WO2015100975A1 - 一种选择认证算法的方法、装置及系统 - Google Patents

一种选择认证算法的方法、装置及系统 Download PDF

Info

Publication number
WO2015100975A1
WO2015100975A1 PCT/CN2014/080736 CN2014080736W WO2015100975A1 WO 2015100975 A1 WO2015100975 A1 WO 2015100975A1 CN 2014080736 W CN2014080736 W CN 2014080736W WO 2015100975 A1 WO2015100975 A1 WO 2015100975A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
algorithm
user equipment
authentication algorithm
supported
Prior art date
Application number
PCT/CN2014/080736
Other languages
English (en)
French (fr)
Inventor
甘露
何承东
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP14876188.5A priority Critical patent/EP3079392A1/en
Priority to KR1020167020662A priority patent/KR20160103115A/ko
Publication of WO2015100975A1 publication Critical patent/WO2015100975A1/zh
Priority to US15/197,343 priority patent/US20160316368A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method, apparatus, and system for selecting an authentication algorithm. Background technique
  • the Proximity Service (ProSe) technology mainly establishes a secure communication channel between two user equipments (UEs) that are close to each other, so that the data can be carried out when the two UEs perform end-to-end data transmission. Secure exchange.
  • UEs user equipments
  • Secure exchange when two UEs establish a communication channel, they need to use a subscription network. The UE needs to pass network authentication to access the network, and then establish a communication channel with other UEs.
  • the UE and the Home Subscriber Server mainly use the Milenage algorithm to generate authentication parameters and keys required for authentication.
  • Tuak algorithm UEs or HSSs with different authentication capabilities also come into being, including UEs or HSSs that support only one authentication algorithm, or UEs that can support multiple authentication algorithms or
  • the HSS is such that when the UE and the HSS combination with different authentication capabilities authenticate the UE, it is impossible to determine which authentication algorithm is used for authentication, or the UE can be authenticated by using the Milenage algorithm.
  • the UE and the HSS cannot select the corresponding authentication algorithm to authenticate the UE according to the authentication algorithm supported by the UE or the HSS, or can authenticate the UE by using the Milenage algorithm even if the UE or the HSS supports multiple authentication algorithms.
  • the authentication algorithm has a single form, the authentication algorithm is low in selectivity, and the terminal (including the UE or the HSS) has low resource utilization, and the UE authentication user experience is low. Summary of the invention
  • the embodiment of the invention provides a method, a device and a system for selecting an authentication algorithm, which can select a corresponding authentication algorithm according to an authentication algorithm supported by a user equipment and a service device, and determine identification information of the authentication algorithm according to the selected authentication algorithm.
  • the diversity of authentication algorithm selection and utilization of terminal resources are improved, and the user experience of user equipment authentication is enhanced.
  • a first aspect of the embodiments of the present invention provides a method for selecting an authentication algorithm, which may include: a service device receiving an authentication data request message sent by a control device, where the authentication data request message carries information of an authentication algorithm supported by the user equipment;
  • the service device selects an authentication algorithm according to the authentication data request message and the information of the authentication algorithm supported by the service device;
  • the service device determines the identification information of the authentication algorithm according to the selected authentication algorithm; the service device sends the identification information of the authentication algorithm to the control device, to be sent by the control device to the User equipment.
  • the identifier information of the authentication algorithm that is carried in the authentication data request message includes: a Tuak algorithm supported by the user equipment, and/or the user equipment support Milenage algorithm;
  • the service device selects an authentication algorithm according to the authentication data request message and the information of the authentication algorithm supported by the service device, including:
  • the service device selects an authentication algorithm supported by the user equipment and the service device from an authentication algorithm supported by the user equipment and an authentication algorithm supported by the service device, and sets the authentication algorithm to The selected authentication algorithm;
  • the authentication algorithms supported by the service device include: a Tuak algorithm, and/or a Milenage algorithm.
  • the information about the authentication algorithm supported by the user equipment carried in the authentication data request message is empty;
  • the authentication algorithm information supported by the service device includes: a Tuak algorithm supported by the service device, and/or a Milenage algorithm supported by the service device;
  • the service device selects an authentication algorithm according to the authentication data request message and the information of the authentication algorithm supported by the service device, including:
  • the service device selects a Milenage algorithm from its supported authentication algorithms and sets the Milenage algorithm to the selected authentication algorithm.
  • the identifier information of the authentication algorithm is specifically an authentication vector that is authenticated by the user equipment
  • the service device sets the Tuak algorithm to the selected authentication algorithm, Determining, by the service device, the identification information of the authentication algorithm according to the selected authentication algorithm, including: the service device selecting, in a preset authentication management domain AMF parameter, a flag of an authentication algorithm for authenticating the user equipment And setting the flag bit as a first identifier as the identification information of the Tuak algorithm;
  • the service device generates an authentication vector that authenticates the user equipment according to the AMF parameter and the Tuak algorithm.
  • the identifier information of the authentication algorithm is specifically the authentication of the user equipment authentication.
  • the service device determines the identification information of the authentication algorithm according to the selected authentication algorithm, including: the service The device selects a flag bit of the authentication algorithm that is authenticated by the user equipment in a preset AMF parameter, and sets the flag bit as a second identifier, as the identifier information of the Milenage algorithm;
  • the service device generates an authentication vector for authenticating the user equipment according to the AMF parameter and the Milenage algorithm.
  • a second aspect of the embodiments of the present invention provides a method for selecting an authentication algorithm, which may include: sending, by a user equipment, information about an authentication algorithm supported by the user equipment to a control device;
  • the user equipment determines an authentication algorithm according to the user authentication request message, and authenticates the network according to the authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment includes: a Tuak algorithm supported by the user equipment, and/or supported by the user equipment.
  • Determining, by the user equipment, the authentication algorithm according to the user authentication request message including:
  • the user equipment parses the user authentication request message, and obtains identifier information of an authentication algorithm included in the user authentication request message;
  • the user equipment determines an authentication algorithm according to the identification information.
  • the user authentication request message includes an authentication parameter that is authenticated by the user equipment.
  • the authentication parameter that is authenticated by the user equipment includes an AUTN parameter, and the AUTN parameter includes an AMF parameter;
  • the identification information of the authentication algorithm includes: a first identifier of the flag bit of the authentication algorithm included in the AMF parameter, or a second identifier.
  • the user equipment determines an authentication algorithm according to the identifier information, including:
  • the user equipment sets a Tuak algorithm supported by the user equipment as an authentication algorithm
  • the user equipment sets the Milenage algorithm it supports as the authentication algorithm.
  • the information of the authentication algorithm supported by the user equipment is null
  • the determining, by the user equipment, the authentication algorithm according to the user authentication request message includes: the user equipment setting the Milenage algorithm supported by the user equipment as an authentication algorithm according to the user authentication request message.
  • a third aspect of the embodiments of the present invention provides a method for selecting an authentication algorithm, which may include: the control device receives information of an authentication algorithm supported by the user equipment and sent by the user equipment; and the control device sends an authentication data request to the service device. a message, where the authentication data request message carries information of an authentication algorithm supported by the user equipment;
  • the control device receives the identification information of the authentication algorithm sent by the service device, where the identifier information of the authentication algorithm corresponds to the authentication data request message;
  • the control device sends a user authentication request message to the user equipment, where the user authentication request message carries the identification information of the authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment includes: a Tuak algorithm supported by the user equipment, and/or supported by the user equipment.
  • the identifier information of the authentication algorithm sent by the service device includes: the Tuak selected by the service device The identification information corresponding to the algorithm, and/or the identification information corresponding to the Milenage algorithm selected by the service device, or is empty.
  • a fourth aspect of the embodiments of the present invention provides a service device for selecting an authentication algorithm, which may include: a receiving module, configured to receive an authentication data request message sent by a control device, where the authentication data request message carries the authentication supported by the user equipment. Algorithm information;
  • a selection module configured to select an authentication algorithm according to the authentication data request message received by the receiving module, and information of an authentication algorithm supported by the service device;
  • a processing module configured to determine, according to the authentication algorithm selected by the selection module, identifier information of the authentication algorithm
  • a sending module configured to send the identifier information of the authentication algorithm to the control device, to be sent to the user equipment by using the control device.
  • the identifier information of the authentication algorithm that is carried in the authentication data request message that is received by the receiving module includes: a Tuak algorithm supported by the user equipment, and/ Or the Milenage algorithm supported by the user equipment;
  • the selection module is specifically configured to:
  • the authentication algorithms supported by the service device include: a Tuak algorithm, and/or a Milenage algorithm.
  • the information about the authentication algorithm supported by the user equipment carried in the authentication data request message received by the receiving module is empty;
  • the authentication algorithm information supported by the service device includes: a Tuak algorithm supported by the service device, and/or a Milenage algorithm supported by the service device;
  • the selection module is specifically configured to:
  • the service device selects a Milenage algorithm from its supported authentication algorithms, and The Milenage algorithm is set to the selected authentication algorithm.
  • the identifier information of the authentication algorithm that is determined by the processing module is specifically an authentication vector that is authenticated by the user equipment;
  • the processing module is specifically configured to:
  • An authentication vector for authenticating the user equipment is generated according to the AMF parameter and the Tuak algorithm.
  • the identifier information of the authentication algorithm determined by the processing module is specifically An authentication vector for user equipment authentication
  • the processing module is specifically configured to:
  • An authentication vector for authenticating the user equipment is generated according to the AMF parameter and the Milenage algorithm.
  • a fifth aspect of the embodiments of the present invention provides a user equipment for selecting an authentication algorithm, which may include: a sending module, configured to send, to a control device, information about an authentication algorithm supported by the user equipment; and a receiving module, configured to receive the Controlling a user authentication request message sent by the device;
  • a processing module configured to determine an authentication algorithm according to the user authentication request message, and authenticate the network according to the authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment that is sent by the sending module includes: a Tuak algorithm supported by the user equipment, and/or the user equipment supports Milenage algorithm;
  • the processing module is specifically configured to:
  • An authentication algorithm is determined based on the identification information.
  • the user authentication request message received by the receiving module includes an authentication parameter that is authenticated by the user equipment
  • the authentication parameter that is received by the receiving module and that is authenticated by the user equipment includes
  • AUTN parameter where the AUTN parameter includes an AMF parameter
  • the identification information of the authentication algorithm includes: a first identifier of the flag bit of the authentication algorithm included in the AMF parameter, or a second identifier.
