, and S220, the SGSN receives the access network element by the access network.
  • the SGSN sends a request for the authentication vector to the HSS, so that the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G or 3G network, so that the HSS generates the special Authentication vector
  • the SGSN After receiving the special authentication vector from the HSS, the SGSN sends a UMTS AKA authentication challenge to the access network element, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the HSS After the scenario in which the LTE UE accesses the 2G or 3G network is identified by the HSS, the HSS generates a special authentication vector, so that the SGSN, the access network element, and the LTE UE complete the security authentication, and the implementation does not require the LTE UE. Under the condition that the LTE UE can perform security authentication, the LTE UE can access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • the SGSN, the access network element, and the LTE UE complete the security authentication, where the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE.
  • the LTE UE After the LTE UE performs the verification according to the LTE AKA authentication challenge and generates the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the The SGSN and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
  • the access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, the SGSN comparing the RES with the XRES Whether the same is true, when the comparison result is the same, the SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, the access network element
  • the K ASME is shared with the LTE UE.
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the method for the HSS to receive the request of the SGSN is that the LTE UE accesses the 2G or 3G network, including:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the special authentication vector is generated after the HSS receives the request from the SGSN, including:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format, including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the access network element generates the K ASME according to the CK and or the ⁇ :
  • the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element.
  • the HSS After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, and the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • FIG. 3 shows a schematic flow diagram of a method 300 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention.
  • the method disclosed in Figure 3 and its description may be based on the embodiments of Figures 1 through 2 of the present invention and the methods disclosed in Figures 1 through 2 of the present invention.
  • the method 300 includes:
  • the access network element converts an attach request message from the LTE UE into a UMTS attach request message.
  • the access network element sends the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G or 3G.
  • Network in order for the HSS to generate a special authentication vector
  • the access network element receives the UMTS AKA authentication challenge sent by the SGSN, where the UMTS
  • the AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
  • the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE, so that the access network element, the SGSN, and the LTE UE complete the security authentication.
  • the information sent by the LTE UE is converted to be applicable to the network element of the access network.
  • the information of the 2G or 3G network system is identified by the HSS as the LTE UE accessing the 2G or 3G network.
  • the HSS generates a special authentication vector to enable the access network element, the SGSN, and the LTE UE to complete the security authentication.
  • the UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • the accessing the network element, the SGSN, and the LTE UE to complete the security authentication includes: generating, by the LTE UE, the RES and the key K ASME after verifying the LTE AKA authentication challenge;
  • the access network element receives the LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the access network element, the SGSN, and the LTE UE further complete the security authentication, including:
  • the access network element converts the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, and the access network element sends the UMTS AKA authentication response including the RES to the SGSN, so that the SGSN Comparing whether the RES and the XRES are the same, when the comparison result is the same, the SGSN sends the CK and or IK to the access network element;
  • the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE jointly have the KASME °
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the HSS identifies that the LTE UE accesses the 2G or 3G network, including:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the further generating the special authentication vector for the HSS comprises:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the access network element generates the K ASME according to the CK and or the ⁇ :
  • the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element.
  • the HSS After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • FIG. 4 shows a schematic flow diagram of a method 400 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention.
  • the method 400 includes:
  • the LTE UE accesses the 2G/3G core network through the access network element, and an RRC connection is established between the LTE UE and the access network element.
  • the LTE UE sends an attach request message to the access network element, and the access network element converts the attach request message received from the LTE UE into a UMTS attach request message identifiable by the SGSN of the 2G/3G core network in the UMTS system.
  • the network access NE sends the converted UMTS attach request message to the SGSN.
  • the SGSN sends a request for an authentication vector to the HSS. .
  • the HSS identifies that the LTE UE accesses the 2G/3G network, and includes:
  • the HSS is equipped with a list including LTE UEs accessing the 2G/3G network Identification information;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the HSS generates the special authentication vector, including:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS sets the 0th bit in the authentication management domain AMF to 1 to indicate that the authentication vector is EPS AV;
  • HSS generates RAND, AUTN, CK, IK and XRES;
  • the HSS derives KASME based on CK and IK.
  • EPS AV consists of K ASME , AUTN , XRES , RAND , where the 0th bit of the AMF parameter in the AUTN has a value of 1.
  • the HSS converts the EPS AV into a UMTS AV format such that the EPS AV can be sent to the SGSN through an existing UMTS authentication response.
  • the method for converting EPS AV into UMTS AV format includes: RAND, AUTN and XRES in EPS AV are used as RAND, AUTN and XRES of UMTS AV, and K ASME (256bits) in EPS AV is split into two parts, respectively as UMTS AV's CK (128bits) and IK (128bits). Alternatively, K ASME (256 bits) may also be split unevenly, and the ratio of the CK to the IK may be different.
  • the value of the 0th bit of the AMF in the AUTN is still 1.
  • the vector obtained by converting the EPS AV into the UMTS AV format is the special authentication vector.
  • the HSS transmits the special authentication vector to the SGSN;
  • the SGSN performs a UMTS AKA authentication procedure based on the special authentication vector received from the HSS.
  • the SGSN sends a UMTS AKA authentication challenge to the access network element, the UMTS AKA authentication challenge Contains RAND and AUTNo
  • the access network element converts the received UMTS AKA authentication challenge into an LTE AKA authentication challenge.
  • the RAND and AUTN in the UMTS AKA authentication challenge are sent to the LTE UE in the LTE AKA authentication challenge.
  • the LTE UE verifies the AUTN. Further, since the value of the 0th bit of the AMF in the AUTN is
  • the LTE UE will pass the check of AMF.
  • the LTE UE generates the RES and the key K ASME .
  • the LTE UE sends an LTE AKA authentication response to the access network element, and the LTE AKA authentication response includes the RES.
  • the access network element converts the LTE AKA authentication response into a UMTS AKA authentication response, and sends the RES in the LTE AKA authentication response to the SGSN in the UMTS AKA authentication response.
  • the SGSN compares whether the RES and the XRES are the same.
  • the security authentication is suspended;
  • the SGSN initiates a security mode process, in which CK and or IK are sent to the access network element.
  • the access network element generates K ASME according to CK and or IK.
  • the access network element generates K ASME according to CK and or IK.
  • the access network element and the LTE UE share the key K ASME .
  • the LTE NAS SMC process and the LTE AS SMC process are performed between the access network element and the LTE UE to establish an LTE air interface security.
  • the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element.
  • the HSS After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN.
  • the LTE UE does not need to be modified, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources. .
  • the home subscriber server HSS500 includes: a receiving module 510, an identification module 520, a processing module 530, a sending module 540;
  • the receiving module 510 is configured to receive a request for the authentication vector sent by the SGSN, where the request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request message sent by the access network element, where the After the receiving module 510 receives the request for the authentication vector, it is identified that the LTE UE accesses the 2G or 3G network;
  • the processing module 530 is configured to generate a special authentication vector after the identification module 520 identifies that the LTE UE accesses the 2G or 3G network;
  • the sending module 540 is configured to send the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the HSS in order to enable the LTE UE to use the 2G or 3G core network, after the HSS recognizes that the LTE UE accesses the 2G/3G core network, the HSS generates a special authentication vector for the LTE UE, so that the SGSN, the SGSN, The access network element and the LTE UE complete the security authentication, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
  • the security authentication is performed by the SGSN, the access network element, and the LTE UE, including:
  • the SGSN sends a UMTS AKA authentication challenge to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the challenge to the LTE UE, where the LTE UE performs the LTE AKA authentication challenge.
  • the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
  • the access network element converts the LTE ⁇ authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, where the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, The SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the HSS further includes a storage module 550, where the storage module 550 is configured to store a list, where the list includes identifier information of the LTE UE that accesses the 2G/3G network;
  • the identifying module 520 learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the processing module 530 is configured to: after the identifying module 520 identifies that the LTE UE accesses the 2G or 3G network, generating a special authentication vector, including:
  • the processing module 530 is configured to add indication information to the request for requesting the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the processing module 530 is configured to generate an EPS AV for the LTE UE;
  • the processing module 530 is configured to set the 0th bit in the authentication management domain AMF to 1 to indicate that the authentication vector is EPS AV;
  • the processing module 530 is configured to generate RAND, AUTN, CK, IK, and XRES;
  • EPS AV consists of K ASME , AUTN , XRES , RAND , where the 0th bit of the AMF parameter in the AUTN has a value of 1.
  • the processing module 530 is configured to convert the EPS AV into a UMTS AV format, so that the method of the AV format includes: using RAND, AUTN, and XRES in the EPS AV as the RAND, AUTN, and XRES of the UMTS AV, and the EPS K ASME (256bits) in AV is split into two parts, which are CK (128bits) and IK (128bits) of UMTS AV.
  • the EPS AV is converted into the UMTS AV format
  • the value of the 0th bit of the AMF in the AUTN is still 1.
  • the vector obtained by converting the EPS AV into the UMTS AV format is the special authentication vector.
  • the access network element generates the K ASME according to the CK and or IK, including:
  • the access network element in accordance with the generation rule K ASME CKIIIK, which generates based on the K ASME and CK or IK. ⁇ indicates concatenation, IK is added after CK.
  • the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element.
  • the HSS After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • Figure 6 shows a schematic block diagram of a GPRS service support node 600 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 6 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 based on the embodiment of the present invention may also be based on the embodiment of the present invention and FIG. 5 and FIG. Revealed device.
  • the GPRS service support node SGSN600 includes: a receiving module 610; a sending module 620;
  • the receiving module 610 is configured to receive a UMTS attach request message sent by an access network element, where the UMTS attach request is obtained by converting, by the access network element, an attach request message sent by the LTE UE;
  • the sending module 620 is configured to receive the UMTS attach request in the receiving module 610. After receiving the request, the request for the authentication vector is sent to the HSS, so that the HSS receives the request and identifies that the LTE UE accesses the 2G or 3G network, so that the HSS generates the special authentication vector; the receiving module 610 is further configured to receive The special authentication vector from the HSS, the sending module 620 is further configured to send a UMTS AKA authentication challenge to the access network element after the receiving module 610 receives the special authentication vector, so that the SGSN, the access network The network element and the LTE UE complete the security authentication.
  • the HSS After the scenario in which the LTE UE accesses the 2G or 3G core network is identified by the HSS, the HSS generates a special authentication vector, so that the SGSN, the access network element, and the LTE UE complete the security authentication, and the implementation does not need to be performed. Under the condition that the LTE UE is modified, the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • the SGSN, the access network element, and the LTE UE complete the security authentication, where the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE.
  • the LTE UE After the LTE UE performs the verification according to the LTE AKA authentication challenge and generates the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the The SGSN and the LTE UE further complete the security authentication.
  • the SGSN further includes a processing module 630;
  • the special authentication vector includes XRES, CK, and IK;
  • the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
  • the access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the receiving module 610, where the processing module 630 is configured to compare whether the RES and the XRES are the same, when the comparison is performed.
  • the sending module 620 sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, and the CK and or IK are sent by the sending module 620.
  • the processing module 630 compares whether the RES and the XRES are the same. Further, when the comparison result is different, the security authentication is suspended.
  • the HSS After the HSS receives the request, it is identified that the LTE UE accesses the 2G or 3G network includes: the HSS is equipped with a list, and the list includes the identifier information of the LTE UE accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating the special authentication vector by the HSS includes:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format, including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the access network element generates the K ASME according to the CK and or the ⁇ :
  • the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element.
  • the HSS After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. No modification to the LTE UE is required, so that the LTE UE can complete
  • the security authentication accesses the 2G or 3G network, so that the LTE UE uses 2G or 3G core network resources.
  • FIG. 7 shows a schematic block diagram of an access network element 700 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 7 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 according to the embodiment of the present invention may also be based on the embodiments of the present invention and FIGS. 5 to 6 and The apparatus disclosed in Figures 5-6.
  • the access network element 700 includes: a receiving module 710, a processing module 720, and a sending module 730;
  • the receiving module 710 is configured to receive an attach request message from an LTE UE; the processing module 720 is configured to convert the attach request message into a UMTS attach request message;
  • the sending module 730 is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN to identify that the LTE UE accesses the 2G or 3G network. In order for the HSS to generate a special authentication vector;
  • the receiving module 710 is further configured to receive the UMTS AKA authentication challenge sent by the SGSN, where the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS; the processing module 720 is further configured to authenticate the UMTS AKA.
  • the challenge is converted into an LTE AKA authentication challenge, and the sending module 730 is further configured to send the LTE AKA authentication challenge to the LTE UE, so that the access network element, the SGSN, and the LTE UE complete the security authentication.
  • the information sent by the LTE UE is converted into the information applicable to the 2G or 3G network system by the access network element, and the scene that the LTE UE accesses the 2G or 3G network is identified by the HSS, and is generated by the HSS.
  • the special authentication vector enables the access network element, the SGSN, and the LTE UE to complete the security authentication, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • the access network element, the SGSN, and the LTE UE complete the security authentication, where the LTE UE verifies the LTE AKA authentication challenge, and generates a RES and a key K ASME ;
  • the receiving module 710 is configured to receive an LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the access network element, the SGSN, and the LTE UE further complete the security authentication, including:
  • the processing module 720 is further configured to convert the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, where the sending module 730 is further configured to send the UMTS AKA authentication response including the RES to the SGSN, so that The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access network element.
  • the processing module 720 is further configured to generate a K ASME according to the CK and or IK, where the access network element and the LTE UE share the K ASME .
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the HSS After receiving the request from the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, including:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the further generating the special authentication vector for the HSS comprises:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME (256 bits) in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the message sent by the LTE UE is converted into a message applicable to the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G core through the access network element.
  • the HSS After the scenario of the network, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • FIG. 8 shows a schematic block diagram of a home subscriber server 800 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 8 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 based on the embodiment of the present invention, and FIG. 5 to FIG. 7 based on the embodiment of the present invention and based on The apparatus disclosed in Figures 5 to 7 of the embodiment of the present invention.
  • the home subscriber server HSS800 includes: a receiver 810, a first processor 820, a second processor 830, and a transmitter 840;
  • the receiver 810 is configured to receive a request for an authentication vector sent by the SGSN, where the request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request message sent by the access network element, the first processor The 820 is configured to: after the receiver 810 receives the request for the authentication vector, identify that the LTE UE accesses the 2G or 3G network;
  • the second processor 830 is configured to generate a special authentication vector after the first processor 820 recognizes that the LTE UE accesses the 2G or 3G network;
  • the transmitter 840 is configured to send the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the HSS in order to enable the LTE UE to use the 2G or 3G core network, in the HSS After the LTE UE accesses the 2G/3G core network, the HSS generates a special authentication vector for the LTE UE, so that the SGSN, the access network element, and the LTE UE complete the security authentication, so that the LTE UE accesses the 2G or 3G. Network, so that LTE UEs can use 2G or 3G core network resources.
  • the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
  • the security authentication is performed by the SGSN, the access network element, and the LTE UE, including:
  • the SGSN sends a UMTS AKA authentication challenge to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the challenge to the LTE UE, where the LTE UE performs the LTE AKA authentication challenge.
  • the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication. .
  • the special authentication vector includes XRES, CK, and IK;
  • the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
  • the access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, and the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the The SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the HSS further includes a memory 850, where the memory 850 is configured to store a list, where the list includes identifier information of the LTE UE that accesses the 2G/3G network;
  • the first processor 820 is located in the identifier information in the list, and the identifier information of the LTE UE is included in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G.
  • the internet is located in the identifier information in the list, and the identifier information of the LTE UE is included in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G. The internet.
  • the generating, by the second processor 830, the special authentication vector after the first processor 820 identifies that the LTE UE accesses the 2G or 3G network includes:
  • the second processor 830 is configured to add indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the second processor 830 is configured to generate EPS AV for the LTE UE;
  • the second processor 830 is configured to set the 0th bit in the authentication management domain AMF to 1 to indicate that the authentication vector is EPS AV;
  • the second processor 830 is configured to generate RAND, AUTN, CK, IK and XRES;
  • EPS AV consists of K ASME , AUTN , XRES , RAND , where the 0th bit of the AMF parameter in the AUTN has a value of 1.
  • the second processor 830 is configured to convert the EPS AV into a UMTS AV format, so that the EPS AV can be sent to the SGSN through an existing UMTS authentication response.
  • the method of converting EPS AV into UMTS AV format includes: using RAND, AUTN and XRES in EPS AV as RAND, AUTN and XRES of UMTS AV, and splitting K ASME (256bits) in EPS AV into two parts, respectively as UMTS AV's CK (128bits) and IK (128bits).
  • K ASME 256bits
  • the value of the 0th bit of the AMF in the AUTN is still 1.
  • the vector obtained by converting the EPS AV into the UMTS AV format is the special authentication vector.
  • the access network element generates the K ASME according to the CK and or IK, including:
  • the access network element in accordance with the generation rule K ASME CKIIIK, which generates based on the K ASME and CK or IK. ⁇ indicates concatenation, IK is added after CK.
  • the message sent by the LTE UE is converted to be applicable to the network element of the access network.
  • the message of the 2G or 3G network is recognized by the HSS.
  • the LTE UE accesses the 2G or 3G through the access network element.
  • the HSS After the scenario of the network, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN.
  • the LTE UE does not need to be modified, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • Figure 9 shows a schematic block diagram of a GPRS service support node 900 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention.
  • the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 according to the embodiment of the present invention may also be based on the embodiment of the present invention, FIG. 5 and FIG. Revealed device.
  • the GPRS service supporting node SGSN900 includes: a receiver 910; a transmitter 920;
  • the receiver 910 is configured to receive a UMTS attach request message sent by an access network element, where the UMTS attach request is obtained by converting, by the access network element, an attach request message sent by the LTE UE;
  • the transmitter 920 is configured to send a request for an authentication vector to the HSS after the receiver 910 receives the UMTS attach request message, so that the HSS receives the request and identifies that the LTE UE accesses the 2G or 3G network, and further So that the HSS generates the special authentication vector;
  • the receiver 910 is further configured to receive the special authentication vector from the HSS, where the transmitter 920 is further configured to send a UMTS AKA authentication challenge to the access network element after the receiver 910 receives the special authentication vector. So that the SGSN, the access network element, and the LTE UE complete the security authentication.
  • the HSS After the scenario in which the LTE UE accesses the 2G or 3G core network is identified by the HSS, the HSS generates a special authentication vector, so that the SGSN, the access network element, and the LTE UE complete the security authentication, and the implementation does not need to be performed. Under the condition that the LTE UE is modified, the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • the SGSN, the access network element, and the LTE UE complete the security authentication, where the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE.
  • the LTE UE After the LTE UE performs the verification according to the LTE AKA authentication challenge and generates the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the The SGSN and the LTE UE further complete the security recognition Certificate.
  • the SGSN further includes a processor 930;
  • the special authentication vector includes XRES, CK, and IK;
  • the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
  • the access network element converts the LTE ⁇ authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the receiver 910
  • the processor 930 is configured to compare whether the RES and the XRES are the same, when the comparison When the result is the same, the transmitter 920 sends the CK and or IK to the access network element, and the access network element generates the K ASME according to the CK and or IK, and the CK and or IK are sent by the The 920 is sent, and the access network element and the LTE UE share the K ASME .
  • the comparing, by the processor 930, whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
  • the HSS After the HSS receives the request, it is identified that the LTE UE accesses the 2G or 3G network includes: the HSS is equipped with a list, and the list includes the identifier information of the LTE UE accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
  • the generating the special authentication vector by the HSS includes:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format, including:
  • the HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS The AUTN in the EPS AV is used as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, and the HSS splits the K ASME in the EPS AV into two parts, respectively as the UMTS AV of the CK and the IK.
  • the access network element generates the K ASME according to the CK and or the ⁇ :
  • the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element.
  • the HSS After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • FIG. 10 shows a schematic block diagram of an access network element 1000 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 10 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 based on the embodiment of the present invention may also be based on the embodiments of the present invention and FIGS. 5 to 9 and The apparatus disclosed in Figures 5-9.
  • the access network element 1000 includes: a receiver 1010, a processor 1020, and a transmitter 1030.
  • the receiver 1010 is configured to receive an attach request message from an LTE UE, where the processor 1020 is configured to convert the attach request message into a UMTS attach request message.
  • the transmitter 1030 is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN to identify that the LTE UE accesses the 2G or 3G network.
  • the receiver 1010 is further configured to receive a UMTS AKA authentication challenge sent by the SGSN, where the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
  • the 1020 is further configured to convert the UMTS AKA authentication challenge into an LTE AKA authentication challenge, where the transmitter 1030 is further configured to send the LTE AKA authentication challenge to the LTE UE, where the access network element, the SGSN, and the LTE UE are used.
  • Complete safety certification is
  • the information sent by the LTE UE is converted into the information applicable to the 2G or 3G network system by the access network element, and the scene that the LTE UE accesses the 2G or 3G network is identified by the HSS, and is generated by the HSS.
  • the special authentication vector enables the access network element, the SGSN, and the LTE UE to perform security authentication, so that the LTE UE can use the existing 2G or 3G core network.
  • the access network element, the SGSN, and the LTE UE complete the security authentication, where the LTE UE verifies the LTE AKA authentication challenge, and generates a RES and a key K ASME ;
  • the receiver 1010 is configured to receive an LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete security authentication.
  • the special authentication vector includes XRES, CK, and IK;
  • the access network element, the SGSN, and the LTE UE further complete the security authentication, including:
  • the processor 1020 is further configured to convert the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, where the transmitter 1030 is further configured to send the UMTS AKA authentication response including the RES to the SGSN, so that The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access network element.
  • the processor 1020 is further configured to generate a K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
  • whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
  • the HSS After receiving the request from the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, including:
  • the HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
  • the HSS learns that the identifier information of the LTE UE is included in the identifier information in the list. In the list, the HSS recognizes that the LTE UE accesses the 2G or 3G network.
  • the further generating the special authentication vector for the HSS comprises:
  • the HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
  • the HSS generates EPS AV for the LTE UE
  • the HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
  • the HSS converts the EPS AV into a UMTS AV format, including:
  • the HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS
  • the K ASME (256 bits) in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
  • the message sent by the LTE UE is converted to be applicable to the network element of the access network.
  • the message of the 2G or 3G network is identified by the HSS.
  • the HSS After the LTE UE accesses the 2G or 3G core network through the access network element, the HSS generates a special authentication vector, and completes the LTE UE through the access network element and the SGSN. Security certification between the network and the network.
  • the LTE UE does not need to be modified, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a computer. Take this as an example but Not limited to: Computer readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage device, or can be used to carry or store desired program code in the form of an instruction or data structure. And any other medium that can be accessed by a computer. Also. Any connection may suitably be a computer readable medium.
  • a disk and a disc include a compact disc (CD), a laser disc, a compact disc, a digital versatile disc (DVD), a floppy disc, and a Blu-ray disc, wherein the disc is usually magnetically copied, and the disc is The laser is used to optically replicate the data.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Disclosed are a method and a network device for security authentication of a mobile communication system. The method for security authentication of a mobile communication system comprises: after receiving a request for an authentication vector sent by an SGSN, an HSS identifying that an LTE UE accesses a 2G or 3G network, wherein the request for an authentication vector is sent to the SGSN after the SGSN receives a UMTS attach request message sent by a network element of an access network; the HSS generating a special authentication vector after identifying that the LTE UE accesses a 2G or 3G network; and the HSS sending the special authentication vector to the SGSN, so that the SGSN, the network element of the access network, and the LTE UE complete security authentication. The disclosed method and network device for security authentication of a mobile communication system enable an LTE UE to use a 2G/3G network.

