WO2018196587A1 - User authentication method and apparatus in converged network - Google Patents

User authentication method and apparatus in converged network Download PDF

Info

Publication number
WO2018196587A1
WO2018196587A1 PCT/CN2018/082289 CN2018082289W WO2018196587A1 WO 2018196587 A1 WO2018196587 A1 WO 2018196587A1 CN 2018082289 W CN2018082289 W CN 2018082289W WO 2018196587 A1 WO2018196587 A1 WO 2018196587A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
network element
terminal device
type
parameter
Prior art date
Application number
PCT/CN2018/082289
Other languages
French (fr)
Chinese (zh)
Inventor
李汉成
于游洋
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2018196587A1 publication Critical patent/WO2018196587A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/062Pre-authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a user authentication method and apparatus in a converged network.
  • the mobile terminal device from the Third Generation Partnership Project (3 rd Generation Partnership Project, 3GPP ) network access bearer extensible authentication protocol (Extensible Authentication Protocol-based non-access stratum (Non-access stratum, NAS) , EAP) completes access authentication to the mobile core network.
  • 3GPP Third Generation Partnership Project
  • 3GPP Third Generation Partnership Project
  • EAP Extensible Authentication Protocol-based non-access stratum
  • the Customer Premises Equipment also known as the customer front-end equipment, is based on Ethernet Point to Point Protocol over Ethernet (PPPoE) or Ethernet Protocol over Ethernet (IPoE).
  • PPPoE Point to Point Protocol over Ethernet
  • IPoE Ethernet Protocol over Ethernet
  • the prior art cannot implement the fixed network terminal accessing the mobile core network. Therefore, for scenarios where both fixed and mobile networks need to be supported, two core networks need to be deployed to manage the mobile terminal and the fixed network terminal respectively, which will bring about a problem of high network cost.
  • next-generation communication network architecture As shown in the schematic diagram of the next-generation communication system architecture shown in FIG.
  • the architecture supports not only standard 3GPP defined set of wireless technologies (e.g., long term evolution (Long Term Evolution, LTE), a fifth-generation mobile communication (5 th Generation, 5G), etc.) access the core network side (Core network), and supports non
  • the 3GPP access technology can access the core network side through a non-3GPP Interworking Function (N3IWF) or a next generation packet data gateway (ngPDG) to implement a converged network.
  • N3IWF non-3GPP Interworking Function
  • ngPDG next generation packet data gateway
  • the application provides a user authentication method and device in a converged network to solve the user authentication problem in the converged network.
  • An aspect of the present application provides a user authentication method in a converged network, where the method includes: an access network element receives an authentication negotiation request from a terminal device, where the authentication negotiation request is used to negotiate to determine the terminal device.
  • An authentication parameter the access network element sends an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element; and the access network element receives At least one authentication parameter from the control network element and transmitting the at least one authentication parameter to the terminal device, the at least one authentication parameter corresponding to the access protocol type, each type of authentication parameter includes a type An authentication type, and/or a parameter corresponding to the authentication type; the access network element determines one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter, Obtaining the user authentication information of the terminal device, and sending the user authentication information and the determined one of the authentication parameters to the control network element for authentication; NE receives an authentication result from the control network element and transmitting the authentication result to the
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device.
  • the terminal device may also provide the supported authentication type, but the authentication type is used for the terminal device to negotiate with the access network element, and the control network element may preferably use the authentication supported by the terminal device. Types of.
  • the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
  • PAP is a simple type of authentication that enables fast authentication.
  • the at least one type of authentication includes a challenge handshake protocol CHAP
  • the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  • CHAP is a highly secure authentication type that enables secure and reliable authentication.
  • the terminal device includes a mobile terminal device or a fixed network terminal device.
  • Another aspect of the present application provides a user authentication method in a converged network, where the method includes: the terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine the terminal device.
  • An authentication parameter the terminal device receives at least one authentication parameter from the access network element, the at least one authentication parameter corresponding to the access protocol type, each authentication parameter includes an authentication type, and/ Or a parameter corresponding to the authentication type; the terminal device determines one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter, and sends the authentication parameter to the access network
  • the element transmits user authentication information; the terminal device receives an authentication result from the access network element.
  • user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device.
  • the terminal device may also provide the requested authentication type, but which authentication type is used for authentication, and the terminal device needs to negotiate with the access network element, and the control network element may preferably adopt the authentication supported by the terminal device. Types of.
  • the terminal device includes a mobile terminal device or a fixed network terminal device.
  • a further aspect of the present application provides a user authentication method in a converged network, the method comprising: controlling a network element to receive an authentication parameter request from an access network element, where the authentication parameter request includes: a terminal device access station An access protocol type of the access network element, where the control network element generates at least one authentication parameter according to the authentication parameter request, and sends the at least one authentication parameter to the access network element, where At least one type of authentication parameter corresponding to the access protocol type, each type of authentication parameter includes a type of authentication supported by the authentication parameter request, and/or a parameter corresponding to the type of the authentication; the control network Receiving, by the UE, the user authentication information from the access network element, and one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter, and adopting the determined An authentication parameter is used to authenticate the user authentication information, and the authentication result is obtained; the control network element sends the authentication result to the access network element.
  • the authentication parameter request includes: a terminal device access station An access protocol type of the
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device.
  • the terminal device may also provide the requested authentication type, but which authentication type is used for authentication, and the terminal device needs to negotiate with the access network element, and the control network element may preferably adopt the authentication supported by the terminal device. Types of.
  • the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
  • PAP is a simple type of authentication that enables fast authentication.
  • the at least one type of authentication includes a challenge handshake protocol CHAP
  • the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  • CHAP is a highly secure authentication type that enables secure and reliable authentication.
  • the terminal device includes a mobile terminal device or a fixed network terminal device.
  • an access network element is provided, and the access network element has a function of implementing access network element behavior in the foregoing method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the method and the beneficial effects of the above-mentioned possible access network elements can be referred to the implementation of the method and the beneficial effects. Therefore, the implementation of the device can refer to the implementation of the method, and the method is repeated. I won't go into details here.
  • a terminal device having a function of implementing the behavior of the terminal device in the above method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the principle and the beneficial effects of the device can be referred to the method embodiments of the foregoing possible terminal devices and the beneficial effects thereof. Therefore, the implementation of the device can refer to the implementation of the method, and the repetition is not Let me repeat.
  • a control network element is provided, and the control network element has a function of implementing the behavior of controlling a network element in the foregoing method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the principle and the beneficial effects of the device can be referred to the method embodiments of the foregoing possible control network elements and the beneficial effects thereof. Therefore, the implementation of the device can be referred to the implementation of the method. No longer.
  • a user authentication method in a converged network comprising: an access network element receiving an authentication negotiation request from a terminal device, where the authentication negotiation request is used to request negotiation to determine the The type of authentication for the terminal device to perform user authentication; the access network element determines that the authentication type of the terminal device for user authentication is plaintext authentication; and the access network element receives user authentication information from the terminal device, and The user authentication information and the authentication type are sent to the control network element for authentication; the access network element receives the authentication result from the control network element and sends the authentication result to the terminal device.
  • the access network element determines that the authentication type of the terminal device is plaintext authentication
  • the method includes: configuring, by the access network element, that the authentication type of the terminal device is plaintext authentication; And sending, by the terminal device, an authentication type negotiation request, where the negotiation request is used to negotiate that the authentication type is plaintext authentication; and the access network element receives a first negotiation feedback message from the terminal device, where the A negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plain text authentication.
  • the access network element determines that the authentication type of the terminal device is plain text authentication
  • the method includes: determining, by the access network element, that the authentication type of the terminal device is a plaintext according to the authentication negotiation request. Authentication, wherein the authentication negotiation request is further used to indicate that the authentication type supported by the terminal device is plaintext authentication; the access network element sends a second negotiation feedback message to the terminal device, where the second negotiation feedback is The message is used to indicate that the access network element agrees that the authentication type is plain text authentication.
  • the terminal device includes a mobile terminal device or a fixed network terminal device.
  • a still further aspect of the present application provides a user authentication method in a converged network, where the method includes: the terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to request negotiation to determine the terminal.
  • the authentication type of the device for user authentication the terminal device determines that the authentication type of the user authentication is plain text authentication; the terminal device sends user authentication information to the access network element; and the terminal device receives the access network element from the access network element.
  • Certification results.
  • user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element directly determine that the authentication type is plaintext.
  • Authentication eliminates the need to request authentication parameters from the control network element, simplifying the authentication process.
  • the terminal device determines that the authentication type of the user authentication is plain text authentication, and the method includes: the terminal device receives a negotiation request from the access network element, and the negotiation request is used to negotiate the authentication type.
  • the terminal device sends a first negotiation feedback message to the access network element, where the first negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plain text authentication.
  • the terminal device determines that the authentication type of the user authentication is plain text authentication, and the method includes: the terminal device receives a second negotiation feedback message from the access network element, and the second negotiation feedback message And indicating that the access network element agrees that the authentication type is plaintext authentication.
  • the terminal device includes a mobile terminal device or a fixed network terminal device.
  • an access network element has a function of implementing access network element behavior in the foregoing method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the method and the beneficial effects of the above-mentioned possible access network elements can be referred to the implementation of the method and the beneficial effects. Therefore, the implementation of the device can refer to the implementation of the method, and the method is repeated. I won't go into details here.
  • a terminal device having a function of implementing a behavior of a terminal device in the above method.
  • the functions may be implemented by hardware or by corresponding software implemented by hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the principle and the beneficial effects of the device can be referred to the method embodiments of the foregoing possible terminal devices and the beneficial effects thereof. Therefore, the implementation of the device can refer to the implementation of the method, and the repetition is not Let me repeat.
  • Yet another aspect of the present application provides a computer readable storage medium having instructions stored therein that, when executed on a computer, cause the computer to perform the methods described in the above aspects.
  • Yet another aspect of the present application provides a computer program product comprising instructions which, when run on a computer, cause the computer to perform the methods described in the various aspects above.
  • FIG. 1 is a schematic diagram of an exemplary communication system architecture
  • FIG. 2 is a schematic diagram of interaction of a user authentication method in a converged network according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of interaction of another user authentication method in a converged network according to an embodiment of the present disclosure
  • FIG. 4 is a schematic diagram of a module for accessing a network element according to an embodiment of the present disclosure
  • FIG. 5 is a schematic diagram of a module of a terminal device according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic diagram of a module for controlling a network element according to an embodiment of the present disclosure
  • FIG. 7 is a schematic diagram of another module for accessing a network element according to an embodiment of the present disclosure.
  • FIG. 8 is a schematic diagram of another terminal device according to an embodiment of the present disclosure.
  • FIG. 9 is a schematic diagram of a hardware architecture of an access network element/terminal device/control network element according to an embodiment of the present invention.
  • the communication system involved in the embodiments of the present invention mainly includes: an access network element, a user plane function network element, and a control plane network element.
  • the control plane network element may also be referred to as a control network element.
  • the access network element is mainly responsible for access management of the terminal equipment (User Equipment, UE), and the user plane function network element is mainly responsible for packet data packet forwarding, QoS control, accounting information statistics, etc.; the control plane function network element is mainly responsible for User authentication, sending packet forwarding policies to users, QoS control policies, and so on.
  • the communication system may be a 5G communication system (for example, a New Radio (NR) system, a communication system in which a plurality of communication technologies are integrated (for example, a communication system in which LTE technology and NR technology are integrated), or a subsequent evolved communication system.
  • the terminal device in the example may be a fixed network terminal device; or may be a mobile terminal device, for example, a handheld device having a wireless communication function, an in-vehicle device, a wearable device, a computing device, or other processing device connected to the wireless modem.
  • Terminal devices in different networks may be called different names, such as: user equipment, access terminals, subscriber units, subscriber stations, mobile stations, mobile stations, remote stations, remote terminals, mobile devices, user terminals, terminals, wireless communications.
  • Device, user agent or user device cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, Wireless Local Loop (WLL) station, Personal Digital Assistant (PDA), Terminal equipment in a 5G network or a future
  • the embodiments of the present invention mainly relate to communication between a terminal device, an access network element, and a control network element, and perform user authentication.
  • the terminal device requests the negotiation to determine the authentication parameter of the terminal device by sending an authentication negotiation request, where the authentication negotiation request includes the access protocol type of the terminal device, and the access network element sends an authentication parameter request to the control network element to control
  • the network element generates at least one type of authentication parameter corresponding to the access protocol type of the terminal device, and sends the authentication parameter to the access network element, and the access network element negotiates with the terminal device to determine a type supported by the terminal device and the control network element.
  • the authentication parameter, the access network element sends the determined authentication parameter and the user authentication information received from the terminal device to the control network element for user authentication, and obtains the authentication result. Therefore, the user authentication method and device in the converged network provided by the embodiment of the present invention enable user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably. .
  • FIG. 1 is a schematic diagram of an exemplary 5G communication system architecture.
  • the access network element Access Network, AN
  • the radio access network element Radio Access Network, RAN
  • the user plane function network element UPF
  • Yuan Control Plane, CP
  • the AN, the UPF, and the CP respectively correspond to the access network element, the user plane function network element, and the control plane function network element described above.
  • UPF is mainly responsible for packet data packet forwarding, QoS control, accounting information statistics, etc.
  • the CP is mainly responsible for sending data packet forwarding policies and QoS control policies to the user plane.
  • the CP specifically includes an Access and Mobility Management Funnel (AMF), a Session Management Funnel (SMF), an Authentication Service Function (AUSF), and a unified data management network.
  • AMF Access and Mobility Management Funnel
  • SMF Session Management Funnel
  • AUSF Authentication Service Function
  • UDM Unified Data Management
  • PCF Policy Control Function
  • AF Application Function Network
  • AMF is used for access management in a converged network
  • UDM is used to manage user subscription information.
  • the types of access protocols that the UE accesses the converged network include PPPoE, 802.1X, and so on.
  • the PPPoE discovery process may be performed between the UE and the AN.
  • the discovery process may include the following steps (not shown):
  • Step 1 The UE discovers the access network and sends a PPPoE Active Discovery Initiation (PADI) to the AN to initiate the PPPoE discovery process.
  • PADI PPPoE Active Discovery Initiation
  • the discovery of the access network is a logical process to illustrate the point in time when the PADI is initiated. Generally, when the UE is powered on and establishes a physical link, it is considered to be connected to the network; or it may be manual, such as clicking a PPPoE connection.
  • Step 2 AN selects AMF.
  • AMF is a component of CP, responsible for access and mobility management, as shown in Figure 1, but this embodiment describes the CP as a whole, but only when it specifically refers to the AMF component of the CP, The interaction of the AN with the AMF component is described in this step.
  • the AN may select the AMF based on a prior configuration or an access protocol type of the UE or the like.
  • Step 3 The AN generates a Registration NAS message according to the received PADI from the UE, and sends the message to the CP.
  • the Registration NAS message can also be said to be generated by the UE and then sent to the AN, which is not limited herein.
  • the registration NAS message carries the Network Access Identity (NAI), and the NAI contains user information from the PADI, such as: device identification, circuit ID, virtual local area network identifier (Vlan ID), user physics. At least one of the address (user MAC) and the host name.
  • NAI Network Access Identity
  • Step 4 The AN and the core network side complete the authentication and registration process according to the existing definition, and then the AN and the UE side complete the PPPoE discovery process. Specifically, the method further includes: Step 41) completing the authentication process of the AN and the core network, where the AN replaces the UE in response to the NAS message; Step 42) The core network side answers the registration completion message; Step 43) The AN allocates the session identifier ( Session ID), completes the PPPoE discovery process with the UE.
  • Session ID session identifier
  • a PPPoE session process may be performed, where the PPPoE session process includes user authentication, IP address allocation, and formal session.
  • Embodiments of the present invention generally relate to a user authentication process therein.
  • FIG. 2 is a schematic diagram of interaction of a user authentication method in a converged network according to an embodiment of the present invention, where the method is applicable to the foregoing communication system. Specifically, the method can include the following steps:
  • the terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device.
  • the access protocol type of the UE accessing the converged network includes the PPPoE, the 802.1X, and the Dynamic Host Configuration Protocol (DHCP).
  • the AN can configure the access protocol type of the UE, or can be an AN according to the AN.
  • the user packet of the UE received in the PPPoE discovery process determines the access protocol type of the UE, which is not limited herein.
  • Each access protocol type can correspond to one or more authentication parameters, and the same authentication parameters are required between the UE and the CP for authentication, so that the user authentication process can be successfully completed. Therefore, based on these protocols, the access network is used for user authentication.
  • the authentication parameters are negotiated between the UE and the AN.
  • the PPPoE access protocol is used as an example
  • the UE sends a Link Control Protocol (LCP) negotiation request to the AN as an authentication negotiation request
  • the LCP negotiation request is used to negotiate to determine the UE's authentication parameter, the LCP.
  • the negotiation request includes the type of access protocol that the UE accesses the AN.
  • the authentication parameter includes an authentication type and a parameter corresponding to the authentication type.
  • the AN receives an LCP negotiation request from the UE.
  • LCP Link Control Protocol
  • the LCP negotiation request may also include an authentication type supported by the UE, or an authentication type that the UE expects to perform.
  • the access network element sends an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element.
  • the AN constructs an authentication parameter request, and the authentication parameter request includes an access protocol type in which the terminal device accesses the AN.
  • the AN then sends an authentication parameter request to the CP.
  • the CP receives an authentication parameter request from the AN.
  • the AN may choose to carry the authentication type supported by the UE in the authentication parameter request, or may choose not to carry the authentication type supported by the UE in the authentication parameter request. If the AN does not carry the authentication type supported by the UE, and the authentication parameter received by the AN from the CP is all the authentication parameters supported by the CP corresponding to the access protocol type, the authentication parameters received by the AN from the CP generally include the UE. The type of authentication supported.
  • the control network element generates, according to the authentication parameter request, at least one type of authentication parameter, where each type of authentication parameter includes: determining, according to the authentication parameter request, a type of authentication supported, and/or corresponding to the type of authentication. Parameters.
  • the CP selects one or more types of authentication corresponding to the type of the access protocol according to the type of the access protocol included in the authentication parameter request. Then, since the CP has previously completed the authentication and registration process with the UE, the CP has been configured according to the UE.
  • the user information obtains the user subscription information of the UE (the user subscription information is previously stored in the UDM), and therefore, the CP generates parameters corresponding to each authentication type according to the user subscription information of the UE and the selected authentication type.
  • the CP itself stores the authentication parameters. Specifically, the authentication parameters are generated by the AUSF module in the CP.
  • Authentication types include the Password Authentication Protocol (PAP) or the Challenge Handshake Authentication Protocol (CHAP).
  • PAP the corresponding parameter is null, that is, its parameter is: ⁇ PAP: NULL ⁇ , or the parameter corresponding to PAP is not included in the authentication parameter.
  • CHAP its corresponding parameters include: algorithm, challenge identifier, and/or challenge identifier length, for example, its parameters are: ⁇ CHAP: ⁇ algorithm: 5 (MD5); Challenge ID Length: 16; Challenge ID: *** * ⁇ .
  • the CP priority response only supports the authentication type, and provides corresponding Parameter information. For example, if the authentication type requested by the UE is PAP, and the CP supports both the PAP and CHAP authentication types, the type of authentication that the CP can answer is PAP.
  • the control network element sends the at least one authentication parameter to the access network element.
  • the access network element sends the at least one authentication parameter to the terminal device.
  • the CP sends the generated one or more authentication parameters to the AN, and the AN receives at least one authentication parameter from the CP.
  • the AN sends the received one or more authentication parameters to the UE, and the UE receives at least one authentication parameter from the AN.
  • the access network element determines, in the at least one type of authentication parameter, one of the authentication parameters supported by the terminal device and the control network element.
  • the terminal device determines, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element.
  • the negotiation process may be implemented in multiple ways: the AN may send a negotiation request to the UE, the UE feeds back the authentication type supported by the UE, and then the AN responds; or the UE sends a negotiation request to the AN, the negotiation.
  • the request carries the type of authentication supported by the UE, and the AN responds.
  • the AN negotiates with the UE to determine one of the authentication parameters supported by the UE and the CP.
  • the AN may respond to the CP support or not support the authentication type, or the AN allows the UE to re-feed back one or more authentications sent.
  • the type of authentication supported by the UE in the type is not limited.
  • the terminal device sends user authentication information to the access network element.
  • the UE After the UE negotiates with the AN to determine the authentication type, the UE sends the user authentication information corresponding to the authentication type to the AN.
  • the user authentication information is, for example, a username and a password.
  • the AN receives user authentication information from the UE.
  • the access network element sends the user authentication information and the determined one of the authentication parameters to the control network element for authentication.
  • the AN will negotiate with the UE to determine the good authentication parameters (specifically, the authentication type is negotiated), and the user authentication information sent by the UE is sent to the CP for authentication.
  • the CP receives user authentication information from the AN and one of the determined authentication parameters.
  • the control network element authenticates the user authentication information by using the determined one of the authentication parameters, and obtains an authentication result.
  • the CP obtains the comparison information according to the authentication parameters. For example, if it is a CHAP authentication type, the authentication parameter determined by the negotiation and the user subscription information are used for calculation, and the comparison information is obtained; if it is the PAP authentication type, the user subscription information is directly obtained as the comparison information. The comparison process and the user authentication information are then used for comparison to complete the authentication process.
  • the comparison process is: user subscription information is (user name: A, password: B); authentication parameters are, for example, ⁇ algorithm: 5 (MD5); Change ID Length: 16; Change ID: C ⁇
  • MD5 ⁇ algorithm
  • Change ID Length 16
  • Change ID: C Change ID: C
  • the CP receives the user authentication information as: (user name: A, password: D)
  • the password B in the user subscription information and the challenge identifier C in the authentication parameter are used for MD5 calculation, and the digital string E is calculated, and then the ratio is calculated. Correct.
  • the user name is A. If the password D and the numeric string E are equal, the user is legal, otherwise it is illegal.