  • the processing module is specifically configured to:
  • the Tuak algorithm supported by the user equipment is set as an authentication algorithm
  • the Milenage algorithm supported by the user equipment is set as an authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment sent by the sending module is empty;
  • the processing module is specifically configured to:
  • a sixth aspect of the embodiments of the present invention provides a control device for selecting an authentication algorithm, which may include: a receiving module, configured to receive, by a user equipment, information about an authentication algorithm supported by the user equipment;
  • a sending module configured to send an authentication data request message to the service device, where the authentication data request message carries information of an authentication algorithm supported by the user equipment;
  • the receiving module is configured to receive identifier information of an authentication algorithm sent by the service device, where the identifier information of the authentication algorithm corresponds to the authentication data request message;
  • the sending module is configured to send a user authentication request message to the user equipment, where the user authentication request message carries the identifier information of the authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment that is received by the receiving module includes: a Tuak algorithm supported by the user equipment, and/or the user equipment supports The Milenage algorithm, or null.
  • the identifier information of the authentication algorithm that is received by the receiving module includes: the Tuak selected by the service device The identification information corresponding to the algorithm, and/or the identification information corresponding to the Milenage algorithm selected by the service device, or is empty.
  • a seventh aspect of the embodiments of the present invention provides a system for selecting an authentication algorithm, which may include: the service device provided by the fourth aspect of the embodiment of the present invention, the user equipment provided by the fifth aspect of the foregoing embodiment of the present invention, and the foregoing A control device provided by a sixth aspect of the invention.
  • the authentication algorithm supported by the user equipment and the service device is used to select a corresponding authentication algorithm to generate information such as an authentication vector required for authentication, thereby improving diversity of authentication algorithm selection and utilization of terminal resources, and enhancing user equipment authentication.
  • FIG. 1 is a schematic flow chart of a first embodiment of a method for selecting an authentication algorithm according to an embodiment of the present invention
  • FIG. 2 is a first interaction diagram of a method for selecting an authentication algorithm according to an embodiment of the present invention
  • FIG. 3 is a second interaction diagram of a method for selecting an authentication algorithm according to an embodiment of the present invention
  • FIG. 5 is a schematic flowchart diagram of a second embodiment of a method for selecting an authentication algorithm according to an embodiment of the present invention
  • FIG. 6 is a schematic flow chart of a third embodiment of a method for selecting an authentication algorithm according to an embodiment of the present invention.
  • FIG. 7 is a fourth interaction diagram of a method for selecting an authentication algorithm according to an embodiment of the present invention.
  • FIG. 8 is a fifth interaction diagram of a method for selecting an authentication algorithm according to an embodiment of the present invention;
  • FIG. 9 is a sixth interaction diagram of a method for selecting an authentication algorithm according to an embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of an embodiment of a user equipment for selecting an authentication algorithm according to an embodiment of the present invention.
  • FIG. 12 is a schematic structural diagram of an embodiment of a control device for selecting an authentication algorithm according to an embodiment of the present invention.
  • FIG. 13 is a schematic structural diagram of an embodiment of a system for selecting an authentication algorithm according to an embodiment of the present invention. detailed description
  • the service device described in the embodiment of the present invention may include a Home Location Register (HLR) in a 3G communication system, or a Home Subscriber Server (HSS) in a 4G communication system, below.
  • HLR Home Location Register
  • HSS Home Subscriber Server
  • the method, device and system for selecting an authentication algorithm described in the embodiments of the present invention will be specifically described by taking the HSS as an example.
  • the user equipment described in the embodiment of the present invention may include a mobile subscriber (MS) in a 3G communication system, or a UE in a 4G communication system. The following is a description of the UE in the embodiment of the present invention.
  • the method, device and system for selecting an authentication algorithm are specifically described.
  • control device described in the embodiment of the present invention may include a Visitor Location Register (VLR) and a Serving GPRS Support Node (SGSN) in a 3G communication system, or a mobile in a 4G communication system.
  • VLR Visitor Location Register
  • SGSN Serving GPRS Support Node
  • a method, an apparatus, and a system for selecting an authentication algorithm described in the embodiments of the present invention are specifically described below by using an MME as an example.
  • FIG. 1 is a schematic flowchart diagram of a first embodiment of a method for selecting an authentication algorithm according to an embodiment of the present invention.
  • the method for selecting an authentication algorithm described in this embodiment includes the following steps: S101.
  • the service device receives an authentication data request message sent by the control device.
  • the service device selects an authentication algorithm according to the authentication data request message and information of an authentication algorithm supported by the service device.
  • the authentication data request message received by the HSS from the MME carries the information of the authentication algorithm supported by the user equipment, where the information of the authentication algorithm supported by the user equipment may include: a Tuak algorithm supported by the UE, or The Milenage algorithm supported by the UE, and the like.
  • the HSS when the authentication data request message received by the HSS from the MME includes the information of the authentication algorithm supported by the UE, and the HSS supports the authentication algorithm selection (that is, the HSS can support the Tuak algorithm and the Milenage algorithm), the HSS may be based on the foregoing authentication data.
  • the information of the authentication algorithm supported by the UE included in the request message the authentication algorithm supported by the HSS (that is, the authentication algorithm supported by the UE and the HSS) is selected, and the selected authentication algorithm is set as the authentication for the UE authentication.
  • the authentication algorithm supported by the HSS that is, the authentication algorithm supported by the UE and the HSS
  • the HSS may be based on the authentication algorithm supported by the HSS.
  • the authentication algorithm supported by the HSS is selected as the authentication algorithm for the UE authentication.
  • the HSS can select the Tuak algorithm from the UE-supported authentication algorithm as the authentication for the UE authentication.
  • Algorithm When the HSS supports the Milenage algorithm, the HSS can select the Milenage algorithm as the authentication algorithm for UE authentication from the authentication algorithms supported by the UE; when the HSS supports the Tuak algorithm and also supports the Milenage algorithm, the HSS can be authenticated from the UE. Any one of the algorithms is used as an authentication algorithm for UE authentication.
  • the HSS does not support the authentication algorithm selection (that is, the HSS only supports the Milenage algorithm)
  • the HSS receives the authentication data request message from the MME, the information about the authentication algorithm supported by the UE is included (including the UE supporting Tuak).
  • the algorithm and the Milenage algorithm the HSS selects the default authentication algorithm as the authentication algorithm for UE authentication, that is, the HSS defaults to the Milenage algorithm, and sets the above-mentioned Milenage algorithm as the authentication algorithm for UE authentication, as shown in FIG.
  • the HSS selects the Milenage algorithm and sets the above-mentioned Milenage algorithm as an authentication algorithm for UE authentication. That is, as shown in Figure 4, if the HSS supports authentication algorithm selection (ie, the HSS can support the Tuak algorithm and the Milenage algorithm), then the HSS receives the authentication from the MME.
  • the information of the authentication algorithm supported by the UE carried in the data request message is empty, and the HSS selects a default authentication algorithm, that is, the HSS selects the Milenage algorithm as the authentication algorithm for UE authentication.
  • the service device determines identification information of the authentication algorithm according to the selected authentication algorithm.
  • the selected authentication algorithm may be set in an Authentication Management Field (AMF) parameter of the sub-device.
  • AMF Authentication Management Field
  • the identifier information of the selected authentication algorithm may be set in the preset AMF parameter, and Calculating an authentication vector for UE authentication according to the AMF parameter and the selected authentication algorithm, wherein the authentication code calculated by the HSS according to the selected authentication algorithm includes an authentication parameter AUTN, MAC, XRES and a key for UE authentication. CK, IK, ⁇ , etc.
  • the HSS may select the Xth bit as the flag for UE authentication in the preset AMF parameters, and then set the Xth bit of the AMF parameter to 1 (ie, the first identifier), used as identification information of the Tuak algorithm for UE authentication; when the HSS selects the Milenage algorithm as the authentication algorithm for UE authentication, the HSS may select the Xth bit in the preset AMF parameter.
  • the Xth bit of the AMF parameter may be set to 0 (ie, the second identifier), which is used as identification information of an authentication algorithm for UE authentication, where the X of the AMF parameter is The bit can be any of the 8 bits that are free in the AMF parameter, ie 1 X 7.
  • the HSS does not support the authentication algorithm selection, after the HSS selects the authentication algorithm for the UE authentication, the HSS does not set the identifier of the UE authentication authentication algorithm for the preset AMF parameter. Information, the HSS may calculate an authentication vector for UE authentication according to a preset AMF parameter and a selected authentication algorithm. As shown in Figure 3, since the HSS does not support the authentication algorithm selection, the identification information of the authentication algorithm for the UE authentication cannot be set in the AMF parameter.
  • the HSS may calculate the authentication vector for the UE authentication according to the preset AMF parameter and the above-mentioned Milenage algorithm, where the Xth bit of the AMF parameter in the above authentication vector is The default value is 0, and the default value of the Xth bit of the above AMF is used as the identification information of the Milenage algorithm for UE authentication.
  • the service device sends the identifier information of the authentication algorithm to the control device.
  • the foregoing authentication algorithm may be used.
  • the identification information (specifically, the authentication vector for UE authentication) is sent to the MME.
  • the HSS may send the foregoing authentication vector to the MME by using an authentication data response message, where the authentication vector message sent to the MME includes identification information of the authentication algorithm that is authenticated by the UE. As shown in FIG. 2 or FIG.
  • the HSS selects the Tuak algorithm or the Milenage algorithm as the authentication algorithm for UE authentication according to the authentication data request message sent by the MEE, and sets the Tuak algorithm in the Xth bit of the preset AMF parameter.
  • the authentication vector for the UE authentication may be determined according to the AMF parameter and the selected authentication algorithm, and further Sending an authentication vector message including the information of the Xth bit of the AMF parameter to the MEE, after receiving the authentication vector message, the MME may save the authentication vector message and send the authentication parameter information of the UE authentication to the authentication vector message.
  • UE As shown in FIG.
  • the HSS selects the Milenage algorithm as the authentication algorithm for the UE authentication and determines the authentication vector for the UE authentication according to the Milenage algorithm, and then sends the authentication vector to the MME.
  • the identifier information of the authentication algorithm for the UE authentication included in the foregoing authentication vector message is the identifier information set by default in the preset AMF parameter, that is, the Xth bit of the AMF parameter in the above authentication vector is set to 0 by default, and the HSS may be Transmitting an authentication vector including the information of the Xth bit of the AMF parameter to the MME.
  • the MME may save the authentication vector message and send the authentication parameter information of the authentication vector message to the UE. .
  • the HSS when the HSS supports the authentication algorithm selection, the HSS may select the UE and the HSS according to the information of the authentication algorithm supported by the UE carried in the authentication data request message sent by the MME, and the information of the authentication algorithm supported by the HSS.
  • the supported authentication algorithm is used as an authentication algorithm for the UE authentication (including the Tuak algorithm or the Milenage algorithm), and sets the value of the Xth bit (including 0 and 1) of the AMF parameter according to the above selected authentication algorithm for UE authentication, and further Determining an authentication vector for UE authentication according to the AMF and the selected authentication algorithm, and including the selected UE authentication
  • the authentication vector of the identification information of the authentication algorithm is sent to the MME.
  • the HSS selects the Milenage algorithm as the authentication algorithm for UE authentication by default after receiving the authentication data request message sent by the MME, and determines the authentication vector for the UE authentication according to the preset AMF parameter and the above-mentioned Milenage algorithm. And transmitting the above-mentioned UE-authenticated authentication vector to the MME.