Description

移动通信系统的安全 ^人证的方法和网络设备  Mobile communication system security method and network device
技术领域 Technical field
本发明实施例涉及通信领域, 尤其涉及移动通信系统的安全认证的方法和 网络设备。  Embodiments of the present invention relate to the field of communications, and in particular, to a method and a network device for secure authentication of a mobile communication system.
背景技术 长期演进( Long Term Evolution ,筒称为 "LTE" )/系统架构演进 (System Architecture Evolution , 筒称为 "SAE" )网络是标准组织第三代合作伙伴计 划(3rd Generation Partnership Project , 筒称为 "3GPP" )制定的新的移动通 信系统。 这种网络将是现有的包括宽带码分多址 (Wideband Code Division Multiple Access , 筒称为 "WCDMA" ) 网络、 时分-同步码分多址 (Time Division-Synchronous Code Division Multiple Access , 筒称为 "TD-SCDMA" ) 网络、 码分多址 2000 (Code Division Multiple Access 2000 , 筒称为 "CDMA2000" )网络在内的 3G网络的下一步演进方向。 目前在某些国家, 已经有商业部署的 LTE/SAE网络正在运行。安全是移动通信系统商业运营必 不可少的特性, 认证是安全特性中的一个重要特性。 通用移动通信系统 ( Universal Mobile Telecommunication System, 筒称为 "UMTS" ) 网络和 LTE/SAE网络制定了认证和密钥协商 (Authentication and Key Agreement , 筒称为 "AKA" )机制来执行 UE和网络之间的双向认证。 UMTS网络的双 向认证机制称为 UMTS AKA, LTE/SAE网络的双向认证机制称为演进分组 系统 ( Evolved Packet System, 筒称为 "EPS" ) AKA。 在某些特殊场景下, 存在着 LTE 用户设备(User Equipment, 筒称为 "UE" ) 通过 LTE接入网 接入 2G/3G核心网的情况。 由于 2G/3G核心网只能从 HSS获得 UMTS AV , 而 LTE UE在通过 LTE网络接入时, 会拒绝使用 UMTS AV进行认证, 因此 LTE UE不能够通过 LTE接入网接入 2G/3G核心网。 发明内容 BACKGROUND OF THE INVENTION Long Term Evolution (Long Term Evolution) is a system organization evolution (System Architecture Evolution, "SAE") is a standard organization 3rd Generation Partnership Project (3rd Generation Partnership Project) A new mobile communication system for "3GPP". Such a network will be an existing Wideband Code Division Multiple Access (WCDMA) network, Time Division-Synchronous Code Division Multiple Access (Time Division-Synchronous Code Division Multiple Access) "TD-SCDMA") The next evolution direction of 3G networks such as network and Code Division Multiple Access 2000 ("CDMA Division"). Currently in some countries, commercial deployments of LTE/SAE networks are in operation. Security is an indispensable feature of the commercial operation of mobile communication systems. Authentication is an important feature in security features. The Universal Mobile Telecommunication System (UMTS) network and the LTE/SAE network have developed an Authentication and Key Agreement ("AKA") mechanism to perform UE and network. Two-way authentication. The two-way authentication mechanism of the UMTS network is called UMTS AKA, and the two-way authentication mechanism of the LTE/SAE network is called an Evolved Packet System ("EPS") AKA. In some special scenarios, there is a case where an LTE user equipment (User Equipment, called "UE") accesses a 2G/3G core network through an LTE access network. Since the 2G/3G core network can only obtain UMTS AV from the HSS, the LTE UE refuses to use the UMTS AV for authentication when accessing through the LTE network. Therefore, the LTE UE cannot access the 2G/3G core network through the LTE access network. . Summary of the invention
有鉴于此, 本发明实施例提供了一种移动通信系统的安全认证的方法和网 络设备, 能够使 LTE UE完成安全认证接入 2G/3G网络。 第一方面, 提供了一种移动通信系统的安全认证方法, 包括: 归属用户服务器 HSS接收 GPRS服务支撑节点 SGSN发送的要求认证向 量的请求后, 该 HSS识别是 LTE UE接入 2G或 3G网络, 该要求认证向量 的请求由该 SGSN在接收到接入网网元发送的 UMTS 附着请求 attach request 消息后发送给该 SGSN; In view of this, the embodiments of the present invention provide a method and a network device for secure authentication of a mobile communication system, which enable the LTE UE to complete the secure authentication and access the 2G/3G network. The first aspect provides a security authentication method for a mobile communication system, including: after the home subscriber server HSS receives the request for the authentication vector sent by the GPRS service support node SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, The request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request attach request message sent by the access network element;
该 HSS识别出是 LTE UE接入 2G或 3G网络后, 该 HSS生成特殊认证 向量;  The HSS recognizes that after the LTE UE accesses the 2G or 3G network, the HSS generates a special authentication vector;
该 HSS将该特殊认证向量发送给该 SGSN , 以便该 SGSN、 该接入网网 元和该 LTE UE完成安全认证。  The HSS sends the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
在第一种可能的实现方式中, 该 UMTS attach request消息是该接入网网 元将附着请求 attach request消息转换所得,该 attach request消息由该 LTE UE 发送。  In a first possible implementation, the UMTS attach request message is obtained by the access network element converting the attach request attach message, and the attach request message is sent by the LTE UE.
在第二种可能的实现方式中, 结合第一方面或第一方面的第一种可能的 实现方式, 该以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证包括: 该 SGSN发送 UMTS AKA认证挑战给该接入网网元, 该接入网网元将 该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给该 LTE UE, 该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该接入网网元, 以便 该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 In a second possible implementation manner, in combination with the first aspect or the first possible implementation manner of the first aspect, the SGSN, the access network element, and the LTE UE completing the security authentication include: sending, by the SGSN The UMTS AKA authentication challenge is performed to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge, and then sends the LTE UE to the LTE UE, and the LTE UE performs verification and generates according to the LTE AKA authentication challenge. After the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
在第三种可能的实现方式中, 结合第一方面或第一方面的第一种至第二 种可能的实现方式,  In a third possible implementation manner, in combination with the first aspect or the first to second possible implementation manners of the first aspect,
该特殊认证向量中包含 XRES、 CK、 IK;  The special authentication vector includes XRES, CK, and IK;
该以便该接入网网元、该 SGSN和该 LTE UE进一步完成安全认证包括: 该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME, 该接入网网元和该 LTE UE共享该 KASMEAnd the SG AKA authentication response is converted into a UMTS The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access. The network element, the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
在第四种可能的实现方式中, 结合第一方面的第三种可能的实现方式, 该 SGSN比较该 RES和该 XRES是否相同还包括,当该比较结果为不相同时, 中止进行安全认证。  In a fourth possible implementation manner, in combination with the third possible implementation manner of the first aspect, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
在第五种可能的实现方式中, 结合第一方面或第一方面的第一至第四任 一种可能的实现方式, 该 HSS识别是 LTE UE接入 2G或 3G网络包括: 该 HSS配备一个列表,该列表包括通过接入 2G/3G网络的 LTE UE的标 识信息;  In a fifth possible implementation, in combination with the first aspect or the first to the fourth possible implementation manners of the first aspect, the HSS identifies that the LTE UE accesses the 2G or 3G network, and the HSS includes: a list including identification information of an LTE UE that accesses a 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
在第六种可能的实现方式中, 结合第一方面或第一方面的第一至第五任 一种可能的实现方式, 该 HSS生成特殊认证向量包括:  In a sixth possible implementation, in combination with the first aspect or the first to the fifth possible implementation manners of the first aspect, the generating, by the HSS, the special authentication vector includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
在第七种可能的实现方式中,第一方面的第六种可能的实现方式,该 HSS 将该 EPS AV转换成 UMTS AV格式包括:  In a seventh possible implementation manner, the sixth possible implementation manner of the first aspect, the HSS converting the EPS AV into the UMTS AV format includes:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
在第八种可能的实现方式中, 结合第一方面的第三至第七任一种可能的 实现方式, 该接入网网元根据该 CK和或 ΙΚ生成 KASME包括: 该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该In an eighth possible implementation, in combination with the third to the seventh possible implementation manners of the foregoing aspect, the access network element generating the K ASME according to the CK and or the 包括 includes: The access network element generates the base according to the CK and or IK according to the generation rule K ASME =CKIIIK
KASME。 KASME.
第二方面, 提供了一种移动通信系统的安全认证方法, 包括:  In a second aspect, a method for secure authentication of a mobile communication system is provided, including:
SGSN接收接入网网元发送 UMTS attach request消息, 该 UMTS attach request消息是该接入网网元将 LTE UE发送的 attach request消息转换所得; 该 SGSN接收到由该接入网网元发送的该 UMTS attach request消息后, 该 SGSN向 HSS发送要求认证向量的请求, 以便该 HSS收到该 SGSN的该 请求后识别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成该特殊 认证向量;  The SGSN receives the UMTS attach request message, and the UMTS attach request message is obtained by the access network element converting the attach request message sent by the LTE UE; the SGSN receives the sent by the access network element After the UMTS attach request message, the SGSN sends a request for the authentication vector to the HSS, so that the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G or 3G network, so that the HSS generates the special authentication vector;
该 SGSN接收来自于该 HSS的该特殊认证向量后, 发送 UMTS AKA认 证挑战给该接入网网元, 以便该 SGSN、 该接入网网元和该 LTE UE完成安 全认证。  After receiving the special authentication vector from the HSS, the SGSN sends a UMTS AKA authentication challenge to the access network element, so that the SGSN, the access network element, and the LTE UE complete security authentication.
在第一种可能的实现方式中, 该以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证包括:  In a first possible implementation, the SGSN, the access network element, and the LTE UE complete the security authentication, including:
该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发 送给该 LTE UE,该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES 和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该 接入网网元, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证。 After the UMTS AKA authentication challenge is converted into an LTE AKA authentication challenge, the access network element is sent to the LTE UE, and after the LTE UE performs verification according to the LTE AKA authentication challenge and generates a RES and a key K ASME , the LTE UE will The LTE AKA authentication response including the RES is sent to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
在第二种可能的实现方式中, 结合第二方面或第二方面的第一种可能的 实现方式, 该特殊认证向量包含 XRES、 CK、 IK;  In a second possible implementation manner, in combination with the second aspect or the first possible implementation manner of the second aspect, the special authentication vector includes XRES, CK, and IK;
该以便该接入网网元、该 SGSN和该 LTE UE进一步完成安全认证包括: 该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME, 该接入网网元和该 LTE UE共享该 KASMEAnd the SG AKA authentication response is converted into a UMTS The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access network element, and the access network element generates according to the CK and or IK. K ASME , the access network element and the The LTE UE shares the K ASME .
在第三种可能的实现方式中, 结第二方面的第二种可能的实现方式, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结果为不相同时, 中止进行安全认证。  In a third possible implementation manner, the second possible implementation manner of the second aspect, the SGSN comparing whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
在第四种可能的实现方式中, 结合第二方面或第二方面的第一种至第三 种任一可能的实现方式, 该以便该 HSS收到该 SGSN的该请求后识别是该 LTE UE接入 2G或 3G网络包括:  In a fourth possible implementation, in combination with the second aspect or any one of the first to third possible implementation manners of the second aspect, the HSS receives the request of the SGSN and identifies the LTE UE. Access to 2G or 3G networks includes:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
在第五种可能的实现方式中, 结合第二方面或第二方面的第一种至第四 种可能的实现方式,该以便该 HSS收到该 SGSN的该请求后生成该特殊认证 向量包括:  In a fifth possible implementation, in combination with the second aspect or the first to fourth possible implementation manners of the second aspect, the generating, by the HSS, the special authentication vector after receiving the request of the SGSN includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
在第六种可能的实现方式中, 结合第二方面第五种可能的实现方式, 该 In a sixth possible implementation, in combination with the fifth possible implementation of the second aspect,
HSS将该 EPS AV转换成 UMTS AV格式包括: The HSS converts the EPS AV into the UMTS AV format including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
在第七种可能的实现方式中, 结合第二方面的第二种至第六种任一可能 的实现方式, 该接入网网元根据该 CK和或 IK生成 KASME包括: 该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该In a seventh possible implementation, combining any of the second to sixth aspects of the second aspect The implementation manner, the access network element generating the K ASME according to the CK and or IK includes: the access network element is generated according to the CK and or IK according to the generation rule K ASME =CKIIIK
KASME。 KASME.
第三方面, 提供了一种移动通信系统的安全认证方法, 包括:  In a third aspect, a method for secure authentication of a mobile communication system is provided, including:
接入网网元将来自于 LTE UE的 attach request消息转换为 UMTS attach request消息;  The access network element converts the attach request message from the LTE UE into a UMTS attach request message;
该接入网网元将该 UMTS attach request消息发送给 SGSN,以便该 SGSN 向 HSS发送要求认证向量的请求, 该 HSS收到该 SGSN的该请求后识别是 该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成特殊认证向量;  The access network element sends the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN to identify that the LTE UE accesses the 2G or 3G network. In order for the HSS to generate a special authentication vector;
该接入网网元接收该 SGSN发送的 UMTS AKA认证挑战,该 UMTS AKA 认证挑战为该 SGSN收到该 HSS发送的该特殊认证向量后发送;  The access network element receives the UMTS AKA authentication challenge sent by the SGSN, and the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发 送给该 LTE UE, 以便该接入网网元、 该 SGSN和该 LTE UE完成安全认证。  The access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the challenge to the LTE UE, so that the access network element, the SGSN, and the LTE UE complete the security authentication.
在第一种可能的实现方式中, 该以便接入网网元、该 SGSN和该 LTE UE 完成安全认证包括:  In a first possible implementation, the accessing the network element, the SGSN, and the LTE UE to complete the security authentication includes:
该 LTE UE验证该 LTE AKA认证挑战后生成 RES和密钥 KASME; After the LTE UE verifies the LTE AKA authentication challenge, the RES and the key K ASME are generated;
该接入网网元接收该 LTE UE发送的包含该 RES的 LTE AKA认证响应, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。  The access network element receives the LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
在第二种可能的实现方式中,结合第三方面或第三方面的第一种可能的实 现方式, 该特殊认证向量包含 XRES、 CK和 IK;  In a second possible implementation manner, in combination with the third aspect or the first possible implementation manner of the third aspect, the special authentication vector includes XRES, CK, and IK;
该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证包括: 该接入网网元将包含该 RES的 LTE AKA认证响应转换为包含该 RES的 UMTS AKA认证响应,该接入网网元将该包含该 RES的 UMTS AKA认证响 应发送给该 SGSN, 以便该 SGSN比较该 RES和该 XRES是否相同, 当该比 较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入网网元;  The LTE AKA authentication response including the RES is converted into a UMTS AKA authentication response including the RES, where the access network element, the SGSN, and the LTE UE further perform security authentication, the access network element: The network element sends the UMTS AKA authentication response including the RES to the SGSN, so that the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the SGSN. Network access network element;
该接入网网元根据该 CK和或 IK生成 KASME,该接入网网元和该 LTE UE 共早该 KASME ° The access network element generates K ASME according to the CK and or IK, the access network element and the LTE UE A total of KASME °
在第三种可能的实现方式中, 结合第三方面的第二种可能的实现方式, 该 SGSN比较该 RES和该 XRES是否相同还包括,当该比较结果为不相同时, 中止进行安全认证。  In a third possible implementation manner, in combination with the second possible implementation manner of the third aspect, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
在第四种可能的实现方式中, 结合第三方面或第三方面的第一至第三任 一种可能的实现方式, 该 HSS收到该 SGSN的该请求后识别是该 LTE UE接 入 2G或 3G网络包括:  In a fourth possible implementation, in combination with the third aspect or the first to the third possible implementation manners of the third aspect, the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G. Or 3G networks include:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
在第五种可能的实现方式中, 结合第三方面或第三方面的第一至第四任 一种可能的实现方式, 该进而以便该 HSS生成特殊认证向量包括:  In a fifth possible implementation, in combination with the third aspect or the first to the fourth possible implementation manners of the third aspect, the generating, by the HSS, the special authentication vector includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量; 该 HSS为该 LTE UE生成 EPS AV ;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to instruct the HSS to generate the special authentication vector; the HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
在第六种可能的实现方式中, 结合第三方面的第五种可能的实现方式, 该 HSS将该 EPS AV转换成 UMTS AV格式包括:  In a sixth possible implementation manner, in combination with the fifth possible implementation manner of the third aspect, the HSS converting the EPS AV into the UMTS AV format includes:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN , 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
在第七种可能的实现方式中, 结合第三方面的第二至第六任一种可能的 实现方式, 该接入网网元根据该 CK和或 ΙΚ生成 KASME包括: In a seventh possible implementation, in combination with the second to the sixth possible implementation manners of the third aspect, the access network element generating the K ASME according to the CK and or the 包括 includes:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该 KASME。 The access network element generates the base according to the CK and or IK according to the generation rule K ASME =CKIIIK KASME.
第四方面, 提供了一种 HSS , 包括: 接收模块, 识别模块, 处理模块, 发送模块;  In a fourth aspect, an HSS is provided, including: a receiving module, an identifying module, a processing module, and a sending module;
该接收模块用于接收 SGSN发送的要求认证向量的请求, 该要求认证向 量的请求由该 SGSN在接收到接入网网元发送的 UMTS attach request消息后 发送给该 SGSN, 该识别模块用于在该接收模块接收该要求认证向量的请求 后识别出是 LTE UE接入 2G或 3G网络;  The receiving module is configured to receive a request for an authentication vector sent by the SGSN, where the request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request message sent by the access network element, where the identifying module is used to Receiving the request for the authentication vector, the receiving module identifies that the LTE UE accesses the 2G or 3G network;
该处理模块用于在该识别模块识别出是 LTE UE接入 2G或 3G网络后生 成特殊认证向量;  The processing module is configured to generate a special authentication vector after the identification module identifies that the LTE UE accesses the 2G or 3G network;
该发送模块用于将该特殊认证向量发送给该 SGSN , 以便该 SGSN、该接 入网网元和该 LTE UE完成安全认证。  The sending module is configured to send the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
在第一种可能的实现方式中, 该 UMTS attach request消息是该接入网网 元将 attach request消息转换所得, 该 attach request消息由该 LTE UE发送。  In a first possible implementation, the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
在第二种可能的实现方式中, 结合第四方面或第四方面的第一种可能的 实现方式, 该以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证包括: 该 SGSN发送 UMTS AKA认证挑战给该接入网网元, 该接入网网元将 该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给该 LTE UE, 该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该接入网网元, 以便 该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 In a second possible implementation, in combination with the fourth aspect or the first possible implementation manner of the fourth aspect, the SGSN, the access network element, and the LTE UE completing the security authentication include: sending, by the SGSN The UMTS AKA authentication challenge is performed to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge, and then sends the LTE UE to the LTE UE, and the LTE UE performs verification and generates according to the LTE AKA authentication challenge. After the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
在第三种可能的实现方式中, 结合第四方面或第四方面的第一种至第二 种可能的实现方式, 该特殊认证向量中包含 XRES、 CK、 IK;  In a third possible implementation, in combination with the fourth aspect or the first to the second possible implementation manner of the fourth aspect, the special authentication vector includes XRES, CK, and IK;
该以便该接入网网元、该 SGSN和该 LTE UE进一步完成安全认证包括: 该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME, 该接入网网元和该 LTE UE共享该 KASMEAnd the SG AKA authentication response is converted into a UMTS The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access. The network element, the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
在第四种可能的实现方式中, 第四方面的第三种可能的实现方式, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结果为不相同时, 中止进行安全认证。  In a fourth possible implementation manner, the third possible implementation manner of the fourth aspect, the SGSN comparing whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
在第五种可能的实现方式中, 结合第四方面或第四方面的第一至第四任 一种可能的实现方式, 该 HSS还包括存储模块, 该存储模块用于存储一个列 表, 该列表包括通过接入 2G/3G网络的 LTE UE的标识信息;  In a fifth possible implementation, in combination with the fourth or fourth possible implementation of the fourth aspect, the HSS further includes a storage module, where the storage module is configured to store a list, the list Including identification information of an LTE UE that accesses a 2G/3G network;
该识别模块根据该列表中的该标识信息, 获知该 LTE UE的标识信息包 含在该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The identification module, according to the identification information in the list, knows that the identifier information of the LTE UE is included in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
在第六种可能的实现方式中, 结合第四方面或第四方面的第一至第五任 一种可能的实现方式, 该处理模块用于在该识别模块识别出是 LTE UE接入 2G或 3G网络后生成特殊认证向量包括:  In a sixth possible implementation, the processing module is configured to identify, by the identification module, that the LTE UE accesses the 2G or the fourth aspect, or the first to the fifth possible implementation manner of the fourth aspect, Generating special authentication vectors after the 3G network includes:
该处理模块用于在该要求认证向量的请求中增加指示信息, 该指示信息 用于指示该 HSS生成该特殊认证向量; 该处理模块用于为该 LTE UE生成 EPS AV;  The processing module is configured to add indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector; the processing module is configured to generate an EPS AV for the LTE UE;
该处理模块用于将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式的 EPS AV为该特殊认证向量。  The processing module is configured to convert the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
在第七种可能的实现方式中, 第四方面的第六种可能的实现方式, 该处 理模块用于将该 EPS AV转换成 UMTS AV格式包括:  In a seventh possible implementation manner, the sixth possible implementation manner of the fourth aspect, the processing module is configured to convert the EPS AV into the UMTS AV format, including:
该处理模块用于将该 EPS AV中的 RAND作为该 UMTS AV的 RAND, 该处理模块用于将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该处 理模块用于将该 EPS AV中的 XRES作为该 UMTS AV的 XRES , 该处理模 块用于将该 EPS AV中的 KASME拆分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The processing module is configured to use RAND in the EPS AV as the RAND of the UMTS AV, and the processing module is configured to use the AUTN in the EPS AV as the AUTN of the UMTS AV, and the processing module is used to use the XRES in the EPS AV As the XRES of the UMTS AV, the processing module is configured to split the K ASME in the EPS AV into two parts, respectively, as the CK and the IK of the UMTS AV.
在第八种可能的实现方式中, 结合第四方面的第三至第七任一种可能的 实现方式, 该接入网网元根据该 CK和或 IK生成 KASME包括: In an eighth possible implementation, combining any of the third to seventh aspects of the fourth aspect In an implementation manner, the access network element generates a K ASME according to the CK and or IK, including:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该The access network element generates the base according to the CK and or IK according to the generation rule K ASME =CKIIIK
KASME。 KASME.
第五方面, 提供了一种 SGSN, 包括: 接收模块; 发送模块;  In a fifth aspect, an SGSN is provided, including: a receiving module; a sending module;
该接收模块用于接收接入网网元发送的 UMTS attach request消息, 该 The receiving module is configured to receive a UMTS attach request message sent by an access network element, where the
UMTS attach request是该接入网网元将 LTE UE发送的 attach request消息转 换所得; The UMTS attach request is obtained by converting, by the access network element, the attach request message sent by the LTE UE;
该发送模块用于在该接收模块接收到该 UMTS attach request消息后, 向 HSS发送要求认证向量的请求, 以便该 HSS收到该请求后识别是该 LTE UE 接入 2G或 3G网络, 进而以便该 HSS生成该特殊认证向量;  The sending module is configured to send a request for an authentication vector to the HSS after the receiving module receives the UMTS attach request message, so that the HSS receives the request and identifies that the LTE UE accesses the 2G or 3G network, and thus The HSS generates the special authentication vector;
该接收模块还用于接收来自于该 HSS的该特殊认证向量, 该发送模块还 用于在该接收模块接收到该特殊认证向量后发送 UMTS AKA认证挑战给该 接入网网元, 以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证。  The receiving module is further configured to receive the special authentication vector from the HSS, where the sending module is further configured to send a UMTS AKA authentication challenge to the access network element after the receiving module receives the special authentication vector, so that the SGSN The access network element and the LTE UE complete the security authentication.
在第一种可能的实现方式中, 该以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证包括:  In a first possible implementation, the SGSN, the access network element, and the LTE UE complete the security authentication, including:
该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发 送给该 LTE UE,该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES 和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该 接入网网元, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证。 After the UMTS AKA authentication challenge is converted into an LTE AKA authentication challenge, the access network element is sent to the LTE UE, and after the LTE UE performs verification according to the LTE AKA authentication challenge and generates a RES and a key K ASME , the LTE UE will The LTE AKA authentication response including the RES is sent to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
在第二种可能的实现方式中, 结合第五方面或第五方面的第一种可能的 实现方式, 该 SGSN还包括处理模块;  In a second possible implementation manner, in combination with the fifth aspect or the first possible implementation manner of the fifth aspect, the SGSN further includes a processing module;
该特殊认证向量包含 XRES、 CK、 IK;  The special authentication vector contains XRES, CK, IK;