  • the comparison user name is A
  • the password D and the subscription information B are directly compared. If they are equal, the user is legal, otherwise it is illegal.
  • the control network element sends the authentication result to the access network element.
  • the authentication result includes the authentication, the user is a legitimate user, or the authentication fails.
  • the user is an illegal user.
  • the CP sends the authentication result to the AN, and the AN receives the authentication result from the CP.
  • the access network element sends the authentication result to the terminal device.
  • the AN notifies the UE of the authentication result of the CP, and the UE receives the authentication result from the AN.
  • the UE can be a mobile terminal device or a fixed network terminal device. Any terminal device can access the converged network for user authentication in this manner, so that any terminal device can access the converged network securely and reliably.
  • the user authentication method in the converged network implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • FIG. 3 is a schematic diagram of interaction of another user authentication method in a converged network according to an embodiment of the present invention, where the method is applicable to the foregoing communication system. Specifically, the method can include the following steps:
  • the terminal device sends an authentication negotiation request to the access network element.
  • the UE sends an authentication negotiation request to the AN to perform user authentication.
  • the authentication negotiation request is used to request negotiation to determine the type of authentication in which the UE performs user authentication.
  • the authentication negotiation request may be used to indicate that the authentication type supported by the UE is plaintext authentication. In another implementation manner, the authentication negotiation request does not include the indication.
  • the AN receives an authentication negotiation request from the UE.
  • the access network element and the terminal device determine that the authentication type of the terminal device for user authentication is plaintext authentication.
  • the authentication type of the plain text authentication (that is, PAP authentication) is adopted, and the AN does not need to obtain the authentication parameter from the CP, and the AN and the UE directly determine that the authentication type for performing user authentication is plain text authentication.
  • the access network element determines that the authentication type of the terminal device is a plaintext authentication, and the method includes: configuring, by the access network element, that the authentication type of the terminal device is a plaintext
  • the access network element sends an authentication type negotiation request to the terminal device, where the negotiation request is used to negotiate that the authentication type is plaintext authentication; and the access network element receives the first from the terminal device.
  • the first negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plaintext authentication.
  • the terminal device determines that the authentication type of the user authentication is plain text authentication, and the method includes: the terminal device receives a negotiation request from the access network element, and the negotiation request is used to negotiate that the authentication type is plaintext.
  • the terminal device sends a first negotiation feedback message to the access network element, where the first negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plaintext authentication.
  • the AN configures the authentication type of the UE to be plaintext authentication, and then negotiates with the UE.
  • the access network element determines that the authentication type of the terminal device is plaintext authentication, and the method includes: determining, by the access network element, the terminal device according to the authentication negotiation request.
  • the authentication type is a plain text authentication
  • the authentication negotiation request is further used to indicate that the authentication type supported by the terminal device is plaintext authentication
  • the access network element sends a second negotiation feedback message to the terminal device, where The second negotiation feedback message is used to indicate that the access network element agrees that the authentication type is plain text authentication.
  • the terminal device determines that the authentication type of the user authentication is the plain text authentication, and the method includes: the terminal device receives a second negotiation feedback message from the access network element, where the second negotiation feedback message is used to indicate The access network element agrees that the authentication type is plain text authentication.
  • the UE indicates in the authentication negotiation request that the supported authentication type is plain text authentication, and then the AN feeds back whether it agrees to adopt the authentication type of the plain text authentication, thereby completing the negotiation process.
  • the terminal device sends user authentication information to the access network element.
  • the UE After the UE negotiates with the AN to determine that the authentication type is plaintext authentication, the UE sends the user authentication information corresponding to the authentication type to the AN.
  • the AN receives user authentication information from the UE.
  • the user authentication information is, for example, a username and a password.
  • the access network element sends the user authentication information and the authentication type to the control network element for authentication.
  • the AN authenticates the user authentication information and the authentication type as a plain text authentication notification CP, and the user authenticates the user authentication information.
  • the CP receives user authentication information and authentication type from the AN.
  • the user subscription information is (user name: A, password: B).
  • the CP receives the user authentication information as: (user name: A, password: D)
  • the comparison user name is A
  • the password is directly compared.
  • D and the contract information B are equal. If they are equal, the user is legal, otherwise it is illegal.
  • the control network element authenticates the user authentication information according to the authentication type, and obtains an authentication result.
  • the control network element sends the authentication result to the access network element.
  • the AN receives the authentication result from the CP.
  • the access network element sends the authentication result to the terminal device.
  • the UE receives the authentication result from the AN.
  • the terminal device and the access network element directly determine that the authentication type is plaintext authentication, and the authentication parameter is not required to be requested from the control network element, which simplifies the authentication process.
  • the UE can directly configure the UE to perform the authentication without the need for the authentication, that is, the authentication is not required.
  • the AN receives the LCP negotiation request, the AN sends the indication that the UE does not need to be authenticated to the UE, and the UE can access the network for subsequent operations. .
  • the user authentication method in the converged network implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device
  • the access network element directly determines that the authentication type is plain text authentication, and does not need to request an authentication parameter from the control network element, which simplifies the authentication process.
  • FIG. 4 is a schematic diagram of a module for accessing a network element according to an embodiment of the present invention.
  • the access network element may be an access network element described in the foregoing communication system.
  • the access network element 1000 includes: a receiving unit 11, a sending unit 12, and a determining unit 13; wherein:
  • the receiving unit 11 is configured to receive an authentication negotiation request from the terminal device, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
  • the sending unit 12 is configured to send an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
  • the receiving unit 11 is further configured to receive at least one authentication parameter from the control network element, where the at least one authentication parameter corresponds to the access protocol type, and each type of authentication parameter includes an authentication type, and / or a parameter corresponding to the type of authentication;
  • the sending unit 12 is further configured to send the at least one authentication parameter to the terminal device;
  • the determining unit 13 is configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
  • the receiving unit 11 is further configured to acquire user authentication information of the terminal device
  • the sending unit 12 is further configured to send the user authentication information and the determined one of the authentication parameters to the control network element for authentication;
  • the receiving unit 11 is further configured to receive an authentication result from the control network element.
  • the sending unit 12 is further configured to send the authentication result to the terminal device.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
  • the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
  • the at least one type of authentication includes a challenge handshake protocol CHAP
  • the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  • An access network element implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • FIG. 5 is a schematic diagram of a module of a terminal device according to an embodiment of the present invention.
  • the terminal device may be a terminal device described in the foregoing communication system.
  • the terminal device 2000 includes: a sending unit 21, a receiving unit 22, and a determining unit 23; wherein:
  • the sending unit 21 is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device.
  • the receiving unit 22 is configured to receive at least one authentication parameter from the access network element, where the at least one authentication parameter corresponds to the access protocol type, each authentication parameter includes an authentication type, and/or a parameter corresponding to the authentication type;
  • a determining unit 23 configured to determine, in the at least one type of authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
  • the sending unit 21 is further configured to send user authentication information to the access network element.
  • the receiving unit 22 is further configured to receive an authentication result from the access network element.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
  • a terminal device implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • FIG. 6 is a schematic diagram of a module for controlling a network element according to an embodiment of the present invention.
  • the control network element may be a control network element described in the foregoing communication system.
  • the control network element 3000 includes: a receiving unit 31, a generating unit 32, a sending unit 33, and an authenticating unit 34; wherein:
  • the receiving unit 31 is configured to receive an authentication parameter request from the access network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
  • the generating unit 32 is configured to generate, according to the authentication parameter request, at least one type of authentication parameter, where the at least one type of authentication parameter corresponds to the access protocol type, and each type of the authentication parameter comprises: supporting according to the authentication parameter request confirmation An authentication type, and/or a parameter corresponding to the authentication type;
  • the sending unit 33 is configured to send the at least one authentication parameter to the access network element
  • the receiving unit 31 is further configured to receive user authentication information from the access network element, and the terminal device and the control network element in the at least one authentication parameter of the access network element An authentication parameter;
  • the authentication unit 34 is configured to authenticate the user authentication information by using the determined one of the authentication parameters to obtain an authentication result.
  • the sending unit 33 is further configured to send the authentication result to the access network element.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
  • the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
  • the at least one type of authentication includes a challenge handshake protocol CHAP
  • the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  • a control network element implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • FIG. 7 is a schematic diagram of another module of an access network element according to an embodiment of the present invention.
  • the access network element may be an access network element in the foregoing communication system.
  • the access network element 4000 may include: a receiving unit 41, a determining unit 42 and a sending unit 43; wherein:
  • the receiving unit 41 is configured to receive an authentication negotiation request from the terminal device, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
  • the determining unit 42 is configured to determine that the authentication type of the terminal device is plain text authentication
  • the receiving unit 41 is further configured to receive user authentication information from the terminal device;
  • the sending unit 43 is configured to send the user authentication information and the authentication type to the control network element for authentication;
  • the receiving unit 41 is further configured to receive an authentication result from the control network element.
  • the sending unit 43 is further configured to send the authentication result to the terminal device.
  • An access network element implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access device
  • the network element directly determines that the authentication type is plain text authentication, and does not need to request authentication parameters from the control network element, which simplifies the authentication process.
  • FIG. 8 is a schematic diagram of another terminal device according to an embodiment of the present disclosure, where the terminal device may be a terminal device in the foregoing communication system.
  • the terminal device 5000 may include: a sending unit 51, a determining unit 52, and a receiving unit 53; wherein:
  • the sending unit 51 is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
  • a determining unit 52 configured to determine that the authentication type of the user authentication is plaintext authentication
  • the sending unit 51 is further configured to send user authentication information to the access network element.
  • the receiving unit 53 is configured to receive an authentication result from the access network element.
  • a terminal device implements user authentication when any terminal device accesses a converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element
  • the authentication type is directly determined to be plain text authentication, and the authentication parameters are not required to be requested from the control network element, which simplifies the authentication process.
  • the embodiment of the present invention further provides an access network element, where the access network element can be an access network element in the foregoing communication system, and the access network element can adopt the hardware architecture shown in FIG.
  • the access network element can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus.
  • the related functions implemented by the receiving unit 11 in FIG. 4 may be implemented by a receiver, and related functions implemented by the transmitting unit 12 may be implemented by a transmitter, and related functions implemented by the determining unit 13 may pass through one or more processors. to realise.
  • the memory includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an Erasable Programmable Read Only Memory (EPROM), or a portable Compact Disc Read-Only Memory (CD-ROM), which is used for related instructions and data.
  • RAM random access memory
  • ROM read-only memory
  • EPROM Erasable Programmable Read Only Memory
  • CD-ROM portable Compact Disc Read-Only Memory
  • the receiver is for receiving data and/or signals
  • the transmitter is for transmitting data and/or signals.
  • the transmitter and receiver can be separate devices or a single device.
  • the processor may include one or more processors, for example, including one or more central processing units (CPUs).
  • CPUs central processing units
  • the CPU may be a single-core CPU, or may be Multi-core CPU.
  • the memory is used to store program code and data of the network device.
  • the receiver is configured to receive an authentication negotiation request from a terminal device, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
  • the transmitter is configured to send an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
  • the receiver is further configured to receive at least one authentication parameter from the control network element, where the at least one authentication parameter corresponds to the access protocol type, each authentication parameter includes an authentication type, and/or a parameter corresponding to the authentication type;
  • the transmitter is further configured to send the at least one authentication parameter to the terminal device;
  • the processor is configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
  • the receiver is further configured to acquire user authentication information of the terminal device
  • the transmitter is further configured to send the user authentication information and the determined one of the authentication parameters to the control network element for authentication;
  • the receiver is further configured to receive an authentication result from the control network element
  • the transmitter is further configured to send the authentication result to the terminal device.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
  • the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
  • the at least one type of authentication includes a challenge handshake protocol CHAP
  • the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  • Figure 9 only shows a simplified design of the access network element.
  • the access network element may further include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all access network elements that can implement the embodiments of the present invention. All are within the scope of the invention.
  • An access network element implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • the embodiment of the present invention further provides a terminal device, which may be a terminal device in the foregoing communication system, and the terminal device may adopt the hardware architecture shown in FIG.
  • the terminal device may include a receiver, a transmitter, a memory, and a processor, the receiver, the transmitter, the memory, and the processor being connected to each other by a bus.
  • the related functions implemented by the transmitting unit 21 in FIG. 5 may be implemented by a transmitter, and related functions implemented by the receiving unit 22 may be implemented by a receiver, and related functions implemented by the determining unit 23 may pass through one or more processors. to realise.
  • the memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
  • the receiver is for receiving data and/or signals
  • the transmitter is for transmitting data and/or signals.
  • the transmitter and receiver can be separate devices or a single device.
  • the processor may include one or more processors, for example including one or more CPUs.
  • the processor may be a single core CPU or a multi-core CPU.
  • the memory is used to store program code and data of the terminal device.
  • the transmitter is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
  • the receiver is configured to receive at least one authentication parameter from the access network element, the at least one authentication parameter corresponding to the access protocol type, each authentication parameter including an authentication type, and/or a parameter corresponding to the authentication type;
  • the processor is configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
  • the transmitter is further configured to send user authentication information to the access network element
  • the receiver is further configured to receive an authentication result from the access network element.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
  • Figure 9 only shows a simplified design of the terminal device.
  • the terminal device may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all terminal devices that can implement the present invention are protected by the present invention.
  • the terminal device may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all terminal devices that can implement the present invention are protected by the present invention.
  • a terminal device implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • the embodiment of the present invention further provides a hardware architecture diagram of the control network element, where the control network element may be a control network element in the foregoing communication system, and the control network element may adopt the hardware architecture shown in FIG.
  • the control network element can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus.
  • the related functions implemented by the receiving unit 31 in FIG. 6 may be implemented by a receiver, and related functions implemented by the transmitting unit 33 may be implemented by a transmitter, and related functions implemented by the generating unit 32 and the authenticating unit 34 may be performed by one or Implemented by multiple processors.
  • the memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
  • the receiver is for receiving data and/or signals
  • the transmitter is for transmitting data and/or signals.
  • the transmitter and receiver can be separate devices or a single device.
  • the processor may include one or more processors, for example including one or more CPUs.
  • the processor may be a single core CPU or a multi-core CPU.
  • the memory is used to store program code and data for controlling the network element.
  • the receiver is configured to receive an authentication parameter request from an access network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
  • the processor is configured to generate, according to the authentication parameter request, at least one type of authentication parameter, where the at least one type of authentication parameter corresponds to the access protocol type, and each type of the authentication parameter includes a request for confirmation according to the authentication parameter request.
  • the transmitter is configured to send the at least one authentication parameter to the access network element
  • the receiver is further configured to receive user authentication information from the access network element, and one of the terminal device and the control network element supported by the at least one authentication parameter of the access network element.
  • the processor is further configured to perform authentication on the user authentication information by using the determined one of the authentication parameters to obtain an authentication result;
  • the transmitter is further configured to send the authentication result to the access network element.
  • the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
  • the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
  • the at least one type of authentication includes a challenge handshake protocol CHAP
  • the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  • control network element may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all control network elements that can implement the present invention are in the present invention. Within the scope of protection.
  • a control network element implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
  • the embodiment of the present invention further provides another access network element, where the access network element may be an access network element in the foregoing communication system, and the access network element may adopt the hardware architecture shown in FIG.
  • the access network element can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus.
  • the related functions implemented by the receiving unit 41 in FIG. 7 may be implemented by a receiver, the related functions implemented by the transmitting unit 43 may be implemented by a transmitter, and the related functions implemented by the determining unit 42 may be passed through one or more processors. to realise.
  • the memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
  • the receiver is for receiving data and/or signals
  • the transmitter is for transmitting data and/or signals.
  • the transmitter and receiver can be separate devices or a single device.
  • the processor may include one or more processors, for example including one or more CPUs.
  • the processor may be a single core CPU or a multi-core CPU.
  • the memory is used to store program code and data of the access network element.
  • the receiver is configured to receive an authentication negotiation request from a terminal device, where the authentication negotiation request is used to request negotiation to determine an authentication type of the terminal device to perform user authentication.
  • the processor is configured to determine that the authentication type of the terminal device is plain text authentication
  • the receiver is further configured to receive user authentication information from the terminal device
  • the transmitter is configured to send the user authentication information and the authentication type to a control network element for authentication
  • the transmitter is further configured to receive an authentication result from the control network element
  • the transmitter is further configured to send the authentication result to the terminal device.
  • Figure 9 only shows a simplified design of the access network element.
  • the access network element may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all access network elements that can implement the present invention are Within the scope of protection of the present invention.
  • An access network element implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access device
  • the network element directly determines that the authentication type is plain text authentication, and does not need to request authentication parameters from the control network element, which simplifies the authentication process.
  • the embodiment of the present invention further provides a schematic diagram of a hardware architecture of another terminal device, where the terminal device may be a terminal device in the foregoing communication system, and the terminal device may adopt the hardware architecture shown in FIG.
  • the terminal device can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus 118.
  • the related functions implemented by the receiving unit 53 in FIG. 8 may be implemented by a receiver, the related functions implemented by the transmitting unit 51 may be implemented by a transmitter, and the related functions implemented by the determining unit 52 may be passed through one or more processors. to realise.
  • the memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
  • the receiver is for receiving data and/or signals
  • the transmitter is for transmitting data and/or signals.
  • the transmitter and receiver can be separate devices or a single device.
  • the processor may include one or more processors, for example including one or more CPUs.
  • the processor may be a single core CPU or a multi-core CPU.
  • the memory is used to store program code and data of the terminal device.
  • the transmitter is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
  • the processor is configured to determine that the authentication type of the user authentication is plain text authentication
  • the transmitter is further configured to send user authentication information to the access network element
  • the receiver is configured to receive an authentication result from the access network element.
  • Figure 9 only shows a simplified design of the terminal device.
  • the terminal device may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all terminal devices that can implement the present invention are protected by the present invention.
  • the terminal device may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all terminal devices that can implement the present invention are protected by the present invention.
  • a terminal device implements user authentication when any terminal device accesses a converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element
  • the authentication type is directly determined to be plain text authentication, and the authentication parameters are not required to be requested from the control network element, which simplifies the authentication process.
  • the disclosed systems, devices, and methods may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above embodiments it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof.
  • software it may be implemented in whole or in part in the form of a computer program product.
  • the computer program product includes one or more computer instructions.
  • the computer program instructions When the computer program instructions are loaded and executed on a computer, the processes or functions described in accordance with embodiments of the present invention are generated in whole or in part.
  • the computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable device.
  • the computer instructions can be stored in or transmitted by a computer readable storage medium.
  • the computer instructions can be from a website site, computer, server or data center to another website site by wire (eg, coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (eg, infrared, wireless, microwave, etc.) Transfer from a computer, server, or data center.
  • the computer readable storage medium can be any available media that can be accessed by a computer or a data storage device such as a server, data center, or the like that includes one or more available media.
  • the usable medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (such as a Solid State Disk (SSD)) or the like.
  • the program can be stored in a computer readable storage medium, when the program is executed
  • the flow of the method embodiments as described above may be included.
  • the foregoing storage medium includes various media that can store program codes, such as a ROM or a random access memory RAM, a magnetic disk, or an optical disk.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Disclosed are a user authentication method and apparatus in a converged network. The method comprises: an access network element receives an authentication negotiation request from a terminal device, the authentication negotiation request being used for determining authentication parameters of the terminal device by negotiation, sends an authentication parameter request to a control network element, receives at least one authentication parameter from the control network element, determines, among the at least one authentication parameter, one of authentication parameters that both the terminal device and the control network element support, obtains user authentication information of the terminal device, sends the user authentication information and the authentication parameters determined by negotiation to the control network element for authentication, and receives an authentication result from the control element and sends same to the terminal device. Also disclosed is a corresponding apparatus. The present application implements user authentication during access of any terminal device to a converged network, so that any terminal device can securely and reliably access the converged network.