  • the HSS may select an authentication algorithm supported by the UE and the HSS as an authentication algorithm for UE authentication according to an authentication algorithm supported by the UE and an authentication algorithm supported by the UE, and determine an identifier of the authentication algorithm according to the selected authentication algorithm.
  • the information and the authentication vector for the UE authentication are used to notify the UE of the authentication algorithm for the authentication by the identification information of the authentication algorithm, improve the diversity of the selection of the authentication algorithm for the UE authentication, and the resource utilization of the UE and the HSS, and enhance the UE authentication. User experience.
  • FIG. 5 it is a schematic flowchart of a second embodiment of a method for selecting an authentication algorithm according to an embodiment of the present invention.
  • the method for selecting an authentication algorithm described in this embodiment includes the following steps:
  • the user equipment sends, to the control device, information about an authentication algorithm supported by the user equipment.
  • the UE may send a request message to the MME, and send the information of the authentication algorithm supported by the UE to the MME by using the foregoing request message; or
  • the MME may send a request message to the UE, requesting the UE to send the information of the authentication algorithm supported by the UE to the MME, and after receiving the request sent by the MME, the UE may send the request to the MME.
  • the information of the authentication algorithm supported by the UE is sent to the MME by using the foregoing response message.
  • the embodiment of the present invention does not specifically limit the sending manner of the information of the authentication algorithm supported by the UE to the MME.
  • the sending manner of the information of the authentication algorithm supported by the request message or the response message to the MME is only an example.
  • the embodiment of the present invention will be specifically described by taking an example of sending a message of an authentication algorithm supported by a UE to an MME by using a request message.
  • the request message sent by the UE to the MME may be an Attach request, or a Tracking Area Update (TAU) request or a registration request, and the like, and the embodiment of the present invention does not limit the message of the request message.
  • the request message sent by the UE to the MME may be added to the request message by adding the information of the authentication algorithm supported by the UE to the MME.
  • the UE when the UE supports the authentication algorithm selection (that is, the UE can support the Tuak algorithm and the Milenage algorithm), when the UE sends the request message to the MME, the UE may support the authentication algorithm (including the Tuak algorithm or the Milenage algorithm) supported by the UE.
  • the request message is sent to the MME, as shown in Figure 2 or Figure 3,
  • the request message sent by the UE to the MME carries the information of the Tuak algorithm or the Milenage algorithm supported by the UE.
  • the UE does not support the authentication algorithm selection (that is, the UE only supports the Milenage algorithm)
  • the UE sends the request message to the MME the UE does not
  • the information of the authentication algorithm supported by the UE is sent to the MME, that is, the information of the authentication algorithm supported by the UE carried in the request message sent by the UE to the MME is empty.
  • the user equipment receives a user authentication request message sent by the control device.
  • the user equipment determines an authentication algorithm according to the user authentication request message, and performs authentication on the network according to the authentication algorithm.
  • the MME may send an authentication data request message to the HSS according to the request message sent by the UE, and the HSS may receive the authentication data request message sent by the MME according to the foregoing authentication data request.
  • the message selects an authentication algorithm for the UE authentication, and sets the identification information of the authentication algorithm according to the selected authentication algorithm to determine an authentication vector for the UE authentication, and then sends the authentication vector of the identifier information including the foregoing authentication algorithm to the MME through the MME.
  • UE may send an authentication data request message to the HSS according to the request message sent by the UE, and the HSS may receive the authentication data request message sent by the MME according to the foregoing authentication data request.
  • the MME may save the foregoing identifier information of the UE-authenticated authentication algorithm (specifically, an authentication vector that is authenticated by the UE), and send a user authentication request to the UE.
  • the identifier information of the authentication algorithm for the UE authentication is sent to the UE.
  • the UE may determine an authentication algorithm for the network to authenticate according to the user authentication request message, and then determine an authentication algorithm according to the authentication algorithm of the network for the authentication (ie, the UE authentication algorithm for network authentication). And authenticating the network according to the authentication algorithm for the network determined above.
  • the user authentication request message sent by the UE to the MME includes the authentication parameter for the UE authentication, that is, the parameter included in the authentication vector for the UE authentication set by the HSS according to the request message sent by the UE, including the AUTN, the RAND parameter, and the like.
  • the UE when the UE supports the authentication algorithm selection, after the UE adds the information of the authentication algorithm it supports to the request message and sends the information to the MME, when the UE receives the user authentication request message from the MME, the UE The user authentication request message may be parsed, and the identifier information of the network-authenticated authentication algorithm is obtained from the authentication parameters included in the user authentication request message.
  • the HSS when the HSS supports the authentication algorithm, and the authentication data request message received by the HSS from the MME carries the information of the authentication algorithm supported by the UE, the HSS may be determined according to the authentication algorithm supported by the UE and the authentication algorithm supported by the UE.
  • the AMF parameter of the information is calculated to obtain an authentication vector for UE authentication.
  • the MME may send the authentication parameter for UE authentication in the above authentication vector to the UE.
  • the UE may parse the authentication parameter included in the user authentication request message, and obtain, from the foregoing authentication parameter, identifier information of the network-to-UE authentication algorithm, where the network is used by the UE.
  • the identification information of the authenticated authentication algorithm includes: a first identifier (for example, 1) or a second identifier (for example, 0) of a flag bit of the authentication algorithm for the UE authentication in the AMF parameter (ie, the Xth bit in the AMF parameter). ).
  • the UE may analyze the Xth bit of the AMF parameter in the user authentication request message, and obtain the identifier of the authentication algorithm from the Xth bit of the AMF parameter.
  • the information (including 0 or 1) determines the authentication algorithm for the network to authenticate according to the obtained identification information, and then determines the authentication algorithm for authenticating the network (consistent with the authentication algorithm of the network for its authentication).
  • the UE when the UE obtains the value of the Xth bit of the AMF from the AMF parameter that is 1 (ie, the first identifier), it may be determined that the authentication algorithm for the network authentication is the Tuak algorithm, and the UE determines that the network authenticates the network. After the authentication algorithm, it can be determined that the authentication algorithm for the network authentication is the Tuak algorithm, and then the network can be authenticated according to the Tuak algorithm; when the UE obtains the AMF parameter from the AMF parameter, the value of the Xth bit of the AMF is 0 ( That is, when the second identifier is used, it can be determined that the authentication algorithm for the network authentication is the Milenage algorithm. After the UE determines the authentication algorithm for the network authentication, the UE can determine that the authentication algorithm for the network authentication is the Milenage algorithm, and then The above Milenage algorithm authenticates the network.
  • the UE when the UE does not support the authentication algorithm selection, the UE sends the information of the authentication algorithm supported by the UE carried in the request message to the MME to be empty, and the UE carried by the HSS through the authentication data request message received by the MME The information of the supported authentication algorithm is also empty.
  • the HSS selects the default authentication algorithm (Milenage algorithm), and the identification information of the authentication algorithm for the UE authentication included in the authentication vector determined by the HSS according to the selected authentication algorithm is the AMF parameter.
  • the second identifier (0) of the X bit as shown in Figure 4.
  • the UE After receiving the user authentication request sent by the MME, the UE authenticates the network according to the default authentication algorithm (ie, the Milenage algorithm), that is, the authentication algorithm of the network authentication for the UE and the authentication algorithm for the network authentication by the UE are both the Milenage algorithm.
  • the information about the network authentication authentication algorithm may be sent to the MME by using the user authentication response, so that the UE completes the network authentication of the UE by using the MME, and allows the UE to Access to the network.
  • the PDCCH after receiving the information included in the request message sent by the UE, determines the identifier of the authentication algorithm and the authentication algorithm that is authenticated by the UE according to the information, and sends the identifier information of the authentication algorithm and the like by using the MME.
  • the PDCCH determines the identifier of the authentication algorithm and the authentication algorithm that is authenticated by the UE according to the information, and sends the identifier information of the authentication algorithm and the like by using the MME.
  • the UE when the UE supports the authentication algorithm selection, the UE may send the authentication algorithm supported by the UE to the MME through the request message, and may also obtain the information of the authentication algorithm authenticated by the network according to the user authentication request sent by the MME.
  • the authentication algorithm for the network is set as its authentication algorithm for network authentication, and the network is authenticated according to the above authentication algorithm.
  • the UE sends a request message to the MME, and the network receives the request message. After the request message is sent, the default Milenage algorithm is selected as the authentication algorithm for the UE authentication.
  • the default algorithm Milenage algorithm can be set as the authentication algorithm for the network authentication, thereby implementing The authentication algorithm is unified, and the UE is authenticated by the MME, and the UE is allowed to access the network.
  • the embodiment of the invention improves the diversity of the authentication algorithm selected by the UE and the resource utilization of the terminal, and enhances the user experience of the UE authentication.
  • FIG. 6 is a schematic flowchart diagram of a third embodiment of a method for selecting an authentication algorithm according to an embodiment of the present invention.
  • the method for selecting an authentication algorithm described in this embodiment includes the following steps:
  • the control device receives information about an authentication algorithm supported by the user equipment sent by the user equipment.
  • S302 The control device sends an authentication data request message to the service device.
  • the control device receives the identifier information of the authentication algorithm sent by the service device.
  • S304 The control device sends a user authentication request message to the user equipment.
  • the UE when the UE needs to send the information of the authentication algorithm supported by the UE to the MME, the UE may send a request message to the MME, and send the information of the authentication algorithm supported by the UE to the MME by using the foregoing request message; or
  • the MME may send a request message to the UE, requesting the UE to send the information of the authentication algorithm supported by the UE to the MME, and after receiving the request sent by the MME, the UE may send the request to the MME.
  • the information of the authentication algorithm supported by the UE is sent to the MME by using the foregoing response message.
  • the embodiment of the present invention does not specifically limit the sending manner of the information of the authentication algorithm supported by the UE to the MME, and the foregoing sends the information of the authentication algorithm supported by the request message or the response message to the MME.
  • the manner of sending the MME is only an example, and is not exhaustive.
  • the embodiment of the present invention will be specifically described by taking the sending manner of the information of the authentication algorithm supported by the UE to the MME by using the request message.
  • the information about the authentication algorithm supported by the UE includes: a Tuak algorithm supported by the UE, or a Milenage algorithm supported by the UE, or is null.
  • the MME when the UE supports the authentication algorithm selection (that is, the UE supports the Tuak algorithm and the Milenage algorithm), when the UE sends the request message to the MME, the information of the authentication algorithm supported by the UE may be sent to the MME through the foregoing request message; when the UE does not support the authentication algorithm selection When the UE only supports the Milenage algorithm, the information of the authentication algorithm supported by the UE carried in the request message sent by the UE to the MME is empty. After receiving the request message sent by the UE, the MME may send an authentication data request message to the HSS according to the request message.