该以便该接入网网元、该 SGSN和该 LTE UE进一步完成安全认证包括: 该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该接收模块, 该处理模块用于比较该 RES和 该 XRES是否相同, 当该比较结果为相同时, 该发送模块将该 CK和或 IK发 送给该接入网网元, 该接入网网元才艮据该 CK和或 IK生成 KASME , 该 CK和 或 IK由该发送模块发送, 该接入网网元和该 LTE UE共享该 KASMEThe further completing the security authentication for the access network element, the SGSN, and the LTE UE includes: the access network element converting the LTE AKA authentication response into a UMTS AKA authentication response and transmitting the UMTS AKA authentication response to the receiving Module, the processing module is used to compare the RES and Whether the XRES is the same. When the comparison result is the same, the sending module sends the CK and or IK to the access network element, and the access network element generates the K ASME according to the CK and or IK. CK and or IK are sent by the sending module, and the access network element and the LTE UE share the K ASME .
在第三种可能的实现方式中, 结第五方面的第二种可能的实现方式, 该 处理模块用于比较该 RES和该 XRES是否相同还包括, 当该比较结果为不相 同时, 中止进行安全认证。  In a third possible implementation manner, the second possible implementation manner of the fifth aspect, the processing module is configured to compare whether the RES and the XRES are the same, and further includes: when the comparison result is different, the suspension is performed. safety certificate.
在第四种可能的实现方式中, 结合第五方面或第五方面的第一种至第三 种任一可能的实现方式, 该以便该 HSS收到该请求后识别是该 LTE UE接入 2G或 3G网络包括:  In a fourth possible implementation, in combination with the fifth aspect or any one of the first to third possible implementation manners of the fifth aspect, the HSS is configured to identify that the LTE UE accesses the 2G after receiving the request. Or 3G networks include:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
在第五种可能的实现方式中, 结合第五方面或第五方面的第一种至第四 种可能的实现方式, 该以便该 HSS生成该特殊认证向量包括:  In a fifth possible implementation, in combination with the first to fourth possible implementation manners of the fifth aspect or the fifth aspect, the generating, by the HSS, the special authentication vector includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量; 该 HSS为该 LTE UE生成 EPS AV;  The HSS adds indication information to the request for the authentication vector, the indication information is used to indicate that the HSS generates the special authentication vector; the HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
在第六种可能的实现方式中, 结合第五方面第五种可能的实现方式, 该 In a sixth possible implementation manner, in combination with the fifth possible implementation manner of the fifth aspect,
HSS将该 EPS AV转换成 UMTS AV格式包括: The HSS converts the EPS AV into the UMTS AV format including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
在第七种可能的实现方式中, 结合第五方面的第二种至第六种任一可能 的实现方式, 该接入网网元根据该 CK和或 IK生成 KASME包括: 该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该In a seventh possible implementation, combining any of the second to sixth aspects of the fifth aspect The implementation manner, the access network element generating the K ASME according to the CK and or IK includes: the access network element is generated according to the CK and or IK according to the generation rule K ASME =CKIIIK
KASME。 KASME.
第六方面, 提供了一种接入网网元, 包括: 接收模块, 处理模块, 发送 模块;  A sixth aspect provides an access network element, including: a receiving module, a processing module, and a sending module;
该接收模块用于接收来自 LTE UE的 attach request消息; 该处理模块用 于将该 attach request消息转换为 UMTS attach request消息;  The receiving module is configured to receive an attach request message from an LTE UE; the processing module is configured to convert the attach request message into a UMTS attach request message;
该发送模块用于将该 UMTS attach request消息发送给 SGSN, 以便该 SGSN向 HSS发送要求认证向量的请求,该 HSS收到该 SGSN的该请求后识 别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成特殊认证向量; 该接收模块还用于接收该 SGSN发送的 UMTS AKA认证挑战,该 UMTS AKA认证挑战为该 SGSN收到该 HSS发送的该特殊认证向量后发送;  The sending module is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and after receiving the request of the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, and further The receiving module is further configured to receive a UMTS AKA authentication challenge sent by the SGSN, where the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
该处理模块还用于将该 UMTS AKA认证挑战转换成 LTE AKA认证挑 战, 该发送模块还用于将该 LTE AKA认证挑战发送给该 LTE UE, 以便该接 入网网元、 该 SGSN和该 LTE UE完成安全认证。  The processing module is further configured to convert the UMTS AKA authentication challenge into an LTE AKA authentication challenge, where the sending module is further configured to send the LTE AKA authentication challenge to the LTE UE, so that the access network element, the SGSN, and the LTE are The UE completes the security certification.
在第一种可能的实现方式中, 该以便该接入网网元、 该 SGSN和该 LTE UE完成安全认证包括:  In a first possible implementation manner, the security authentication of the access network element, the SGSN, and the LTE UE is performed by:
该 LTE UE验证该 LTE AKA认证挑战后生成 RES和密钥 KASME; After the LTE UE verifies the LTE AKA authentication challenge, the RES and the key K ASME are generated;
该接收模块用于接收该 LTE UE发送的包含该 RES的 LTE AKA认证响 应, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。  The receiving module is configured to receive an LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete security authentication.
在第二种可能的实现方式中,结合第六方面或第六方面的第一种可能的实 现方式, 该特殊认证向量包含 XRES、 CK和 IK;  In a second possible implementation manner, in combination with the sixth aspect or the first possible implementation manner of the sixth aspect, the special authentication vector includes XRES, CK, and IK;
该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证包括: 该处理模块还用于将包含该 RES的 LTE AKA认证响应转换为包含该 RES的 UMTS AKA认证响应, 该发送模块还用于将该包含该 RES的 UMTS AKA认证响应发送给该 SGSN , 以便该 SGSN比较该 RES和该 XRES是否 相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入网网 元; The processing module is further configured to convert the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, where the sending module further comprises: the processing module further configured to: Also used to send the UMTS AKA authentication response containing the RES to the SGSN, so that the SGSN compares the RES and the XRES Similarly, when the comparison result is the same, the SGSN sends the CK and or IK to the access network element;
该处理模块还用于根据该 CK和或 IK生成 KASME ,该接入网网元和该 LTE UE共早该 KASME。 The processing module is further configured to generate a K ASME according to the CK and or IK, the access network element and the LTE UE being the KASME.
在第三种可能的实现方式中, 结合第六方面的第二种可能的实现方式, 该 SGSN比较该 RES和该 XRES是否相同还包括,当该比较结果为不相同时, 中止进行安全认证。  In a third possible implementation manner, in combination with the second possible implementation manner of the sixth aspect, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
在第四种可能的实现方式中, 结合第六方面或第六方面的第一至第三任 一种可能的实现方式, 该 HSS收到该 SGSN的该请求后识别是该 LTE UE接 入 2G或 3G网络包括:  In a fourth possible implementation manner, in combination with the first to third possible implementation manners of the sixth aspect or the sixth aspect, the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G. Or 3G networks include:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
在第五种可能的实现方式中, 结合第六方面或第六方面的第一至第四任 一种可能的实现方式, 该进而以便该 HSS生成特殊认证向量包括:  In a fifth possible implementation, in combination with the first to fourth possible implementation manners of the sixth aspect or the sixth aspect, the generating, by the HSS, the special authentication vector includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV ;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
在第六种可能的实现方式中, 结合第六方面的第五种可能的实现方式, 该 HSS将该 EPS AV转换成 UMTS AV格式包括:  In a sixth possible implementation manner, in combination with the fifth possible implementation manner of the sixth aspect, the HSS converting the EPS AV into the UMTS AV format includes:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN , 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME ( 256bits ) 拆分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS K ASME in the EPS AV (256bits) Split into two parts, respectively as the CK and the IK of the UMTS AV.
在第七种可能的实现方式中, 结合第六方面的第二至第六任一种可能的 实现方式, 该处理模块进一步用于按照生成规则 KASME=CKIIIK , 根据该 CK 和或 IK生成该 KASMEIn a seventh possible implementation, in combination with the second to the sixth possible implementation manners of the sixth aspect, the processing module is further configured to generate the according to the CK and or IK according to the generation rule K ASME =CKIIIK K ASME .
通过上述方案, HSS识别是 LTE UE接入 2G/3G网络, HSS生成特殊认证向量, 通过 SGSN、接入网网元,使 LTE UE接入 2G/3G网络完成安全认证, 以便 LTE UE 可以使用 2G/3G核心网资源。 附图说明  Through the above scheme, the HSS identifies that the LTE UE accesses the 2G/3G network, and the HSS generates a special authentication vector, and the LTE UE accesses the 2G/3G network to complete the security authentication through the SGSN and the access network element, so that the LTE UE can use the 2G. /3G core network resources. DRAWINGS
为了更清楚地说明本发明实施例的技术方案, 下面将对本发明实施例中所 需要使用的附图作筒单地介绍, 显而易见地, 下面描述中的附图仅仅是本发明 的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动的前提下, 还可以根据这些附图获得其他的附图。  In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings to be used in the embodiments of the present invention will be briefly described. It is obvious that the drawings in the following description are only some embodiments of the present invention. Other drawings may also be obtained from those of ordinary skill in the art in view of the drawings.
图 1是根据本发明实施例的移动通信系统的认证方法的示意性流程图; 图 2 是根据本发明另一实施例的移动通信系统的认证方法的示意图流程 图;  1 is a schematic flowchart of an authentication method of a mobile communication system according to an embodiment of the present invention; FIG. 2 is a schematic flowchart of an authentication method of a mobile communication system according to another embodiment of the present invention;
图 3 是根据本发明另一实施例的移动通信系统的认证方法的示意性流程 图;  3 is a schematic flow chart of an authentication method of a mobile communication system according to another embodiment of the present invention;
图 4 是根据本发明另一实施例的移动通信系统的认证方法的示意性流程 图;  4 is a schematic flow chart of an authentication method of a mobile communication system according to another embodiment of the present invention;
图 5是根据本发明实施例的归属用户服务器的示意性框图;  FIG. 5 is a schematic block diagram of a home subscriber server according to an embodiment of the present invention; FIG.
图 6是根据本发明实施例的 GPRS服务支撑节点的示意性框图;  6 is a schematic block diagram of a GPRS service support node according to an embodiment of the present invention;
图 7是根据本发明实施例的接入网网元的示意性框图;  7 is a schematic block diagram of an access network element according to an embodiment of the present invention;
图 8是根据本发明另一实施例的归属用户服务器的示意性框图;  FIG. 8 is a schematic block diagram of a home subscriber server according to another embodiment of the present invention; FIG.
图 9是根据本发明另一实施例的 GPRS服务支撑节点的示意性框图; 图 10是根据本发明另一实施例的接入网网元的示意性框图。 具体实施方式 9 is a schematic block diagram of a GPRS service support node according to another embodiment of the present invention; and FIG. 10 is a schematic block diagram of an access network element according to another embodiment of the present invention. detailed description
下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案进行清 楚、 完整地描述, 显然, 所描述的实施例是本发明的一部分实施例, 而不是全 部实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作出创造性劳 动的前提下所获得的所有其他实施例, 都应属于本发明保护的范围。  BRIEF DESCRIPTION OF THE DRAWINGS The technical solutions in the embodiments of the present invention will be described in detail below with reference to the accompanying drawings in the embodiments of the present invention. It is obvious that the described embodiments are a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of the present invention.
应理解, 本发明实施例的技术方案可以应用于各种 2G或 3G通信系统, 例 如: 全球移动通讯( Global System of Mobile communication, 筒称为 "GSM" ) 系统、 码分多址(Code Division Multiple Access , 筒称为 "CDMA" ) 系统、 宽 带码分多址( Wideband Code Division Multiple Access , 筒称为 "WCDMA" ) 系 统、 通用分组无线业务(General Packet Radio Service, 筒称为 "GPRS" )、 通用 移动通信系统 ( Universal Mobile Telecommunication System, 筒称为 "UMTS" )、 全球互联微波接入 ( Worldwide Interoperability for Microwave Access , 筒称为 "WiMAX" )通信系统等。  It should be understood that the technical solution of the embodiments of the present invention can be applied to various 2G or 3G communication systems, for example: Global System of Mobile communication ("GSM") system, code division multiple access (Code Division Multiple) Access, called "CDMA" system, Wideband Code Division Multiple Access ("WCDMA") system, General Packet Radio Service (General Packet Radio Service) Universal Mobile Telecommunication System (UMT), Worldwide Interoperability for Microwave Access ("Wireless") communication system, etc.
本发明实施例中的接入网网元, 是一种增强的接入网网元, 用于支持 LTE UE接入 2G/3G核心网。在发明所有实施例中,接入网网元可具备如下功能: LTE eNB的功能, LTE UE可以不需要进行修改通过该接入网网元接入 2G/3G核心网, 而且使 LTE UE认为其正在接入的是 LTE网络, 而不是 2G/3G核心网; 本发明 实施例中的接入网网元还可以实现部分移动性管理实体( Mobility Management Entity , 筒称为 "ΜΜΕ" ) 的功能, 如对非接入层( Non- Access Stratum, 筒称 为 "NAS" )信令的安全保护功能。  The access network element in the embodiment of the present invention is an enhanced access network element for supporting the LTE UE to access the 2G/3G core network. In all the embodiments of the present invention, the access network element may have the following functions: The function of the LTE eNB, the LTE UE may access the 2G/3G core network through the access network element without modification, and the LTE UE considers that The LTE network is being accessed, instead of the 2G/3G core network; the access network element in the embodiment of the present invention can also implement the function of a Mobility Management Entity (called "ΜΜΕ"). Such as the security protection function of the non-access stratum ("Non-Access Stratum").
图 1示出了根据本发明实施例的移动通信系统的安全认证的方法 100的示 意性流程图。 如图 1所示, 该方法 100包括:  1 shows a schematic flow diagram of a method 100 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention. As shown in FIG. 1, the method 100 includes:
S110 , HSS接收 SGSN发送的要求认证向量的请求后, 该 HSS识别是 S110. After receiving the request for the authentication vector sent by the SGSN, the HSS identifies that the HSS is
LTE UE接入 2G或 3G网络, 该要求认证向量的请求由该 SGSN在接收到接 入网网元发送的 UMTS attach request消息后发送给该 SGSN; The LTE UE accesses the 2G or 3G network, and the request for the authentication vector is received by the SGSN. Sending the UMTS attach request message sent by the network element to the SGSN;
SI 20 , 该 HSS识别出是 LTE UE接入 2G或 3G网络后, 该 HSS生成特 殊认证向量;  SI 20, the HSS recognizes that after the LTE UE accesses the 2G or 3G network, the HSS generates a special authentication vector;
该 HSS将该特殊认证向量发送给该 SGSN , 以便该 SGSN、 该接入网网 元和该 LTE UE完成安全认证。  The HSS sends the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
在本发明实施例中, 为了使 LTE UE能够使用 2G或 3G核心网, 在 HSS 识别出是 LTE UE接入 2G/3G核心网后, HSS为该 LTE UE生成特殊认证向量, 以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证使得 LTE UE接入 2G或 3G网络, 以便使 LTE UE可以使用 2G或 3G核心网资源。  In the embodiment of the present invention, in order to enable the LTE UE to use the 2G or 3G core network, after the HSS recognizes that the LTE UE accesses the 2G/3G core network, the HSS generates a special authentication vector for the LTE UE, so that the SGSN, the SGSN, The access network element and the LTE UE complete the security authentication to enable the LTE UE to access the 2G or 3G network, so that the LTE UE can use the 2G or 3G core network resources.
可选地, 该 UMTS attach request消息是该接入网网元将 attach request消 息转换所得, 该 attach request消息由该 LTE UE发送。  Optionally, the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
可选地,该以便该 SGSN、该接入网网元和该 LTE UE完成安全认证包括: 该 SGSN发送 UMTS AKA认证挑战给该接入网网元, 该接入网网元将 该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给该 LTE UE, 该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该接入网网元, 以便 该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 Optionally, the SGSN, the access network element, and the LTE UE complete the security authentication, where the SGSN sends a UMTS AKA authentication challenge to the access network element, and the access network element authenticates the UMTS AKA. After the challenge is converted into an LTE AKA authentication challenge, and sent to the LTE UE, after the LTE UE performs verification according to the LTE AKA authentication challenge and generates a RES and a key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the LTE AKA authentication challenge. Accessing the network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
可选地, 该特殊认证向量中包含 XRES、 CK、 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全 认证包括:  Optionally, the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME, 该接入网网元和该The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, and the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the The SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, the access network element and the
LTE UE共享该 KASMEThe LTE UE shares the K ASME .
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。 Optionally, the SGSN compares whether the RES and the XRES are the same, and includes, when the comparison is If the results are different, the safety certification is suspended.
可选地, 该 HSS识别是 LTE UE接入 2G或 3G网络包括:  Optionally, the HSS identification is that the LTE UE accesses the 2G or 3G network, including:
该 HSS配备一个列表,该列表包括通过接入 2G/3G网络的 LTE UE的标 识信息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
可选地, 该 HSS生成特殊认证向量包括:  Optionally, the HSS generates a special authentication vector including:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括:  Optionally, the HSS converts the EPS AV into a UMTS AV format, including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN , 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
可选地, 该接入网网元才艮据该 CK和或 ΙΚ生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or the 包括:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该 KASME。 The access network element generates the K A SME according to the CK and or IK according to the generation rule K ASME =CKIIIK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 核心网的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以 完成安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, the message sent by the LTE UE is converted into a message applicable to the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G core through the access network element. After the scenario of the network, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 2示出了根据本发明实施例的移动通信系统的安全认证的方法 200的示 意性流程图。 图 2及其说明所揭示的方法, 可基于本发明实施例图 1和基于本 发明实施例图 1所揭示的方法。 如图 2所示, 该方法 200包括: 2 shows an illustration of a method 200 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention. Intentional flow chart. 2 and its description of the disclosed method may be based on the embodiment of the present invention and the method disclosed in FIG. 1 based on an embodiment of the present invention. As shown in FIG. 2, the method 200 includes:
S210 , SGSN接收接入网网元发送 UMTS attach request消息, 该 UMTS attach request是该接入网网元将 LTE UE发送的 attach request消息转换所得; S220 , 该 SGSN接收到由该接入网网元发送的该 UMTS attach request消 息后, 该 SGSN向 HSS发送要求认证向量的请求,以便该 HSS收到该 SGSN 的该请求后识别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成该 特殊认证向量;  S210, the SGSN receives the UMTS attach request message, where the UMTS attach request is that the access network element converts the attach request message sent by the LTE UE, and S220, the SGSN receives the access network element by the access network. After the UMTS attach request message is sent, the SGSN sends a request for the authentication vector to the HSS, so that the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G or 3G network, so that the HSS generates the special Authentication vector
S230,该 SGSN接收来自于该 HSS的该特殊认证向量后,发送 UMTS AKA 认证挑战给该接入网网元, 以便该 SGSN、 该接入网网元和该 LTE UE完成 安全认证。  S230. After receiving the special authentication vector from the HSS, the SGSN sends a UMTS AKA authentication challenge to the access network element, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
在本发明实施例中,通过 HSS识别出 LTE UE接入 2G或 3G网络的场景后, HSS生成特殊认证向量, 使 SGSN、 接入网网元和该 LTE UE完成安全认证, 实现不需要对 LTEUE进行修改的条件下 LTE UE可以完成安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, after the scenario in which the LTE UE accesses the 2G or 3G network is identified by the HSS, the HSS generates a special authentication vector, so that the SGSN, the access network element, and the LTE UE complete the security authentication, and the implementation does not require the LTE UE. Under the condition that the LTE UE can perform security authentication, the LTE UE can access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
可选地,该以便该 SGSN、该接入网网元和该 LTE UE完成安全认证包括: 该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发 送给该 LTE UE,该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES 和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该 接入网网元, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证。 Optionally, the SGSN, the access network element, and the LTE UE complete the security authentication, where the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE. After the LTE UE performs the verification according to the LTE AKA authentication challenge and generates the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the The SGSN and the LTE UE further complete the security authentication.
可选地, 该特殊认证向量包含 XRES、 CK、 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全 认证包括:  Optionally, the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME , 该接入网网元和该 LTE UE共享该 KASMEThe access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, the SGSN comparing the RES with the XRES Whether the same is true, when the comparison result is the same, the SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, the access network element The K ASME is shared with the LTE UE.
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。  Optionally, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
可选地, 该以便该 HSS收到该 SGSN的该请求后识别是该 LTE UE接入 2G或 3G网络包括:  Optionally, the method for the HSS to receive the request of the SGSN is that the LTE UE accesses the 2G or 3G network, including:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
可选地, 该以便该 HSS收到该 SGSN的该请求后生成该特殊认证向量包 括:  Optionally, the special authentication vector is generated after the HSS receives the request from the SGSN, including:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV ;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括:  Optionally, the HSS converts the EPS AV into a UMTS AV format, including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN , 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
可选地, 该接入网网元才艮据该 CK和或 ΙΚ生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or the 包括:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该The access network element generates the base according to the CK and or IK according to the generation rule K ASME =CKIIIK
KASME。 本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, LTE UE可以完成安全 认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。 KASME. In the embodiment of the present invention, the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element. After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, and the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 3示出了根据本发明实施例的移动通信系统的安全认证的方法 300的示 意性流程图。 图 3及其说明所揭示的方法, 可基于本发明实施例图 1至图 2以 及基于本发明实施例图 1至图 2所揭示的方法。 如图 3所示, 该方法 300包括: 3 shows a schematic flow diagram of a method 300 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention. The method disclosed in Figure 3 and its description may be based on the embodiments of Figures 1 through 2 of the present invention and the methods disclosed in Figures 1 through 2 of the present invention. As shown in FIG. 3, the method 300 includes:
S310 , 接入网网元将来自于 LTE UE的 attach request消息转换为 UMTS attach request消息; S310. The access network element converts an attach request message from the LTE UE into a UMTS attach request message.
S320 , 该接入网网元将该 UMTS attach request消息发送给 SGSN, 以便 该 SGSN向 HSS发送要求认证向量的请求, 该 HSS收到该 SGSN的该请求 后识别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成特殊认证向 量;  S320, the access network element sends the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN and identifies that the LTE UE accesses the 2G or 3G. Network, in order for the HSS to generate a special authentication vector;
S330,该接入网网元接收该 SGSN发送的 UMTS AKA认证挑战,该 UMTS S330. The access network element receives the UMTS AKA authentication challenge sent by the SGSN, where the UMTS
AKA认证挑战为该 SGSN收到该 HSS发送的该特殊认证向量后发送; The AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
S340 ,该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑 战后发送给该 LTE UE, 以便该接入网网元、 该 SGSN和该 LTE UE完成安 全认证。  S340. The access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE, so that the access network element, the SGSN, and the LTE UE complete the security authentication.
在本发明实施例中, 通过接入网网元将 LTE UE发送的信息转换为适用于 In the embodiment of the present invention, the information sent by the LTE UE is converted to be applicable to the network element of the access network.
2G或 3G网络系统的信息,由 HSS识别出为 LTE UE接入 2G或 3G网络的场景, 通过 HSS生成特殊的认证向量, 使接入网网元、 SGSN和 LTE UE能够完成安 全认证, 使 LTE UE可以完成安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。 The information of the 2G or 3G network system is identified by the HSS as the LTE UE accessing the 2G or 3G network. The HSS generates a special authentication vector to enable the access network element, the SGSN, and the LTE UE to complete the security authentication. The UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
可选地, 该以便接入网网元、 该 SGSN和该 LTE UE完成安全认证包括: 该 LTE UE验证该 LTE AKA认证挑战后生成 RES和密钥 KASME; 该接入网网元接收该 LTE UE发送的包含该 RES的 LTE AKA认证响应, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 Optionally, the accessing the network element, the SGSN, and the LTE UE to complete the security authentication includes: generating, by the LTE UE, the RES and the key K ASME after verifying the LTE AKA authentication challenge; The access network element receives the LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete the security authentication.
可选地, 该特殊认证向量包含 XRES、 CK和 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证包括:  Optionally, the access network element, the SGSN, and the LTE UE further complete the security authentication, including:
该接入网网元将包含该 RES的 LTE AKA认证响应转换为包含该 RES的 UMTS AKA认证响应,该接入网网元将该包含该 RES的 UMTS AKA认证响 应发送给该 SGSN , 以便该 SGSN比较该 RES和该 XRES是否相同, 当该比 较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入网网元;  The access network element converts the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, and the access network element sends the UMTS AKA authentication response including the RES to the SGSN, so that the SGSN Comparing whether the RES and the XRES are the same, when the comparison result is the same, the SGSN sends the CK and or IK to the access network element;