Description

融合网络中的用户认证方法及装置User authentication method and device in converged network
本申请要求于2017年4月25日提交中国专利局、申请号为201710277650.4、发明名称为“融合网络中的用户认证方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims the priority of the Chinese Patent Application filed on Apr. 25, 2017, the Chinese Patent Application No. PCT Application No. PCT Application No. In the application.
技术领域Technical field
本发明涉及通信技术领域,尤其涉及一种融合网络中的用户认证方法及装置。The present invention relates to the field of communications technologies, and in particular, to a user authentication method and apparatus in a converged network.
背景技术Background technique
目前,移动终端设备从第三代合作伙伴计划(3 rd Generation Partnership Project,3GPP)网络接入时,基于非接入层(Non-access stratum,NAS)承载可扩展的认证协议(Extensible Authentication Protocol,EAP)到移动核心网完成接入认证。 Currently, the mobile terminal device from the Third Generation Partnership Project (3 rd Generation Partnership Project, 3GPP ) network access bearer extensible authentication protocol (Extensible Authentication Protocol-based non-access stratum (Non-access stratum, NAS) , EAP) completes access authentication to the mobile core network.
而固网终端设备(Customer Premises Equipment,CPE,又称客户前端设备)基于以太网的点对点协议(Point to Point Protocol over Ethernet,PPPoE)或基于以太的互联网协议(Internet Protocol over Ethernet,IPoE)到固网核心网完成接入认证。The Customer Premises Equipment (CPE), also known as the customer front-end equipment, is based on Ethernet Point to Point Protocol over Ethernet (PPPoE) or Ethernet Protocol over Ethernet (IPoE). The network core network completes access authentication.
由于固网终端与移动终端支持不同的协议栈,现有技术无法实现固网终端接入移动核心网。因此,对于需同时支持固网与移动网络的场景,需要部署两张核心网,分别管理移动终端与固网终端,这样会带来布网成本较高的问题。Since the fixed network terminal and the mobile terminal support different protocol stacks, the prior art cannot implement the fixed network terminal accessing the mobile core network. Therefore, for scenarios where both fixed and mobile networks need to be supported, two core networks need to be deployed to manage the mobile terminal and the fixed network terminal respectively, which will bring about a problem of high network cost.
为了应对无线宽带技术的挑战,保持3GPP网络的领先优势,3GPP标准组制定了下一代通信网络架构,如图1所示的下一代通信系统架构示意图。该架构不但支持3GPP标准组定义的无线技术(如长期演进(Long Term Evolution,LTE),第五代移动通信(5 th Generation,5G)等)接入核心网络侧(Core network),而且支持non-3GPP接入技术通过non-3GPP转换功能(non-3GPP Interworking Function,N3IWF)或下一代接入网元(next Generation packet data Gateway,ngPDG)接入核心网络侧,即可实现融合网络。而接入网络时,进行用户认证是必须的过程之一,目前尚未有融合网络中如何进行用户认证的方案。 In order to meet the challenges of wireless broadband technology and maintain the leading edge of 3GPP networks, the 3GPP standards group has developed a next-generation communication network architecture, as shown in the schematic diagram of the next-generation communication system architecture shown in FIG. The architecture supports not only standard 3GPP defined set of wireless technologies (e.g., long term evolution (Long Term Evolution, LTE), a fifth-generation mobile communication (5 th Generation, 5G), etc.) access the core network side (Core network), and supports non The 3GPP access technology can access the core network side through a non-3GPP Interworking Function (N3IWF) or a next generation packet data gateway (ngPDG) to implement a converged network. When accessing the network, user authentication is one of the necessary processes. Currently, there is no solution for how to perform user authentication in the converged network.
发明内容Summary of the invention
本申请提供了一种融合网络中的用户认证方法及装置,以解决融合网络中的用户认证问题。The application provides a user authentication method and device in a converged network to solve the user authentication problem in the converged network.
本申请的一方面,提供了一种融合网络中的用户认证方法,所述方法包括:接入网元接收来自终端设备的认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;所述接入网元发送认证参数请求给控制网元,所述认证参数请求包括:所述终端设备接入所述接入网元的接入协议类型;所述接入网元接收来自所述控制网元的至少一种认证参数并发送所述至少一种认证参数给所述终端设备,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;所述 接入网元在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数,并获取所述终端设备的用户认证信息,并将所述用户认证信息和确定的其中一种认证参数发送给所述控制网元进行认证;所述接入网元接收来自所述控制网元的认证结果并发送所述认证结果给所述终端设备。在该实现方式中,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。An aspect of the present application provides a user authentication method in a converged network, where the method includes: an access network element receives an authentication negotiation request from a terminal device, where the authentication negotiation request is used to negotiate to determine the terminal device. An authentication parameter; the access network element sends an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element; and the access network element receives At least one authentication parameter from the control network element and transmitting the at least one authentication parameter to the terminal device, the at least one authentication parameter corresponding to the access protocol type, each type of authentication parameter includes a type An authentication type, and/or a parameter corresponding to the authentication type; the access network element determines one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter, Obtaining the user authentication information of the terminal device, and sending the user authentication information and the determined one of the authentication parameters to the control network element for authentication; NE receives an authentication result from the control network element and transmitting the authentication result to the terminal device. In this implementation manner, user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。在该实现方式中,终端设备也可以提供所支持的认证类型,但最终采用哪种认证类型进行认证,需要终端设备与接入网元进行协商,控制网元可以优选采用终端设备所支持的认证类型。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. . In this implementation manner, the terminal device may also provide the supported authentication type, but the authentication type is used for the terminal device to negotiate with the access network element, and the control network element may preferably use the authentication supported by the terminal device. Types of.
在另一种实现方式中,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。在该实现方式中,PAP是一种简单的认证类型,可实现快速的认证。In another implementation manner, the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null. In this implementation, PAP is a simple type of authentication that enables fast authentication.
在又一种实现方式中,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。在该实现方式中,CHAP是一种安全性较高的认证类型,可实现安全、可靠的认证。In still another implementation manner, the at least one type of authentication includes a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length. In this implementation, CHAP is a highly secure authentication type that enables secure and reliable authentication.
在又一种实现方式中,所述终端设备包括移动终端设备或固网终端设备。In still another implementation manner, the terminal device includes a mobile terminal device or a fixed network terminal device.
本申请的另一方面,提供了一种融合网络中的用户认证方法,所述方法包括:终端设备向接入网元发送认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;所述终端设备接收来自所述接入网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;所述终端设备在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数,并向所述接入网元发送用户认证信息;所述终端设备接收来自所述接入网元的认证结果。在该实现方式中,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。Another aspect of the present application provides a user authentication method in a converged network, where the method includes: the terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine the terminal device. An authentication parameter; the terminal device receives at least one authentication parameter from the access network element, the at least one authentication parameter corresponding to the access protocol type, each authentication parameter includes an authentication type, and/ Or a parameter corresponding to the authentication type; the terminal device determines one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter, and sends the authentication parameter to the access network The element transmits user authentication information; the terminal device receives an authentication result from the access network element. In this implementation manner, user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。在该实现方式中,终端设备也可以提供所请求的认证类型,但最终采用哪种认证类型进行认证,需要终端设备与接入网元进行协商,控制网元可以优选采用终端设备所支持的认证类型。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. . In this implementation manner, the terminal device may also provide the requested authentication type, but which authentication type is used for authentication, and the terminal device needs to negotiate with the access network element, and the control network element may preferably adopt the authentication supported by the terminal device. Types of.
在又一种实现方式中,所述终端设备包括移动终端设备或固网终端设备。In still another implementation manner, the terminal device includes a mobile terminal device or a fixed network terminal device.
本申请的又一方面,提供了一种融合网络中的用户认证方法,所述方法包括:控制网元接收来自接入网元的认证参数请求,所述认证参数请求包括:终端设备接入所述接入网元的接入协议类型;所述控制网元根据所述认证参数请求,生成至少一种认证参数,并将所述至少一种认证参数发送给所述接入网元,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括根据所述认证参数请求确认所支持的一种认证类型、和/或与所述认证类型对应的参数;所述控制网元接收来自所述接入网元的用户认证信息、以及所述至少一种认证参数中的所述终端设备和所述控制网元均支持的其中一种认证参数,并采用所述确定的其中一种认证参数对所述用户认证信息进行认证,得到认证结果;所述控制网元 将所述认证结果发送给所述接入网元。在该实现方式中,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。A further aspect of the present application provides a user authentication method in a converged network, the method comprising: controlling a network element to receive an authentication parameter request from an access network element, where the authentication parameter request includes: a terminal device access station An access protocol type of the access network element, where the control network element generates at least one authentication parameter according to the authentication parameter request, and sends the at least one authentication parameter to the access network element, where At least one type of authentication parameter corresponding to the access protocol type, each type of authentication parameter includes a type of authentication supported by the authentication parameter request, and/or a parameter corresponding to the type of the authentication; the control network Receiving, by the UE, the user authentication information from the access network element, and one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter, and adopting the determined An authentication parameter is used to authenticate the user authentication information, and the authentication result is obtained; the control network element sends the authentication result to the access network element. In this implementation manner, user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。在该实现方式中,终端设备也可以提供所请求的认证类型,但最终采用哪种认证类型进行认证,需要终端设备与接入网元进行协商,控制网元可以优选采用终端设备所支持的认证类型。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. . In this implementation manner, the terminal device may also provide the requested authentication type, but which authentication type is used for authentication, and the terminal device needs to negotiate with the access network element, and the control network element may preferably adopt the authentication supported by the terminal device. Types of.
在另一种实现方式中,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。在该实现方式中,PAP是一种简单的认证类型,可实现快速的认证。In another implementation manner, the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null. In this implementation, PAP is a simple type of authentication that enables fast authentication.
在又一种实现方式中,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。在该实现方式中,CHAP是一种安全性较高的认证类型,可实现安全、可靠的认证。In still another implementation manner, the at least one type of authentication includes a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length. In this implementation, CHAP is a highly secure authentication type that enables secure and reliable authentication.
在又一种实现方式中,所述终端设备包括移动终端设备或固网终端设备。In still another implementation manner, the terminal device includes a mobile terminal device or a fixed network terminal device.
本申请的再一方面,提供了一种接入网元,该接入网元具有实现上述方法中接入网元行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。In a further aspect of the present application, an access network element is provided, and the access network element has a function of implementing access network element behavior in the foregoing method. The functions may be implemented by hardware or by corresponding software implemented by hardware. The hardware or software includes one or more modules corresponding to the functions described above.
基于同一发明构思,由于该装置解决问题的原理以及有益效果可以参见上述各可能的接入网元的方法实施方式以及所带来的有益效果,因此该装置的实施可以参见方法的实施,重复之处不再赘述。Based on the same inventive concept, the method and the beneficial effects of the above-mentioned possible access network elements can be referred to the implementation of the method and the beneficial effects. Therefore, the implementation of the device can refer to the implementation of the method, and the method is repeated. I won't go into details here.
本申请的再一方面,提供了一种终端设备,该终端设备具有实现上述方法中终端设备行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。In a further aspect of the present application, a terminal device is provided, the terminal device having a function of implementing the behavior of the terminal device in the above method. The functions may be implemented by hardware or by corresponding software implemented by hardware. The hardware or software includes one or more modules corresponding to the functions described above.
基于同一发明构思,由于该装置解决问题的原理以及有益效果可以参见上述各可能的终端设备的方法实施方式以及所带来的有益效果,因此该装置的实施可以参见方法的实施,重复之处不再赘述。Based on the same inventive concept, the principle and the beneficial effects of the device can be referred to the method embodiments of the foregoing possible terminal devices and the beneficial effects thereof. Therefore, the implementation of the device can refer to the implementation of the method, and the repetition is not Let me repeat.
本申请的再一方面,提供了一种控制网元,该控制网元具有实现上述方法中控制网元行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。In a further aspect of the present application, a control network element is provided, and the control network element has a function of implementing the behavior of controlling a network element in the foregoing method. The functions may be implemented by hardware or by corresponding software implemented by hardware. The hardware or software includes one or more modules corresponding to the functions described above.
基于同一发明构思,由于该装置解决问题的原理以及有益效果可以参见上述各可能的控制网元的方法实施方式以及所带来的有益效果,因此该装置的实施可以参见方法的实施,重复之处不再赘述。Based on the same inventive concept, the principle and the beneficial effects of the device can be referred to the method embodiments of the foregoing possible control network elements and the beneficial effects thereof. Therefore, the implementation of the device can be referred to the implementation of the method. No longer.
本申请的再又一方面,提供了一种融合网络中的用户认证方法,所述方法包括:接入网元接收来自终端设备的认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;所述接入网元确定所述终端设备进行用户认证的认证类型为明文认证;所述接入网元接收来自所述终端设备的用户认证信息,并将所述用户认证信息和所述认证类型发送给所述控制网元进行认证;所述接入网元接收来自所述控制网元的认证结果并发送所述认证结果给所述终端设备。在该实现方式中,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备 与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。In still another aspect of the present application, a user authentication method in a converged network is provided, the method comprising: an access network element receiving an authentication negotiation request from a terminal device, where the authentication negotiation request is used to request negotiation to determine the The type of authentication for the terminal device to perform user authentication; the access network element determines that the authentication type of the terminal device for user authentication is plaintext authentication; and the access network element receives user authentication information from the terminal device, and The user authentication information and the authentication type are sent to the control network element for authentication; the access network element receives the authentication result from the control network element and sends the authentication result to the terminal device. In this implementation manner, user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element directly determine that the authentication type is plaintext. Authentication eliminates the need to request authentication parameters from the control network element, simplifying the authentication process.
在一种实现方式中,所述接入网元确定所述终端设备的认证类型为明文认证,包括:所述接入网元配置所述终端设备的认证类型为明文认证;所述接入网元向所述终端设备发送认证类型的协商请求,所述协商请求用于协商所述认证类型为明文认证;所述接入网元接收来自所述终端设备的第一协商反馈消息,所述第一协商反馈消息用于指示所述终端设备同意所述认证类型为明文认证。In an implementation manner, the access network element determines that the authentication type of the terminal device is plaintext authentication, and the method includes: configuring, by the access network element, that the authentication type of the terminal device is plaintext authentication; And sending, by the terminal device, an authentication type negotiation request, where the negotiation request is used to negotiate that the authentication type is plaintext authentication; and the access network element receives a first negotiation feedback message from the terminal device, where the A negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plain text authentication.
在另一种实现方式中,所述接入网元确定所述终端设备的认证类型为明文认证,包括:所述接入网元根据所述认证协商请求确定所述终端设备的认证类型为明文认证,其中,所述认证协商请求还用于指示所述终端设备所支持的认证类型为明文认证;所述接入网元向所述终端设备发送第二协商反馈消息,所述第二协商反馈消息用于指示所述接入网元同意所述认证类型为明文认证。In another implementation manner, the access network element determines that the authentication type of the terminal device is plain text authentication, and the method includes: determining, by the access network element, that the authentication type of the terminal device is a plaintext according to the authentication negotiation request. Authentication, wherein the authentication negotiation request is further used to indicate that the authentication type supported by the terminal device is plaintext authentication; the access network element sends a second negotiation feedback message to the terminal device, where the second negotiation feedback is The message is used to indicate that the access network element agrees that the authentication type is plain text authentication.
在又一种实现方式中,所述终端设备包括移动终端设备或固网终端设备。In still another implementation manner, the terminal device includes a mobile terminal device or a fixed network terminal device.
本申请的再又一方面,提供了一种融合网络中的用户认证方法,所述方法包括:终端设备向接入网元发送认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;所述终端设备确定用户认证的认证类型为明文认证;所述终端设备向所述接入网元发送用户认证信息;所述终端设备接收来自所述接入网元的认证结果。在该实现方式中,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。A still further aspect of the present application provides a user authentication method in a converged network, where the method includes: the terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to request negotiation to determine the terminal. The authentication type of the device for user authentication; the terminal device determines that the authentication type of the user authentication is plain text authentication; the terminal device sends user authentication information to the access network element; and the terminal device receives the access network element from the access network element. Certification results. In this implementation manner, user authentication when any terminal device accesses the converged network is implemented, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element directly determine that the authentication type is plaintext. Authentication eliminates the need to request authentication parameters from the control network element, simplifying the authentication process.
在一种实现方式中,所述终端设备确定用户认证的认证类型为明文认证,包括:所述终端设备接收来自所述接入网元的协商请求,所述协商请求用于协商所述认证类型为明文认证;所述终端设备向所述接入网元发送第一协商反馈消息,所述第一协商反馈消息用于指示所述终端设备同意所述认证类型为明文认证。In an implementation manner, the terminal device determines that the authentication type of the user authentication is plain text authentication, and the method includes: the terminal device receives a negotiation request from the access network element, and the negotiation request is used to negotiate the authentication type. The terminal device sends a first negotiation feedback message to the access network element, where the first negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plain text authentication.
在另一种实现方式中,所述终端设备确定用户认证的认证类型为明文认证,包括:所述终端设备接收来自所述接入网元的第二协商反馈消息,所述第二协商反馈消息用于指示所述接入网元同意所述认证类型为明文认证。In another implementation manner, the terminal device determines that the authentication type of the user authentication is plain text authentication, and the method includes: the terminal device receives a second negotiation feedback message from the access network element, and the second negotiation feedback message And indicating that the access network element agrees that the authentication type is plaintext authentication.
在又一种实现方式中,所述终端设备包括移动终端设备或固网终端设备。In still another implementation manner, the terminal device includes a mobile terminal device or a fixed network terminal device.
本申请的再又一方面,提供了一种接入网元,该接入网元具有实现上述方法中接入网元行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。In still another aspect of the present application, an access network element is provided, and the access network element has a function of implementing access network element behavior in the foregoing method. The functions may be implemented by hardware or by corresponding software implemented by hardware. The hardware or software includes one or more modules corresponding to the functions described above.
基于同一发明构思,由于该装置解决问题的原理以及有益效果可以参见上述各可能的接入网元的方法实施方式以及所带来的有益效果,因此该装置的实施可以参见方法的实施,重复之处不再赘述。Based on the same inventive concept, the method and the beneficial effects of the above-mentioned possible access network elements can be referred to the implementation of the method and the beneficial effects. Therefore, the implementation of the device can refer to the implementation of the method, and the method is repeated. I won't go into details here.
本申请的再又一方面,提供了一种终端设备,该终端设备具有实现上述方法中终端设备行为的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。In still another aspect of the present application, a terminal device having a function of implementing a behavior of a terminal device in the above method is provided. The functions may be implemented by hardware or by corresponding software implemented by hardware. The hardware or software includes one or more modules corresponding to the functions described above.
基于同一发明构思,由于该装置解决问题的原理以及有益效果可以参见上述各可能的 终端设备的方法实施方式以及所带来的有益效果,因此该装置的实施可以参见方法的实施,重复之处不再赘述。Based on the same inventive concept, the principle and the beneficial effects of the device can be referred to the method embodiments of the foregoing possible terminal devices and the beneficial effects thereof. Therefore, the implementation of the device can refer to the implementation of the method, and the repetition is not Let me repeat.
本申请的又一方面提供了一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行上述各方面所述的方法。Yet another aspect of the present application provides a computer readable storage medium having instructions stored therein that, when executed on a computer, cause the computer to perform the methods described in the above aspects.