  • the authentication algorithm selection that is, the UE supports the Tuak algorithm and the Milenage algorithm
  • the MME may send the information of the authentication algorithm supported by the UE to the HSS through the foregoing authentication data request message;
  • the information of the authentication algorithm supported by the UE carried in the request message is empty, when the MME sends an authentication data request message to the HSS, the information of the authentication algorithm supported by the UE carried in the authentication data request message is empty.
  • the HSS may determine an authentication algorithm for the UE authentication according to the foregoing authentication data request message, and calculate an authentication algorithm for the UE authentication according to the determined authentication algorithm.
  • Identification information (specifically, an authentication vector for UE authentication).
  • the HSS may send the authentication vector to the MME by using the authentication data response message.
  • the MME may save the authentication vector included in the authentication data response message, and then send a user authentication request message to the UE, and authenticate the UE that is included in the authentication message that is authenticated by the UE.
  • the authentication parameters are sent to the UE, as shown in Figure 2, Figure 3 or Figure 4.
  • the UE may obtain information such as an authentication parameter that the network authenticates, and then determine an authentication algorithm for the network authentication according to the foregoing authentication parameter.
  • the method for determining the authentication algorithm and the authentication vector for the UE to be authenticated by the HSS according to the authentication data request message sent by the MME, and transmitting the information such as the authentication vector to the MME by using the authentication data response message may be referred to the embodiment of the present invention.
  • the first embodiment of the method for selecting an authentication algorithm is provided, and details are not described herein again.
  • the foregoing UE sends a request message to the MME, and determines a pair according to the user authentication request sent by the MME.
  • the second embodiment of the method for selecting an authentication algorithm provided by the embodiment of the present invention, and details are not described herein again.
  • the MME when the MME supports the saving and forwarding of the information of the authentication algorithm supported by the UE , if the request message sent by the UE to the MME carries the information of the authentication algorithm supported by the UE (that is, the UE supports the Tuak algorithm and the Milenage algorithm). After receiving the request message sent by the UE, the MME may save the information of the authentication algorithm supported by the UE, and send the information of the authentication algorithm supported by the UE to the HSS through the authentication data request message, as shown in FIG. 2 or FIG. 3; The information of the authentication algorithm supported by the UE carried in the request message sent to the MME is empty.
  • the MME may send an authentication data request message to the HSS, where the authentication algorithm supported by the UE carried in the authentication data request message is The information is empty, as shown in Figure 4.
  • the MME does not support the information of the authentication algorithm supported by the UE, if the request message sent by the UE to the MME carries the information of the authentication algorithm supported by the UE (that is, the UE supports the Tuak algorithm and the Milenage algorithm), the MME receives the UE and sends the message. After the request message, the information of the authentication algorithm supported by the UE cannot be saved.
  • the MME sends the authentication data request message to the HSS the information of the authentication algorithm supported by the UE carried in the authentication data request message is empty, as shown in FIG.
  • the MME may send an authentication data request message to the HSS after receiving the request message sent by the UE, where the authentication data request message is sent.
  • the information of the authentication algorithm supported by the UE carried in the space is empty, as shown in FIG. 9.
  • the MME may also obtain the user authentication response message from the UE, and complete the authentication of the UE according to the authentication vector of the UE authentication sent by the saved HSS, and further Allow the UE to access the network.
  • the MME may receive the information of the authentication algorithm supported by the UE and send the authentication data request message to the HSS according to the information of the authentication algorithm supported by the UE, and obtain the HSS from the HSS according to the foregoing authentication data request message.
  • the information of the authentication information of the UE authentication authentication algorithm (specifically, the authentication vector for the UE authentication) is sent to the UE, and the user authentication request is sent to the UE, and the identifier information of the authentication algorithm of the HSS is sent to the UE.
  • the MME may also obtain the user authentication response message from the UE, and complete the authentication of the UE access network by combining the information such as the authentication vector of the UE authentication sent by the HSS, thereby allowing the UE to access the UE.
  • Network MME can also be configured according to its own (ie whether it supports UE-supported authentication)
  • the information of the algorithm is saved and forwarded.
  • the authentication data request message is sent to the HSS, which enriches the diversity of the authentication algorithm of the UE authentication, improves the terminal utilization rate of the UE authentication, and enhances the user experience of the UE authentication.
  • FIG. 10 is a schematic structural diagram of an embodiment of a service device for selecting an authentication algorithm according to an embodiment of the present invention.
  • the service device described in this embodiment includes:
  • the receiving module 10 is configured to receive an authentication data request message sent by the control device, where the authentication data request message carries information of an authentication algorithm supported by the user equipment.
  • the selecting module 20 is configured to select an authentication algorithm according to the authentication data request message received by the receiving module and the information of the authentication algorithm supported by the service device.
  • the processing module 30 is configured to determine identification information of the authentication algorithm according to the authentication algorithm selected by the selection module.
  • the sending module 40 is configured to send the identifier information of the authentication algorithm to the control device, to be sent to the user equipment by using the control device.
  • the identifier information of the authentication algorithm carried in the authentication data request message received by the receiving module 10 includes: a Tuak algorithm supported by the user equipment, and/or supported by the user equipment. Milenage algorithm;
  • the selection module 20 is specifically configured to:
  • the authentication algorithms supported by the service device include: a Tuak algorithm, and/or a Milenage algorithm.
  • the information about the authentication algorithm supported by the user equipment carried in the authentication data request message received by the receiving module 10 is empty;
  • the authentication algorithm information supported by the service device includes: a Tuak algorithm supported by the service device, and/or a Milenage algorithm supported by the service device;
  • the selection module 20 is specifically configured to:
  • the service device selects a Milenage algorithm from its supported authentication algorithms and sets the Milenage algorithm to the selected authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment is included in the authentication data request message received by the receiving module 10 of the HSS, where the information about the authentication algorithm supported by the user equipment may include: Tuak algorithm, or UE-supported Milenage algorithm.
  • the selecting module 20 may And selecting an authentication algorithm supported by the HSS (that is, an authentication algorithm supported by the UE and the HSS) according to the information of the authentication algorithm supported by the UE included in the authentication data request message, and setting the selected authentication algorithm to be the pair.
  • UE authentication authentication algorithm For example, as shown in FIG.
  • the selection module 20 may be based on the HSS.
  • the supported authentication algorithm selects the authentication algorithm supported by the HSS as the authentication algorithm for the UE authentication. For example, when the HSS supports the Tuak algorithm, the selection module 20 can select the Tuak algorithm from the authentication algorithms supported by the UE.
  • the selection module 20 may select the Milenage algorithm as the authentication algorithm for UE authentication from the authentication algorithms supported by the UE; when the HSS supports the Tuak algorithm and also supports the Milenage algorithm, The selection module 20 may select one of the authentication algorithms supported by the UE as an authentication algorithm for UE authentication.
  • the HSS does not support the authentication algorithm selection (that is, the HSS only supports the Milenage algorithm)
  • the receiving module 10 receives the authentication data request message from the MME
  • the information about the authentication algorithm supported by the UE is included.
  • the selection module 20 selects the default authentication algorithm as the authentication algorithm for the UE authentication, that is, the selection module 20 selects the Milenage algorithm by default, and sets the above-mentioned Milenage algorithm as the authentication algorithm for the UE authentication, as shown in the figure. 3.
  • the information of the authentication algorithm supported by the UE that is carried in the authentication data request message received by the receiving module 10 from the MME is empty, that is, the authentication data request message does not include the authentication algorithm information supported by the UE.
  • the selection module 20 selects the Milenage algorithm and sets the above-described Milenage algorithm as an authentication algorithm for UE authentication. That is, as shown in FIG.
  • the selection module 20 selects a default authentication algorithm, that is, the selection module 20 selects the Milenage algorithm as the authentication algorithm for UE authentication.
  • the receiving, by the receiving module and the selecting module of the HSS, according to the received authentication data request message sent by the MME, the specific implementation process of the authentication algorithm for the UE authentication may be referred to the first implementation of the selective authentication algorithm provided by the embodiment of the present invention. Steps S101-S102 of the example are not described herein again.
  • the identifier information of the authentication algorithm determined by the processing module 30 is specifically an authentication vector that is authenticated by the user equipment.
  • the processing module 30 is specifically configured to:
  • An authentication vector for authenticating the user equipment is generated according to the AMF parameter and the Tuak algorithm.
  • the identifier information of the authentication algorithm determined by the processing module 30 is specifically an authentication vector that is authenticated by the user equipment.
  • the processing module 30 is specifically configured to:
  • An authentication vector for authenticating the user equipment is generated according to the AMF parameter and the Milenage algorithm.
  • the processing module 30 may set the selected authentication in the preset AMF parameter.
  • the processing module 30 may set the selected authentication algorithm in the preset AMF parameter.
  • the processing module 30 includes the authentication vector calculated according to the authentication algorithm selected by the selection module 20 Authentication parameters AUTN, MAC, XRES and keys CK, ⁇ , ⁇ , etc. for UE authentication. For example, when the selection module 20 of the HSS selects the Tuak algorithm as the authentication algorithm for the UE authentication, the processing module 30 of the HSS may select the Xth bit in the preset AMF parameter as the flag for the UE authentication, and then the AMF.
  • the Xth bit of the parameter is set to 1 (ie, the first identifier) for use as identification information of the Tuak algorithm for UE authentication; when the selection module 20 of the HSS selects the Milenage algorithm as the authentication algorithm for UE authentication, the HSS
  • the processing module 30 may select the Xth bit as the flag for UE authentication in the preset AMF parameter, and further set the Xth bit of the AMF parameter to 0 (ie, the second identifier), as the Milenage algorithm.
  • Identification information wherein the Xth bit of the above AMF parameter may be any one of the 8 bits that are free in the AMF parameter, that is, 1 X 7.
  • the processing module 30 of the HSS does not set the preset AMF parameter.
  • the processing module 30 of the HSS may calculate the authentication vector for the UE authentication according to the preset AMF parameter and the selected authentication algorithm. As shown in FIG. 3, the HSS does not support the authentication algorithm selection, and the processing module 30 cannot set the identifier information of the authentication algorithm for the UE authentication in the AMF parameter.
  • the processing module 30 of the HSS can calculate the authentication vector for the UE authentication according to the preset AMF parameter and the above-mentioned Milenage algorithm.
  • the Xth bit of the AMF parameter is the default value of 0, and the default value of the Xth bit of the above AMF is used as the identification information of the Milenage algorithm for UE authentication.
  • the processing module 30 of the HSS determines the authentication algorithm for UE authentication according to the authentication data request message sent by the MME received by the receiving module 10, and determines the authentication of the UE authentication according to the selected authentication algorithm.
  • the sending module 40 may send the authentication vector determined by the processing module 30 to the MME.
  • the authentication data response message sent by the sending module 40 that the HSS can send to the MME sends the authentication vector to the MME, and the authentication vector message sent by the sending module 40 to the MME includes the identification information of the authentication algorithm that is authenticated by the UE. As shown in FIG. 2 or FIG.