该接入网网元才艮据该 CK和或 IK生成 KASME ,该接入网网元和该 LTE UE 共早该 KASME ° The access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE jointly have the KASME °
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。  Optionally, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
可选地, 该 HSS收到该 SGSN的该请求后识别是该 LTE UE接入 2G或 3G网络包括:  Optionally, after receiving the request of the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, including:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
可选地, 该进而以便该 HSS生成特殊认证向量包括:  Optionally, the further generating the special authentication vector for the HSS comprises:
该 HSS在该要求认证向量的请求中增加指示信息,该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV ;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括: 该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 Optionally, the HSS converts the EPS AV into a UMTS AV format including: The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
可选地, 该接入网网元才艮据该 CK和或 ΙΚ生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or the 包括:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该 KASME。 The access network element generates the KASME according to the CK and or IK according to the generation rule K ASME =CKIIIK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使 LTE UE可以完成安 全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element. After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 4示出了根据本发明实施例的移动通信系统的安全认证的方法 400的示 意性流程图。 本发明实施例图 1至图 3和基于本发明实施例图 1至图 3所揭示 图 3和基于本发明实施例图 1至图 3所揭示的方法可参考图 4及其说明所揭示 的方法。 如图 4所示, 该方法 400包括:  4 shows a schematic flow diagram of a method 400 of secure authentication of a mobile communication system in accordance with an embodiment of the present invention. FIG. 1 to FIG. 3 and the method disclosed in FIG. 3 and FIG. 3 based on the embodiment of the present invention, and the method disclosed in FIG. 4 and FIG. . As shown in FIG. 4, the method 400 includes:
可选地, LTE UE通过接入网网元接入到 2G/3G核心网, LTE UE和接入网 网元之间建立 RRC连接。  Optionally, the LTE UE accesses the 2G/3G core network through the access network element, and an RRC connection is established between the LTE UE and the access network element.
LTE UE发送 attach request消息给接入网网元, 接入网网元将从 LTE UE处 收到的该 attach request消息转换为 UMTS系统中 2G/3G核心网 SGSN可识别的 UMTS attach request消息,接入网网元将转换后的 UMTS attach request消息发送 给 SGSN。  The LTE UE sends an attach request message to the access network element, and the access network element converts the attach request message received from the LTE UE into a UMTS attach request message identifiable by the SGSN of the 2G/3G core network in the UMTS system. The network access NE sends the converted UMTS attach request message to the SGSN.
SGSN向 HSS发送要求认证向量的请求。。  The SGSN sends a request for an authentication vector to the HSS. .
可选地, HSS识别是 LTE UE接入 2G/3G网络, 包括:  Optionally, the HSS identifies that the LTE UE accesses the 2G/3G network, and includes:
可选地, 该 HSS配备一个列表, 该列表包括接入 2G/3G网络的 LTE UE 的标识信息; Optionally, the HSS is equipped with a list including LTE UEs accessing the 2G/3G network Identification information;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
该 HSS生成该特殊认证向量, 包括:  The HSS generates the special authentication vector, including:
该 HSS在该要求认证向量的请求中增加指示信息,该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
可选地, 该 HSS为该 LTE UE生成 EPS AV;  Optionally, the HSS generates EPS AV for the LTE UE;
进一步的,  further,
HSS将认证管理域 AMF中第 0个 bit设为 1 以标示此认证向量为 EPS AV;  The HSS sets the 0th bit in the authentication management domain AMF to 1 to indicate that the authentication vector is EPS AV;
HSS生成 RAND、 AUTN、 CK、 IK和 XRES;  HSS generates RAND, AUTN, CK, IK and XRES;
HSS根据 CK和 IK推演得到 KASME , 推演规则可以为 KASME =KDF ( CK, IK ) , KDF为密钥推演函数; The HSS derives KASME based on CK and IK. The deduction rule can be K ASME =KDF ( CK, IK ) and KDF is the key derivation function;
EPS AV由 KASME、 AUTN , XRES , RAND组成, 其中 AUTN中的 AMF 参数的第 0个比特的值为 1。 EPS AV consists of K ASME , AUTN , XRES , RAND , where the 0th bit of the AMF parameter in the AUTN has a value of 1.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式, 以使得 EPS AV可 以通过现有的 UMTS认证响应发送给 SGSN。 EPS AV转换成 UMTS AV格式的 方法包括: 将 EPS AV中的 RAND、 AUTN和 XRES作为 UMTS AV的 RAND、 AUTN和 XRES,将 EPS AV中的 KASME( 256bits )拆分为两部分,分别作为 UMTS AV的 CK ( 128bits )和 IK ( 128bits )。 可选地, 也可对 KASME ( 256bits )不平均 拆分,该 CK和该 IK所占的比例可以不相同。 该 EPS AV转换成 UMTS AV格 式后, AUTN中的 AMF的第 0个比特的值仍然为 1。将该 EPS AV转换成 UMTS AV格式后所得的向量为该特殊认证向量。 Optionally, the HSS converts the EPS AV into a UMTS AV format such that the EPS AV can be sent to the SGSN through an existing UMTS authentication response. The method for converting EPS AV into UMTS AV format includes: RAND, AUTN and XRES in EPS AV are used as RAND, AUTN and XRES of UMTS AV, and K ASME (256bits) in EPS AV is split into two parts, respectively as UMTS AV's CK (128bits) and IK (128bits). Alternatively, K ASME (256 bits) may also be split unevenly, and the ratio of the CK to the IK may be different. After the EPS AV is converted into the UMTS AV format, the value of the 0th bit of the AMF in the AUTN is still 1. The vector obtained by converting the EPS AV into the UMTS AV format is the special authentication vector.
该 HSS将该特殊认证向量传输给该 SGSN;  The HSS transmits the special authentication vector to the SGSN;
该 SGSN根据从该 HSS处接收到的特殊认证向量执行 UMTS AKA认证流 程。 SGSN发送 UMTS AKA认证挑战给接入网网元, 该 UMTS AKA认证挑战 中包含 RAND和 AUTNo The SGSN performs a UMTS AKA authentication procedure based on the special authentication vector received from the HSS. The SGSN sends a UMTS AKA authentication challenge to the access network element, the UMTS AKA authentication challenge Contains RAND and AUTNo
接入网网元将接收到的 UMTS AKA认证挑战转换成 LTE AKA认证挑战。 UMTS AKA认证挑战中的 RAND和 AUTN被放在 LTE AKA认证挑战中发送给 LTE UE。  The access network element converts the received UMTS AKA authentication challenge into an LTE AKA authentication challenge. The RAND and AUTN in the UMTS AKA authentication challenge are sent to the LTE UE in the LTE AKA authentication challenge.
LTE UE验证 AUTN。 进一步的, 由于 AUTN中 AMF的第 0个比特的值为 The LTE UE verifies the AUTN. Further, since the value of the 0th bit of the AMF in the AUTN is
1 , 因此 LTE UE会通过对 AMF的检查。 LTE UE生成 RES和密钥 KASME1 , so the LTE UE will pass the check of AMF. The LTE UE generates the RES and the key K ASME .
LTE UE发送 LTE AKA认证响应给接入网网元,该 LTE AKA认证响应中包 含 RES。  The LTE UE sends an LTE AKA authentication response to the access network element, and the LTE AKA authentication response includes the RES.
接入网网元将 LTE AKA认证响应转换为 UMTS AKA认证响应, 将 LTE AKA认证响应中的该 RES放在 UMTS AKA认证响应中发送给 SGSN。  The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response, and sends the RES in the LTE AKA authentication response to the SGSN in the UMTS AKA authentication response.
SGSN比较该 RES和该 XRES是否相同。  The SGSN compares whether the RES and the XRES are the same.
可选地, 如果比较结果为该 RES和该 XRES不相同, 则中止进行安全认 证;  Optionally, if the comparison result is that the RES is different from the XRES, then the security authentication is suspended;
可选地, 如果比较结果为该 RES和该 XRES相同, 则 SGSN发起安全模 式过程, 在安全模式过程中, CK和或 IK被发送给接入网网元。  Optionally, if the comparison result is that the RES and the XRES are the same, the SGSN initiates a security mode process, in which CK and or IK are sent to the access network element.
可选地, 接入网网元根据 CK和或 IK生成 KASME。 可选地, 接入网网元根 据 CK和或 IK生成 KASME的生成规则为 KASME=CKIIIK, "II"表示串联, 即将 IK 加在 CK后面。 Optionally, the access network element generates K ASME according to CK and or IK. Optionally, the access network element generates K ASME according to CK and or IK. The generation rule is K ASME =CKIIIK, and "II" indicates concatenation, that is, IK is added after CK.
接入网网元和 LTE UE共享密钥 KASMEThe access network element and the LTE UE share the key K ASME .
可选地,接入网网元和 LTE UE之间执行 LTE NAS SMC流程和 LTE AS SMC 流程建立 LTE空口安全。  Optionally, the LTE NAS SMC process and the LTE AS SMC process are performed between the access network element and the LTE UE to establish an LTE air interface security.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以完成 安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。。 图 5示出了根据本发明实施例的移动通信系统的安全认证的归属用户服务 器 500的示意性框图。 图 5及其说明所揭示的装置, 可基于本发明实施例图 1 至图 4以及基于本发明实施例图 1至图 4所揭示的方法。 如图 5所示, 该归属 用户服务器 HSS500包括: 接收模块 510 , 识别模块 520 , 处理模块 530, 发 送模块 540; In the embodiment of the present invention, the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element. After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. The LTE UE does not need to be modified, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources. . FIG. 5 shows a schematic block diagram of a home subscriber server 500 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 5 and its description of the disclosed apparatus may be based on the embodiments of the present invention, FIGS. 1 through 4, and the methods disclosed in FIGS. 1 through 4 of the present invention. As shown in Figure 5, the home subscriber server HSS500 includes: a receiving module 510, an identification module 520, a processing module 530, a sending module 540;
该接收模块 510用于接收 SGSN发送的要求认证向量的请求, 该要求认 证向量的请求由该 SGSN在接收到接入网网元发送的 UMTS attach request消 息后发送给该 SGSN, 该识别模块 520用于在该接收模块 510接收该要求认 证向量的请求后识别出是 LTE UE接入 2G或 3G网络;  The receiving module 510 is configured to receive a request for the authentication vector sent by the SGSN, where the request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request message sent by the access network element, where the After the receiving module 510 receives the request for the authentication vector, it is identified that the LTE UE accesses the 2G or 3G network;
该处理模块 530用于在该识别模块 520识别出是 LTE UE接入 2G或 3G 网络后生成特殊认证向量;  The processing module 530 is configured to generate a special authentication vector after the identification module 520 identifies that the LTE UE accesses the 2G or 3G network;
该发送模块 540用于将该特殊认证向量发送给该 SGSN, 以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证。  The sending module 540 is configured to send the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
在本发明实施例中, 为了使 LTE UE能够使用 2G或 3G核心网, 在 HSS 识别出是 LTE UE接入 2G/3G核心网后, HSS为该 LTE UE生成特殊认证向量, 以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证, 使得 LTE UE可以 完成安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, in order to enable the LTE UE to use the 2G or 3G core network, after the HSS recognizes that the LTE UE accesses the 2G/3G core network, the HSS generates a special authentication vector for the LTE UE, so that the SGSN, the SGSN, The access network element and the LTE UE complete the security authentication, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
可选地, 该 UMTS attach request消息是该接入网网元将 attach request消 息转换所得, 该 attach request消息由该 LTE UE发送。  Optionally, the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
可选地, 该以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证包 括:  Optionally, the security authentication is performed by the SGSN, the access network element, and the LTE UE, including:
该 SGSN发送 UMTS AKA认证挑战给该接入网网元, 该接入网网元将 该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给该 LTE UE, 该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该接入网网元, 以便 该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 可选地, 该特殊认证向量中包含 XRES、 CK、 IK; The SGSN sends a UMTS AKA authentication challenge to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the challenge to the LTE UE, where the LTE UE performs the LTE AKA authentication challenge. After the RES and the key K ASME are verified and generated, the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication. . Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全 认证包括:  Optionally, the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
该接入网网元将该 LTE ΑΚΑ认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME, 该接入网网元和该 LTE UE共享该 KASMEThe access network element converts the LTE ΑΚΑ authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, where the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, The SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。  Optionally, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
可选的, 该 HSS还包括存储模块 550 , 该存储模块 550用于存储一个列 表, 该列表包括通过接入 2G/3G网络的 LTE UE的标识信息;  Optionally, the HSS further includes a storage module 550, where the storage module 550 is configured to store a list, where the list includes identifier information of the LTE UE that accesses the 2G/3G network;
可选地, 该识别模块 520根据该列表中的该标识信息, 获知该 LTE UE 的标识信息包含在该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G 网络。  Optionally, the identifying module 520 learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
可选地, 该处理模块 530用于在该识别模块 520识别出是 LTE UE接入 2G或 3G网络后生成特殊认证向量包括:  Optionally, the processing module 530 is configured to: after the identifying module 520 identifies that the LTE UE accesses the 2G or 3G network, generating a special authentication vector, including:
该处理模块 530用于在该要求认证向量的请求中增加指示信息, 该指示 信息用于指示该 HSS生成该特殊认证向量;  The processing module 530 is configured to add indication information to the request for requesting the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该处理模块 530用于为该 LTE UE生成 EPS AV;  The processing module 530 is configured to generate an EPS AV for the LTE UE;
进一步的,  further,
该处理模块 530用于将认证管理域 AMF中第 0个 bit设为 1以标示此认 证向量为 EPS AV;  The processing module 530 is configured to set the 0th bit in the authentication management domain AMF to 1 to indicate that the authentication vector is EPS AV;
该处理模块 530用于生成 RAND、 AUTN、 CK、 IK和 XRES;  The processing module 530 is configured to generate RAND, AUTN, CK, IK, and XRES;
该处理模块 530用于根据 CK和 IK推演得到 KASME , 推演规则可以 为 KASME =KDF ( CK, IK ) , KDF为密钥推演函数; EPS AV由 KASME、 AUTN , XRES , RAND组成, 其中 AUTN中的 AMF 参数的第 0个比特的值为 1。 The processing module 530 is configured to derive KASME according to CK and IK, and the derivation rule may be K ASME =KDF ( CK, IK ), and KDF is a key derivation function; EPS AV consists of K ASME , AUTN , XRES , RAND , where the 0th bit of the AMF parameter in the AUTN has a value of 1.
可选地,该处理模块 530用于将该 EPS AV转换成 UMTS AV格式, 以使 AV格式的方法包括: 将 EPS AV中的 RAND、 AUTN和 XRES作为 UMTS AV 的 RAND、 AUTN和 XRES, 将 EPS AV中的 KASME ( 256bits )拆分为两部分, 分别作为 UMTS AV的 CK ( 128bits )和 IK ( 128bits )。该 EPS AV转换成 UMTS AV格式后, AUTN中的 AMF的第 0个比特的值仍然为 1。将该 EPS AV转换 成 UMTS AV格式后所得的向量为该特殊认证向量。 Optionally, the processing module 530 is configured to convert the EPS AV into a UMTS AV format, so that the method of the AV format includes: using RAND, AUTN, and XRES in the EPS AV as the RAND, AUTN, and XRES of the UMTS AV, and the EPS K ASME (256bits) in AV is split into two parts, which are CK (128bits) and IK (128bits) of UMTS AV. After the EPS AV is converted into the UMTS AV format, the value of the 0th bit of the AMF in the AUTN is still 1. The vector obtained by converting the EPS AV into the UMTS AV format is the special authentication vector.
可选地, 该接入网网元根据该 CK和或 IK生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or IK, including:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该 KASME。 ΊΓ 表示串联, 即将 IK加在 CK后面。 The access network element in accordance with the generation rule K ASME = CKIIIK, which generates based on the K ASME and CK or IK. ΊΓ indicates concatenation, IK is added after CK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以完成 安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element. After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 6示出了根据本发明实施例的移动通信系统的安全认证的 GPRS服务支 撑节点 600的示意性框图。 图 6及其说明所揭示的装置, 可基于本发明实施例 图 1至图 4以及基于本发明实施例图 1至图 4所揭示的方法, 也可以基于本发 明实施例图 5以及图 5所揭示的装置。 如图 6所示, 该 GPRS服务支撑节点 SGSN600包括: 接收模块 610; 发送模块 620;  Figure 6 shows a schematic block diagram of a GPRS service support node 600 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 6 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 based on the embodiment of the present invention may also be based on the embodiment of the present invention and FIG. 5 and FIG. Revealed device. As shown in Figure 6, the GPRS service support node SGSN600 includes: a receiving module 610; a sending module 620;
该接收模块 610用于接收接入网网元发送的 UMTS attach request消息, 该 UMTS attach request是该接入网网元将 LTE UE发送的 attach request消息 转换所得;  The receiving module 610 is configured to receive a UMTS attach request message sent by an access network element, where the UMTS attach request is obtained by converting, by the access network element, an attach request message sent by the LTE UE;
该发送模块 620用于在该接收模块 610接收到该 UMTS attach request消 息后, 向 HSS发送要求认证向量的请求, 以便该 HSS收到该请求后识别是 该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成该特殊认证向量; 该接收模块 610还用于接收来自于该 HSS的该特殊认证向量, 该发送模 块 620还用于在该接收模块 610接收到该特殊认证向量后发送 UMTS AKA 认证挑战给该接入网网元, 以便该 SGSN、 该接入网网元和该 LTE UE完成 安全认证。 The sending module 620 is configured to receive the UMTS attach request in the receiving module 610. After receiving the request, the request for the authentication vector is sent to the HSS, so that the HSS receives the request and identifies that the LTE UE accesses the 2G or 3G network, so that the HSS generates the special authentication vector; the receiving module 610 is further configured to receive The special authentication vector from the HSS, the sending module 620 is further configured to send a UMTS AKA authentication challenge to the access network element after the receiving module 610 receives the special authentication vector, so that the SGSN, the access network The network element and the LTE UE complete the security authentication.
在本发明实施例中, 通过 HSS识别出 LTE UE接入 2G或 3G核心网的场景 后, HSS生成特殊认证向量, 使 SGSN、 接入网网元和该 LTE UE完成安全 认证, 实现不需要对 LTEUE进行修改的条件下使 LTE UE可以完成安全认证接 入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, after the scenario in which the LTE UE accesses the 2G or 3G core network is identified by the HSS, the HSS generates a special authentication vector, so that the SGSN, the access network element, and the LTE UE complete the security authentication, and the implementation does not need to be performed. Under the condition that the LTE UE is modified, the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
可选地,该以便该 SGSN、该接入网网元和该 LTE UE完成安全认证包括: 该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发 送给该 LTE UE ,该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES 和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该 接入网网元, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证。 Optionally, the SGSN, the access network element, and the LTE UE complete the security authentication, where the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE. After the LTE UE performs the verification according to the LTE AKA authentication challenge and generates the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the The SGSN and the LTE UE further complete the security authentication.
可选地, 该 SGSN还包括处理模块 630 ;  Optionally, the SGSN further includes a processing module 630;
可选地, 该特殊认证向量包含 XRES、 CK、 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全 认证包括:  Optionally, the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该接收模块 610 ,该处理模块 630用于比较该 RES和该 XRES是否相同, 当该比较结果为相同时,该发送模块 620将该 CK 和或 IK发送给该接入网网元, 该接入网网元根据该 CK和或 IK生成 KASME , 该 CK和或 IK由该发送模块 620发送, 该接入网网元和该 LTE UE共享该 KASME。 可选地, 该处理模块 630比较该 RES和该 XRES是否相同还包括, 当该 比较结果为不相同时, 中止进行安全认证。 The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the receiving module 610, where the processing module 630 is configured to compare whether the RES and the XRES are the same, when the comparison is performed. When the result is the same, the sending module 620 sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, and the CK and or IK are sent by the sending module 620. Sending, the access network element and the LTE UE share the KASME. Optionally, the processing module 630 compares whether the RES and the XRES are the same. Further, when the comparison result is different, the security authentication is suspended.
可选地 ,  Optionally,
该以便该 HSS收到该请求后识别是该 LTE UE接入 2G或 3G网络包括: 该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  After the HSS receives the request, it is identified that the LTE UE accesses the 2G or 3G network includes: the HSS is equipped with a list, and the list includes the identifier information of the LTE UE accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。 可选地, 该以 便该 HSS生成该特殊认证向量包括:  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network. Optionally, the generating the special authentication vector by the HSS includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV ;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括:  Optionally, the HSS converts the EPS AV into a UMTS AV format, including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN , 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
可选地, 该接入网网元才艮据该 CK和或 ΙΚ生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or the 包括:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该 KASME。 The access network element generates the KASME according to the CK and or IK according to the generation rule K ASME =CKIIIK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以完成 安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。 In the embodiment of the present invention, the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element. After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. No modification to the LTE UE is required, so that the LTE UE can complete The security authentication accesses the 2G or 3G network, so that the LTE UE uses 2G or 3G core network resources.
图 7示出了根据本发明实施例的移动通信系统的安全认证的接入网网元 700 的示意性框图。 图 7及其说明所揭示的装置, 可基于本发明实施例图 1至图 4 以及基于本发明实施例图 1至图 4所揭示的方法,也可以基于本发明实施例图 5 至图 6以及图 5至图 6所揭示的装置。 如图 7所示, 该接入网网元 700包括: 接收模块 710 , 处理模块 720 , 发送模块 730;  FIG. 7 shows a schematic block diagram of an access network element 700 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 7 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 according to the embodiment of the present invention may also be based on the embodiments of the present invention and FIGS. 5 to 6 and The apparatus disclosed in Figures 5-6. As shown in FIG. 7, the access network element 700 includes: a receiving module 710, a processing module 720, and a sending module 730;
该接收模块 710用于接收来自 LTE UE的 attach request消息; 该处理模 块 720用于将该 attach request消息转换为 UMTS attach request消息;  The receiving module 710 is configured to receive an attach request message from an LTE UE; the processing module 720 is configured to convert the attach request message into a UMTS attach request message;
该发送模块 730用于将该 UMTS attach request消息发送给 SGSN, 以便 该 SGSN向 HSS发送要求认证向量的请求, 该 HSS收到该 SGSN的该请求 后识别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成特殊认证向 量;  The sending module 730 is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN to identify that the LTE UE accesses the 2G or 3G network. In order for the HSS to generate a special authentication vector;
该接收模块 710还用于接收该 SGSN发送的 UMTS AKA认证挑战, 该 UMTS AKA认证挑战为该 SGSN收到该 HSS发送的该特殊认证向量后发送; 该处理模块 720还用于将该 UMTS AKA认证挑战转换成 LTE AKA认证 挑战, 该发送模块 730还用于将该 LTE AKA认证挑战发送给该 LTE UE, 以 便该接入网网元、 该 SGSN和该 LTE UE完成安全认证。  The receiving module 710 is further configured to receive the UMTS AKA authentication challenge sent by the SGSN, where the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS; the processing module 720 is further configured to authenticate the UMTS AKA. The challenge is converted into an LTE AKA authentication challenge, and the sending module 730 is further configured to send the LTE AKA authentication challenge to the LTE UE, so that the access network element, the SGSN, and the LTE UE complete the security authentication.
在本发明实施例中, 通过接入网网元将 LTE UE发送的信息转换为适用于 2G或 3G网络系统的信息,由 HSS识别出为 LTE UE接入 2G或 3G网络的场景, 通过 HSS生成特殊的认证向量, 使接入网网元、 SGSN和 LTE UE能够完成安 全认证, 使得 LTE UE可以完成安全认证接入 2G或 3G网络, 以便 LTE UE使 用 2G或 3G核心网资源。  In the embodiment of the present invention, the information sent by the LTE UE is converted into the information applicable to the 2G or 3G network system by the access network element, and the scene that the LTE UE accesses the 2G or 3G network is identified by the HSS, and is generated by the HSS. The special authentication vector enables the access network element, the SGSN, and the LTE UE to complete the security authentication, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
可选地, 该接入网网元、 该 SGSN和该 LTE UE完成安全认证包括: 该 LTE UE验证该 LTE AKA认证挑战后生成 RES和密钥 KASME; Optionally, the access network element, the SGSN, and the LTE UE complete the security authentication, where the LTE UE verifies the LTE AKA authentication challenge, and generates a RES and a key K ASME ;
该接收模块 710用于接收该 LTE UE发送的包含该 RES的 LTE AKA认 证响应, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 可选地, 该特殊认证向量包含 XRES、 CK和 IK; The receiving module 710 is configured to receive an LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete security authentication. Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证包括:  Optionally, the access network element, the SGSN, and the LTE UE further complete the security authentication, including:
该处理模块 720还用于将包含该 RES的 LTE AKA认证响应转换为包含 该 RES的 UMTS AKA认证响应,该发送模块 730还用于将该包含该 RES的 UMTS AKA认证响应发送给该 SGSN ,以便该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元;  The processing module 720 is further configured to convert the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, where the sending module 730 is further configured to send the UMTS AKA authentication response including the RES to the SGSN, so that The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access network element.
该处理模块 720还用于才艮据该 CK和或 IK生成 KASME, 该接入网网元和 该 LTE UE共享该 KASMEThe processing module 720 is further configured to generate a K ASME according to the CK and or IK, where the access network element and the LTE UE share the K ASME .
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。  Optionally, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
可选地,  Optionally,
该 HSS收到该 SGSN的该请求后识别是该 LTE UE接入 2G或 3G网络 包括:  After receiving the request from the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, including:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network.