本申请的又一方面提供了一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机执行上述各方面所述的方法。Yet another aspect of the present application provides a computer program product comprising instructions which, when run on a computer, cause the computer to perform the methods described in the various aspects above.
附图说明DRAWINGS
为了更清楚地说明本发明实施例或背景技术中的技术方案,下面将对本发明实施例或背景技术中所需要使用的附图进行说明。In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the background art, the drawings to be used in the embodiments of the present invention or the background art will be described below.
图1为示例的通信系统架构示意图;1 is a schematic diagram of an exemplary communication system architecture;
图2为本发明实施例提供的一种融合网络中的用户认证方法的交互示意图;2 is a schematic diagram of interaction of a user authentication method in a converged network according to an embodiment of the present invention;
图3为本发明实施例提供的另一种融合网络中的用户认证方法的交互示意图;FIG. 3 is a schematic diagram of interaction of another user authentication method in a converged network according to an embodiment of the present disclosure;
图4为本发明实施例提供的一种接入网元的模块示意图;FIG. 4 is a schematic diagram of a module for accessing a network element according to an embodiment of the present disclosure;
图5为本发明实施例提供的一种终端设备的模块示意图;FIG. 5 is a schematic diagram of a module of a terminal device according to an embodiment of the present disclosure;
图6为本发明实施例提供的一种控制网元的模块示意图;FIG. 6 is a schematic diagram of a module for controlling a network element according to an embodiment of the present disclosure;
图7为本发明实施例提供的另一种接入网元的模块示意图;FIG. 7 is a schematic diagram of another module for accessing a network element according to an embodiment of the present disclosure;
图8为本发明实施例提供的另一种终端设备的模块示意图;FIG. 8 is a schematic diagram of another terminal device according to an embodiment of the present disclosure;
图9为本发明实施例提供的一种接入网元/终端设备/控制网元的硬件架构示意图。FIG. 9 is a schematic diagram of a hardware architecture of an access network element/terminal device/control network element according to an embodiment of the present invention.
具体实施方式detailed description
下面结合本发明实施例中的附图对本发明实施例进行描述。The embodiments of the present invention are described below in conjunction with the accompanying drawings in the embodiments of the present invention.
本发明的各个实施例涉及的通信系统主要包括:接入网元、用户面功能网元和控制面网元,其中,控制面网元又可以称为控制网元。其中,接入网元主要负责终端设备(User Equipment,UE)的接入管理,用户面功能网元主要负责分组数据包的转发、QoS控制、计费信息统计等;控制面功能网元主要负责用户认证、向用户面下发数据包转发策略、QoS控制策略等。该通信系统可以是5G通信系统(例如新空口(New Radio,NR)系统、多种通信技术融合的通信系统(例如LTE技术和NR技术融合的通信系统),或者后续演进通信系统。本发明实施例中的终端设备可以是固网终端设备;也可以是移动终端设备,例如可以是具有无线通信功能的手持设备、车载设备、可穿戴设备、计算设备或连接到无线调制解调器的其它处理设备等。在不同的网络中终端设备可以叫做不同的名称,例如:用户设备、接入终端、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、终端、无线通信设备、用户代理或用户装置、蜂窝电话、无绳电话、会话启动协议(Session Initiation Protocol,SIP)电话、无线本地环路(Wireless Local Loop,WLL)站、个人数字处理(Personal Digital Assistant,PDA)、5G网络或未来演进网络中的终端设备等。The communication system involved in the embodiments of the present invention mainly includes: an access network element, a user plane function network element, and a control plane network element. The control plane network element may also be referred to as a control network element. The access network element is mainly responsible for access management of the terminal equipment (User Equipment, UE), and the user plane function network element is mainly responsible for packet data packet forwarding, QoS control, accounting information statistics, etc.; the control plane function network element is mainly responsible for User authentication, sending packet forwarding policies to users, QoS control policies, and so on. The communication system may be a 5G communication system (for example, a New Radio (NR) system, a communication system in which a plurality of communication technologies are integrated (for example, a communication system in which LTE technology and NR technology are integrated), or a subsequent evolved communication system. The terminal device in the example may be a fixed network terminal device; or may be a mobile terminal device, for example, a handheld device having a wireless communication function, an in-vehicle device, a wearable device, a computing device, or other processing device connected to the wireless modem. Terminal devices in different networks may be called different names, such as: user equipment, access terminals, subscriber units, subscriber stations, mobile stations, mobile stations, remote stations, remote terminals, mobile devices, user terminals, terminals, wireless communications. Device, user agent or user device, cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, Wireless Local Loop (WLL) station, Personal Digital Assistant (PDA), Terminal equipment in a 5G network or a future evolution network.
本发明实施例主要涉及终端设备、接入网元和控制网元之间的通信,进行用户的认证。本发明实施例中,终端设备通过发送认证协商请求,请求协商确定终端设备的认证参数, 该认证协商请求包括终端设备的接入协议类型,接入网元发送认证参数请求给控制网元,控制网元生成与终端设备的接入协议类型对应的至少一种认证参数,并将认证参数发送给接入网元,接入网元与终端设备协商确定终端设备和控制网元共同支持的一种认证参数,接入网元将确定的认证参数和从终端设备接收到的用户认证信息发送给控制网元进行用户认证,得到认证结果。因此,采用本发明实施例提供的一种融合网络中的用户认证方法及装置,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。The embodiments of the present invention mainly relate to communication between a terminal device, an access network element, and a control network element, and perform user authentication. In the embodiment of the present invention, the terminal device requests the negotiation to determine the authentication parameter of the terminal device by sending an authentication negotiation request, where the authentication negotiation request includes the access protocol type of the terminal device, and the access network element sends an authentication parameter request to the control network element to control The network element generates at least one type of authentication parameter corresponding to the access protocol type of the terminal device, and sends the authentication parameter to the access network element, and the access network element negotiates with the terminal device to determine a type supported by the terminal device and the control network element. The authentication parameter, the access network element sends the determined authentication parameter and the user authentication information received from the terminal device to the control network element for user authentication, and obtains the authentication result. Therefore, the user authentication method and device in the converged network provided by the embodiment of the present invention enable user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably. .
图1为示例的5G通信系统架构示意图。在该通信系统架构中,主要包括接入网元(Access Network,AN)或无线接入网元(Radio Access Network,RAN)、用户面功能网元(User Plane Function,UPF)和控制面功能网元(Control Plane,CP)。AN、UPF和CP分别对应前面描述的接入网元、用户面功能网元和控制面功能网元。其中,UPF主要负责分组数据包的转发、QoS控制、计费信息统计等;CP主要负责向用户面下发数据包转发策略、QoS控制策略等。CP又具体包括接入及移动性管理网元(Access and Mobility Management Funtion,AMF)、会话管理网元(Session Management Funtion,SMF)、认证服务网元(Authentication Server Function,AUSF)、统一数据管理网元(Unified Data Management,UDM)、策略控制功能网元(Policy Control Function,PCF)和应用功能网元(Application Function,AF)。其中,AMF用于在融合网络中进行接入管理;UDM用于管理用户签约信息。FIG. 1 is a schematic diagram of an exemplary 5G communication system architecture. In the communication system architecture, the access network element (Access Network, AN) or the radio access network element (Radio Access Network, RAN), the user plane function network element (UPF), and the control plane function network are mainly included. Yuan (Control Plane, CP). The AN, the UPF, and the CP respectively correspond to the access network element, the user plane function network element, and the control plane function network element described above. Among them, UPF is mainly responsible for packet data packet forwarding, QoS control, accounting information statistics, etc. The CP is mainly responsible for sending data packet forwarding policies and QoS control policies to the user plane. The CP specifically includes an Access and Mobility Management Funnel (AMF), a Session Management Funnel (SMF), an Authentication Service Function (AUSF), and a unified data management network. Unified Data Management (UDM), Policy Control Function (PCF), and Application Function Network (Application Function, AF). Among them, AMF is used for access management in a converged network; UDM is used to manage user subscription information.
UE接入融合网络的接入协议类型包括PPPoE、802.1X等。以UE的接入协议类型为PPPoE为例,可选地,UE与AN之间可先完成PPPoE发现过程,该发现过程可以包括以下步骤(未示出):The types of access protocols that the UE accesses the converged network include PPPoE, 802.1X, and so on. For example, the PPPoE discovery process may be performed between the UE and the AN. The discovery process may include the following steps (not shown):
步骤1:UE发现接入网络,向AN发送PPPoE激活发现初始消息(PPPoE Active Discovery Initiation,PADI),用于发起PPPoE发现流程。其中,发现接入网络是个逻辑过程,是为了说明发起PADI的时间点,一般是UE上电并建立物理链路,就认为接入网络了;也可以是手动的,比如点击PPPoE连接。Step 1: The UE discovers the access network and sends a PPPoE Active Discovery Initiation (PADI) to the AN to initiate the PPPoE discovery process. The discovery of the access network is a logical process to illustrate the point in time when the PADI is initiated. Generally, when the UE is powered on and establishes a physical link, it is considered to be connected to the network; or it may be manual, such as clicking a PPPoE connection.
步骤2:AN选择AMF。其中,AMF是CP的一个组件,负责接入及移动性管理,如图1所示,但本实施例是将CP作为一个整体进行描述的,只是这里具体涉及CP的AMF组件时,才单独在该步骤中描述该AN与该AMF组件的交互。另外,AN可以基于预先的配置或者UE的接入协议类型等选择AMF。Step 2: AN selects AMF. Among them, AMF is a component of CP, responsible for access and mobility management, as shown in Figure 1, but this embodiment describes the CP as a whole, but only when it specifically refers to the AMF component of the CP, The interaction of the AN with the AMF component is described in this step. In addition, the AN may select the AMF based on a prior configuration or an access protocol type of the UE or the like.
步骤3:AN根据接收到的来自UE的PADI,生成注册(Registration)NAS消息,发送到CP。当然,该Registration NAS消息也可以说UE生成,然后发送给AN,在此不作限定。Registration NAS消息中携带网络接入标识(Network Access Identity,NAI),而NAI中又包含来自PADI的用户信息,例如:设备标识,线路标识(circuit ID),虚拟局域网标识(Vlan ID),用户物理地址(user MAC),主机名(host name)中的至少一个。Step 3: The AN generates a Registration NAS message according to the received PADI from the UE, and sends the message to the CP. Of course, the Registration NAS message can also be said to be generated by the UE and then sent to the AN, which is not limited herein. The registration NAS message carries the Network Access Identity (NAI), and the NAI contains user information from the PADI, such as: device identification, circuit ID, virtual local area network identifier (Vlan ID), user physics. At least one of the address (user MAC) and the host name.
步骤4:AN和核心网络侧按照现有定义完成鉴权及注册过程,之后AN和UE侧完成PPPoE发现过程。具体来讲,又包括:步骤41)完成AN和核心网的鉴权过程,AN在这个过程中代替UE应答NAS消息;步骤42)核心网络侧应答注册完成消息;步骤43)AN分配会话标识(session ID),和UE之间完成PPPoE发现过程。Step 4: The AN and the core network side complete the authentication and registration process according to the existing definition, and then the AN and the UE side complete the PPPoE discovery process. Specifically, the method further includes: Step 41) completing the authentication process of the AN and the core network, where the AN replaces the UE in response to the NAS message; Step 42) The core network side answers the registration completion message; Step 43) The AN allocates the session identifier ( Session ID), completes the PPPoE discovery process with the UE.
完成PPPoE发现过程之后,可进行PPPoE会话过程,其中,PPPoE会话过程又包括用户认证、IP地址分配和正式的会话。本发明实施例主要涉及其中的用户认证过程。After the PPPoE discovery process is completed, a PPPoE session process may be performed, where the PPPoE session process includes user authentication, IP address allocation, and formal session. Embodiments of the present invention generally relate to a user authentication process therein.
图2为本发明实施例提供的一种融合网络中的用户认证方法的交互示意图,该方法可应用于上述通信系统中。具体地,该方法可以包括以下步骤:FIG. 2 is a schematic diagram of interaction of a user authentication method in a converged network according to an embodiment of the present invention, where the method is applicable to the foregoing communication system. Specifically, the method can include the following steps:
S101、终端设备向接入网元发送认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数。S101. The terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device.
本实施例中,UE接入融合网络的接入协议类型包括PPPoE、802.1X、动态主机配置协议(Dynamic Host Configuration Protocol,DHCP)等,AN可以配置UE的接入协议类型,也可以是AN根据上述PPPoE发现过程中接收到的UE的用户报文确定UE的接入协议类型,在此不作限定。每种接入协议类型可对应一种或多种认证参数,而需要UE与CP之间使用相同的认证参数进行认证,才能顺利地完成用户的认证过程。因此,基于这些协议接入网络进行用户的认证,首先UE与AN之间需进行认证参数的协商。因此,例如,以PPPoE接入协议为例,UE向AN发送链路控制协议(Link Control Protocol,LCP)协商请求,作为认证协商请求,该LCP协商请求用于协商确定UE的认证参数,该LCP协商请求包括UE接入AN的接入协议类型。其中,认证参数包括认证类型、以及认证类型对应的参数。AN接收来自UE的LCP协商请求。In this embodiment, the access protocol type of the UE accessing the converged network includes the PPPoE, the 802.1X, and the Dynamic Host Configuration Protocol (DHCP). The AN can configure the access protocol type of the UE, or can be an AN according to the AN. The user packet of the UE received in the PPPoE discovery process determines the access protocol type of the UE, which is not limited herein. Each access protocol type can correspond to one or more authentication parameters, and the same authentication parameters are required between the UE and the CP for authentication, so that the user authentication process can be successfully completed. Therefore, based on these protocols, the access network is used for user authentication. First, the authentication parameters are negotiated between the UE and the AN. For example, the PPPoE access protocol is used as an example, the UE sends a Link Control Protocol (LCP) negotiation request to the AN as an authentication negotiation request, and the LCP negotiation request is used to negotiate to determine the UE's authentication parameter, the LCP. The negotiation request includes the type of access protocol that the UE accesses the AN. The authentication parameter includes an authentication type and a parameter corresponding to the authentication type. The AN receives an LCP negotiation request from the UE.
可选地,LCP协商请求也可以还包括UE支持的认证类型,或UE期望以哪种认证类型进行认证。Optionally, the LCP negotiation request may also include an authentication type supported by the UE, or an authentication type that the UE expects to perform.
S102、所述接入网元发送认证参数请求给控制网元,所述认证参数请求包括:所述终端设备接入所述接入网元的接入协议类型。S102: The access network element sends an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element.
AN构建认证参数请求,该认证参数请求包括终端设备接入AN的接入协议类型。然后,AN将认证参数请求发送给CP。CP接收来自AN的认证参数请求。The AN constructs an authentication parameter request, and the authentication parameter request includes an access protocol type in which the terminal device accesses the AN. The AN then sends an authentication parameter request to the CP. The CP receives an authentication parameter request from the AN.
可选地,如果LCP协商请求还包括UE支持的认证类型,则AN可以选择在认证参数请求中携带该UE支持的认证类型,也可以选择在认证参数请求中不携带该UE支持的认证类型。如果AN不携带该UE支持的认证类型,而AN从CP接收到的认证参数是与该接入协议类型对应的、CP支持的所有认证参数,则AN从CP接收到的认证参数一般会包含UE所支持的认证类型的。Optionally, if the LCP negotiation request further includes the authentication type supported by the UE, the AN may choose to carry the authentication type supported by the UE in the authentication parameter request, or may choose not to carry the authentication type supported by the UE in the authentication parameter request. If the AN does not carry the authentication type supported by the UE, and the authentication parameter received by the AN from the CP is all the authentication parameters supported by the CP corresponding to the access protocol type, the authentication parameters received by the AN from the CP generally include the UE. The type of authentication supported.
S103、所述控制网元根据所述认证参数请求,生成至少一种认证参数,每种认证参数包括根据所述认证参数请求确认所支持的一种认证类型、和/或与所述认证类型对应的参数。S103. The control network element generates, according to the authentication parameter request, at least one type of authentication parameter, where each type of authentication parameter includes: determining, according to the authentication parameter request, a type of authentication supported, and/or corresponding to the type of authentication. Parameters.
CP根据认证参数请求中包括的接入协议类型,选择与该接入协议类型对应的一种或多种认证类型;然后,由于CP之前已与UE完成鉴权和注册过程,CP已根据UE的用户信息获得UE的用户签约信息(用户签约信息是之前就存储在UDM中的),因此,CP根据UE的用户签约信息以及选择的认证类型,生成与每种认证类型对应的参数。CP自身存储该认证参数。具体地,由CP中的AUSF模块生成认证参数。The CP selects one or more types of authentication corresponding to the type of the access protocol according to the type of the access protocol included in the authentication parameter request. Then, since the CP has previously completed the authentication and registration process with the UE, the CP has been configured according to the UE. The user information obtains the user subscription information of the UE (the user subscription information is previously stored in the UDM), and therefore, the CP generates parameters corresponding to each authentication type according to the user subscription information of the UE and the selected authentication type. The CP itself stores the authentication parameters. Specifically, the authentication parameters are generated by the AUSF module in the CP.
认证类型包括简单密码认证协议(Password Authentication Protocol,PAP)或挑战握手协议(Challenge Handshake Authentication Protocol,CHAP)等。对于PAP,其对应的参数为空,即其参数为:{PAP:NULL},或者在认证参数中不包括PAP对应的参数。对于CHAP,其对应的参数包括:算法、挑战标识、和/或挑战标识长度,例如,其参数为:{CHAP:{算 法:5(MD5);Challenge ID Length:16;Challenge ID:****}}。需要说明的是,示例中的参数表示方式仅是为了示例参数内容,并不限定其具体表示方式。Authentication types include the Password Authentication Protocol (PAP) or the Challenge Handshake Authentication Protocol (CHAP). For PAP, the corresponding parameter is null, that is, its parameter is: {PAP: NULL}, or the parameter corresponding to PAP is not included in the authentication parameter. For CHAP, its corresponding parameters include: algorithm, challenge identifier, and/or challenge identifier length, for example, its parameters are: {CHAP: {algorithm: 5 (MD5); Challenge ID Length: 16; Challenge ID: *** *}}. It should be noted that the parameter representation in the example is only for the purpose of exemplifying the parameter content, and the specific representation manner is not limited.
可选的,如果CP接收到的认证参数请求中包含接入协议类型,以及支持的认证类型,在CP支持这种认证类型的情况下,则CP优先应答仅支持这种认证类型,并提供相应的参数信息。例如UE请求的认证类型为PAP,在CP同时支持PAP和CHAP两种认证类型的情况下,CP可以应答支持的认证类型为:PAP。Optionally, if the authentication parameter request received by the CP includes an access protocol type and a supported authentication type, if the CP supports the authentication type, the CP priority response only supports the authentication type, and provides corresponding Parameter information. For example, if the authentication type requested by the UE is PAP, and the CP supports both the PAP and CHAP authentication types, the type of authentication that the CP can answer is PAP.
S104、所述控制网元将所述至少一种认证参数发送给所述接入网元。S104. The control network element sends the at least one authentication parameter to the access network element.
S105、所述接入网元将所述至少一种认证参数发送给所述终端设备。S105. The access network element sends the at least one authentication parameter to the terminal device.
CP将生成的一种或多种认证参数发送给AN,AN接收来自CP的至少一种认证参数。AN将接收到的一种或多种认证参数发送给UE,UE接收来自AN的至少一种认证参数。The CP sends the generated one or more authentication parameters to the AN, and the AN receives at least one authentication parameter from the CP. The AN sends the received one or more authentication parameters to the UE, and the UE receives at least one authentication parameter from the AN.
S106、所述接入网元在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数。S106. The access network element determines, in the at least one type of authentication parameter, one of the authentication parameters supported by the terminal device and the control network element.
同样地,所述终端设备在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数。在本步骤中,协商过程可以有多种实现方式:可以是AN向UE发送协商请求,UE反馈其所支持的认证类型,然后AN再进行应答;也可以是UE向AN发送协商请求,该协商请求携带UE所支持的认证类型,AN进行应答。最终AN与UE协商确定出UE和CP均支持的其中一种认证参数。Similarly, the terminal device determines, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element. In this step, the negotiation process may be implemented in multiple ways: the AN may send a negotiation request to the UE, the UE feeds back the authentication type supported by the UE, and then the AN responds; or the UE sends a negotiation request to the AN, the negotiation. The request carries the type of authentication supported by the UE, and the AN responds. Finally, the AN negotiates with the UE to determine one of the authentication parameters supported by the UE and the CP.
可选地,对于前述的UE在LCP协商请求中携带UE所请求的认证类型的情况,AN可以应答CP支持或不支持该认证类型,或者AN让UE重新反馈在发送的一种或多种认证类型中UE所支持的认证类型。Optionally, in the case that the foregoing UE carries the authentication type requested by the UE in the LCP negotiation request, the AN may respond to the CP support or not support the authentication type, or the AN allows the UE to re-feed back one or more authentications sent. The type of authentication supported by the UE in the type.
S107、所述终端设备向所述接入网元发送用户认证信息。S107. The terminal device sends user authentication information to the access network element.
在UE与AN协商确定好认证类型后,UE向AN发送与该认证类型对应的用户认证信息。用户认证信息例如是用户名和密码。AN接收来自UE的用户认证信息。After the UE negotiates with the AN to determine the authentication type, the UE sends the user authentication information corresponding to the authentication type to the AN. The user authentication information is, for example, a username and a password. The AN receives user authentication information from the UE.
S108、所述接入网元将所述用户认证信息和确定的其中一种认证参数发送给所述控制网元进行认证。S108. The access network element sends the user authentication information and the determined one of the authentication parameters to the control network element for authentication.
AN将与UE协商确定好的认证参数(具体协商的是认证类型)、以及UE发送的用户认证信息发送给CP进行认证。CP接收来自AN的用户认证信息和确定的其中一种认证参数。The AN will negotiate with the UE to determine the good authentication parameters (specifically, the authentication type is negotiated), and the user authentication information sent by the UE is sent to the CP for authentication. The CP receives user authentication information from the AN and one of the determined authentication parameters.
S109、所述控制网元采用所述确定的其中一种认证参数对所述用户认证信息进行认证,得到认证结果。S109. The control network element authenticates the user authentication information by using the determined one of the authentication parameters, and obtains an authentication result.
CP根据认证参数,取得比对信息。例如如果是CHAP认证类型,则使用协商确定的认证参数和用户签约信息进行计算,获得比对信息;如果是PAP认证类型,则直接获取用户签约信息作为比对信息。之后使用比对信息和用户认证信息进行比对,从而完成认证过程。The CP obtains the comparison information according to the authentication parameters. For example, if it is a CHAP authentication type, the authentication parameter determined by the negotiation and the user subscription information are used for calculation, and the comparison information is obtained; if it is the PAP authentication type, the user subscription information is directly obtained as the comparison information. The comparison process and the user authentication information are then used for comparison to complete the authentication process.