  • the processing module 30 may determine the authentication vector for the UE authentication according to the AMF parameter and the selected authentication algorithm, and further include the information of the Xth bit of the AMF parameter by using the sending module 40.
  • the authentication vector message is sent to the MEE.
  • the MME may save the authentication vector message and send the authentication parameter information for the UE authentication in the authentication vector message to the UE.
  • the selection module 20 of the HSS selects the Milenage algorithm as the authentication algorithm for the UE authentication by default and determines the authentication vector for the UE authentication by the processing module 30 according to the Milenage algorithm selected by the selection module 20.
  • the sending module 40 may send the foregoing authentication vector to the MME, where the identifier information of the authentication algorithm for the UE authentication included in the authentication vector message is the identifier information that is preset by default in the preset AMF parameter, that is, the foregoing authentication vector.
  • the X-th bit of the AMF parameter is set to 0 by default, and the sending module 40 of the HSS may send an authentication vector containing the information of the X-th bit of the AMF parameter to the MME, and after receiving the above-mentioned authentication vector message, the MME may save the above.
  • the authentication vector message is sent to the UE by the authentication parameter information for the UE authentication in the above authentication vector message.
  • the method for selecting the authentication algorithm provided by the processing module and the sending module of the HSS according to the authentication algorithm selected by the selecting module to determine the authentication vector for the UE authentication and sending the authentication vector to the MME may be referred to the method for selecting the authentication algorithm provided by the embodiment of the present invention. Steps S103-S104 in the first embodiment are not described herein again.
  • the HSS may select the UE authentication method according to the information of the authentication algorithm supported by the UE carried in the authentication data request message sent by the MME, and the information of the authentication algorithm supported by the UE.
  • An authentication algorithm including a Tuak algorithm or a Milenage algorithm
  • setting an X-th bit of the AMF parameter including 0 and 1 according to the above-mentioned selected UE-authenticated authentication algorithm, and further according to the AMF and the selected authentication algorithm
  • the authentication vector for the UE authentication is determined, and the above-mentioned authentication vector including the selected identification information of the authentication algorithm for the UE authentication is sent to the MME.
  • the HSS selects the Milenage algorithm as the authentication algorithm for the UE authentication by default after receiving the authentication data request message sent by the MME, and determines the authentication vector for the UE authentication according to the preset AMF parameter and the above-mentioned Milenage algorithm. Furthermore, the above-mentioned authentication vector for UE authentication is transmitted to the MME.
  • the HSS described in the embodiments of the present invention may be based on the UE.
  • FIG. 11 is a schematic structural diagram of an embodiment of a user equipment for selecting an authentication algorithm according to an embodiment of the present invention.
  • the user equipment described in this embodiment includes:
  • the sending module 50 is configured to send, to the control device, information about an authentication algorithm supported by the user equipment.
  • the receiving module 60 is configured to receive a user authentication request message sent by the control device.
  • the processing module 70 is configured to determine an authentication algorithm according to the user authentication request message, and authenticate the network according to the authentication algorithm.
  • the UE when the UE needs to send the information of the authentication algorithm supported by the UE to the MME, the UE may send a request message to the MME, and send the information of the authentication algorithm supported by the UE to the MME by using the foregoing request message; or
  • the MME may send a request message to the UE, requesting the UE to send the information of the authentication algorithm supported by the UE to the MME, and after receiving the request sent by the MME, the UE may send the request to the MME.
  • the information of the authentication algorithm supported by the UE is sent to the MME by using the foregoing response message.
  • the embodiment of the present invention does not specifically limit the sending manner of the information of the authentication algorithm supported by the UE to the MME.
  • the sending manner of the information of the authentication algorithm supported by the request message or the response message to the MME is only an example.
  • the embodiment of the present invention will be specifically described by taking an example of sending a message of an authentication algorithm supported by a UE to an MME by using a request message.
  • the request message sent by the sending module 50 of the UE to the MME may be an Attach request, or a TAU request or a registration request, and the like.
  • the embodiment of the present invention does not limit the message type of the request message.
  • the request message sent by the UE to the MME may be added to the request message by adding the information of the authentication algorithm supported by the UE to the MME.
  • the sending module 50 of the UE can send the request message to the MME to support the authentication algorithm (including the Tuak algorithm or the Milenage algorithm).
  • the information is sent to the MME in the above request message, as shown in FIG. 2 or FIG. 3, that is, the sending module 50 of the UE at this time
  • the request message sent by the MME carries the information of the Tuak algorithm or the Milenage algorithm supported by the UE.
  • the sending module 50 of the UE sends the request message to the MME, it will not The information of the authentication algorithm supported by the UE is sent to the MME, that is, the information of the authentication algorithm supported by the UE carried in the request message sent by the sending module 50 of the UE to the MME is empty.
  • the specific implementation process of the sending module of the UE to the MME may be referred to step S201 in the second embodiment of the selective authentication algorithm provided in the embodiment of the present invention, and details are not described herein.
  • the information about the authentication algorithm supported by the user equipment sent by the sending module 50 includes: a Tuak algorithm supported by the user equipment, and/or a Milenage algorithm supported by the user equipment;
  • the processing module 70 is specifically configured to:
  • An authentication algorithm is determined based on the identification information.
  • the user authentication request message received by the receiving module 60 includes an authentication parameter that is authenticated by the user equipment.
  • the AUTN parameter is included in the authentication parameter that is received by the receiving module 60 for the user equipment, and the AUTN parameter includes an AMF parameter.
  • the identification information of the authentication algorithm includes: a first identifier of the flag bit of the authentication algorithm included in the AMF parameter, or a second identifier.
  • the processing module 70 is specifically configured to:
  • the Tuak algorithm supported by the user equipment is set as an authentication algorithm
  • the Milenage algorithm supported by the user equipment is set as an authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment sent by the sending module 50 is null;
  • the processing module 70 is specifically configured to: The Milenage algorithm it supports is set as an authentication algorithm according to the user authentication request message.
  • the MME may send an authentication data request message to the HSS according to the request message sent by the UE, and the HSS may receive the authentication data request message sent by the MME according to the The authentication data request message is used to select an authentication algorithm for the UE authentication, and the identifier information of the authentication algorithm is set according to the selected authentication algorithm, and the authentication vector for the UE authentication is determined, and then the identifier information including the foregoing authentication algorithm is used by the MME.
  • the authentication vector is sent to the UE.
  • the MME may save the identifier information of the authentication algorithm for the UE authentication.
  • the identifier information of the specific authentication algorithm is sent to the UE.
  • the receiving module 60 of the UE receives the MME sending.
  • the processing module 70 may determine the authentication algorithm for the network authentication according to the user authentication request message received by the receiving module 60, and then determine the authentication algorithm for the network authentication according to the authentication algorithm of the network for its authentication.
  • the user authentication request message sent by the MME received by the receiving module of the UE includes the authentication parameter for the UE authentication, that is, the HSS is sent according to the UE.
  • the parameters in the authentication vector for UE authentication set by the request message include AUTN, RAND parameters, and the like.
  • the sending module 50 of the UE adds the information of the authentication algorithm supported by the UE to the request message and sends the information to the MME, and the receiving module 60 of the UE receives the information from the MME.
  • the processing module 70 may parse the user authentication request message received by the receiving module 60, and obtain the identification information of the authentication algorithm that is authenticated by the UE from the authentication parameters included in the user authentication request message.
  • the HSS when the HSS supports the authentication algorithm, and the authentication data request message received by the HSS from the MME carries the information of the authentication algorithm supported by the UE, the HSS may be determined according to the authentication algorithm supported by the UE and the authentication algorithm supported by the UE.
  • the MME may send the authentication parameter for UE authentication in the above authentication vector to the UE.
  • the processing module 70 may parse the user authentication request message, and obtain a network pair from the authentication parameters included in the user authentication request message.
  • the identification information of the authentication algorithm of the UE authentication where the identifier information of the authentication algorithm of the UE for the UE authentication includes: the first identifier of the identifier of the UE that is authenticated in the AMF parameter (ie, the Xth bit in the AMF parameter) (eg 1) or a second identifier (eg 0). As shown in FIG.
  • the processing module 70 may analyze the Xth bit of the AMF parameter in the user authentication request message, from the Xth of the AMF parameter. Obtaining the identification information of the authentication algorithm (including 0 or 1), determining the authentication algorithm for the network authentication according to the obtained identification information, and determining the authentication algorithm for authenticating the network (the authentication algorithm for authenticating with the network is saved) Consistent).
  • the processing module 70 of the UE may determine that the authentication algorithm for the network authentication is the Tuak algorithm, and the processing module After determining the network authentication algorithm for the UE authentication, the UE may determine that the UE authentication algorithm for the network authentication is the Tuak algorithm Tuak; when the processing module 70 obtains the AMF parameter from the AMF parameter, the value of the Xth bit of the AMF is 0 (ie, When the identifier is used, the authentication algorithm of the network authentication for the UE is determined to be the Milenage algorithm. After the processing module 70 determines the authentication algorithm for the UE authentication, the UE may determine that the authentication algorithm of the UE for the network authentication is the Milenage algorithm.
  • the sending module 50 of the UE sends the information of the authentication algorithm supported by the UE carried in the request message to the MME, and the HSS receives the authentication data request message through the MME.
  • the information of the authentication algorithm supported by the UE carried in the UE is also empty.
  • the HSS selects a default authentication algorithm (Milenage algorithm), and the identifier information of the authentication algorithm for the UE authentication included in the authentication vector determined by the HSS according to the selected authentication algorithm is The second identifier (0) of the Xth bit of the AMF parameter, as shown in FIG.
  • the processing module 70 determines the authentication algorithm for the network authentication according to the default authentication algorithm (ie, the Milenage algorithm), that is, the network-to-UE authentication algorithm and the UE-to-network.
  • the authentication algorithms for authentication are all Milenage algorithms.
  • the processing module 70 determines the authentication algorithm for the network authentication, the information about the network authentication authentication algorithm may be sent to the MME by using the user authentication response, so that the network completes the UE authentication by the MME, and allows the UE to access. The internet.
  • the MME determines an authentication algorithm and an authentication vector for authenticating the UE according to the foregoing information, and sends the information such as the authentication vector to the UE through the MME.
  • the selection authentication calculation provided by the embodiment of the present invention can be referred to. The first embodiment of the method will not be described herein.
  • the receiving module and the processing module of the UE receiving the user authentication request sent by the MME, and determining the specific implementation process of the network authentication authentication algorithm according to the receiving user authentication request refer to the selection authentication algorithm provided by the embodiment of the present invention. Steps S202-S203 in the second embodiment are not described herein again.