可选地, 该进而以便该 HSS生成特殊认证向量包括:  Optionally, the further generating the special authentication vector for the HSS comprises:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括: 该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME ( 256bits ) 拆分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 Optionally, the HSS converts the EPS AV into a UMTS AV format including: The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME (256 bits) in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
可选地, 该处理模块 720进一步用于按照生成规则 KASME=CKIIIK , 根 据该 CK和或 IK生成该 KASME。 ΊΓ 表示串联, 即将 IK加在 CK后面。 Alternatively, the processing module 720 is further used for generating rules according to K ASME = CKIIIK, which generates based on the K ASME and CK or IK. ΊΓ indicates concatenation, IK is added after CK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 核心网的场景后, HSS 生成特殊的认证向量, 通过该接入网网元、 SGSN 完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以 完成安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, the message sent by the LTE UE is converted into a message applicable to the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G core through the access network element. After the scenario of the network, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 8 示出了根据本发明实施例的移动通信系统的安全认证的归属用户服务 器 800的示意性框图。 图 8及其说明所揭示的装置, 可基于本发明实施例图 1 至图 4以及基于本发明实施例图 1至图 4所揭示的方法, 以及基于本发明实施 例图 5至图 7以及基于本发明实施例图 5至图 7所揭示的装置。 如图 8所示, 该归属用户服务器 HSS800包括: 接收器 810 , 第一处理器 820 , 第二处理器 830 , 发送器 840;  Figure 8 shows a schematic block diagram of a home subscriber server 800 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 8 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 based on the embodiment of the present invention, and FIG. 5 to FIG. 7 based on the embodiment of the present invention and based on The apparatus disclosed in Figures 5 to 7 of the embodiment of the present invention. As shown in FIG. 8, the home subscriber server HSS800 includes: a receiver 810, a first processor 820, a second processor 830, and a transmitter 840;
该接收器 810用于接收 SGSN发送的要求认证向量的请求, 该要求认证 向量的请求由该 SGSN在接收到接入网网元发送的 UMTS attach request消息 后发送给该 SGSN, 该第一处理器 820用于在该接收器 810接收该要求认证 向量的请求后识别出是 LTE UE接入 2G或 3G网络;  The receiver 810 is configured to receive a request for an authentication vector sent by the SGSN, where the request for the authentication vector is sent by the SGSN to the SGSN after receiving the UMTS attach request message sent by the access network element, the first processor The 820 is configured to: after the receiver 810 receives the request for the authentication vector, identify that the LTE UE accesses the 2G or 3G network;
该第二处理器 830用于在该第一处理器 820识别出是 LTE UE接入 2G 或 3G网络后生成特殊认证向量;  The second processor 830 is configured to generate a special authentication vector after the first processor 820 recognizes that the LTE UE accesses the 2G or 3G network;
该发送器 840用于将该特殊认证向量发送给该 SGSN, 以便该 SGSN、该 接入网网元和该 LTE UE完成安全认证。  The transmitter 840 is configured to send the special authentication vector to the SGSN, so that the SGSN, the access network element, and the LTE UE complete the security authentication.
在本发明实施例中, 为了使 LTE UE能够使用 2G或 3G核心网, 在 HSS 识别出是 LTE UE接入 2G/3G核心网后, HSS为该 LTE UE生成特殊认证向量, 以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证, 使得 LTE UE接 入 2G或 3G网络, 以便使 LTE UE可以使用 2G或 3G核心网资源。 In the embodiment of the present invention, in order to enable the LTE UE to use the 2G or 3G core network, in the HSS After the LTE UE accesses the 2G/3G core network, the HSS generates a special authentication vector for the LTE UE, so that the SGSN, the access network element, and the LTE UE complete the security authentication, so that the LTE UE accesses the 2G or 3G. Network, so that LTE UEs can use 2G or 3G core network resources.
可选地, 该 UMTS attach request消息是该接入网网元将 attach request消 息转换所得, 该 attach request消息由该 LTE UE发送。  Optionally, the UMTS attach request message is obtained by the access network element converting the attach request message, and the attach request message is sent by the LTE UE.
可选地, 该以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证包 括:  Optionally, the security authentication is performed by the SGSN, the access network element, and the LTE UE, including:
该 SGSN发送 UMTS AKA认证挑战给该接入网网元, 该接入网网元将 该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给该 LTE UE, 该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该接入网网元, 以便 该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。 The SGSN sends a UMTS AKA authentication challenge to the access network element, and the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the challenge to the LTE UE, where the LTE UE performs the LTE AKA authentication challenge. After the RES and the key K ASME are verified and generated, the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the SGSN, and the LTE UE further complete the security authentication. .
可选地, 该特殊认证向量中包含 XRES、 CK、 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全 认证包括:  Optionally, the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
该接入网网元将该 LTE AKA认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该 SGSN, 该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元, 该接入网网元根据该 CK和或 IK生成 KASME, 该接入网网元和该 LTE UE共享该 KASMEThe access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN, and the SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the The SGSN sends the CK and or IK to the access network element, and the access network element generates K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。  Optionally, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
可选的, 该 HSS还包括存储器 850 , 该存储器 850用于存储一个列表, 该列表包括通过接入 2G/3G网络的 LTE UE的标识信息;  Optionally, the HSS further includes a memory 850, where the memory 850 is configured to store a list, where the list includes identifier information of the LTE UE that accesses the 2G/3G network;
可选地, 该第一处理器 820 居该列表中的该标识信息, 获知该 LTE UE 的标识信息包含在该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G 网络。 Optionally, the first processor 820 is located in the identifier information in the list, and the identifier information of the LTE UE is included in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G. The internet.
可选地, 该第二处理器 830用于在该第一处理器 820识别出是 LTE UE 接入 2G或 3G网络后生成特殊认证向量包括:  Optionally, the generating, by the second processor 830, the special authentication vector after the first processor 820 identifies that the LTE UE accesses the 2G or 3G network includes:
该第二处理器 830用于在该要求认证向量的请求中增加指示信息, 该指 示信息用于指示该 HSS生成该特殊认证向量;  The second processor 830 is configured to add indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该第二处理器 830用于为该 LTE UE生成 EPS AV;  The second processor 830 is configured to generate EPS AV for the LTE UE;
进一步的,  further,
该第二处理器 830用于将认证管理域 AMF中第 0个 bit设为 1以标示此 认证向量为 EPS AV;  The second processor 830 is configured to set the 0th bit in the authentication management domain AMF to 1 to indicate that the authentication vector is EPS AV;
该第二处理器 830用于生成 RAND、 AUTN, CK、 IK和 XRES;  The second processor 830 is configured to generate RAND, AUTN, CK, IK and XRES;
该第二处理器 830用于根据 CK和 IK推演得到 KASME , 推演规则可 以为 KASME =KDF ( CK, IK ) , KDF为密钥推演函数; The second processor 830 is configured to derive KASME according to CK and IK, and the derivation rule may be K ASME =KDF ( CK, IK ), and KDF is a key derivation function;
EPS AV由 KASME、 AUTN , XRES , RAND组成, 其中 AUTN中的 AMF 参数的第 0个比特的值为 1。 EPS AV consists of K ASME , AUTN , XRES , RAND , where the 0th bit of the AMF parameter in the AUTN has a value of 1.
可选地,该第二处理器 830用于将该 EPS AV转换成 UMTS AV格式, 以 使得 EPS AV可以通过现有的 UMTS认证响应发送给 SGSN。 EPS AV转换成 UMTS AV格式的方法包括:将 EPS AV中的 RAND、 AUTN和 XRES作为 UMTS AV的 RAND、 AUTN和 XRES ,将 EPS AV中的 KASME ( 256bits )拆分为两部分, 分别作为 UMTS AV的 CK ( 128bits )和 IK ( 128bits )。该 EPS AV转换成 UMTS AV格式后, AUTN中的 AMF的第 0个比特的值仍然为 1。将该 EPS AV转换 成 UMTS AV格式后所得的向量为该特殊认证向量。 Optionally, the second processor 830 is configured to convert the EPS AV into a UMTS AV format, so that the EPS AV can be sent to the SGSN through an existing UMTS authentication response. The method of converting EPS AV into UMTS AV format includes: using RAND, AUTN and XRES in EPS AV as RAND, AUTN and XRES of UMTS AV, and splitting K ASME (256bits) in EPS AV into two parts, respectively as UMTS AV's CK (128bits) and IK (128bits). After the EPS AV is converted into the UMTS AV format, the value of the 0th bit of the AMF in the AUTN is still 1. The vector obtained by converting the EPS AV into the UMTS AV format is the special authentication vector.
可选地, 该接入网网元才艮据该 CK和或 IK生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or IK, including:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该 KASME。 ΊΓ 表示串联, 即将 IK加在 CK后面。 The access network element in accordance with the generation rule K ASME = CKIIIK, which generates based on the K ASME and CK or IK. ΊΓ indicates concatenation, IK is added after CK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 In the embodiment of the present invention, the message sent by the LTE UE is converted to be applicable to the network element of the access network.
2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以完成 安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。 The message of the 2G or 3G network is recognized by the HSS. The LTE UE accesses the 2G or 3G through the access network element. After the scenario of the network, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. The LTE UE does not need to be modified, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 9示出了根据本发明实施例的移动通信系统的安全认证的 GPRS服务支 撑节点 900的示意性框图。 图 9及其说明所揭示的装置, 可基于本发明实施例 图 1至图 4以及基于本发明实施例图 1至图 4所揭示的方法, 也可以基于本发 明实施例图 5以及图 8所揭示的装置。 如图 9所示, 该 GPRS服务支撑节点 SGSN900包括: 接收器 910; 发送器 920;  Figure 9 shows a schematic block diagram of a GPRS service support node 900 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 9 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 according to the embodiment of the present invention may also be based on the embodiment of the present invention, FIG. 5 and FIG. Revealed device. As shown in FIG. 9, the GPRS service supporting node SGSN900 includes: a receiver 910; a transmitter 920;
该接收器 910用于接收接入网网元发送的 UMTS attach request消息, 该 UMTS attach request是该接入网网元将 LTE UE发送的 attach request消息转 换所得;  The receiver 910 is configured to receive a UMTS attach request message sent by an access network element, where the UMTS attach request is obtained by converting, by the access network element, an attach request message sent by the LTE UE;
该发送器 920用于在该接收器 910接收到该 UMTS attach request消息后, 向 HSS发送要求认证向量的请求, 以便该 HSS收到该请求后识别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成该特殊认证向量;  The transmitter 920 is configured to send a request for an authentication vector to the HSS after the receiver 910 receives the UMTS attach request message, so that the HSS receives the request and identifies that the LTE UE accesses the 2G or 3G network, and further So that the HSS generates the special authentication vector;
该接收器 910还用于接收来自于该 HSS的该特殊认证向量,该发送器 920 还用于在该接收器 910接收到该特殊认证向量后发送 UMTS AKA认证挑战 给该接入网网元, 以便该 SGSN、 该接入网网元和该 LTE UE完成安全认证。  The receiver 910 is further configured to receive the special authentication vector from the HSS, where the transmitter 920 is further configured to send a UMTS AKA authentication challenge to the access network element after the receiver 910 receives the special authentication vector. So that the SGSN, the access network element, and the LTE UE complete the security authentication.
在本发明实施例中, 通过 HSS识别出 LTE UE接入 2G或 3G核心网的场景 后, HSS生成特殊认证向量, 使 SGSN、 接入网网元和该 LTE UE完成安全 认证, 实现不需要对 LTEUE进行修改的条件下使 LTE UE可以完成安全认证接 入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, after the scenario in which the LTE UE accesses the 2G or 3G core network is identified by the HSS, the HSS generates a special authentication vector, so that the SGSN, the access network element, and the LTE UE complete the security authentication, and the implementation does not need to be performed. Under the condition that the LTE UE is modified, the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
可选地,该以便该 SGSN、该接入网网元和该 LTE UE完成安全认证包括: 该接入网网元将该 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发 送给该 LTE UE,该 LTE UE根据该 LTE AKA认证挑战进行验证并生成 RES 和密钥 KASME后, 该 LTE UE将包含该 RES的 LTE AKA认证响应发送给该 接入网网元, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证。 Optionally, the SGSN, the access network element, and the LTE UE complete the security authentication, where the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends the LTE UE to the LTE UE. After the LTE UE performs the verification according to the LTE AKA authentication challenge and generates the RES and the key K ASME , the LTE UE sends an LTE AKA authentication response including the RES to the access network element, so that the access network element, the The SGSN and the LTE UE further complete the security recognition Certificate.
可选地, 该 SGSN还包括处理器 930;  Optionally, the SGSN further includes a processor 930;
可选地, 该特殊认证向量包含 XRES、 CK、 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全 认证包括:  Optionally, the security authentication is further performed by the access network element, the SGSN, and the LTE UE, including:
该接入网网元将该 LTE ΑΚΑ认证响应转换为 UMTS AKA认证响应并将 该 UMTS AKA认证响应发送给该接收器 910 ,该处理器 930用于比较该 RES 和该 XRES是否相同, 当该比较结果为相同时, 该发送器 920将该 CK和或 IK发送给该接入网网元, 该接入网网元才艮据该 CK和或 IK生成 KASME , 该 CK和或 IK由该发送器 920发送,该接入网网元和该 LTE UE共享该 KASMEThe access network element converts the LTE ΑΚΑ authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the receiver 910, the processor 930 is configured to compare whether the RES and the XRES are the same, when the comparison When the result is the same, the transmitter 920 sends the CK and or IK to the access network element, and the access network element generates the K ASME according to the CK and or IK, and the CK and or IK are sent by the The 920 is sent, and the access network element and the LTE UE share the K ASME .
可选地, 该处理器 930比较该 RES和该 XRES是否相同还包括, 当该比 较结果为不相同时, 中止进行安全认证。  Optionally, the comparing, by the processor 930, whether the RES and the XRES are the same further includes: when the comparison result is different, the security authentication is suspended.
可选地 ,  Optionally,
该以便该 HSS收到该请求后识别是该 LTE UE接入 2G或 3G网络包括: 该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  After the HSS receives the request, it is identified that the LTE UE accesses the 2G or 3G network includes: the HSS is equipped with a list, and the list includes the identifier information of the LTE UE accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。 可选地, 该以 便该 HSS生成该特殊认证向量包括:  The HSS learns that the identifier information of the LTE UE is included in the list according to the identifier information in the list, and the HSS identifies that the LTE UE accesses the 2G or 3G network. Optionally, the generating the special authentication vector by the HSS includes:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括:  Optionally, the HSS converts the EPS AV into a UMTS AV format, including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME拆 分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS The AUTN in the EPS AV is used as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, and the HSS splits the K ASME in the EPS AV into two parts, respectively as the UMTS AV of the CK and the IK.
可选地, 该接入网网元才艮据该 CK和或 ΙΚ生成 KASME包括: Optionally, the access network element generates the K ASME according to the CK and or the 包括:
该接入网网元按照生成规则 KASME=CKIIIK , 根据该 CK和或 IK生成该The access network element generates the base according to the CK and or IK according to the generation rule K ASME =CKIIIK
KASME。 KASME.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 网络的场景后, HSS生成特殊的认证向量, 通过该接入网网元、 SGSN完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以完成 安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。  In the embodiment of the present invention, the message sent by the LTE UE is converted into a message suitable for the 2G or 3G network by the access network element, and the HSS identifies that the LTE UE accesses the 2G or 3G network through the access network element. After the scenario, the HSS generates a special authentication vector, and completes the security authentication between the LTE UE and the network through the access network element and the SGSN. There is no need to modify the LTE UE, so that the LTE UE can complete the secure authentication access to the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources.
图 10 示出了根据本发明实施例的移动通信系统的安全认证的接入网网元 1000的示意性框图。 图 10及其说明所揭示的装置, 可基于本发明实施例图 1至 图 4以及基于本发明实施例图 1至图 4所揭示的方法, 也可以基于本发明实施 例图 5至图 9以及图 5至图 9所揭示的装置。 如图 10所示, 该接入网网元 1000 包括: 接收器 1010 , 处理器 1020 , 发送器 1030;  FIG. 10 shows a schematic block diagram of an access network element 1000 for secure authentication of a mobile communication system in accordance with an embodiment of the present invention. 10 and its description, the apparatus disclosed in FIG. 1 to FIG. 4 and the method disclosed in FIG. 1 to FIG. 4 based on the embodiment of the present invention may also be based on the embodiments of the present invention and FIGS. 5 to 9 and The apparatus disclosed in Figures 5-9. As shown in FIG. 10, the access network element 1000 includes: a receiver 1010, a processor 1020, and a transmitter 1030.
该接收器 1010用于接收来自 LTE UE的 attach request消息; 该处理器 1020用于将该 attach request消息转换为 UMTS attach request消息;  The receiver 1010 is configured to receive an attach request message from an LTE UE, where the processor 1020 is configured to convert the attach request message into a UMTS attach request message.
该发送器 1030用于将该 UMTS attach request消息发送给 SGSN, 以便该 SGSN向 HSS发送要求认证向量的请求,该 HSS收到该 SGSN的该请求后识 别是该 LTE UE接入 2G或 3G网络, 进而以便该 HSS生成特殊认证向量; 该接收器 1010还用于接收该 SGSN发送的 UMTS AKA认证挑战, 该 UMTS AKA认证挑战为该 SGSN收到该 HSS发送的该特殊认证向量后发送; 该处理器 1020还用于将该 UMTS AKA认证挑战转换成 LTE AKA认证 挑战, 该发送器 1030还用于将该 LTE AKA认证挑战发送给该 LTE UE, 以 便该接入网网元、 该 SGSN和该 LTE UE完成安全认证。 在本发明实施例中, 通过接入网网元将 LTE UE发送的信息转换为适用于 2G或 3G网络系统的信息,由 HSS识别出为 LTE UE接入 2G或 3G网络的场景, 通过 HSS生成特殊的认证向量, 使接入网网元、 SGSN和 LTE UE能够完成安 全认证, 使得 LTE UE可以使用现有 2G或 3G核心网。 The transmitter 1030 is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for the authentication vector to the HSS, and the HSS receives the request of the SGSN to identify that the LTE UE accesses the 2G or 3G network. The receiver 1010 is further configured to receive a UMTS AKA authentication challenge sent by the SGSN, where the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS; The 1020 is further configured to convert the UMTS AKA authentication challenge into an LTE AKA authentication challenge, where the transmitter 1030 is further configured to send the LTE AKA authentication challenge to the LTE UE, where the access network element, the SGSN, and the LTE UE are used. Complete safety certification. In the embodiment of the present invention, the information sent by the LTE UE is converted into the information applicable to the 2G or 3G network system by the access network element, and the scene that the LTE UE accesses the 2G or 3G network is identified by the HSS, and is generated by the HSS. The special authentication vector enables the access network element, the SGSN, and the LTE UE to perform security authentication, so that the LTE UE can use the existing 2G or 3G core network.
可选地, 该接入网网元、 该 SGSN和该 LTE UE完成安全认证包括: 该 LTE UE验证该 LTE AKA认证挑战后生成 RES和密钥 KASME; Optionally, the access network element, the SGSN, and the LTE UE complete the security authentication, where the LTE UE verifies the LTE AKA authentication challenge, and generates a RES and a key K ASME ;
该接收器 1010用于接收该 LTE UE发送的包含该 RES的 LTE AKA认证 响应, 以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认证。  The receiver 1010 is configured to receive an LTE AKA authentication response that is sent by the LTE UE and includes the RES, so that the access network element, the SGSN, and the LTE UE further complete security authentication.
可选地, 该特殊认证向量包含 XRES、 CK和 IK;  Optionally, the special authentication vector includes XRES, CK, and IK;
可选地, 该以便该接入网网元、 该 SGSN和该 LTE UE进一步完成安全认 证包括:  Optionally, the access network element, the SGSN, and the LTE UE further complete the security authentication, including:
该处理器 1020还用于将包含该 RES的 LTE AKA认证响应转换为包含该 RES的 UMTS AKA认证响应, 该发送器 1030还用于将该包含该 RES的 UMTS AKA认证响应发送给该 SGSN ,以便该 SGSN比较该 RES和该 XRES 是否相同, 当该比较结果为相同时, 该 SGSN将该 CK和或 IK发送给该接入 网网元;  The processor 1020 is further configured to convert the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, where the transmitter 1030 is further configured to send the UMTS AKA authentication response including the RES to the SGSN, so that The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the access network element.
该处理器 1020还用于才艮据该 CK和或 IK生成 KASME, 该接入网网元和 该 LTE UE共享该 KASMEThe processor 1020 is further configured to generate a K ASME according to the CK and or IK, and the access network element and the LTE UE share the K ASME .
可选地, 该 SGSN比较该 RES和该 XRES是否相同还包括, 当该比较结 果为不相同时, 中止进行安全认证。  Optionally, whether the SGSN compares whether the RES and the XRES are the same further includes: when the comparison result is different, suspending the security authentication.
可选地,  Optionally,
该 HSS收到该 SGSN的该请求后识别是该 LTE UE接入 2G或 3G网络 包括:  After receiving the request from the SGSN, the HSS identifies that the LTE UE accesses the 2G or 3G network, including:
该 HSS配备一个列表,该列表包括接入 2G/3G网络的 LTE UE的标识信 息;  The HSS is provided with a list including identification information of LTE UEs accessing the 2G/3G network;
该 HSS根据该列表中的该标识信息, 获知该 LTE UE的标识信息包含在 该列表中, 则该 HSS识别出是该 LTE UE接入 2G或 3G网络。 The HSS learns that the identifier information of the LTE UE is included in the identifier information in the list. In the list, the HSS recognizes that the LTE UE accesses the 2G or 3G network.
可选地, 该进而以便该 HSS生成特殊认证向量包括:  Optionally, the further generating the special authentication vector for the HSS comprises:
该 HSS在该要求认证向量的请求中增加指示信息, 该指示信息用于指示 该 HSS生成该特殊认证向量;  The HSS adds indication information to the request for the authentication vector, where the indication information is used to indicate that the HSS generates the special authentication vector;
该 HSS为该 LTE UE生成 EPS AV;  The HSS generates EPS AV for the LTE UE;
该 HSS将该 EPS AV转换成 UMTS AV格式, 该转换为 UMTS AV格式 的 EPS AV为该特殊认证向量。  The HSS converts the EPS AV into a UMTS AV format, and the EPS AV converted to the UMTS AV format is the special authentication vector.
可选地, 该 HSS将该 EPS AV转换成 UMTS AV格式 包括:  Optionally, the HSS converts the EPS AV into a UMTS AV format, including:
该 HSS将该 EPS AV中的 RAND作为该 UMTS AV的 RAND , 该 HSS 将该 EPS AV中的 AUTN作为该 UMTS AV的 AUTN, 该 HSS将该 EPS AV 中的 XRES作为该 UMTS AV的 XRES , 该 HSS将该 EPS AV中的 KASME ( 256bits ) 拆分为两部分, 分别作为该 UMTS AV的该 CK和该 IK。 The HSS uses RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as the XRES of the UMTS AV, the HSS The K ASME (256 bits) in the EPS AV is split into two parts, which are the CK and the IK of the UMTS AV, respectively.
可选地, 该处理器 1020进一步用于按照生成规则 KASME=CKIIIK , 根据 该 CK和或 IK生成该 KASME。 ΊΓ 表示串联, 即将 IK加在 CK后面。 Alternatively, the processor 1020 is further used for generating rules according to K ASME = CKIIIK, which generates based on the K ASME and CK or IK. ΊΓ indicates concatenation, IK is added after CK.
本发明实施例中,通过该接入网网元将 LTE UE所发送的消息转换为适用于 In the embodiment of the present invention, the message sent by the LTE UE is converted to be applicable to the network element of the access network.
2G或 3G网络的消息, 由 HSS识别出 LTE UE通过该接入网网元接入 2G或 3G 核心网的场景后, HSS 生成特殊的认证向量, 通过该接入网网元、 SGSN 完成 LTE UE和网络之间的安全认证。 不需要对 LTE UE做修改, 使得 LTE UE可以 完成安全认证接入 2G或 3G网络, 以便 LTE UE使用 2G或 3G核心网资源。 通过以上的实施方式的描述, 所属领域的技术人员可以清楚地了解到本 发明可以用硬件实现, 或固件实现, 或它们的组合方式来实现。 当使用软件 实现时, 可以将上述功能存储在计算机可读介质中或作为计算机可读介质上 的一个或多个指令或代码进行传输。 计算机可读介质包括计算机存储介质和 通信介质, 其中通信介质包括便于从一个地方向另一个地方传送计算机程序 的任何介质。 存储介质可以是计算机能够存取的任何可用介质。 以此为例但 不限于: 计算机可读介质可以包括 RAM、 ROM, EEPROM、 CD-ROM或其 他光盘存储、 磁盘存储介质或者其他磁存储设备、 或者能够用于携带或存储 具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他 介质。 此外。 任何连接可以适当的成为计算机可读介质。 例如, 如果软件是 使用同轴电缆、 光纤光缆、 双绞线、 数字用户线 (DSL ) 或者诸如红外线、 无线电和微波之类的无线技术从网站、 服务器或者其他远程源传输的, 那么 同轴电缆、 光纤光缆、 双绞线、 DSL或者诸如红外线、 无线和微波之类的无 线技术包括在所属介质的定影中。 如本发明所使用的, 盘( Disk )和碟( disc ) 包括压缩光碟(CD ) 、 激光碟、 光碟、 数字通用光碟(DVD ) 、 软盘和蓝光 光碟, 其中盘通常磁性的复制数据, 而碟则用激光来光学的复制数据。 上面 的组合也应当包括在计算机可读介质的保护范围之内。 总之, 以上所述仅为本发明技术方案的较佳实施例而已, 并非用于限定 本发明的保护范围。 凡在本发明的精神和原则之内, 所作的任何修改、 等同 替换、 改进等, 均应包含在本发明的保护范围之内。 The message of the 2G or 3G network is identified by the HSS. After the LTE UE accesses the 2G or 3G core network through the access network element, the HSS generates a special authentication vector, and completes the LTE UE through the access network element and the SGSN. Security certification between the network and the network. The LTE UE does not need to be modified, so that the LTE UE can complete the security authentication to access the 2G or 3G network, so that the LTE UE uses the 2G or 3G core network resources. Through the description of the above embodiments, it will be apparent to those skilled in the art that the present invention can be implemented in hardware, firmware implementation, or a combination thereof. When implemented in software, the functions described above may be stored in or transmitted as one or more instructions or code on a computer readable medium. Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another. A storage medium may be any available media that can be accessed by a computer. Take this as an example but Not limited to: Computer readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage device, or can be used to carry or store desired program code in the form of an instruction or data structure. And any other medium that can be accessed by a computer. Also. Any connection may suitably be a computer readable medium. For example, if the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable , fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, wireless, and microwaves are included in the fixing of the associated media. As used in the present invention, a disk and a disc include a compact disc (CD), a laser disc, a compact disc, a digital versatile disc (DVD), a floppy disc, and a Blu-ray disc, wherein the disc is usually magnetically copied, and the disc is The laser is used to optically replicate the data. Combinations of the above should also be included within the scope of the computer readable media. In summary, the above description is only a preferred embodiment of the technical solution of the present invention, and is not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the present invention are intended to be included within the scope of the present invention.