例如,对于CHAP认证,其比对过程为:用户签约信息为(用户名:A,密码:B);认证参数例如为{算法:5(MD5);Change ID Length:16;Change ID:C},当CP接收到用户认证信息为:(用户名:A,密码:D)时,使用用户签约信息中的密码B和认证参数中的挑战标识C进行MD5计算,算出数字串E,之后进行比对。用户名都是A,密码D 和数字串E如果相等,则用户合法,否则非法。For example, for CHAP authentication, the comparison process is: user subscription information is (user name: A, password: B); authentication parameters are, for example, {algorithm: 5 (MD5); Change ID Length: 16; Change ID: C} When the CP receives the user authentication information as: (user name: A, password: D), the password B in the user subscription information and the challenge identifier C in the authentication parameter are used for MD5 calculation, and the digital string E is calculated, and then the ratio is calculated. Correct. The user name is A. If the password D and the numeric string E are equal, the user is legal, otherwise it is illegal.
对于PAP认证,则对比用户名都为A后,直接对比密码D和签约信息B是否相等,如果相等,则用户合法,否则非法。For PAP authentication, if the comparison user name is A, the password D and the subscription information B are directly compared. If they are equal, the user is legal, otherwise it is illegal.
当然还可以采用其他现有认证过程,这里不作限定。Of course, other existing authentication processes can also be used, which are not limited herein.
S110、所述控制网元将所述认证结果发送给所述接入网元。S110. The control network element sends the authentication result to the access network element.
认证结果包括认证通过,该用户为合法用户;或认证失败,该用户为非法用户。CP将该认证结果发送给AN,AN接收来自CP的认证结果。The authentication result includes the authentication, the user is a legitimate user, or the authentication fails. The user is an illegal user. The CP sends the authentication result to the AN, and the AN receives the authentication result from the CP.
S111、所述接入网元将所述认证结果发送给所述终端设备。S111. The access network element sends the authentication result to the terminal device.
AN将CP的认证结果通知UE,UE接收来自AN的认证结果。该UE可以是移动终端设备或固网终端设备,任一终端设备都可以通过这种方式接入融合网络进行用户认证,使得任一终端设备可以安全、可靠地接入融合网络。The AN notifies the UE of the authentication result of the CP, and the UE receives the authentication result from the AN. The UE can be a mobile terminal device or a fixed network terminal device. Any terminal device can access the converged network for user authentication in this manner, so that any terminal device can access the converged network securely and reliably.
根据本发明实施例提供的一种融合网络中的用户认证方法,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。The user authentication method in the converged network according to the embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
图3为本发明实施例提供的另一种融合网络中的用户认证方法的交互示意图,该方法可应用于上述通信系统中。具体地,该方法可以包括以下步骤:FIG. 3 is a schematic diagram of interaction of another user authentication method in a converged network according to an embodiment of the present invention, where the method is applicable to the foregoing communication system. Specifically, the method can include the following steps:
S201、终端设备向接入网元发送认证协商请求。S201. The terminal device sends an authentication negotiation request to the access network element.
UE向AN发送认证协商请求,进行用户认证。该认证协商请求用于请求协商确定UE进行用户认证的认证类型。可选地,作为一种实现方式,该认证协商请求还可以用于指示UE所支持的认证类型为明文认证;作为另一种实现方式,则该认证协商请求不包含这种指示。AN接收来自UE的认证协商请求。The UE sends an authentication negotiation request to the AN to perform user authentication. The authentication negotiation request is used to request negotiation to determine the type of authentication in which the UE performs user authentication. Optionally, the authentication negotiation request may be used to indicate that the authentication type supported by the UE is plaintext authentication. In another implementation manner, the authentication negotiation request does not include the indication. The AN receives an authentication negotiation request from the UE.
S202、所述接入网元与所述终端设备确定所述终端设备进行用户认证的认证类型为明文认证。S202. The access network element and the terminal device determine that the authentication type of the terminal device for user authentication is plaintext authentication.
本实施例采用明文认证(即PAP认证)的认证类型,则AN无须向CP获取认证参数,直接由AN与UE协商确定进行用户认证的认证类型为明文认证。In this embodiment, the authentication type of the plain text authentication (that is, PAP authentication) is adopted, and the AN does not need to obtain the authentication parameter from the CP, and the AN and the UE directly determine that the authentication type for performing user authentication is plain text authentication.
具体地,作为一种实现方式,对于AN侧,所述接入网元确定所述终端设备的认证类型为明文认证,具体包括:所述接入网元配置所述终端设备的认证类型为明文认证;所述接入网元向所述终端设备发送认证类型的协商请求,所述协商请求用于协商所述认证类型为明文认证;所述接入网元接收来自所述终端设备的第一协商反馈消息,所述第一协商反馈消息用于指示所述终端设备同意所述认证类型为明文认证。对于UE侧,所述终端设备确定用户认证的认证类型为明文认证,具体包括:所述终端设备接收来自所述接入网元的协商请求,所述协商请求用于协商所述认证类型为明文认证;所述终端设备向所述接入网元发送第一协商反馈消息,所述第一协商反馈消息用于指示所述终端设备同意所述认证类型为明文认证。Specifically, as an implementation manner, for the AN side, the access network element determines that the authentication type of the terminal device is a plaintext authentication, and the method includes: configuring, by the access network element, that the authentication type of the terminal device is a plaintext The access network element sends an authentication type negotiation request to the terminal device, where the negotiation request is used to negotiate that the authentication type is plaintext authentication; and the access network element receives the first from the terminal device. Negotiating the feedback message, the first negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plaintext authentication. For the UE side, the terminal device determines that the authentication type of the user authentication is plain text authentication, and the method includes: the terminal device receives a negotiation request from the access network element, and the negotiation request is used to negotiate that the authentication type is plaintext. The terminal device sends a first negotiation feedback message to the access network element, where the first negotiation feedback message is used to indicate that the terminal device agrees that the authentication type is plaintext authentication.
在该实现方式中,AN配置UE的认证类型为明文认证,然后再与UE协商。In this implementation manner, the AN configures the authentication type of the UE to be plaintext authentication, and then negotiates with the UE.
作为另一种实现方式,对于AN侧,所述接入网元确定所述终端设备的认证类型为明文认证,具体包括:所述接入网元根据所述认证协商请求确定所述终端设备的认证类型为明文认证,其中,所述认证协商请求还用于指示所述终端设备所支持的认证类型为明文认证;所述接入网元向所述终端设备发送第二协商反馈消息,所述第二协商反馈消息用于指 示所述接入网元同意所述认证类型为明文认证。对于UE侧,所述终端设备确定用户认证的认证类型为明文认证,具体包括:所述终端设备接收来自所述接入网元的第二协商反馈消息,所述第二协商反馈消息用于指示所述接入网元同意所述认证类型为明文认证。As another implementation manner, for the AN side, the access network element determines that the authentication type of the terminal device is plaintext authentication, and the method includes: determining, by the access network element, the terminal device according to the authentication negotiation request. The authentication type is a plain text authentication, where the authentication negotiation request is further used to indicate that the authentication type supported by the terminal device is plaintext authentication, and the access network element sends a second negotiation feedback message to the terminal device, where The second negotiation feedback message is used to indicate that the access network element agrees that the authentication type is plain text authentication. For the UE side, the terminal device determines that the authentication type of the user authentication is the plain text authentication, and the method includes: the terminal device receives a second negotiation feedback message from the access network element, where the second negotiation feedback message is used to indicate The access network element agrees that the authentication type is plain text authentication.
在该实现方式中,UE在认证协商请求中指示其所支持的认证类型为明文认证,然后AN反馈其是否同意采用明文认证的认证类型,从而完成协商过程。In this implementation manner, the UE indicates in the authentication negotiation request that the supported authentication type is plain text authentication, and then the AN feeds back whether it agrees to adopt the authentication type of the plain text authentication, thereby completing the negotiation process.
S203、所述终端设备向所述接入网元发送用户认证信息。S203. The terminal device sends user authentication information to the access network element.
在UE与AN协商确定好认证类型为明文认证后,UE向AN发送与该认证类型对应的用户认证信息。AN接收来自UE的用户认证信息。用户认证信息例如是用户名和密码。After the UE negotiates with the AN to determine that the authentication type is plaintext authentication, the UE sends the user authentication information corresponding to the authentication type to the AN. The AN receives user authentication information from the UE. The user authentication information is, for example, a username and a password.
S204、所述接入网元将所述用户认证信息和所述认证类型发送给控制网元进行认证。S204. The access network element sends the user authentication information and the authentication type to the control network element for authentication.
AN将用户认证信息、以及认证类型为明文认证通知CP,由CP对该用户认证信息进行认证。CP接收来自AN的用户认证信息和认证类型。例如,用户签约信息为(用户名:A,密码:B),当CP接收到用户认证信息为:(用户名:A,密码:D)时,则对比用户名都为A后,直接对比密码D和签约信息B是否相等,如果相等,则用户合法,否则非法。The AN authenticates the user authentication information and the authentication type as a plain text authentication notification CP, and the user authenticates the user authentication information. The CP receives user authentication information and authentication type from the AN. For example, the user subscription information is (user name: A, password: B). When the CP receives the user authentication information as: (user name: A, password: D), then the comparison user name is A, and the password is directly compared. D and the contract information B are equal. If they are equal, the user is legal, otherwise it is illegal.
S205、所述控制网元根据所述认证类型对所述用户认证信息进行认证,得到认证结果。S205. The control network element authenticates the user authentication information according to the authentication type, and obtains an authentication result.
S206、所述控制网元将所述认证结果发送给所述接入网元。S206. The control network element sends the authentication result to the access network element.
AN接收来自CP的认证结果。The AN receives the authentication result from the CP.
S207、所述接入网元将所述认证结果发送给所述终端设备。S207. The access network element sends the authentication result to the terminal device.
UE接收来自AN的认证结果。The UE receives the authentication result from the AN.
本实施例中,通过终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。In this embodiment, the terminal device and the access network element directly determine that the authentication type is plaintext authentication, and the authentication parameter is not required to be requested from the control network element, which simplifies the authentication process.
可选地,也可以AN直接配置UE不需认证,即不需要认证,当AN接收到LCP协商请求时,AN将该UE不需认证的指示发送给UE,则UE可以接入网络进行后续操作。Optionally, the UE can directly configure the UE to perform the authentication without the need for the authentication, that is, the authentication is not required. When the AN receives the LCP negotiation request, the AN sends the indication that the UE does not need to be authenticated to the UE, and the UE can access the network for subsequent operations. .
根据本发明实施例提供的一种融合网络中的用户认证方法,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。The user authentication method in the converged network according to the embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device The access network element directly determines that the authentication type is plain text authentication, and does not need to request an authentication parameter from the control network element, which simplifies the authentication process.
上述详细阐述了本发明实施例的方法,下面提供了本发明实施例的装置。The above describes the method of the embodiment of the present invention in detail, and the apparatus of the embodiment of the present invention is provided below.
图4为本发明实施例提供的一种接入网元的模块示意图,该接入网元可以是上述通信系统中描述的接入网元。具体地,该接入网元1000包括:接收单元11、发送单元12和确定单元13;其中:FIG. 4 is a schematic diagram of a module for accessing a network element according to an embodiment of the present invention. The access network element may be an access network element described in the foregoing communication system. Specifically, the access network element 1000 includes: a receiving unit 11, a sending unit 12, and a determining unit 13; wherein:
接收单元11,用于接收来自终端设备的认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;The receiving unit 11 is configured to receive an authentication negotiation request from the terminal device, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
发送单元12,用于发送认证参数请求给控制网元,所述认证参数请求包括:所述终端设备接入所述接入网元的接入协议类型;The sending unit 12 is configured to send an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
所述接收单元11,还用于接收来自所述控制网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;The receiving unit 11 is further configured to receive at least one authentication parameter from the control network element, where the at least one authentication parameter corresponds to the access protocol type, and each type of authentication parameter includes an authentication type, and / or a parameter corresponding to the type of authentication;
所述发送单元12,还用于发送所述至少一种认证参数给所述终端设备;The sending unit 12 is further configured to send the at least one authentication parameter to the terminal device;
确定单元13,用于在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数;The determining unit 13 is configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
所述接收单元11,还用于获取所述终端设备的用户认证信息;The receiving unit 11 is further configured to acquire user authentication information of the terminal device;
所述发送单元12还用于将所述用户认证信息和确定的其中一种认证参数发送给所述控制网元进行认证;The sending unit 12 is further configured to send the user authentication information and the determined one of the authentication parameters to the control network element for authentication;
所述接收单元11,还用于接收来自所述控制网元的认证结果;The receiving unit 11 is further configured to receive an authentication result from the control network element.
所述发送单元12,还用于发送所述认证结果给所述终端设备。The sending unit 12 is further configured to send the authentication result to the terminal device.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
在另一种实现方式中,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。In another implementation manner, the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
在又一种实现方式中,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。In still another implementation manner, the at least one type of authentication includes a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
根据本发明实施例提供的一种接入网元,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。An access network element according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
图5为本发明实施例提供的一种终端设备的模块示意图,该终端设备可以是上述通信系统中描述的终端设备。具体地,该终端设备2000包括:发送单元21、接收单元22和确定单元23;其中:FIG. 5 is a schematic diagram of a module of a terminal device according to an embodiment of the present invention. The terminal device may be a terminal device described in the foregoing communication system. Specifically, the terminal device 2000 includes: a sending unit 21, a receiving unit 22, and a determining unit 23; wherein:
发送单元21,用于向接入网元发送认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;The sending unit 21 is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device.
接收单元22,用于接收来自所述接入网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;The receiving unit 22 is configured to receive at least one authentication parameter from the access network element, where the at least one authentication parameter corresponds to the access protocol type, each authentication parameter includes an authentication type, and/or a parameter corresponding to the authentication type;
确定单元23,用于在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数;a determining unit 23, configured to determine, in the at least one type of authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
所述发送单元21,还用于向所述接入网元发送用户认证信息;The sending unit 21 is further configured to send user authentication information to the access network element.
所述接收单元22,还用于接收来自所述接入网元的认证结果。The receiving unit 22 is further configured to receive an authentication result from the access network element.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
根据本发明实施例提供的一种终端设备,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。A terminal device according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
图6为本发明实施例提供的一种控制网元的模块示意图,该控制网元可以是上述通信系统中描述的控制网元。具体地,该控制网元3000包括:接收单元31、生成单元32、发送单元33和认证单元34;其中:FIG. 6 is a schematic diagram of a module for controlling a network element according to an embodiment of the present invention. The control network element may be a control network element described in the foregoing communication system. Specifically, the control network element 3000 includes: a receiving unit 31, a generating unit 32, a sending unit 33, and an authenticating unit 34; wherein:
接收单元31,用于接收来自接入网元的认证参数请求,所述认证参数请求包括:终端设备接入所述接入网元的接入协议类型;The receiving unit 31 is configured to receive an authentication parameter request from the access network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
生成单元32,用于根据所述认证参数请求,生成至少一种认证参数,所述至少一种认 证参数与所述接入协议类型对应,每种认证参数包括根据所述认证参数请求确认所支持的一种认证类型、和/或与所述认证类型对应的参数;The generating unit 32 is configured to generate, according to the authentication parameter request, at least one type of authentication parameter, where the at least one type of authentication parameter corresponds to the access protocol type, and each type of the authentication parameter comprises: supporting according to the authentication parameter request confirmation An authentication type, and/or a parameter corresponding to the authentication type;
发送单元33,用于将所述至少一种认证参数发送给所述接入网元;The sending unit 33 is configured to send the at least one authentication parameter to the access network element;
所述接收单元31,还用于接收来自所述接入网元的用户认证信息、以及接入网元所述至少一种认证参数中的所述终端设备和所述控制网元均支持的其中一种认证参数;The receiving unit 31 is further configured to receive user authentication information from the access network element, and the terminal device and the control network element in the at least one authentication parameter of the access network element An authentication parameter;
认证单元34,用于采用所述确定的其中一种认证参数对所述用户认证信息进行认证,得到认证结果;The authentication unit 34 is configured to authenticate the user authentication information by using the determined one of the authentication parameters to obtain an authentication result.
所述发送单元33,还用于将所述认证结果发送给所述接入网元。The sending unit 33 is further configured to send the authentication result to the access network element.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
在另一种实现方式中,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。In another implementation manner, the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
在又一种实现方式中,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。In still another implementation manner, the at least one type of authentication includes a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
根据本发明实施例提供的一种控制网元,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。A control network element according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
图7为本发明实施例提供的另一种接入网元的模块示意图,该接入网元可以是上述通信系统中的接入网元。具体地,该接入网元4000可包括:接收单元41、确定单元42和发送单元43;其中:FIG. 7 is a schematic diagram of another module of an access network element according to an embodiment of the present invention. The access network element may be an access network element in the foregoing communication system. Specifically, the access network element 4000 may include: a receiving unit 41, a determining unit 42 and a sending unit 43; wherein:
接收单元41,用于接收来自终端设备的认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;The receiving unit 41 is configured to receive an authentication negotiation request from the terminal device, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
确定单元42,用于确定所述终端设备的认证类型为明文认证;The determining unit 42 is configured to determine that the authentication type of the terminal device is plain text authentication;
所述接收单元41,还用于接收来自所述终端设备的用户认证信息;The receiving unit 41 is further configured to receive user authentication information from the terminal device;
发送单元43,用于将所述用户认证信息和所述认证类型发送给控制网元进行认证;The sending unit 43 is configured to send the user authentication information and the authentication type to the control network element for authentication;
所述接收单元41,还用于接收来自所述控制网元的认证结果;The receiving unit 41 is further configured to receive an authentication result from the control network element.
所述发送单元43,还用于发送所述认证结果给所述终端设备。The sending unit 43 is further configured to send the authentication result to the terminal device.
根据本发明实施例提供的一种接入网元,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。An access network element according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access device The network element directly determines that the authentication type is plain text authentication, and does not need to request authentication parameters from the control network element, which simplifies the authentication process.
图8为本发明实施例提供的另一种终端设备的模块示意图,该终端设备可以是上述通信系统中的终端设备。具体地,该终端设备5000可包括:发送单元51、确定单元52和接收单元53;其中:FIG. 8 is a schematic diagram of another terminal device according to an embodiment of the present disclosure, where the terminal device may be a terminal device in the foregoing communication system. Specifically, the terminal device 5000 may include: a sending unit 51, a determining unit 52, and a receiving unit 53; wherein:
发送单元51,用于向接入网元发送认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;The sending unit 51 is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
确定单元52,用于确定用户认证的认证类型为明文认证;a determining unit 52, configured to determine that the authentication type of the user authentication is plaintext authentication;
所述发送单元51,还用于向所述接入网元发送用户认证信息;The sending unit 51 is further configured to send user authentication information to the access network element.
接收单元53,用于接收来自所述接入网元的认证结果。The receiving unit 53 is configured to receive an authentication result from the access network element.
根据本发明实施例提供的一种终端设备,实现了任一终端设备接入融合网络时的用户 认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。According to an embodiment of the present invention, a terminal device implements user authentication when any terminal device accesses a converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element The authentication type is directly determined to be plain text authentication, and the authentication parameters are not required to be requested from the control network element, which simplifies the authentication process.
本发明实施例还提供一种接入网元,该接入网元可以是上述通信系统中的接入网元,该接入网元可以采用图9所示的硬件架构。该接入网元可以包括接收器、发射器、存储器和处理器,所述接收器、发射器、存储器和处理器通过总线相互连接。图4中的接收单元11所实现的相关功能可以由接收器来实现,发送单元12所实现的相关功能可以由发射器来实现,确定单元13所实现的相关功能可以通过一个或多个处理器来实现。The embodiment of the present invention further provides an access network element, where the access network element can be an access network element in the foregoing communication system, and the access network element can adopt the hardware architecture shown in FIG. The access network element can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus. The related functions implemented by the receiving unit 11 in FIG. 4 may be implemented by a receiver, and related functions implemented by the transmitting unit 12 may be implemented by a transmitter, and related functions implemented by the determining unit 13 may pass through one or more processors. to realise.