  • the UE may send the authentication algorithm supported by the UE to the MME through the request message, and may also obtain the information of the authentication algorithm authenticated by the network according to the user authentication request sent by the MME. Then, the authentication algorithm of the network is set to its authentication algorithm for network authentication; if the UE does not support the authentication algorithm selection, the UE sends a request message to the MME, and the network selects the default Milenage after receiving the request message sent by the network.
  • the algorithm may set the default algorithm Milenage algorithm to the network authentication authentication algorithm, thereby implementing the unification of the authentication algorithm, and completing the UE by using the MME. Authentication, allowing the UE to access the network.
  • the embodiment of the invention improves the diversity of the authentication algorithm selected by the UE and the resource utilization of the terminal, and enhances the user experience of the UE authentication.
  • FIG. 12 it is a schematic structural diagram of an embodiment of a control device for selecting an authentication algorithm according to an embodiment of the present invention.
  • the control device described in this embodiment includes:
  • the receiving module 80 is configured to receive information about an authentication algorithm supported by the user equipment sent by the user equipment.
  • the sending module 90 is configured to send an authentication data request message to the service device, where the authentication data request message carries information of an authentication algorithm supported by the user equipment.
  • the receiving module 80 is configured to receive identifier information of an authentication algorithm sent by the service device, where the identifier information of the authentication algorithm corresponds to the authentication data request message.
  • the sending module 90 is configured to send a user authentication request message to the user equipment, where the user authentication request message carries the identifier information of the authentication algorithm.
  • the information about the authentication algorithm supported by the user equipment received by the receiving module 80 includes: a Tuak algorithm supported by the user equipment, and/or a Milenage algorithm supported by the user equipment, or is empty.
  • the identifier information of the authentication algorithm received by the receiving module 80 includes: identifier information corresponding to the Tuak algorithm selected by the service device, and/or a Milenage algorithm selected by the service device. Corresponding identification information, or empty.
  • the UE when the UE needs to send the information of the authentication algorithm supported by the UE to the MME, the UE may send a request message to the MME, and send the information of the authentication algorithm supported by the UE to the MME by using the foregoing request message; or
  • the MME may send a request message to the UE, requesting the UE to send the information of the authentication algorithm supported by the UE to the MME, and after receiving the request sent by the MME, the UE may send the request to the MME.
  • the information of the authentication algorithm supported by the UE is sent to the MME by using the foregoing response message.
  • the embodiment of the present invention does not specifically limit the sending manner of the information of the authentication algorithm supported by the UE to the MME.
  • the sending manner of the information of the authentication algorithm supported by the request message or the response message to the MME is only an example.
  • the embodiment of the present invention will be specifically described by taking an example of sending a message of an authentication algorithm supported by a UE to an MME by using a request message.
  • the request message sent by the UE received by the UE from the UE may include information about the authentication algorithm supported by the UE, including: a Tuak algorithm supported by the UE, or a Milenage algorithm supported by the UE, or is null.
  • the UE when the UE supports the authentication algorithm selection (that is, the UE supports the Tuak algorithm and the Milenage algorithm), when the UE sends the request message to the MME, the information of the authentication algorithm supported by the UE may be sent to the MME through the foregoing request message; when the UE does not support the authentication algorithm selection When the UE only supports the Milenage algorithm, the information of the authentication algorithm supported by the UE carried in the request message sent by the UE to the MME is empty.
  • the sending module 90 may send an authentication data request message to the HSS according to the request message received by the receiving module 80.
  • the request message sent by the UE carries the information of the authentication algorithm supported by the UE
  • the sending module 90 of the MME sends the authentication data request message to the HSS
  • the information of the authentication algorithm supported by the UE may be sent to the HSS through the foregoing authentication data request message.
  • the information of the authentication algorithm supported by the UE carried in the request message sent by the UE is empty
  • the sending module 90 of the MME sends the authentication data request message to the HSS
  • the information of the authentication algorithm supported by the UE carried in the authentication data request message is It is empty.
  • the HSS may determine the authentication algorithm for the UE authentication according to the foregoing authentication data request message. And obtaining an authentication vector for UE authentication according to the authentication algorithm determined above. After determining the authentication algorithm for the UE authentication according to the authentication data request message sent by the MME, and determining the authentication vector for the UE authentication according to the foregoing authentication algorithm, the HSS may send the authentication vector to the MME by using the authentication data response message.
  • the MME may save the authentication vector included in the authentication data response message, and then send a user authentication request message to the UE through the sending module 90, and perform the above authentication on the UE authentication.
  • the authentication parameters for UE authentication included in the vector are sent to the UE, as shown in Figure 2, Figure 3 or Figure 4.
  • the UE may obtain information such as an authentication parameter that the network authenticates, and then determine an authentication algorithm for the network authentication according to the foregoing authentication parameter.
  • the method for determining the authentication algorithm and the authentication vector for the UE to be authenticated by the HSS according to the authentication data request message sent by the MME, and transmitting the information such as the authentication vector to the MME by using the authentication data response message may be referred to the embodiment of the present invention.
  • the first embodiment of the method for selecting an authentication algorithm is provided, and details are not described herein again.
  • a second embodiment of the method for selecting an authentication algorithm according to the embodiment of the present invention is described in the foregoing example, and the method for sending the request message to the MME and determining the authentication algorithm for the network authentication according to the user authentication request sent by the MME may be omitted. .
  • the MME when the MME supports the saving and forwarding of the information of the authentication algorithm supported by the UE , if the request message sent by the UE to the MME carries the information of the authentication algorithm supported by the UE (that is, the UE supports the Tuak algorithm and the Milenage algorithm).
  • the receiving module 80 of the MME may save the information of the authentication algorithm supported by the UE, and send the information of the authentication algorithm supported by the UE to the HSS through the sending module 90, such as FIG. 2 or FIG.
  • the receiving module 80 of the MME may send the authentication data request to the HSS through the sending module 90 after receiving the request message.
  • the message, wherein the information of the authentication algorithm supported by the UE carried in the foregoing authentication data request message is empty, as shown in FIG.
  • the MME does not support the saving and forwarding of the information of the authentication algorithm supported by the UE, if the request message sent by the UE to the MME carries the information of the authentication algorithm supported by the UE (that is, the UE supports the Tuak algorithm and the Milenage algorithm), the MME passes the receiving module 80.
  • the sending module 90 of the MME sends the authentication data request message to the HSS
  • the information of the authentication algorithm supported by the UE carried in the authentication data request message is Empty, as shown in Figure 7 or Figure 8; if the UE sends to the MME
  • the sending module 90 may send an authentication data request message to the HSS, where the authentication data request is sent.
  • the information of the authentication algorithm supported by the UE carried in the message is empty, as shown in FIG. 9.
  • the specific implementation process of the control device in the embodiment of the present invention may be referred to the steps S301-S304 in the third embodiment of the method for selecting an authentication algorithm provided by the embodiment of the present invention, and details are not described herein again.
  • the MME may also obtain the user authentication response message from the UE, and complete the authentication of the UE according to the authentication vector of the UE authentication sent by the saved HSS, and further Allow the UE to access the network.
  • the MME may receive the request message sent by the UE, send an authentication data request message to the HSS according to the request message sent by the UE, and obtain an authentication vector for the UE authentication determined by the HSS according to the authentication data request message, and the like.
  • the information is sent to the UE, and the information about the authentication vector and the UE is sent to the UE for the UE to determine the authentication algorithm for the network authentication.
  • the MME may also obtain the user authentication response message from the UE.
  • the information such as the authentication vector of the UE authentication sent by the HSS completes the authentication of the UE accessing the network, thereby allowing the UE to access the network.
  • the MME may also configure according to its own configuration (ie, whether to support the information of the authentication algorithm supported by the UE. Forwarding)
  • the authentication data request message is sent to the HSS, which enriches the diversity of the authentication algorithm of the UE authentication, improves the terminal utilization rate of the UE authentication, and enhances the user experience of the UE authentication.
  • FIG. 13 is a schematic structural diagram of an embodiment of a system for selecting an authentication algorithm according to an embodiment of the present invention.
  • the system for selecting an authentication algorithm described in this embodiment includes:
  • the user equipment 100 that selects the authentication algorithm provided by the embodiment of the present invention the control device 200 that selects the authentication algorithm provided in the foregoing embodiment of the present invention, and the service device 300 that selects the authentication algorithm provided by the foregoing embodiment of the present invention.
  • the specific interaction process of the foregoing user equipment 100, the control device 200, and the service device 300 in the process of selecting an authentication algorithm may refer to the first embodiment and the second embodiment of the method for selecting an authentication algorithm provided by the embodiment of the present invention.
  • the specific implementation process described in the third embodiment is not described herein again.
  • the readable storage medium when executed, may include the flow of an embodiment of the methods as described above.