Claims

权 利 要 求 Rights request
1. 一种移动通信系统的安全认证方法, 其特征在于, 包括: 1. A security authentication method for a mobile communication system, characterized by including:
归属用户服务器 HSS接收 GPRS服务支撑节点 SGSN发送的要求认证 向量的请求后, 所述 HSS识别是 LTE UE接入 2G或 3G网络, 所述要求认 证向量的请求由所述 SGSN 在接收到接入网网元发送的 UMTS 附着请求 attach request消息后发送给所述 SGSN; After the home user server HSS receives the request for the authentication vector sent by the GPRS service support node SGSN, the HSS identifies that the LTE UE is accessing the 2G or 3G network. The request for the authentication vector is sent by the SGSN after receiving the access network The UMTS attach request message sent by the network element is then sent to the SGSN;
所述 HSS识别出是 LTE UE接入 2G或 3G网络后, 所述 HSS生成特殊 认证向量; After the HSS identifies that the LTE UE is accessing the 2G or 3G network, the HSS generates a special authentication vector;
所述 HSS将所述特殊认证向量发送给所述 SGSN, 以便所述 SGSN、 所 述接入网网元和所述 LTE UE完成安全认证。 The HSS sends the special authentication vector to the SGSN, so that the SGSN, the access network element and the LTE UE complete security authentication.
2. 根据权利要求 1所述的方法, 其特征在于, 所述 UMTS attach request 消息是所述接入网网元将附着请求 attach request消息转换所得, 所述 attach request消息由所述 LTE UE发送。 2. The method according to claim 1, wherein the UMTS attach request message is obtained by converting the attach request message by the access network element, and the attach request message is sent by the LTE UE.
3. 根据权利要求 1或 2所述的方法,其特征在于,所述以便所述 SGSN、 所述接入网网元和所述 LTE UE完成安全认证包括: 网元将所述 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给所述 和密钥 KASME后, 所述 LTE UE将包含所述 RES的 LTE AKA认证响应发送 给所述接入网网元, 以便所述接入网网元、 所述 SGSN和所述 LTE UE进一 步完成安全认证。 3. The method according to claim 1 or 2, wherein the step of enabling the SGSN, the access network element and the LTE UE to complete security authentication includes: the network element challenges the UMTS AKA authentication After being converted into an LTE AKA authentication challenge and sent to the sum key KASME , the LTE UE sends the LTE AKA authentication response containing the RES to the access network element, so that the access network element , the SGSN and the LTE UE further complete security authentication.
4. 根据权利要求 1至 3任一项所述的方法, 其特征在于, 4. The method according to any one of claims 1 to 3, characterized in that,
所述特殊认证向量中包含 XRES、 CK、 IK; The special authentication vector contains XRES, CK, and IK;
所述以便所述接入网网元、所述 SGSN和所述 LTE UE进一步完成安全 认证包括: The steps for the access network element, the SGSN and the LTE UE to further complete security authentication include:
所述接入网网元将所述 LTE AKA认证响应转换为 UMTS AKA认证响 应并将所述 UMTS AKA认证响应发送给所述 SGSN , 所述 SGSN比较所述 RES和所述 XRES是否相同, 当所述比较结果为相同时, 所述 SGSN将所述 CK和或 IK发送给所述接入网网元, 所述接入网网元根据所述 CK和或 IK 生成 KASME, 所述接入网网元和所述 LTE UE共享所述 KASME The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response. The UMTS AKA authentication response should be sent to the SGSN. The SGSN compares whether the RES and the XRES are the same. When the comparison result is the same, the SGSN sends the CK and or IK to the SGSN. The access network element generates KASME according to the CK and or IK, and the access network element and the LTE UE share the KASME .
5. 根据权利要求 4所述的方法,其特征在于,所述 SGSN比较所述 RES 和所述 XRES是否相同还包括, 当所述比较结果为不相同时, 中止进行安全 认证。 5. The method according to claim 4, wherein the SGSN comparing whether the RES and the XRES are the same also includes, when the comparison result is not the same, suspending security authentication.
6. 根据权利要求 1至 5任一项所述的方法, 其特征在于, 所述 HSS识 别是 LTE UE接入 2G或 3G网络包括: 6. The method according to any one of claims 1 to 5, characterized in that the HSS identification is that the LTE UE accesses the 2G or 3G network including:
所述 HSS配备一个列表,所述列表包括通过接入 2G/3G网络的 LTE UE 的标识信息; The HSS is equipped with a list, and the list includes identification information of LTE UEs accessing the 2G/3G network;
所述 HSS根据所述列表中的所述标识信息,获知所述 LTE UE的标识信 息包含在所述列表中, 则所述 HSS识别出是所述 LTE UE接入 2G或 3G网 络。 The HSS learns that the identification information of the LTE UE is included in the list according to the identification information in the list, and then the HSS identifies that the LTE UE accesses the 2G or 3G network.
7. 根据权利要求 1至 6任一项所述的方法, 其特征在于, 所述 HSS生 成特殊认证向量包括: 7. The method according to any one of claims 1 to 6, characterized in that the HSS generating a special authentication vector includes:
所述 HSS在所述要求认证向量的请求中增加指示信息,该指示信息用于 指示所述 HSS生成所述特殊认证向量; The HSS adds indication information to the request for an authentication vector, and the indication information is used to instruct the HSS to generate the special authentication vector;
所述 HSS为所述 LTE UE生成 EPS AV; The HSS generates EPS AV for the LTE UE;
所述 HSS将所述 EPS AV转换成 UMTS AV格式,所述转换为 UMTS AV 格式的 EPS AV为所述特殊认证向量。 The HSS converts the EPS AV into the UMTS AV format, and the EPS AV converted into the UMTS AV format is the special authentication vector.
8. 根据权利要求 7所述的方法, 其特征在于, 所述 HSS将所述 EPS AV 转换成 UMTS AV格式包括: 8. The method according to claim 7, wherein the HSS converting the EPS AV into the UMTS AV format includes:
所述 HSS将所述 EPS AV中的 RAND作为所述 UMTS AV的 RAND, 所述 HSS将所述 EPS AV中的 AUTN作为所述 UMTS AV的 AUTN, 所述 HSS将所述 EPS AV中的 XRES作为所述 UMTS AV的 XRES ,所述 HSS将 所述 EPS AV中的 KASME拆分为两部分,分别作为所述 UMTS AV的所述 CK 和所述 IK。 The HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as The UMTS AV XRES, the HSS will The KASME in the EPS AV is split into two parts, which are respectively used as the CK and the IK of the UMTS AV.
9. 根据权利要求 4至 8任一项所述的方法, 其特征在于, 所述接入网网 元根据所述 CK和或 ΙΚ生成 KASME包括: 9. The method according to any one of claims 4 to 8, characterized in that, the access network element generating KASME according to the CK and or IK includes:
所述接入网网元按照生成规则 KASME=CKIIIK ,根据所述 CK和或 IK生 成所述 KASME O The access network element generates the KASME O according to the generation rule KASME =CKIIIK according to the CK and or IK
10. 一种移动通信系统的安全认证方法, 其特征在于, 包括: 10. A security authentication method for a mobile communication system, characterized by including:
SGSN接收接入网网元发送 UMTS attach request消息,所述 UMTS attach request消息是所述接入网网元将 LTE UE发送的 attach request消息转换所 得; The SGSN receives the UMTS attach request message sent by the access network element, and the UMTS attach request message is obtained by converting the attach request message sent by the LTE UE by the access network element;
所述 SGSN接收到由所述接入网网元发送的所述 UMTS attach request 消息后, 所述 SGSN向 HSS发送要求认证向量的请求, 以便所述 HSS收到 所述 SGSN的所述请求后识别是所述 LTE UE接入 2G或 3G网络, 进而以 便所述 HSS生成所述特殊认证向量; After the SGSN receives the UMTS attach request message sent by the access network element, the SGSN sends a request for an authentication vector to the HSS, so that the HSS can identify it after receiving the request from the SGSN. The LTE UE accesses the 2G or 3G network, so that the HSS generates the special authentication vector;
所述 SGSN接收来自于所述 HSS的所述特殊认证向量后, 发送 UMTS After receiving the special authentication vector from the HSS, the SGSN sends UMTS
AKA认证挑战给所述接入网网元, 以便所述 SGSN、所述接入网网元和所述 LTE UE完成安全认证。 The AKA authentication challenge is given to the access network element so that the SGSN, the access network element and the LTE UE complete security authentication.
11. 根据权利要求 10所述的方法, 其特征在于, 所述以便所述 SGSN、 所述接入网网元和所述 LTE UE完成安全认证包括: 11. The method according to claim 10, wherein the step of enabling the SGSN, the access network element and the LTE UE to complete security authentication includes:
所述接入网网元将所述 UMTS AKA认证挑战转换成 LTE AKA认证挑 验证并生成 RES和密钥 KASME后,所述 LTE UE将包含所述 RES的 LTE AKA 认证响应发送给所述接入网网元, 以便所述接入网网元、 所述 SGSN和所述 LTE UE进一步完成安全认证。 After the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and verifies it and generates the RES and key K ASME , the LTE UE sends the LTE AKA authentication response containing the RES to the access network element. Access network element, so that the access network element, the SGSN and the LTE UE further complete security authentication.
12. 根据权利要求 10或 11所述的方法, 其特征在于, 12. The method according to claim 10 or 11, characterized in that,
所述特殊认证向量包含 XRES、 CK、 IK; 所述以便所述接入网网元、所述 SGSN和所述 LTE UE进一步完成安全 认证包括: The special authentication vector includes XRES, CK, and IK; The steps for the access network element, the SGSN and the LTE UE to further complete security authentication include:
所述接入网网元将所述 LTE AKA认证响应转换为 UMTS AKA认证响 应并将所述 UMTS AKA认证响应发送给所述 SGSN , 所述 SGSN比较所述 RES和所述 XRES是否相同, 当所述比较结果为相同时, 所述 SGSN将所述 CK和或 IK发送给所述接入网网元, 所述接入网网元根据所述 CK和或 IK 生成 KASME, 所述接入网网元和所述 LTE UE共享所述 KASME The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN. The SGSN compares the RES and the XRES to see whether they are the same. When the comparison results are the same, the SGSN sends the CK and or IK to the access network element, and the access network element generates KASME according to the CK and or IK. The access network The network element and the LTE UE share the KASME .
13. 根据权利要求 12所述的方法, 其特征在于, 所述 SGSN比较所述 RES和所述 XRES是否相同还包括, 当所述比较结果为不相同时, 中止进行 安全认证。 13. The method according to claim 12, wherein the SGSN comparing whether the RES and the XRES are the same also includes, when the comparison result is not the same, suspending the security authentication.
14. 根据权利要求 10至 12任一项所述的方法, 其特征在于, 所述以便 所述 HSS收到所述 SGSN的所述请求后识别是所述 LTE UE接入 2G或 3G 网络包括: 14. The method according to any one of claims 10 to 12, characterized in that, enabling the HSS to identify that the LTE UE accesses the 2G or 3G network after receiving the request from the SGSN includes:
所述 HSS配备一个列表, 所述列表包括接入 2G/3G网络的 LTE UE的 标识信息; The HSS is equipped with a list, and the list includes identification information of LTE UEs accessing the 2G/3G network;
所述 HSS根据所述列表中的所述标识信息,获知所述 LTE UE的标识信 息包含在所述列表中, 则所述 HSS识别出是所述 LTE UE接入 2G或 3G网 络。 The HSS learns that the identification information of the LTE UE is included in the list according to the identification information in the list, and then the HSS identifies that the LTE UE accesses the 2G or 3G network.
15. 根据权利要求 10至 14任一项所述的方法, 其特征在于, 所述以便 所述 HSS收到所述 SGSN的所述请求后生成所述特殊认证向量包括: 15. The method according to any one of claims 10 to 14, wherein the step of generating the special authentication vector after the HSS receives the request from the SGSN includes:
所述 HSS在所述要求认证向量的请求中增加指示信息,该指示信息用于 指示所述 HSS生成所述特殊认证向量; The HSS adds indication information to the request for an authentication vector, and the indication information is used to instruct the HSS to generate the special authentication vector;
所述 HSS为所述 LTE UE生成 EPS AV; The HSS generates EPS AV for the LTE UE;
所述 HSS将所述 EPS AV转换成 UMTS AV格式,所述转换为 UMTS AV 格式的 EPS AV为所述特殊认证向量。 The HSS converts the EPS AV into the UMTS AV format, and the EPS AV converted into the UMTS AV format is the special authentication vector.
16. 根据权利要求 15所述的方法,其特征在于,所述 HSS将所述 EPS AV 转换成 UMTS AV格式包括: 所述 HSS将所述 EPS AV中的 RAND作为所述 UMTS AV的 RAND, 所述 HSS将所述 EPS AV中的 AUTN作为所述 UMTS AV的 AUTN, 所述 HSS将所述 EPS AV中的 XRES作为所述 UMTS AV的 XRES ,所述 HSS将 所述 EPS AV中的 KASME拆分为两部分,分别作为所述 UMTS AV的所述 CK 和所述 IK。 16. The method according to claim 15, wherein the HSS converting the EPS AV into the UMTS AV format includes: The HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as The XRES of the UMTS AV and the HSS split the KASME in the EPS AV into two parts, which are respectively used as the CK and the IK of the UMTS AV.
17. 根据权利要求 12至 16任一项所述的方法, 其特征在于, 所述接入 网网元根据所述 CK和或 ΙΚ生成 KASME包括: 17. The method according to any one of claims 12 to 16, characterized in that, the access network element generating K ASME based on the CK and or IK includes:
所述接入网网元按照生成规则 KASME=CKIIIK ,根据所述 CK和或 IK生 成所述 KASME O The access network element generates the KASME O according to the generation rule KASME =CKIIIK according to the CK and or IK
18. 一种移动通信系统的安全认证方法, 其特征在于, 包括: 18. A security authentication method for a mobile communication system, characterized by including:
接入网网元将来自于 LTE UE的 attach request消息转换为 UMTS attach request消息; The access network element converts the attach request message from the LTE UE into a UMTS attach request message;
所述接入网网元将所述 UMTS attach request消息发送给 SGSN, 以便所 述 SGSN向 HSS发送要求认证向量的请求, 所述 HSS收到所述 SGSN的所 述请求后识别是所述 LTE UE接入 2G或 3G网络, 进而以便所述 HSS生成 特殊认证向量; The access network element sends the UMTS attach request message to the SGSN, so that the SGSN sends a request for an authentication vector to the HSS. After receiving the request from the SGSN, the HSS identifies that it is the LTE UE. Access the 2G or 3G network so that the HSS can generate a special authentication vector;
所述接入网网元接收所述 SGSN发送的 UMTS AKA认证挑战, 所述 UMTS AKA认证 4 战为所述 SGSN收到所述 HSS发送的所述特殊认证向量 后发送; The access network element receives the UMTS AKA authentication challenge sent by the SGSN, and the UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
所述接入网网元将所述 UMTS AKA认证挑战转换成 LTE AKA认证挑 战后发送给所述 LTE UE,以便所述接入网网元、所述 SGSN和所述 LTE UE 完成安全认证。 The access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and sends it to the LTE UE, so that the access network element, the SGSN and the LTE UE complete security authentication.
19. 根据权利要求 18所述的方法, 其特征在于, 所述以便接入网网元、 所述 SGSN和所述 LTE UE完成安全认证包括: 19. The method according to claim 18, wherein the step of completing security authentication for the access network element, the SGSN and the LTE UE includes:
所述 LTE UE验证所述 LTE AKA认证挑战后生成 RES和密钥 KASME; 所述接入网网元接收所述 LTE UE发送的包含所述 RES的 LTE AKA认 证响应, 以便所述接入网网元、 所述 SGSN和所述 LTE UE进一步完成安全 认证。 The LTE UE generates a RES and a key K ASME after verifying the LTE AKA authentication challenge; the access network element receives the LTE AKA authentication sent by the LTE UE and includes the RES. authentication response, so that the access network element, the SGSN and the LTE UE further complete security authentication.
20. 根据权利要求 18或 19所述的方法, 其特征在于, 20. The method according to claim 18 or 19, characterized in that,
所述特殊认证向量包含 XRES、 CK和 IK; The special authentication vector includes XRES, CK and IK;
所述以便所述接入网网元、 所述 SGSN和所述 LTE UE进一步完成安全 认证包括: The steps for the access network element, the SGSN and the LTE UE to further complete the security authentication include:
所述接入网网元将包含所述 RES的 LTE AKA认证响应转换为包含所述 RES的 UMTS AKA认证响应, 所述接入网网元将所述包含所述 RES的 UMTS AKA认证响应发送给所述 SGSN, 以便所述 SGSN比较所述 RES和 所述 XRES是否相同, 当所述比较结果为相同时, 所述 SGSN将所述 CK和 或 IK发送给所述接入网网元; The access network element converts the LTE AKA authentication response including the RES into a UMTS AKA authentication response including the RES, and the access network element sends the UMTS AKA authentication response including the RES to The SGSN is configured to compare whether the RES and the XRES are the same, and when the comparison result is the same, the SGSN sends the CK and or IK to the access network element;
所述接入网网元才艮据所述 CK和或 IK生成 KASME,所述接入网网元和所 述 LTE UE共享所述 KASME The access network element generates KASME based on the CK and or IK, and the access network element and the LTE UE share the KASME .
21. 根据权利要求 20所述的方法, 其特征在于, 所述 SGSN比较所述 RES和所述 XRES是否相同还包括, 当所述比较结果为不相同时, 中止进行 安全认证。 21. The method according to claim 20, wherein the SGSN comparing whether the RES and the XRES are the same also includes, when the comparison result is not the same, suspending the security authentication.
22. 根据权利要求 18至 21任一项所述的方法, 其特征在于, 所述 HSS 收到所述 SGSN的所述请求后识别是所述 LTE UE接入 2G或 3G网络包括: 所述 HSS配备一个列表, 所述列表包括接入 2G/3G网络的 LTE UE的 标识信息; 22. The method according to any one of claims 18 to 21, characterized in that, after the HSS receives the request from the SGSN, identifying that the LTE UE accesses the 2G or 3G network includes: the HSS Equipped with a list, the list includes identification information of LTE UEs accessing the 2G/3G network;
所述 HSS根据所述列表中的所述标识信息, 获知所述 LTE UE的标识 信息包含在所述列表中, 则所述 HSS识别出是所述 LTE UE接入 2G或 3G 网络。 The HSS learns that the identification information of the LTE UE is included in the list according to the identification information in the list, and then the HSS identifies that the LTE UE accesses the 2G or 3G network.
23. 根据权利要求 18至 22任一项所述的方法, 其特征在于, 所述进而 以便所述 HSS生成特殊认证向量包括: 23. The method according to any one of claims 18 to 22, wherein the step of generating a special authentication vector by the HSS includes:
所述 HSS在所述要求认证向量的请求中增加指示信息,该指示信息用于 指示所述 HSS生成所述特殊认证向量; 所述 HSS为所述 LTE UE生成 EPS AV; The HSS adds indication information to the request for authentication vector, and the indication information is used to Instruct the HSS to generate the special authentication vector; The HSS generates EPS AV for the LTE UE;
所述 HSS将所述 EPS AV转换成 UMTS AV格式,所述转换为 UMTS AV 格式的 EPS AV为所述特殊认证向量。 The HSS converts the EPS AV into the UMTS AV format, and the EPS AV converted into the UMTS AV format is the special authentication vector.
24. 根据权利要求 23所述的方法,其特征在于,所述 HSS将所述 EPS AV 转换成 UMTS AV格式包括: 24. The method according to claim 23, wherein the HSS converting the EPS AV into the UMTS AV format includes:
所述 HSS将所述 EPS AV中的 RAND作为所述 UMTS AV的 RAND, 所述 HSS将所述 EPS AV中的 AUTN作为所述 UMTS AV的 AUTN, 所述 HSS将所述 EPS AV中的 XRES作为所述 UMTS AV的 XRES ,所述 HSS将 所述 EPS AV中的 KASME拆分为两部分,分别作为所述 UMTS AV的所述 CK 和所述 IK。 The HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as The XRES of the UMTS AV and the HSS split the KASME in the EPS AV into two parts, which are respectively used as the CK and the IK of the UMTS AV.
25. 根据权利要求 20至 24任一项所述的方法, 其特征在于, 所述接入 网网元根据所述 CK和或 ΙΚ生成 KASME包括: 25. The method according to any one of claims 20 to 24, wherein the access network element generating K ASME based on the CK and or IK includes:
所述接入网网元按照生成规则 KASME=CKIIIK ,根据所述 CK和或 IK生 成所述 KASME The access network element generates the KASME according to the generation rule KASME =CKIIIK according to the CK and or IK.
26. 一种 HSS , 其特征在于, 包括: 接收模块, 识别模块, 处理模块, 发送模块; 26. An HSS, characterized by including: a receiving module, an identification module, a processing module, and a sending module;
所述接收模块用于接收 SGSN发送的要求认证向量的请求,所述要求认 证向量的请求由所述 SGSN在接收到接入网网元发送的 UMTS attach request 消息后发送给所述 SGSN, 所述识别模块用于在所述接收模块接收所述要求 认证向量的请求后识别出是 LTE UE接入 2G或 3G网络; The receiving module is configured to receive a request for an authentication vector sent by the SGSN. The request for an authentication vector is sent to the SGSN by the SGSN after receiving the UMTS attach request message sent by the access network element. The identification module is configured to identify that the LTE UE is accessing the 2G or 3G network after the receiving module receives the request for an authentication vector;
所述处理模块用于在所述识别模块识别出是 LTE UE接入 2G或 3G网 络后生成特殊认证向量; The processing module is used to generate a special authentication vector after the identification module identifies that the LTE UE accesses the 2G or 3G network;
所述发送模块用于将所述特殊认证向量发送给所述 SGSN , 以便所述 SGSN, 所述接入网网元和所述 LTE UE完成安全认证。 The sending module is used to send the special authentication vector to the SGSN, so that the SGSN, the access network element and the LTE UE complete security authentication.