存储器包括但不限于是随机存储记忆体(Random Access Memory,RAM)、只读存储器(Read-Only Memory,ROM)、可擦除可编程只读存储器(Erasable Programmable Read Only Memory,EPROM)、或便携式只读存储器(Compact Disc Read-Only Memory,CD-ROM),该存储器用于相关指令及数据。The memory includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an Erasable Programmable Read Only Memory (EPROM), or a portable Compact Disc Read-Only Memory (CD-ROM), which is used for related instructions and data.
接收器用于接收数据和/或信号,以及发射器用于发送数据和/或信号。发射器和接收器可以是独立的器件,也可以是一个整体的器件。The receiver is for receiving data and/or signals, and the transmitter is for transmitting data and/or signals. The transmitter and receiver can be separate devices or a single device.
处理器可以包括是一个或多个处理器,例如包括一个或多个中央处理器(Central Processing Unit,CPU),在处理器是一个CPU的情况下,该CPU可以是单核CPU,也可以是多核CPU。The processor may include one or more processors, for example, including one or more central processing units (CPUs). In the case where the processor is a CPU, the CPU may be a single-core CPU, or may be Multi-core CPU.
存储器用于存储网络设备的程序代码和数据。The memory is used to store program code and data of the network device.
具体地,所述接收器用于接收来自终端设备的认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;Specifically, the receiver is configured to receive an authentication negotiation request from a terminal device, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
所述发射器用于发送认证参数请求给控制网元,所述认证参数请求包括:所述终端设备接入所述接入网元的接入协议类型;The transmitter is configured to send an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
所述接收器还用于接收来自所述控制网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;The receiver is further configured to receive at least one authentication parameter from the control network element, where the at least one authentication parameter corresponds to the access protocol type, each authentication parameter includes an authentication type, and/or a parameter corresponding to the authentication type;
所述发射器还用于发送所述至少一种认证参数给所述终端设备;The transmitter is further configured to send the at least one authentication parameter to the terminal device;
所述处理器用于在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数;The processor is configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
所述接收器还用于获取所述终端设备的用户认证信息;The receiver is further configured to acquire user authentication information of the terminal device;
所述发射器还用于将所述用户认证信息和确定的其中一种认证参数发送给所述控制网元进行认证;The transmitter is further configured to send the user authentication information and the determined one of the authentication parameters to the control network element for authentication;
所述接收器还用于接收来自所述控制网元的认证结果;The receiver is further configured to receive an authentication result from the control network element;
所述发射器还用于发送所述认证结果给所述终端设备。The transmitter is further configured to send the authentication result to the terminal device.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
在另一种实现方式中,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。In another implementation manner, the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
在又一种实现方式中,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。In still another implementation manner, the at least one type of authentication includes a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
具体可参见方法实施例中的描述,在此不再赘述。For details, refer to the description in the method embodiment, and details are not described herein again.
可以理解的是,图9仅仅示出了接入网元的简化设计。在实际应用中,接入网元还可以分别包含必要的其他元件,包含但不限于任意数量的收发器、处理器、控制器、存储器等,而所有可以实现本发明实施例的接入网元都在本发明的保护范围之内。It will be appreciated that Figure 9 only shows a simplified design of the access network element. In an actual application, the access network element may further include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all access network elements that can implement the embodiments of the present invention. All are within the scope of the invention.
根据本发明实施例提供的一种接入网元,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。An access network element according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
本发明实施例还提供一种终端设备,该终端设备可以是上述通信系统中的终端设备,该终端设备可以采用图9所示的硬件架构。该终端设备可以包括接收器、发射器、存储器和处理器,所述接收器、发射器、存储器和处理器通过总线相互连接。图5中的发送单元21所实现的相关功能可以由发射器来实现,接收单元22所实现的相关功能可以由接收器来实现,确定单元23所实现的相关功能可以通过一个或多个处理器来实现。The embodiment of the present invention further provides a terminal device, which may be a terminal device in the foregoing communication system, and the terminal device may adopt the hardware architecture shown in FIG. The terminal device may include a receiver, a transmitter, a memory, and a processor, the receiver, the transmitter, the memory, and the processor being connected to each other by a bus. The related functions implemented by the transmitting unit 21 in FIG. 5 may be implemented by a transmitter, and related functions implemented by the receiving unit 22 may be implemented by a receiver, and related functions implemented by the determining unit 23 may pass through one or more processors. to realise.
存储器包括但不限于是RAM、ROM、EPROM、CD-ROM,该存储器用于相关指令及数据。The memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
接收器用于接收数据和/或信号,以及发射器用于发送数据和/或信号。发射器和接收器可以是独立的器件,也可以是一个整体的器件。The receiver is for receiving data and/or signals, and the transmitter is for transmitting data and/or signals. The transmitter and receiver can be separate devices or a single device.
处理器可以包括是一个或多个处理器,例如包括一个或多个CPU,在处理器是一个CPU的情况下,该CPU可以是单核CPU,也可以是多核CPU。The processor may include one or more processors, for example including one or more CPUs. In the case where the processor is a CPU, the CPU may be a single core CPU or a multi-core CPU.
存储器用于存储终端设备的程序代码和数据。The memory is used to store program code and data of the terminal device.
具体地,所述发射器用于向接入网元发送认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;Specifically, the transmitter is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
所述接收器用于接收来自所述接入网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;The receiver is configured to receive at least one authentication parameter from the access network element, the at least one authentication parameter corresponding to the access protocol type, each authentication parameter including an authentication type, and/or a parameter corresponding to the authentication type;
所述处理器用于在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数;The processor is configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
所述发射器还用于向所述接入网元发送用户认证信息;The transmitter is further configured to send user authentication information to the access network element;
所述接收器还用于接收来自所述接入网元的认证结果。The receiver is further configured to receive an authentication result from the access network element.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
具体可参见方法实施例中的描述,在此不再赘述。For details, refer to the description in the method embodiment, and details are not described herein again.
可以理解的是,图9仅仅示出了终端设备的简化设计。在实际应用中,终端设备还可以分别包含必要的其他元件,包含但不限于任意数量的收发器、处理器、控制器、存储器等,而所有可以实现本发明的终端设备都在本发明的保护范围之内。It will be understood that Figure 9 only shows a simplified design of the terminal device. In practical applications, the terminal device may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all terminal devices that can implement the present invention are protected by the present invention. Within the scope.
根据本发明实施例提供的一种终端设备,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。A terminal device according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
本发明实施例还提供一种控制网元的硬件架构图,该控制网元可以是上述通信系统中的控制网元,该控制网元可以采用图9所示的硬件架构。该控制网元可以包括接收器、发射器、存储器和处理器,所述接收器、发射器、存储器和处理器通过总线相互连接。图6 中的接收单元31所实现的相关功能可以由接收器来实现,发送单元33所实现的相关功能可以由发射器来实现,生成单元32和认证单元34所实现的相关功能可以通过一个或多个处理器来实现。The embodiment of the present invention further provides a hardware architecture diagram of the control network element, where the control network element may be a control network element in the foregoing communication system, and the control network element may adopt the hardware architecture shown in FIG. The control network element can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus. The related functions implemented by the receiving unit 31 in FIG. 6 may be implemented by a receiver, and related functions implemented by the transmitting unit 33 may be implemented by a transmitter, and related functions implemented by the generating unit 32 and the authenticating unit 34 may be performed by one or Implemented by multiple processors.
存储器包括但不限于是RAM、ROM、EPROM、CD-ROM,该存储器用于相关指令及数据。The memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
接收器用于接收数据和/或信号,以及发射器用于发送数据和/或信号。发射器和接收器可以是独立的器件,也可以是一个整体的器件。The receiver is for receiving data and/or signals, and the transmitter is for transmitting data and/or signals. The transmitter and receiver can be separate devices or a single device.
处理器可以包括是一个或多个处理器,例如包括一个或多个CPU,在处理器是一个CPU的情况下,该CPU可以是单核CPU,也可以是多核CPU。The processor may include one or more processors, for example including one or more CPUs. In the case where the processor is a CPU, the CPU may be a single core CPU or a multi-core CPU.
存储器用于存储控制网元的程序代码和数据。The memory is used to store program code and data for controlling the network element.
具体地,所述接收器用于接收来自接入网元的认证参数请求,所述认证参数请求包括:终端设备接入所述接入网元的接入协议类型;Specifically, the receiver is configured to receive an authentication parameter request from an access network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
所述处理器用于根据所述认证参数请求,生成至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括根据所述认证参数请求确认所支持的一种认证类型、和/或与所述认证类型对应的参数;The processor is configured to generate, according to the authentication parameter request, at least one type of authentication parameter, where the at least one type of authentication parameter corresponds to the access protocol type, and each type of the authentication parameter includes a request for confirmation according to the authentication parameter request. An authentication type, and/or a parameter corresponding to the authentication type;
所述发射器用于将所述至少一种认证参数发送给所述接入网元;The transmitter is configured to send the at least one authentication parameter to the access network element;
所述接收器还用于接收来自所述接入网元的用户认证信息、以及接入网元所述至少一种认证参数中的所述终端设备和所述控制网元均支持的其中一种认证参数;The receiver is further configured to receive user authentication information from the access network element, and one of the terminal device and the control network element supported by the at least one authentication parameter of the access network element. Authentication parameter
所述处理器还用于采用所述确定的其中一种认证参数对所述用户认证信息进行认证,得到认证结果;The processor is further configured to perform authentication on the user authentication information by using the determined one of the authentication parameters to obtain an authentication result;
所述发射器还用于将所述认证结果发送给所述接入网元。The transmitter is further configured to send the authentication result to the access network element.
在一种实现方式中,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。In an implementation manner, the authentication negotiation request and the authentication parameter request further include: an authentication type supported by the terminal device, where the parameter corresponding to the authentication type is a parameter corresponding to the authentication type supported by the terminal device. .
在另一种实现方式中,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。In another implementation manner, the at least one type of authentication includes a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is null.
在又一种实现方式中,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。In still another implementation manner, the at least one type of authentication includes a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
具体可参见方法实施例中的描述,在此不再赘述。For details, refer to the description in the method embodiment, and details are not described herein again.
可以理解的是,图9仅仅示出了控制网元的简化设计。在实际应用中,控制网元还可以分别包含必要的其他元件,包含但不限于任意数量的收发器、处理器、控制器、存储器等,而所有可以实现本发明的控制网元都在本发明的保护范围之内。It will be appreciated that Figure 9 only shows a simplified design of the control network element. In practical applications, the control network element may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all control network elements that can implement the present invention are in the present invention. Within the scope of protection.
根据本发明实施例提供的一种控制网元,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络。A control network element according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably.
本发明实施例还提供了另一种接入网元,该接入网元可以是上述通信系统中的接入网元,该接入网元可以采用图9所示的硬件架构。该接入网元可以包括接收器、发射器、存储器和处理器,所述接收器、发射器、存储器和处理器通过总线相互连接。图7中的接收单元41所实现的相关功能可以由接收器来实现,发送单元43所实现的相关功能可以由发射器来实现,确定单元42所实现的相关功能可以通过一个或多个处理器来实现。The embodiment of the present invention further provides another access network element, where the access network element may be an access network element in the foregoing communication system, and the access network element may adopt the hardware architecture shown in FIG. The access network element can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus. The related functions implemented by the receiving unit 41 in FIG. 7 may be implemented by a receiver, the related functions implemented by the transmitting unit 43 may be implemented by a transmitter, and the related functions implemented by the determining unit 42 may be passed through one or more processors. to realise.
存储器包括但不限于是RAM、ROM、EPROM、CD-ROM,该存储器用于相关指令及数据。The memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
接收器用于接收数据和/或信号,以及发射器用于发送数据和/或信号。发射器和接收器可以是独立的器件,也可以是一个整体的器件。The receiver is for receiving data and/or signals, and the transmitter is for transmitting data and/or signals. The transmitter and receiver can be separate devices or a single device.
处理器可以包括是一个或多个处理器,例如包括一个或多个CPU,在处理器是一个CPU的情况下,该CPU可以是单核CPU,也可以是多核CPU。The processor may include one or more processors, for example including one or more CPUs. In the case where the processor is a CPU, the CPU may be a single core CPU or a multi-core CPU.
存储器用于存储接入网元的程序代码和数据。The memory is used to store program code and data of the access network element.
具体地,所述接收器用于接收来自终端设备的认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;Specifically, the receiver is configured to receive an authentication negotiation request from a terminal device, where the authentication negotiation request is used to request negotiation to determine an authentication type of the terminal device to perform user authentication.
所述处理器用于确定所述终端设备的认证类型为明文认证;The processor is configured to determine that the authentication type of the terminal device is plain text authentication;
所述接收器还用于接收来自所述终端设备的用户认证信息;The receiver is further configured to receive user authentication information from the terminal device;
所述发射器用于将所述用户认证信息和所述认证类型发送给控制网元进行认证;The transmitter is configured to send the user authentication information and the authentication type to a control network element for authentication;
所述发射器还用于接收来自所述控制网元的认证结果;The transmitter is further configured to receive an authentication result from the control network element;
所述发射器还用于发送所述认证结果给所述终端设备。The transmitter is further configured to send the authentication result to the terminal device.
具体可参见方法实施例中的描述,在此不再赘述。For details, refer to the description in the method embodiment, and details are not described herein again.
可以理解的是,图9仅仅示出了接入网元的简化设计。在实际应用中,接入网元还可以分别包含必要的其他元件,包含但不限于任意数量的收发器、处理器、控制器、存储器等,而所有可以实现本发明的接入网元都在本发明的保护范围之内。It will be appreciated that Figure 9 only shows a simplified design of the access network element. In an actual application, the access network element may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all access network elements that can implement the present invention are Within the scope of protection of the present invention.
根据本发明实施例提供的一种接入网元,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。An access network element according to an embodiment of the present invention implements user authentication when any terminal device accesses the converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access device The network element directly determines that the authentication type is plain text authentication, and does not need to request authentication parameters from the control network element, which simplifies the authentication process.
本发明实施例还提供了另一种终端设备的硬件架构示意图,该终端设备可以是上述通信系统中的终端设备,该终端设备可以采用图9所示的硬件架构。该终端设备可以包括接收器、发射器、存储器和处理器,所述接收器、发射器、存储器和处理器通过总线118相互连接。图8中的接收单元53所实现的相关功能可以由接收器来实现,发送单元51所实现的相关功能可以由发射器来实现,确定单元52所实现的相关功能可以通过一个或多个处理器来实现。The embodiment of the present invention further provides a schematic diagram of a hardware architecture of another terminal device, where the terminal device may be a terminal device in the foregoing communication system, and the terminal device may adopt the hardware architecture shown in FIG. The terminal device can include a receiver, a transmitter, a memory, and a processor, the receiver, transmitter, memory, and processor being interconnected by a bus 118. The related functions implemented by the receiving unit 53 in FIG. 8 may be implemented by a receiver, the related functions implemented by the transmitting unit 51 may be implemented by a transmitter, and the related functions implemented by the determining unit 52 may be passed through one or more processors. to realise.
存储器包括但不限于是RAM、ROM、EPROM、CD-ROM,该存储器用于相关指令及数据。The memory includes, but is not limited to, RAM, ROM, EPROM, CD-ROM, which is used for related instructions and data.
接收器用于接收数据和/或信号,以及发射器用于发送数据和/或信号。发射器和接收器可以是独立的器件,也可以是一个整体的器件。The receiver is for receiving data and/or signals, and the transmitter is for transmitting data and/or signals. The transmitter and receiver can be separate devices or a single device.
处理器可以包括是一个或多个处理器,例如包括一个或多个CPU,在处理器是一个CPU的情况下,该CPU可以是单核CPU,也可以是多核CPU。The processor may include one or more processors, for example including one or more CPUs. In the case where the processor is a CPU, the CPU may be a single core CPU or a multi-core CPU.
存储器用于存储终端设备的程序代码和数据。The memory is used to store program code and data of the terminal device.
具体地,所述发射器用于向接入网元发送认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;Specifically, the transmitter is configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
所述处理器用于确定用户认证的认证类型为明文认证;The processor is configured to determine that the authentication type of the user authentication is plain text authentication;
所述发射器还用于向所述接入网元发送用户认证信息;The transmitter is further configured to send user authentication information to the access network element;
所述接收器用于接收来自所述接入网元的认证结果。The receiver is configured to receive an authentication result from the access network element.
具体可参见方法实施例中的描述,在此不再赘述。For details, refer to the description in the method embodiment, and details are not described herein again.
可以理解的是,图9仅仅示出了终端设备的简化设计。在实际应用中,终端设备还可以分别包含必要的其他元件,包含但不限于任意数量的收发器、处理器、控制器、存储器等,而所有可以实现本发明的终端设备都在本发明的保护范围之内。It will be understood that Figure 9 only shows a simplified design of the terminal device. In practical applications, the terminal device may also include other necessary components, including but not limited to any number of transceivers, processors, controllers, memories, etc., and all terminal devices that can implement the present invention are protected by the present invention. Within the scope.
根据本发明实施例提供的一种终端设备,实现了任一终端设备接入融合网络时的用户认证,使得任一终端设备可以安全、可靠地接入融合网络;且终端设备与接入网元直接确定认证类型为明文认证,无需向控制网元请求认证参数,简化了认证过程。According to an embodiment of the present invention, a terminal device implements user authentication when any terminal device accesses a converged network, so that any terminal device can access the converged network securely and reliably; and the terminal device and the access network element The authentication type is directly determined to be plain text authentication, and the authentication parameters are not required to be requested from the control network element, which simplifies the authentication process.
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。A person skilled in the art can clearly understand that for the convenience and brevity of the description, the specific working process of the system, the device and the unit described above can refer to the corresponding process in the foregoing method embodiment, and details are not described herein again.
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、或者计算机软件和电子硬件的结合来实现。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。Those of ordinary skill in the art will appreciate that the elements and algorithm steps of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the solution. A person skilled in the art can use different methods to implement the described functions for each particular application, but such implementation should not be considered to be beyond the scope of the present application.
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。In the several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods may be implemented in other manners. For example, the device embodiments described above are merely illustrative. For example, the division of the unit is only a logical function division. In actual implementation, there may be another division manner, for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本发明实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者通过所述计算机可读存储介质进行传输。所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质(例如固态硬盘(Solid State Disk,SSD))等。In the above embodiments, it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in accordance with embodiments of the present invention are generated in whole or in part. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted by a computer readable storage medium. The computer instructions can be from a website site, computer, server or data center to another website site by wire (eg, coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (eg, infrared, wireless, microwave, etc.) Transfer from a computer, server, or data center. The computer readable storage medium can be any available media that can be accessed by a computer or a data storage device such as a server, data center, or the like that includes one or more available media. The usable medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (such as a Solid State Disk (SSD)) or the like.
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,该流程可以由计算机程序来指令相关的硬件完成,该程序可存储于计算机可读取存储介质中,该程序在执行时,可包括如上述各方法实施例的流程。而前述的存储介质包括:ROM或随机存储记忆体RAM、磁碟或者光盘等各种可存储程序代码的介质。One of ordinary skill in the art can understand all or part of the process of implementing the above embodiments, which can be completed by a computer program to instruct related hardware, the program can be stored in a computer readable storage medium, when the program is executed The flow of the method embodiments as described above may be included. The foregoing storage medium includes various media that can store program codes, such as a ROM or a random access memory RAM, a magnetic disk, or an optical disk.