  • the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Control Of Transmission Device (AREA)

Abstract

本发明实施例公开了一种选择认证算法的方法。所述方法包括以下步骤:服务设备接收控制设备发送的认证数据请求消息(S101);所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算法的信息选定认证算法(S102);所述服务设备根据选定的所述认证算法确定所述认证算法的标识信息(S103);所述服务设备将所述认证算法的标识信息发送给所述控制设备(S104)。本发明实施例还公开了一种选择认证算法的装置及系统。采用本发明实施例,可提高对终端认证的认证算法的选择的多样性和终端的资源利用率,增强对终端认证的用户体验。

Description

一种选择认证算法的方法、 装置及系统 技术领域
本发明涉及通信技术领域, 尤其涉及一种选择认证算法的方法、装置及系 统。 背景技术
近距离通信业务( Proximity Service, ProSe )技术主要是在两个距离较近 的用户终端 ( User Equipment, UE )之间建立安全的通信信道, 使得两个 UE 进行端到端的数据传输时数据能够进行安全的交换。 在 Prose技术中, 两个 UE建立通信信道时需要借助签约网络, UE需要通过网络认证才能接入到网 络, 进而跟其他的 UE建立通信信道。
现有技术中, 网络对 UE 进行认证时, UE 与归属用户服务器 (Home Subscriber Server, HSS )主要使用 Milenage算法生成认证所需的认证参数和 密钥。 然而, 随着新的认证算法 Tuak算法的出现, 具有不同认证能力的 UE 或者 HSS也随着应运而生, 包括只支持一种认证算法的 UE或者 HSS, 或者 可支持多种认证算法的 UE或者 HSS,使得当不同认证能力的 UE和 HSS组合 对 UE进行认证时无法确定具体釆用哪种认证算法进行认证, 或者只能釆用 Milenage算法对 UE进行认证。现有技术中, UE和 HSS无法根据 UE或者 HSS 所支持的认证算法选择相应的认证算法对 UE进行认证, 或者即使 UE或者 HSS支持多种认证算法, 也只能釆用 Milenage算法对 UE进行认证, 认证算 法形式单一, 认证算法可选性低, 终端 (包括 UE或者 HSS ) 资源利用率低, UE认证的用户体验效果低。 发明内容
本发明实施例提供一种选择认证算法的方法、装置及系统, 可根据用户设 备和服务设备所支持的认证算法选择相应的认证算法,并根据选定的认证算法 确定认证算法的标识信息等,提高了认证算法选择的多样性和终端资源的利用 率, 增强用户设备认证的用户体验。 本发明实施例第一方面提供一种选择认证算法的方法, 其可包括: 服务设备接收控制设备发送的认证数据请求消息,所述认证数据请求消息 中携带用户设备支持的认证算法的信息;
所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算 法的信息选定认证算法;
所述服务设备根据选定的所述认证算法确定所述认证算法的标识信息; 所述服务设备将所述认证算法的标识信息发送给所述控制设备,以通过所 述控制设备发送给所述用户设备。
结合第一方面,在第一种可能的实现方式中, 所述认证数据请求消息中携 带的所述认证算法的标识信息包括: 所述用户设备支持的 Tuak算法, 和 /或所 述用户设备支持的 Milenage算法;
所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算 法的信息选定认证算法, 包括:
所述服务设备从所述用户设备支持的认证算法和所述服务设备支持的认 证算法中选择一种所述用户设备和所述服务设备都支持的认证算法,并将所述 认证算法设定为所述选定的所述认证算法;
其中, 所述服务设备支持的认证算法包括: Tuak算法, 和 /或 Milenage 算法。
结合第一方面,在第二种可能的实现方式中, 所述认证数据请求消息中携 带的用户设备支持的认证算法的信息为空;
所述服务设备支持的认证算法信息中包括: 所述服务设备支持的 Tuak算 法, 和 /或所述服务设备支持的 Milenage算法;
所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算 法的信息选定认证算法, 包括:
所述服务设备从其支持的认证算法中选择 Milenage 算法, 并将所述 Milenage算法设定为所述选定的所述认证算法。
结合第一方面第一种可能的实现方式,在第三种可能的实现方式中, 所述 认证算法的标识信息具体为对所述用户设备认证的认证矢量;
当所述服务设备将所述 Tuak算法设定为所述选定的所述认证算法时, 所 述服务设备根据选定的所述认证算法确定所述认证算法的标识信息, 包括: 所述服务设备在预设的认证管理域 AMF参数中选定对所述用户设备认证 的认证算法的标志位, 并将所述标志位设定为第一标识符, 作为所述 Tuak算 法的标识信息;
所述服务设备根据所述 AMF参数和所述 Tuak算法生成对所述用户设备 认证的认证矢量。
结合第一方面第一种可能的实现方式或第一方面第二种可能的实现方式, 在第四种可能的实现方式中,所述认证算法的标识信息具体为对所述用户设备 认证的认证矢量;
当所述服务设备将所述 Milenage算法设定为所述选定的所述认证算法时, 所述服务设备根据选定的所述认证算法确定所述认证算法的标识信息, 包括: 所述服务设备在预设的 AMF参数中选定对所述用户设备认证的认证算法 的标志位, 并将所述标志位设定为第二标识符, 作为所述 Milenage算法的标 识信息;
所述服务设备根据所述 AMF参数和所述 Milenage算法生成对所述用户设 备认证的认证矢量。
本发明实施例第二方面提供了一种选择认证算法的方法, 其可包括: 用户设备向控制设备发送所述用户设备支持的认证算法的信息;
所述用户设备接收所述控制设备发送的用户认证请求消息;
所述用户设备根据所述用户认证请求消息确定认证算法,并根据所述认证 算法对所述网络进行认证。
结合第二方面,在第一种可能的实现方式中, 所述用户设备支持的认证算 法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的
Milenage算法;
所述用户设备根据所述用户认证请求消息确定认证算法, 包括:
所述用户设备对所述用户认证请求消息进行解析,获取所述用户认证请求 消息中包含的认证算法的标识信息;
所述用户设备根据所述标识信息确定认证算法。
结合第二方面第一种可能的实现方式,在第二种可能的实现方式中, 所述 用户认证请求消息中包含对所述用户设备认证的认证参数;
所述对所述用户设备认证的所述认证参数中包含 AUTN参数,所述 AUTN 参数中包含 AMF参数;
所述认证算法的标识信息包括: 所述 AMF参数中包含的所述认证算法的 标志位的第一标识符, 或第二标识符。
结合第二方面第二种可能的实现方式,在第三种可能的实现方式中, 所述 用户设备根据所述标识信息确定认证算法, 包括:
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第一标识符时, 所述用户设备将其支持的 Tuak算法设定为认证算法; 或者
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第二标识符时, 所述用户设备将其支持的 Milenage算法设定为认证算 法。
结合第二方面,在第四种可能的实现方式中, 所述用户设备支持的认证算 法的信息为空;
所述用户设备根据所述用户认证请求消息确定认证算法, 包括: 所述用户设备根据所述用户认证请求消息将其支持的 Milenage算法设定 为认证算法。
本发明实施例第三方面提供了一种选择认证算法的方法, 其可包括: 控制设备接收用户设备发送的所述用户设备支持的认证算法的信息; 所述控制设备向服务设备发送认证数据请求消息,所述认证数据请求消息 中携带所述用户设备支持的认证算法的信息;
所述控制设备接收所述服务设备发送的认证算法的标识信息,所述认证算 法的标识信息对应于所述认证数据请求消息;
所述控制设备向所述用户设备发送用户认证请求消息,所述用户认证请求 消息中携带所述认证算法的标识信息。
结合第三方面,在第一种可能的实现方式中, 所述用户设备支持的认证算 法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的
Milenage算法, 或者为空。 结合第三方面或者第三方面第一种可能的实现方式,在第二种可能的实现 方式中, 所述服务设备发送的所述认证算法的标识信息, 包括: 所述服务设备 选定的 Tuak算法对应的标识信息,和 /或所述服务设备选定的 Milenage算法对 应的标识信息, 或者为空。
本发明实施例第四方面提供了一种选择认证算法的服务设备, 其可包括: 接收模块, 用于接收控制设备发送的认证数据请求消息, 所述认证数据请 求消息中携带用户设备支持的认证算法的信息;
选择模块, 用于根据所述接收模块接收的所述认证数据请求消息, 和所述 服务设备支持的认证算法的信息选定认证算法;
处理模块,用于根据所述选择模块选定的所述认证算法确定所述认证算法 的标识信息;
发送模块, 用于将所述认证算法的标识信息发送给所述控制设备, 以通过 所述控制设备发送给所述用户设备。
结合第四方面,在第一种可能的实现方式中, 所述接收模块接收的所述认 证数据请求消息中携带的所述认证算法的标识信息包括:所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法;
所述选择模块, 具体用于:
从所述用户设备支持的认证算法和所述服务设备支持的认证算法中选择 一种所述用户设备和所述服务设备都支持的认证算法,并将所述认证算法设定 为所述选定的所述认证算法;
其中, 所述服务设备支持的认证算法包括: Tuak算法, 和 /或 Milenage 算法。
结合第四方面第一种可能的实现方式,在第二种可能的实现方式中, 所述 接收模块接收的所述认证数据请求消息中携带的用户设备支持的认证算法的 信息为空;
所述服务设备支持的认证算法信息中包括: 所述服务设备支持的 Tuak算 法, 和 /或所述服务设备支持的 Milenage算法;
所述选择模块, 具体用于:
所述服务设备从其支持的认证算法中选择 Milenage 算法, 并将所述 Milenage算法设定为所述选定的所述认证算法。
结合第四方面第一种可能的实现方式,在第三种可能的实现方式中, 所述 处理模块确定的所述认证算法的标识信息具体为对所述用户设备认证的认证 矢量;
当所述选择模块将所述 Tuak算法设定为所述选定的所述认证算法时, 所 述处理模块, 具体用于:
在预设的 AMF参数中选定对所述用户设备认证的认证算法的标志位, 并 将所述标志位设定为第一标识符, 作为所述 Tuak算法的标识信息;
根据所述 AMF参数和所述 Tuak算法生成对所述用户设备认证的认证矢 量。
结合第四方面第一种可能的实现方式或第四方面第二种可能的实现方式, 在第四种可能的实现方式中,所述处理模块确定的所述认证算法的标识信息具 体为对所述用户设备认证的认证矢量;
当所述选择模块将所述 Milenage算法设定为所述选定的所述认证算法时, 所述处理模块, 具体用于:
在预设的 AMF参数中选定对所述用户设备认证的认证算法的标志位, 并 将所述标志位设定为第二标识符, 作为所述 Milenage算法的标识信息;
根据所述 AMF参数和所述 Milenage算法生成对所述用户设备认证的认证 矢量。
本发明实施例第五方面提供了一种选择认证算法的用户设备, 其可包括: 发送模块, 用于向控制设备发送所述用户设备支持的认证算法的信息; 接收模块, 用于接收所述控制设备发送的用户认证请求消息;
处理模块, 用于根据所述用户认证请求消息确定认证算法, 并根据所述认 证算法对所述网络进行认证。
结合第五方面,在第一种可能的实现方式中, 所述发送模块发送的所述用 户设备支持的认证算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所 述用户设备支持的 Milenage算法;
所述处理模块, 具体用于:
对所述用户认证请求消息进行解析,获取所述用户认证请求消息中包含的 认证算法的标识信息;
根据所述标识信息确定认证算法。
结合第五方面第一种可能的实现方式,在第二种可能的实现方式中, 所述 接收模块接收到的所述用户认证请求消息中包含对所述用户设备认证的认证 参数;
所述接收模块接收的所述对所述用户设备认证的所述认证参数中包含
AUTN参数, 所述 AUTN参数中包含 AMF参数;
所述认证算法的标识信息包括: 所述 AMF参数中包含的所述认证算法的 标志位的第一标识符, 或第二标识符。