27. 根据权利要求 26所述的 HSS ,其特征在于,所述 UMTS attach request 消息是所述接入网网元将 attach request消息转换所得, 所述 attach request 消息由所述 LTE UE发送。 27. The HSS according to claim 26, wherein the UMTS attach request The message is obtained by converting the attach request message by the access network element, and the attach request message is sent by the LTE UE.
28. 根据权利要求 26或 27所述的 HSS , 其特征在于, 所述以便所述 SGSN、 所述接入网网元和所述 LTE UE完成安全认证包括: 网元将所述 UMTS AKA认证挑战转换成 LTE AKA认证挑战后发送给所述 和密钥 KASME后, 所述 LTE UE将包含所述 RES的 LTE AKA认证响应发送 给所述接入网网元, 以便所述接入网网元、 所述 SGSN和所述 LTE UE进一 步完成安全认证。 28. The HSS according to claim 26 or 27, wherein the step of enabling the SGSN, the access network element and the LTE UE to complete security authentication includes: the network element challenges the UMTS AKA authentication After being converted into an LTE AKA authentication challenge and sent to the sum key K ASME , the LTE UE sends the LTE AKA authentication response containing the RES to the access network element, so that the access network element , the SGSN and the LTE UE further complete security authentication.
29. 根据权利要求 26至 28任一项所述的 HSS , 其特征在于, 29. The HSS according to any one of claims 26 to 28, characterized in that,
所述特殊认证向量中包含 XRES、 CK、 IK; The special authentication vector contains XRES, CK, and IK;
所述以便所述接入网网元、所述 SGSN和所述 LTE UE进一步完成安全 认证包括: The steps for the access network element, the SGSN and the LTE UE to further complete security authentication include:
所述接入网网元将所述 LTE AKA认证响应转换为 UMTS AKA认证响 应并将所述 UMTS AKA认证响应发送给所述 SGSN , 所述 SGSN比较所述 RES和所述 XRES是否相同, 当所述比较结果为相同时, 所述 SGSN将所述 CK和或 IK发送给所述接入网网元, 所述接入网网元根据所述 CK和或 IK 生成 KASME, 所述接入网网元和所述 LTE UE共享所述 KASME The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the SGSN. The SGSN compares the RES and the XRES to see whether they are the same. When the comparison results are the same, the SGSN sends the CK and or IK to the access network element, and the access network element generates KASME according to the CK and or IK, and the access network The network element and the LTE UE share the KASME .
30. 根据权利要求 29所述的 HSS , 其特征在于, 所述 SGSN比较所述 30. The HSS according to claim 29, characterized in that the SGSN compares the
RES和所述 XRES是否相同还包括, 当所述比较结果为不相同时, 中止进行 安全认证。 Whether the RES and the XRES are the same also includes: when the comparison result is not the same, the security authentication is suspended.
31. 根据权利要求 26至 30任一项所述的 HSS , 其特征在于, 所述 HSS 还包括存储模块, 所述存储模块用于存储一个列表, 所述列表包括通过接入 2G/3G网络的 LTE UE的标识信息; 31. The HSS according to any one of claims 26 to 30, characterized in that, the HSS further includes a storage module, the storage module is used to store a list, the list includes access to the 2G/3G network Identification information of LTE UE;
所述识别模块根据所述列表中的所述标识信息, 获知所述 LTE UE的标 识信息包含在所述列表中,则所述 HSS识别出是所述 LTE UE接入 2G或 3G 网络。 The identification module obtains the identification information of the LTE UE according to the identification information in the list. If the identification information is included in the list, the HSS identifies that the LTE UE is accessing the 2G or 3G network.
32. 根据权利要求 26至 31任一项所述的 HSS , 其特征在于, 所述处理 模块用于在所述识别模块识别出是 LTE UE接入 2G或 3G网络后生成特殊 认证向量包括: 32. The HSS according to any one of claims 26 to 31, wherein the processing module is configured to generate a special authentication vector after the identification module identifies that the LTE UE accesses the 2G or 3G network, including:
所述处理模块用于在所述要求认证向量的请求中增加指示信息, 该指示 信息用于指示所述 HSS生成所述特殊认证向量; 所述处理模块用于为所述 LTE UE生成 EPS AV; The processing module is configured to add indication information to the request for an authentication vector, and the indication information is used to instruct the HSS to generate the special authentication vector; the processing module is configured to generate EPS AV for the LTE UE;
所述处理模块用于将所述 EPS AV转换成 UMTS AV格式, 所述转换为 UMTS AV格式的 EPS AV为所述特殊认证向量。 The processing module is used to convert the EPS AV into the UMTS AV format, and the EPS AV converted into the UMTS AV format is the special authentication vector.
33. 根据权利要求 32所述的 HSS , 其特征在于, 所述处理模块用于将 所述 EPS AV转换成 UMTS AV格式包括: 33. The HSS according to claim 32, characterized in that the processing module used to convert the EPS AV into the UMTS AV format includes:
所述处理模块用于将所述 EPS AV中的 RAND作为所述 UMTS AV的 RAND , 所述处理模块用于将所述 EPS AV中的 AUTN作为所述 UMTS AV 的 AUTN,所述处理模块用于将所述 EPS AV中的 XRES作为所述 UMTS AV 的 XRES , 所述处理模块用于将所述 EPS AV中的 KASME拆分为两部分, 分 别作为所述 UMTS AV的所述 CK和所述 IK。 The processing module is used to use the RAND in the EPS AV as the RAND of the UMTS AV, the processing module is used to use the AUTN in the EPS AV as the AUTN of the UMTS AV, and the processing module is used to The XRES in the EPS AV is used as the XRES of the UMTS AV, and the processing module is used to split the KASME in the EPS AV into two parts, which are respectively used as the CK and the UMTS AV. IK.
34. 根据权利要求 29至 33任一项所述的 HSS , 其特征在于, 所述接入 网网元根据所述 CK和或 IK生成 KASME包括: 34. The HSS according to any one of claims 29 to 33, wherein the access network element generating KASME according to the CK and or IK includes:
所述接入网网元按照生成规则 KASME=CKIIIK ,根据所述 CK和或 IK生 成所述 KASME O The access network element generates the KASME O according to the generation rule KASME =CKIIIK according to the CK and or IK
35. 一种 SGSN, 其特征在于, 包括: 接收模块; 发送模块; 35. A SGSN, characterized in that it includes: a receiving module; a sending module;
所述接收模块用于接收接入网网元发送的 UMTS attach request消息,所 述 UMTS attach request是所述接入网网元将 LTE UE发送的 attach request 消息转换所得; The receiving module is used to receive the UMTS attach request message sent by the access network element. The UMTS attach request is obtained by converting the attach request message sent by the LTE UE by the access network element;
所述发送模块用于在所述接收模块接收到所述 UMTS attach request消息 后, 向 HSS发送要求认证向量的请求, 以便所述 HSS收到所述请求后识别 是所述 LTE UE接入 2G或 3G网络, 进而以便所述 HSS生成所述特殊认证 向量; The sending module is configured to receive the UMTS attach request message in the receiving module Then, send a request for an authentication vector to the HSS, so that the HSS recognizes that the LTE UE is accessing the 2G or 3G network after receiving the request, and then the HSS generates the special authentication vector;
所述接收模块还用于接收来自于所述 HSS的所述特殊认证向量,所述发 送模块还用于在所述接收模块接收到所述特殊认证向量后发送 UMTS AKA 认证挑战给所述接入网网元, 以便所述 SGSN、 所述接入网网元和所述 LTE UE完成安全认证。 The receiving module is also configured to receive the special authentication vector from the HSS. The sending module is also configured to send a UMTS AKA authentication challenge to the access after the receiving module receives the special authentication vector. network element, so that the SGSN, the access network element and the LTE UE complete security authentication.
36. 根据权利要求 35所述的 SGSN ,其特征在于,所述以便所述 SGSN、 所述接入网网元和所述 LTE UE完成安全认证包括: 36. The SGSN according to claim 35, wherein the step of enabling the SGSN, the access network element and the LTE UE to complete security authentication includes:
所述接入网网元将所述 UMTS AKA认证挑战转换成 LTE AKA认证挑 验证并生成 RES和密钥 KASME后,所述 LTE UE将包含所述 RES的 LTE AKA 认证响应发送给所述接入网网元, 以便所述接入网网元、 所述 SGSN和所述 LTE UE进一步完成安全认证。 After the access network element converts the UMTS AKA authentication challenge into an LTE AKA authentication challenge and verifies it and generates the RES and key K ASME , the LTE UE sends the LTE AKA authentication response containing the RES to the access network element. Access network element, so that the access network element, the SGSN and the LTE UE further complete security authentication.
37. 根据权利要求 35或 36所述的 SGSN , 其特征在于, 所述 SGSN还 包括处理模块; 37. The SGSN according to claim 35 or 36, characterized in that the SGSN further includes a processing module;
所述特殊认证向量包含 XRES、 CK、 IK; The special authentication vector includes XRES, CK, and IK;
所述以便所述接入网网元、所述 SGSN和所述 LTE UE进一步完成安全 认证包括: The steps for the access network element, the SGSN and the LTE UE to further complete security authentication include:
所述接入网网元将所述 LTE AKA认证响应转换为 UMTS AKA认证响 应并将所述 UMTS AKA认证响应发送给所述接收模块, 所述处理模块用于 比较所述 RES和所述 XRES是否相同, 当所述比较结果为相同时, 所述发 送模块将所述 CK和或 IK发送给所述接入网网元, 所述接入网网元根据所 述 CK和或 IK生成 KASME, 所述 CK和或 IK由所述发送模块发送, 所述接 入网网元和所述 LTE UE共享所述 KASME The access network element converts the LTE AKA authentication response into a UMTS AKA authentication response and sends the UMTS AKA authentication response to the receiving module. The processing module is used to compare whether the RES and the XRES are the same, when the comparison results are the same, the sending module sends the CK and or IK to the access network element, and the access network element generates KASME according to the CK and or IK, The CK and or IK are sent by the sending module, and the access network element and the LTE UE share the KASME .
38. 根据权利要求 37所述的 SGSN , 其特征在于, 所述处理模块用于比 较所述 RES和所述 XRES是否相同还包括, 当所述比较结果为不相同时, 中止进行安全认证。 38. The SGSN according to claim 37, characterized in that the processing module is used to compare Comparing whether the RES and the XRES are the same also includes: when the comparison result is not the same, suspending the security authentication.
39. 根据权利要求 47至 50任一项所述的 SGSN , 其特征在于, 所述以 便所述 HSS收到所述请求后识别是所述 LTE UE接入 2G或 3G网络包括: 所述 HSS配备一个列表, 所述列表包括接入 2G/3G网络的 LTE UE的 标识信息; 39. The SGSN according to any one of claims 47 to 50, wherein the step of enabling the HSS to identify that the LTE UE is accessing the 2G or 3G network after receiving the request includes: the HSS is equipped with A list, the list includes identification information of LTE UEs accessing the 2G/3G network;
所述 HSS根据所述列表中的所述标识信息,获知所述 LTE UE的标识信 息包含在所述列表中, 则所述 HSS识别出是所述 LTE UE接入 2G或 3G网 络。 The HSS learns that the identification information of the LTE UE is included in the list according to the identification information in the list, and then the HSS identifies that the LTE UE accesses the 2G or 3G network.
40. 根据权利要求 35至 39任一项所述的 SGSN , 其特征在于, 所述以 便所述 H S S生成所述特殊认证向量包括: 40. The SGSN according to any one of claims 35 to 39, wherein the step of generating the special authentication vector by the HSS includes:
所述 HSS在所述要求认证向量的请求中增加指示信息,该指示信息用于 指示所述 HSS生成所述特殊认证向量; 所述 HSS为所述 LTE UE生成 EPS AV; The HSS adds indication information to the request for an authentication vector, and the indication information is used to instruct the HSS to generate the special authentication vector; the HSS generates EPS AV for the LTE UE;
所述 HSS将所述 EPS AV转换成 UMTS AV格式,所述转换为 UMTS AV 格式的 EPS AV为所述特殊认证向量。 The HSS converts the EPS AV into the UMTS AV format, and the EPS AV converted into the UMTS AV format is the special authentication vector.
41. 根据权利要求 40所述的 SGSN , 其特征在于, 所述 HSS将所述 EPS AV转换成 UMTS AV格式包括: 41. The SGSN according to claim 40, wherein the HSS converting the EPS AV into the UMTS AV format includes:
所述 HSS将所述 EPS AV中的 RAND作为所述 UMTS AV的 RAND, 所述 HSS将所述 EPS AV中的 AUTN作为所述 UMTS AV的 AUTN, 所述 HSS将所述 EPS AV中的 XRES作为所述 UMTS AV的 XRES ,所述 HSS将 所述 EPS AV中的 KASME拆分为两部分,分别作为所述 UMTS AV的所述 CK 和所述 IK。 The HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as The XRES of the UMTS AV and the HSS split the KASME in the EPS AV into two parts, which are respectively used as the CK and the IK of the UMTS AV.
42. 根据权利要求 37至 41任一项所述的 SGSN , 其特征在于, 所述接 入网网元根据所述 CK和或 IK生成 KASME包括: 42. The SGSN according to any one of claims 37 to 41, wherein the access network element generating KASME according to the CK and or IK includes:
所述接入网网元按照生成规则 KASME=CKIIIK ,根据所述 CK和或 IK生 成所述 KASME O The access network element is generated according to the generation rule KASME =CKIIIK according to the CK and or IK. into the KASME O
43. —种接入网网元, 其特征在于, 包括: 接收模块, 处理模块, 发送 模块; 43. An access network element, characterized in that it includes: a receiving module, a processing module, and a sending module;
所述接收模块用于接收来自 LTE UE的 attach request消息; 所述处理模 块用于将所述 attach request消息转换为 UMTS attach request消息; The receiving module is used to receive the attach request message from the LTE UE; the processing module is used to convert the attach request message into a UMTS attach request message;
所述发送模块用于将所述 UMTS attach request消息发送给 SGSN, 以便 所述 SGSN向 HSS发送要求认证向量的请求, 所述 HSS收到所述 SGSN的 所述请求后识别是所述 LTE UE接入 2G或 3G网络, 进而以便所述 HSS生 成特殊认证向量; The sending module is configured to send the UMTS attach request message to the SGSN, so that the SGSN sends a request for an authentication vector to the HSS. After receiving the request from the SGSN, the HSS identifies that the LTE UE is connected. Enter the 2G or 3G network, so that the HSS can generate a special authentication vector;
所述接收模块还用于接收所述 SGSN发送的 UMTS AKA认证挑战, 所 述 UMTS AKA认证挑战为所述 SGSN收到所述 HSS发送的所述特殊认证向 量后发送; The receiving module is also used to receive the UMTS AKA authentication challenge sent by the SGSN. The UMTS AKA authentication challenge is sent after the SGSN receives the special authentication vector sent by the HSS;
所述处理模块还用于将所述 UMTS AKA认证挑战转换成 LTE AKA认 UE, 以便所述接入网网元、 所述 SGSN和所述 LTE UE完成安全认证。 The processing module is also used to convert the UMTS AKA authentication challenge into an LTE AKA authentication UE, so that the access network element, the SGSN and the LTE UE complete security authentication.
44. 根据权利要求 43所述的接入网网元, 其特征在于, 所述以便所述接 入网网元、 所述 SGSN和所述 LTE UE完成安全认证包括: 44. The access network element according to claim 43, wherein the step of enabling the access network element, the SGSN and the LTE UE to complete security authentication includes:
所述 LTE UE验证所述 LTE AKA认证挑战后生成 RES和密钥 KASME; 所述接收模块用于接收所述 LTE UE发送的包含所述 RES的 LTE AKA 认证响应, 以便所述接入网网元、 所述 SGSN和所述 LTE UE进一步完成安 全认证。 The LTE UE generates RES and key K ASME after verifying the LTE AKA authentication challenge; the receiving module is used to receive the LTE AKA authentication response containing the RES sent by the LTE UE, so that the access network The SGSN and the LTE UE further complete security authentication.
45. 根据权利要求 43或 44所述的接入网网元, 其特征在于, 45. The access network element according to claim 43 or 44, characterized in that,
所述特殊认证向量包含 XRES、 CK和 IK; The special authentication vector includes XRES, CK and IK;
所述以便所述接入网网元、 所述 SGSN和所述 LTE UE进一步完成安全 认证包括: The steps for the access network element, the SGSN and the LTE UE to further complete the security authentication include:
所述处理模块还用于将包含所述 RES的 LTE AKA认证响应转换为包含 所述 RES的 UMTS AKA认证响应, 所述发送模块还用于将所述包含所述 RES的 UMTS AKA认证响应发送给所述 SGSN , 以便所述 SGSN比较所述 RES和所述 XRES是否相同, 当所述比较结果为相同时, 所述 SGSN将所述 CK和或 IK发送给所述接入网网元; The processing module is also used to convert the LTE AKA authentication response containing the RES into The UMTS AKA authentication response of the RES, the sending module is also configured to send the UMTS AKA authentication response containing the RES to the SGSN, so that the SGSN compares whether the RES and the XRES are the same, when When the comparison results are the same, the SGSN sends the CK and or IK to the access network element;
所述处理模块还用于根据所述 CK和或 IK生成 KASME,所述接入网网元 和所述 LTE UE共享所述 KASME The processing module is also configured to generate KASME according to the CK and or IK, and the access network element and the LTE UE share the KASME .
46. 根据权利要求 45所述的接入网网元, 其特征在于, 所述 SGSN比 较所述 RES和所述 XRES是否相同还包括, 当所述比较结果为不相同时, 中止进行安全认证。 46. The access network element according to claim 45, wherein the SGSN comparing whether the RES and the XRES are the same also includes, when the comparison result is not the same, suspending security authentication.
47. 根据权利要求 43至 46任一项所述的接入网网元, 其特征在于, 其 特征在于, 所述 HSS收到所述 SGSN的所述请求后识别是所述 LTE UE接 入 2G或 3G网络包括: 47. The access network element according to any one of claims 43 to 46, characterized in that, after receiving the request from the SGSN, the HSS identifies that the LTE UE accesses 2G or 3G network including:
所述 HSS配备一个列表, 所述列表包括接入 2G/3G网络的 LTE UE的 标识信息; The HSS is equipped with a list, and the list includes identification information of LTE UEs accessing the 2G/3G network;
所述 HSS根据所述列表中的所述标识信息, 获知所述 LTE UE的标识 信息包含在所述列表中, 则所述 HSS识别出是所述 LTE UE接入 2G或 3G 网络。 The HSS learns that the identification information of the LTE UE is included in the list according to the identification information in the list, and then the HSS identifies that the LTE UE accesses the 2G or 3G network.
48. 根据权利要求 43至 47任一项所述的接入网网元, 其特征在于, 所 述进而以便所述 HSS生成特殊认证向量包括: 48. The access network element according to any one of claims 43 to 47, wherein the step of generating a special authentication vector for the HSS includes:
所述 HSS在所述要求认证向量的请求中增加指示信息,该指示信息用于 指示所述 HSS生成所述特殊认证向量; The HSS adds indication information to the request for an authentication vector, and the indication information is used to instruct the HSS to generate the special authentication vector;
所述 HSS为所述 LTE UE生成 EPS AV; The HSS generates EPS AV for the LTE UE;
所述 HSS将所述 EPS AV转换成 UMTS AV格式,所述转换为 UMTS AV 格式的 EPS AV为所述特殊认证向量。 The HSS converts the EPS AV into the UMTS AV format, and the EPS AV converted into the UMTS AV format is the special authentication vector.
49. 根据权利要求 48所述的接入网网元, 其特征在于, 所述 HSS将所 述 EPS AV转换成 UMTS AV格式包括: 所述 HSS将所述 EPS AV中的 RAND作为所述 UMTS AV的 RAND, 所述 HSS将所述 EPS AV中的 AUTN作为所述 UMTS AV的 AUTN, 所述 HSS将所述 EPS AV中的 XRES作为所述 UMTS AV的 XRES ,所述 HSS将 所述 EPS AV中的 KASME ( 256bits )拆分为两部分, 分别作为所述 UMTS AV 的所述 CK和所述 IK。 49. The access network element according to claim 48, wherein the HSS converting the EPS AV into the UMTS AV format includes: The HSS uses the RAND in the EPS AV as the RAND of the UMTS AV, the HSS uses the AUTN in the EPS AV as the AUTN of the UMTS AV, and the HSS uses the XRES in the EPS AV as The XRES of the UMTS AV and the HSS split the KASME (256 bits) in the EPS AV into two parts, which are respectively used as the CK and the IK of the UMTS AV.
50. 根据权利要求 45至 49任一项所述的接入网网元, 其特征在于, 所述处理模块进一步用于按照生成规则 KASME=CKIIIK , 根据所述 CK 和或 IK生成所述 KASME 50. The access network element according to any one of claims 45 to 49, characterized in that the processing module is further configured to generate the K according to the generation rule KASME =CKIIIK according to the CK and or IK ASME .
PCT/CN2013/070839 2013-01-22 2013-01-22 Method and network device for security authentication of mobile communication system WO2014113920A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2013/070839 WO2014113920A1 (en) 2013-01-22 2013-01-22 Method and network device for security authentication of mobile communication system
CN201380070864.4A CN104937990B (en) 2013-01-22 2013-01-22 The method and the network equipment of the safety certification of mobile communication system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2013/070839 WO2014113920A1 (en) 2013-01-22 2013-01-22 Method and network device for security authentication of mobile communication system