Claims (30)

  1. 一种融合网络中的用户认证方法,其特征在于,所述方法包括:A user authentication method in a converged network, the method comprising:
    接入网元接收来自终端设备的认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;The access network element receives an authentication negotiation request from the terminal device, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
    所述接入网元发送认证参数请求给控制网元,所述认证参数请求包括:所述终端设备接入所述接入网元的接入协议类型;The access network element sends an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
    所述接入网元接收来自所述控制网元的至少一种认证参数并发送所述至少一种认证参数给所述终端设备,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;The access network element receives at least one authentication parameter from the control network element and sends the at least one authentication parameter to the terminal device, where the at least one authentication parameter corresponds to the access protocol type, Each authentication parameter includes an authentication type, and/or a parameter corresponding to the authentication type;
    所述接入网元在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数,并获取所述终端设备的用户认证信息,并将所述用户认证信息和确定的其中一种认证参数发送给所述控制网元进行认证;Determining, in the at least one type of the authentication parameter, one of the authentication parameters supported by the terminal device and the control network element, and acquiring user authentication information of the terminal device, and User authentication information and one of the determined authentication parameters are sent to the control network element for authentication;
    所述接入网元接收来自所述控制网元的认证结果并发送所述认证结果给所述终端设备。The access network element receives an authentication result from the control network element and sends the authentication result to the terminal device.
  2. 如权利要求1所述的方法,其特征在于,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。The method according to claim 1, wherein the authentication negotiation request and the authentication parameter request further comprise: an authentication type supported by the terminal device, and the parameter corresponding to the authentication type is supported by the terminal device. The parameter corresponding to the type of authentication.
  3. 如权利要求1或2所述的方法,其特征在于,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。The method according to claim 1 or 2, wherein the at least one authentication type comprises a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is empty.
  4. 如权利要求1或2所述的方法,其特征在于,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。The method according to claim 1 or 2, wherein the at least one authentication type comprises a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  5. 一种融合网络中的用户认证方法,其特征在于,所述方法包括:A user authentication method in a converged network, the method comprising:
    终端设备向接入网元发送认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;The terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
    所述终端设备接收来自所述接入网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;Receiving, by the terminal device, at least one type of authentication parameter from the access network element, where the at least one authentication parameter corresponds to the access protocol type, and each type of authentication parameter includes an authentication type, and/or Describe the parameters corresponding to the authentication type;
    所述终端设备在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数,并向所述接入网元发送用户认证信息;Determining, by the terminal device, one of the authentication parameters supported by the terminal device and the control network element, and sending the user authentication information to the access network element;
    所述终端设备接收来自所述接入网元的认证结果。The terminal device receives an authentication result from the access network element.
  6. 如权利要求5所述的方法,其特征在于,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。The method according to claim 5, wherein the authentication negotiation request and the authentication parameter request further comprise: an authentication type supported by the terminal device, and the parameter corresponding to the authentication type is supported by the terminal device. The parameter corresponding to the type of authentication.
  7. 一种融合网络中的用户认证方法,其特征在于,所述方法包括:A user authentication method in a converged network, the method comprising:
    控制网元接收来自接入网元的认证参数请求,所述认证参数请求包括:终端设备接入所述接入网元的接入协议类型;The control network element receives the authentication parameter request from the access network element, where the authentication parameter request includes: an access protocol type in which the terminal device accesses the access network element;
    所述控制网元根据所述认证参数请求,生成至少一种认证参数,并将所述至少一种认 证参数发送给所述接入网元,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括根据所述认证参数请求确认所支持的一种认证类型、和/或与所述认证类型对应的参数;The control network element generates at least one authentication parameter according to the authentication parameter request, and sends the at least one authentication parameter to the access network element, the at least one authentication parameter and the access protocol Corresponding to each type, each authentication parameter includes an authentication type supported by the authentication parameter request, and/or a parameter corresponding to the authentication type;
    所述控制网元接收来自所述接入网元的用户认证信息、以及接入网元所述至少一种认证参数中的所述终端设备和所述控制网元均支持的其中一种认证参数,并采用所述确定的其中一种认证参数对所述用户认证信息进行认证,得到认证结果;The control network element receives the user authentication information from the access network element, and one of the authentication parameters supported by the terminal device and the control network element in the at least one authentication parameter of the access network element. And authenticating the user authentication information by using the determined one of the authentication parameters to obtain an authentication result;
    所述控制网元将所述认证结果发送给所述接入网元。The control network element sends the authentication result to the access network element.
  8. 如权利要求7所述的方法,其特征在于,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。The method according to claim 7, wherein the authentication negotiation request and the authentication parameter request further comprise: an authentication type supported by the terminal device, and the parameter corresponding to the authentication type is supported by the terminal device. The parameter corresponding to the type of authentication.
  9. 如权利要求7或8所述的方法,其特征在于,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。The method according to claim 7 or 8, wherein the at least one authentication type comprises a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is empty.
  10. 如权利要求7或8所述的方法,其特征在于,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。The method according to claim 7 or 8, wherein the at least one authentication type comprises a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length.
  11. 一种融合网络中的用户认证方法,其特征在于,所述方法包括:A user authentication method in a converged network, the method comprising:
    接入网元接收来自终端设备的认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;The access network element receives an authentication negotiation request from the terminal device, where the authentication negotiation request is used to request negotiation to determine the authentication type of the terminal device for performing user authentication.
    所述接入网元确定所述终端设备的认证类型为明文认证;Determining, by the access network element, that the authentication type of the terminal device is plaintext authentication;
    所述接入网元接收来自所述终端设备的用户认证信息,并将所述用户认证信息和所述认证类型发送给控制网元进行认证;The access network element receives the user authentication information from the terminal device, and sends the user authentication information and the authentication type to the control network element for authentication;
    所述接入网元接收来自所述控制网元的认证结果并发送所述认证结果给所述终端设备。The access network element receives an authentication result from the control network element and sends the authentication result to the terminal device.
  12. 一种融合网络中的用户认证方法,其特征在于,所述方法包括:A user authentication method in a converged network, the method comprising:
    终端设备向接入网元发送认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;The terminal device sends an authentication negotiation request to the access network element, where the authentication negotiation request is used to request the negotiation to determine the authentication type of the terminal device for performing user authentication.
    所述终端设备确定用户认证的认证类型为明文认证;The terminal device determines that the authentication type of the user authentication is plain text authentication;
    所述终端设备向所述接入网元发送用户认证信息;Transmitting, by the terminal device, user authentication information to the access network element;
    所述终端设备接收来自所述接入网元的认证结果。The terminal device receives an authentication result from the access network element.
  13. 一种接入网元,其特征在于,包括:An access network element, comprising:
    接收单元,用于接收来自终端设备的认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;a receiving unit, configured to receive an authentication negotiation request from the terminal device, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
    发送单元,用于发送认证参数请求给控制网元,所述认证参数请求包括:所述终端设备接入所述接入网元的接入协议类型;a sending unit, configured to send an authentication parameter request to the control network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
    所述接收单元,还用于接收来自所述控制网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;The receiving unit is further configured to receive at least one authentication parameter from the control network element, where the at least one authentication parameter corresponds to the access protocol type, and each type of authentication parameter includes an authentication type, and/ Or a parameter corresponding to the authentication type;
    所述发送单元,还用于发送所述至少一种认证参数给所述终端设备;The sending unit is further configured to send the at least one authentication parameter to the terminal device;
    确定单元,用于在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持 的其中一种认证参数;a determining unit, configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
    所述接收单元,还用于获取所述终端设备的用户认证信息;The receiving unit is further configured to acquire user authentication information of the terminal device;
    所述发送单元,还用于将所述用户认证信息和确定的其中一种认证参数发送给所述控制网元进行认证;The sending unit is further configured to send the user authentication information and the determined one of the authentication parameters to the control network element for authentication;
    所述接收单元,还用于接收来自所述控制网元的认证结果;The receiving unit is further configured to receive an authentication result from the control network element;
    所述发送单元,还用于发送所述认证结果给所述终端设备。The sending unit is further configured to send the authentication result to the terminal device.
  14. 如权利要求13所述的接入网元,其特征在于,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。The access network element according to claim 13, wherein the authentication negotiation request and the authentication parameter request further comprise: an authentication type supported by the terminal device, and the parameter corresponding to the authentication type is the The parameter corresponding to the authentication type supported by the terminal device.
  15. 如权利要求13或14所述的接入网元,其特征在于,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。The access network element according to claim 13 or 14, wherein the at least one type of authentication comprises a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is empty.
  16. 如权利要求13或14所述的接入网元,其特征在于,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。The access network element according to claim 13 or 14, wherein the at least one authentication type comprises a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier. length.
  17. 一种终端设备,其特征在于,包括:A terminal device, comprising:
    发送单元,用于向接入网元发送认证协商请求,所述认证协商请求用于协商确定所述终端设备的认证参数;a sending unit, configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to negotiate to determine an authentication parameter of the terminal device;
    接收单元,用于接收来自所述接入网元的至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括一种认证类型、和/或与所述认证类型对应的参数;a receiving unit, configured to receive at least one authentication parameter from the access network element, where the at least one authentication parameter corresponds to the access protocol type, each authentication parameter includes an authentication type, and/or a parameter corresponding to the authentication type;
    确定单元,用于在所述至少一种认证参数中确定所述终端设备和所述控制网元均支持的其中一种认证参数;a determining unit, configured to determine, in the at least one authentication parameter, one of the authentication parameters supported by the terminal device and the control network element;
    所述发送单元,还用于向所述接入网元发送用户认证信息;The sending unit is further configured to send user authentication information to the access network element;
    所述接收单元,还用于接收来自所述接入网元的认证结果。The receiving unit is further configured to receive an authentication result from the access network element.
  18. 如权利要求17所述的终端设备,其特征在于,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。The terminal device according to claim 17, wherein the authentication negotiation request and the authentication parameter request further comprise: an authentication type supported by the terminal device, and the parameter corresponding to the authentication type is the terminal device The parameters corresponding to the supported authentication type.
  19. 一种控制网元,其特征在于,包括:A control network element, comprising:
    接收单元,用于接收来自接入网元的认证参数请求,所述认证参数请求包括:终端设备接入所述接入网元的接入协议类型;a receiving unit, configured to receive an authentication parameter request from the access network element, where the authentication parameter request includes: an access protocol type that the terminal device accesses the access network element;
    生成单元,用于根据所述认证参数请求,生成至少一种认证参数,所述至少一种认证参数与所述接入协议类型对应,每种认证参数包括根据所述认证参数请求确认所支持的一种认证类型、和/或与所述认证类型对应的参数;a generating unit, configured to generate, according to the authentication parameter request, at least one type of authentication parameter, where the at least one type of authentication parameter corresponds to the access protocol type, and each type of the authentication parameter includes a request for confirmation according to the authentication parameter request An authentication type, and/or a parameter corresponding to the authentication type;
    发送单元,用于将所述至少一种认证参数发送给所述接入网元;a sending unit, configured to send the at least one authentication parameter to the access network element;
    所述接收单元,还用于接收来自所述接入网元的用户认证信息、以及接入网元所述至少一种认证参数中的所述终端设备和所述控制网元均支持的其中一种认证参数;The receiving unit is further configured to receive user authentication information from the access network element, and one of the terminal device and the control network element supported by the access network element and the at least one authentication parameter. Kind of authentication parameters;
    认证单元,用于采用所述确定的其中一种认证参数对所述用户认证信息进行认证,得到认证结果;An authentication unit, configured to authenticate the user authentication information by using the determined one of the authentication parameters, to obtain an authentication result;
    所述发送单元,还用于将所述认证结果发送给所述接入网元。The sending unit is further configured to send the authentication result to the access network element.
  20. 如权利要求19所述的控制网元,其特征在于,所述认证协商请求和所述认证参数请求还包括:所述终端设备支持的认证类型,则所述认证类型对应的参数为所述终端设备支持的认证类型对应的参数。The control network element according to claim 19, wherein the authentication negotiation request and the authentication parameter request further comprise: an authentication type supported by the terminal device, and the parameter corresponding to the authentication type is the terminal The parameter corresponding to the authentication type supported by the device.
  21. 如权利要求19或20所述的控制网元,其特征在于,所述至少一种认证类型包括简单密码认证协议PAP,所述认证类型对应的参数为空。The control network element according to claim 19 or 20, wherein the at least one type of authentication comprises a simple password authentication protocol PAP, and the parameter corresponding to the authentication type is empty.
  22. 如权利要求19或20所述的控制网元,其特征在于,所述至少一种认证类型包括挑战握手协议CHAP,所述认证类型对应的参数包括:算法、挑战标识、和/或挑战标识长度。The control network element according to claim 19 or 20, wherein the at least one authentication type comprises a challenge handshake protocol CHAP, and the parameters corresponding to the authentication type include: an algorithm, a challenge identifier, and/or a challenge identifier length. .
  23. 一种接入网元,其特征在于,包括:An access network element, comprising:
    接收单元,用于接收来自终端设备的认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;a receiving unit, configured to receive an authentication negotiation request from the terminal device, where the authentication negotiation request is used to request negotiation to determine an authentication type of the terminal device for performing user authentication;
    确定单元,用于确定所述终端设备的认证类型为明文认证;a determining unit, configured to determine that the authentication type of the terminal device is plain text authentication;
    所述接收单元,还用于接收来自所述终端设备的用户认证信息;The receiving unit is further configured to receive user authentication information from the terminal device;
    发送单元,用于将所述用户认证信息和所述认证类型发送给控制网元进行认证;a sending unit, configured to send the user authentication information and the authentication type to a control network element for authentication;
    所述接收单元,还用于接收来自所述控制网元的认证结果;The receiving unit is further configured to receive an authentication result from the control network element;
    所述发送单元,还用于发送所述认证结果给所述终端设备。The sending unit is further configured to send the authentication result to the terminal device.
  24. 一种终端设备,其特征在于,包括:A terminal device, comprising:
    发送单元,用于向接入网元发送认证协商请求,所述认证协商请求用于请求协商确定所述终端设备进行用户认证的认证类型;a sending unit, configured to send an authentication negotiation request to the access network element, where the authentication negotiation request is used to request negotiation to determine an authentication type of the terminal device for performing user authentication;
    确定单元,用于确定用户认证的认证类型为明文认证;a determining unit, configured to determine that the authentication type of the user authentication is plain text authentication;
    所述发送单元,还用于向所述接入网元发送用户认证信息;The sending unit is further configured to send user authentication information to the access network element;
    接收单元,用于接收来自所述接入网元的认证结果。And a receiving unit, configured to receive an authentication result from the access network element.
  25. 一种接入网元,其特征在于,包括处理器,所述处理器用于与存储器耦合,并读取存储器中的指令并根据所述指令执行如权利要求1-4或11中任意一项所述的方法。An access network element, comprising: a processor, the processor for coupling with a memory, and reading an instruction in the memory and performing the method according to any one of claims 1-4 or 11 according to the instruction The method described.
  26. 一种终端设备,其特征在于,包括处理器,所述处理器用于与存储器耦合,并读取存储器中的指令并根据所述指令执行如权利要求5-6或12中任意一项所述的方法。A terminal device, comprising: a processor, the processor for coupling with a memory, and reading an instruction in the memory and performing the method according to any one of claims 5-6 or 12 according to the instruction method.
  27. 一种控制网元,其特征在于,包括处理器,所述处理器用于与存储器耦合,并读取存储器中的指令并根据所述指令执行如权利要求7-10中任意一项所述的方法。A control network element, comprising a processor, the processor for coupling with a memory, and reading instructions in the memory and performing the method of any one of claims 7-10 according to the instructions .
  28. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行如权利要求1-4或11中任意一项所述的方法。A computer readable storage medium, wherein the computer readable storage medium stores instructions that, when run on a computer, cause the computer to perform the method of any one of claims 1-4 or method.
  29. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行如权利要求5-6或12中任意一项所述的方法。A computer readable storage medium, wherein the computer readable storage medium stores instructions that, when run on a computer, cause the computer to perform the method of any one of claims 5-6 or 12 method.
  30. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行如权利要求7-10中任意一项所述的方法。A computer readable storage medium, wherein the computer readable storage medium stores instructions that, when run on a computer, cause the computer to perform the method of any one of claims 7-10.
PCT/CN2018/082289 2017-04-25 2018-04-09 User authentication method and apparatus in converged network WO2018196587A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710277650.4A CN108738019B (en) 2017-04-25 2017-04-25 User authentication method and device in converged network
CN201710277650.4 2017-04-25

Publications (1)

Publication Number Publication Date
WO2018196587A1 true WO2018196587A1 (en) 2018-11-01

Family

ID=63917992

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/082289 WO2018196587A1 (en) 2017-04-25 2018-04-09 User authentication method and apparatus in converged network

Country Status (2)

Country Link
CN (1) CN108738019B (en)
WO (1) WO2018196587A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111988778A (en) * 2019-05-21 2020-11-24 广东美的制冷设备有限公司 Multi-protocol authentication method for device, WIFI module, and computer-readable storage medium

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4016950A4 (en) * 2019-08-18 2022-08-10 Huawei Technologies Co., Ltd. Communication method, device, and system
CN110572804B (en) * 2019-08-27 2022-04-22 暨南大学 Bluetooth communication authentication request, receiving and communication method, mobile terminal and equipment terminal
CN111147471B (en) * 2019-12-20 2023-02-28 视联动力信息技术股份有限公司 Terminal network access authentication method, device, system and storage medium
CN114245376A (en) * 2020-09-07 2022-03-25 中国移动通信有限公司研究院 Data transmission method, user equipment, related network equipment and storage medium
CN114051244A (en) * 2021-11-10 2022-02-15 杭州萤石软件有限公司 Authentication method and system between terminal side equipment and network side equipment

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1536508A (en) * 2003-04-09 2004-10-13 华为技术有限公司 Method for displaying door web page based on Ethernet protocol when the user is logged
WO2006123974A1 (en) * 2005-05-16 2006-11-23 Telefonaktiebolaget Lm Ericsson (Publ) Means and method for ciphering and transmitting data in integrated networks
CN101730102A (en) * 2009-05-15 2010-06-09 中兴通讯股份有限公司 System and method for implementing authentication on user of home base station

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8341700B2 (en) * 2003-10-13 2012-12-25 Nokia Corporation Authentication in heterogeneous IP networks
CN100407687C (en) * 2003-11-21 2008-07-30 华为技术有限公司 Asynchronous transmission mode exchange net user's Ethernet access method
CN101753533A (en) * 2008-12-04 2010-06-23 华为终端有限公司 Method, device and system for negotiating authentication methods
CN103139768B (en) * 2011-11-28 2017-03-01 上海贝尔股份有限公司 Authentication method in fusing wireless network and authentication device
CN103297968B (en) * 2012-03-02 2017-12-29 华为技术有限公司 A kind of method, equipment and the system of wireless terminal certification
CN105306406A (en) * 2014-05-26 2016-02-03 中国移动通信集团公司 Negotiation method of authentication and key negotiation algorithm, network side equipment and user equipment

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1536508A (en) * 2003-04-09 2004-10-13 华为技术有限公司 Method for displaying door web page based on Ethernet protocol when the user is logged
WO2006123974A1 (en) * 2005-05-16 2006-11-23 Telefonaktiebolaget Lm Ericsson (Publ) Means and method for ciphering and transmitting data in integrated networks
CN101730102A (en) * 2009-05-15 2010-06-09 中兴通讯股份有限公司 System and method for implementing authentication on user of home base station

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111988778A (en) * 2019-05-21 2020-11-24 广东美的制冷设备有限公司 Multi-protocol authentication method for device, WIFI module, and computer-readable storage medium
CN111988778B (en) * 2019-05-21 2023-09-26 广东美的制冷设备有限公司 Device, multi-protocol authentication method of WIFI module and computer readable storage medium

Also Published As

Publication number Publication date
CN108738019A (en) 2018-11-02
CN108738019B (en) 2021-02-05

Similar Documents

Publication Publication Date Title
US11716621B2 (en) Apparatus and method for providing mobile edge computing services in wireless communication system
WO2018196587A1 (en) User authentication method and apparatus in converged network
JP7035163B2 (en) Network security management methods and equipment
US7194763B2 (en) Method and apparatus for determining authentication capabilities
JP5934364B2 (en) Mobile device and method for secure online sign-up and provision for WI-FI hotspots using SOAP-XML technology
US20200053131A1 (en) Method for accessing fixed network and access gateway network element
EP2572491B1 (en) Systems and methods for host authentication
US20110154454A1 (en) Method and system for authenticating a network node in a uam-based wlan network
KR20100100641A (en) Dual modem device
US8588742B2 (en) Method and apparatus for providing wireless services to mobile subscribers using existing broadband infrastructure
US11363023B2 (en) Method, device and system for obtaining local domain name
KR20130040210A (en) Method of connecting a mobile station to a communications network
WO2014101449A1 (en) Method for controlling access point in wireless local area network, and communication system
EP2712141A1 (en) Method, system and device for authenticating ip phone and negotiating voice field
JP2019533951A (en) Next-generation system certification
WO2019096287A1 (en) Authentication method and device
WO2019227459A1 (en) Methods and nodes for authentication of a tls connection
WO2015100874A1 (en) Home gateway access management method and system
US20190200226A1 (en) Method of authenticating access to a wireless communication network and corresponding apparatus
US11502987B2 (en) Communication system and method for performing third-party authentication between home service end and foreign service end
CN102143601B (en) Broadband access processing method, radio access network (RAN) and communication system
JP2006345302A (en) Gateway device and program
WO2013166909A1 (en) Method and system for eap authentication triggering, access network device and terminal device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18791645

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18791645

Country of ref document: EP

Kind code of ref document: A1