Publications (1)

Publication Number Publication Date
WO2014113920A1 true WO2014113920A1 (en) 2014-07-31

Family

ID=51226805

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/070839 WO2014113920A1 (en) 2013-01-22 2013-01-22 Method and network device for security authentication of mobile communication system

Country Status (2)

Country Link
CN (1) CN104937990B (en)
WO (1) WO2014113920A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101998348A (en) * 2009-08-25 2011-03-30 中兴通讯股份有限公司 Charging system and charging method thereof
CN101730193B (en) * 2009-06-09 2012-06-13 中兴通讯股份有限公司 Method and system for selecting gateway node
US20120159151A1 (en) * 2010-12-21 2012-06-21 Tektronix, Inc. Evolved Packet System Non Access Stratum Deciphering Using Real-Time LTE Monitoring
WO2012095197A1 (en) * 2011-01-13 2012-07-19 Telefonaktiebolaget L M Ericsson (Publ) Roaming control for ims apn

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2009002841A1 (en) * 2007-06-22 2008-12-31 Interdigital Technology Corporation Method and apparatus for resource management in handover operation
WO2009056938A2 (en) * 2007-10-29 2009-05-07 Nokia Corporation System and method for authenticating a context transfer
CN101909368B (en) * 2009-06-08 2012-06-27 上海贝尔股份有限公司 Wireless network security solution method and equipment
CN101600205B (en) * 2009-07-10 2011-05-04 华为技术有限公司 Method and related device for accessing SIM card user equipment to evolution network

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101730193B (en) * 2009-06-09 2012-06-13 中兴通讯股份有限公司 Method and system for selecting gateway node
CN101998348A (en) * 2009-08-25 2011-03-30 中兴通讯股份有限公司 Charging system and charging method thereof
US20120159151A1 (en) * 2010-12-21 2012-06-21 Tektronix, Inc. Evolved Packet System Non Access Stratum Deciphering Using Real-Time LTE Monitoring
WO2012095197A1 (en) * 2011-01-13 2012-07-19 Telefonaktiebolaget L M Ericsson (Publ) Roaming control for ims apn

Also Published As

Publication number Publication date
CN104937990B (en) 2019-06-21
CN104937990A (en) 2015-09-23

Similar Documents

Publication Publication Date Title
CN111670587B (en) Method and apparatus for multiple registrations
CN109587688B (en) Security in inter-system mobility
JP6727294B2 (en) User equipment UE access method, access device, and access system
CN108781216B (en) Method and apparatus for network access
US20200162913A1 (en) Terminal authenticating method, apparatus, and system
RU2665064C1 (en) Wireless communication, including framework for detecting fast initial communication lines, fils, for network signaling
WO2020221324A1 (en) Registration method and communication apparatus
CN112219415A (en) User authentication in a first network using a subscriber identity module for a second, old network
KR20170102864A (en) Mutual authentication between user equipment and an evolved packet core
JP2010533390A (en) Method, system, and apparatus for negotiating security functions when a terminal moves
WO2015195022A1 (en) Methods and arrangements for identification of user equipments for authentication purposes
CN110583036A (en) Network authentication method, network equipment and core network equipment
WO2013152740A1 (en) Authentication method, device and system for user equipment
WO2014113922A1 (en) Method and network device for security authentication of mobile communication system
WO2014113921A1 (en) Method and network device for security authentication of mobile communication system
CN110226319A (en) Method and apparatus for the parameter exchange during promptly accessing
US10390224B2 (en) Exception handling in cellular authentication
WO2014113920A1 (en) Method and network device for security authentication of mobile communication system
JP2021524167A (en) Methods and devices for multiple registrations
WO2014113918A1 (en) Method and network device for security authentication of mobile communication system
US20230231708A1 (en) Method and apparatus for multiple registrations

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13872483

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13872483

Country of ref document: EP

Kind code of ref document: A1