结合第五方面第二种可能的实现方式,在第三种可能的实现方式中, 所述 处理模块, 具体用于:
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第一标识符时, 将所述用户设备支持的 Tuak算法设定为认证算法; 或 者
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第二标识符时, 将所述用户设备支持的 Milenage算法设定为认证算法。
结合第五方面,在第四种可能的实现方式中, 所述发送模块发送的所述用 户设备支持的认证算法的信息为空;
所述处理模块, 具体用于:
根据所述用户认证请求消息将其支持的 Milenage算法设定为认证算法。 本发明实施例第六方面提供了一种选择认证算法的控制设备, 其可包括: 接收模块, 用于接收用户设备发送的所述用户设备支持的认证算法的信 息;
发送模块, 用于向服务设备发送认证数据请求消息, 所述认证数据请求消 息中携带所述用户设备支持的认证算法的信息;
所述接收模块, 用于接收所述服务设备发送的认证算法的标识信息, 所述 认证算法的标识信息对应于所述认证数据请求消息;
所述发送模块, 用于向所述用户设备发送用户认证请求消息, 所述用户认 证请求消息中携带所述认证算法的标识信息。 结合第六方面,在第一种可能的实现方式中, 所述接收模块接收的所述用 户设备支持的认证算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所 述用户设备支持的 Milenage算法, 或者为空。
结合第六方面或第六方面第一种可能的实现方式,在第二种可能的实现方 式中 , 所述接收模块接收的所述认证算法的标识信息, 包括: 所述服务设备 选定的 Tuak算法对应的标识信息,和 /或所述服务设备选定的 Milenage算法对 应的标识信息, 或者为空。
本发明实施例第七方面提供了一种选择认证算法的系统, 其可包括: 上述 本发明实施例第四方面提供的服务设备、 上述 本发明实施例第五方面提供的 用户设备、 以及上述本发明实施例第六方面提供的控制设备。
本发明实施例可根据用户设备和服务设备所支持的认证算法选择相应的 认证算法生成认证所需的认证矢量等信息,提高了认证算法选择的多样性和终 端资源的利用率, 增强用户设备认证的用户体验。 附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所 需要使用的附图作简单地介绍,显而易见地, 下面描述中的附图仅仅是本发明 的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下, 还可以根据这些附图获得其他的附图。
图 1 是本发明实施例提供的选择认证算法的方法的第一实施例流程示意 图;
图 2是本发明实施例提供的选择认证算法的方法的第一交互示意图; 图 3是本发明实施例提供的选择认证算法的方法的第二交互示意图; 图 4是本发明实施例提供的选择认证算法的方法的第三交互示意图; 图 5 是本发明实施例提供的选择认证算法的方法的第二实施例流程示意 图;
图 6 是本发明实施例提供的选择认证算法的方法的第三实施例流程示意 图;
图 7是本发明实施例提供的选择认证算法的方法的第四交互示意图; 图 8是本发明实施例提供的选择认证算法的方法的第五交互示意图; 图 9是本发明实施例提供的选择认证算法的方法的第六交互示意图; 图 10是本发明实施例提供的选择认证算法的服务设备的实施例结构示意 图;
图 11是本发明实施例提供的选择认证算法的用户设备的实施例结构示意 图;
图 12是本发明实施例提供的选择认证算法的控制设备的实施例结构示意 图;
图 13是本发明实施例提供的选择认证算法的系统的实施例结构示意图。 具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清 楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而不是 全部的实施例。基于本发明中的实施例, 本领域普通技术人员在没有做出创造 性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。
具体实现中, 本发明实施例中所描述的服务设备可包括 3G通信系统中的 归属位置寄存器( Home Location Register, HLR ), 或者 4G通信系统中的归属 用户服务器 (Home Subscriber Server, HSS ), 下面将以 HSS为例, 对本发明 实施例中所描述的选择认证算法的方法、装置及系统进行具体说明。本发明实 施例中所描述的用户设备可包括 3G 通信系统中的移动签约用户 (Mobile Subscriber, MS ), 或者 4G通信系统中的 UE, 下面将以 UE为例, 对本发明 实施例中所描述的选择认证算法的方法、 装置及系统进行具体说明。 此外, 本 发明实施例中所描述的控制设备可包括 3G 通信系统中的拜访位置寄存器 ( Visitor Location Register, VLR ) 和服务 GPRS 支持节点 (Serving GPRS Support Node , SGSN ), 或者 4G 通信系统中的移动管理实体 (Mobility Management Entity, MME ), 下面将以 MME为例, 对本发明实施例中所描述 的选择认证算法的方法、 装置及系统进行具体说明。
参见图 1, 是本发明实施例提供的选择认证算法的方法的第一实施例流程 示意图。 本实施例中所描述的选择认证算法的方法, 包括步骤: S101, 服务设备接收控制设备发送的认证数据请求消息。
S102, 所述服务设备根据所述认证数据请求消息,和所述服务设备支持的 认证算法的信息选定认证算法。
在一些可行的实施方式中, HSS从 MME接收到的认证数据请求消息中携 带用户设备支持的认证算法的信息,其中, 上述用户设备支持的认证算法的信 息可包括: UE支持的 Tuak算法, 或者 UE支持的 Milenage算法等。 具体实 现中,当 HSS从 MME接收到的认证数据请求消息中包含 UE支持的认证算法 的信息, 并且 HSS支持认证算法选择 (即 HSS可支持 Tuak算法和 Milenage 算法 )时, HSS可根据上述认证数据请求消息中所包含的 UE支持的认证算法 的信息,从中选择 HSS也支持的认证算法(即 UE和 HSS都支持的认证算法), 并将上述选定的认证算法设定为对 UE认证的认证算法。例如,如图 2,当 HSS 从 MME接收到的认证数据请求消息中包括 UE支持的认证算法(包括 Tuak 算法和 Milenage算法), 并且 HSS支持认证算法选择时, HSS则可根据其支 持的认证算法从 UE支持的认证算法中选择 HSS也支持的认证算法作为对 UE 认证的认证算法, 例如, 当 HSS支持 Tuak算法时, HSS则可从 UE支持的认 证算法中选择 Tuak算法作为对 UE认证的认证算法; 当 HSS支持 Milenage 算法时, HSS则可从 UE支持的认证算法中选择 Milenage算法作为对 UE认证 的认证算法; 当 HSS支持 Tuak算法, 也支持 Milenage算法时, HSS则可从 UE支持的认证算法中任选一种作为对 UE认证的认证算法。
在一些可行的实施方式中, 若 HSS不支持认证算法选择 (即 HSS只支持 Milenage算法), 则当 HSS从 MME接收到的认证数据请求消息中包含 UE支 持的认证算法的信息(包括 UE支持 Tuak算法和 Milenage算法 ) 时, HSS选 择默认认证算法作为对 UE认证的认证算法,即 HSS默认选择 Milenage算法, 并将上述 Milenage算法设定为对 UE认证的认证算法, 如图 3。
在一些可行的实施方式中, 当 HSS从 MME处接收到的认证数据请求消 息中携带的 UE支持的认证算法的信息为空, 即上述认证数据请求消息中不包 含 UE支持的认证算法信息时, HSS选择 Milenage算法并将上述 Milenage算 法设定为对 UE认证的认证算法。 即, 如图 4, 若 HSS支持认证算法选择(即 HSS可支持 Tuak算法和 Milenage算法), 则当 HSS从 MME处接收到的认证 数据请求消息中携带的 UE支持的认证算法的信息为空, HSS选择默认认证算 法, 即 HSS选择 Milenage算法作为对 UE认证的认证算法。
S 103,所述服务设备根据选定的所述认证算法确定所述认证算法的标识信 息。
在一些可行的实施方式中, HSS根据 MME发送的认证数据请求消息选定 认证算法之后, 则可在子贞设的认证管理域 ( Authentication Management Field, AMF )参数中设定上述选定的认证算法的标识信息, 具体的, 还可上述 AMF 参数和上述选定的认证算法确定对 UE认证的认证矢量。具体实现中,如图 2, 若 HSS支持认证算法选择, 则当 HSS选择对 UE认证的认证算法之后, 则可 在预设的 AMF参数中设定上述选定的认证算法的标识信息, 还可根据上述 AMF参数和选定的认证算法计算得到对 UE认证的认证矢量,其中,上述 HSS 根据选定的认证算法计算得到的认证矢量中包括对 UE 认证的认证参数 AUTN、 MAC, XRES以及密钥 CK、 IK、 ΑΚ等。 例如, 当 HSS选择 Tuak 算法作为对 UE认证的认证算法时, HSS则可在预设的 AMF参数中选择第 X 比特作为对 UE认证的标志位, 进而可将 AMF参数的第 X比特设定为 1 (即 第一标识符), 用以作为对 UE认证的 Tuak算法的标识信息; 当 HSS 选择 Milenage算法作为对 UE认证的认证算法时, HSS则可在预设的 AMF参数中 选择第 X比特作为对 UE认证的标志位,进而可将 AMF参数的第 X比特设定 为 0 (即第二标识符), 用以作为对 UE认证的认证算法的标识信息, 其中, 上 述 AMF参数的第 X比特可为 AMF参数中空闲的 8个比特位中的任意一个, 即 1 X 7。
在一些可行的实施方式中, 如图 3, 若 HSS不支持认证算法选择, 则当 HSS选定对 UE认证的认证算法之后, HSS不对上述预设的 AMF参数设置对 UE认证的认证算法的标识信息, HSS可根据预设的 AMF参数和选定的认证 算法计算对 UE认证的认证矢量。 如图 3, 由于 HSS不支持认证算法选择, 无 法在 AMF参数中设置对 UE认证的认证算法的标识信息, 故此, 当 HSS接收 到 MEE发送的认证数据请求消息并选择默认算法( Milenage算法 M乍为对 UE 认证的认证算法之后, HSS可根据预设的 AMF参数和上述 Milenage算法计算 得到对 UE认证的认证矢量, 此时上述认证矢量中的 AMF参数的第 X比特为 默认值 0, 上述 AMF的第 X比特的默认值则作为对 UE认证的 Milenage算法 的标识信息。
S104, 所述服务设备将所述认证算法的标识信息发送给所述控制设备。 在一些可行的实施方式中, 当 HSS根据 MME发送的认证数据请求消息 确定了对 UE认证的认证算法, 并根据选定的认证算法确定上述认证算法的标 识信息之后, 则可将上述认证算法的标识信息(具体可为对 UE认证的认证矢 量)发送给 MME。 具体实现中, HSS可通过认证数据响应消息将上述认证矢 量发送给 MME, 上述发送给 MME的认证矢量消息中包含对 UE认证的认证 算法的标识信息。 如图 2或者图 4, 当 HSS根据 MEE发送的认证数据请求消 息选定 Tuak算法或者 Milenage算法作为对 UE认证的认证算法, 并在预设的 AMF参数的第 X比特中设定对上述 Tuak算法或者 Milenage算法的标识信息 之后, 即将上述认证矢量中的 AMF参数的第 X比特设定为 0或 1之后, 则可 根据上述 AMF参数和上述选定的认证算法确定对 UE认证的认证矢量, 进而 将包含上述 AMF参数的第 X比特的信息的认证矢量消息发送给 MEE, MME 接收到上述认证矢量消息之后,可保存上述认证矢量消息并将上述认证矢量消 息中对 UE认证的认证参数信息发送给 UE。 如图 3, 当 HSS不支持认证算法 选择时, HSS默认选择 Milenage算法作为对 UE认证的认证算法并根据上述 Milenage算法确定对 UE认证的认证矢量之后, 则可将上述认证矢量发送给 MME, 其中, 上述认证矢量消息中包含的对 UE认证的认证算法的标识信息 为预设的 AMF参数中默认设置的标识信息, 即上述认证矢量中的 AMF参数 的第 X比特默认设定为 0, HSS可将包含上述 AMF参数的第 X比特的信息的 认证矢量发送给 MME, MME接收到上述认证矢量消息之后, 可保存上述认 证矢量消息并将上述认证矢量消息中对 UE认证的认证参数信息发送给 UE。
在本发明实施例中, 当 HSS支持认证算法选择时, HSS可根据 MME发 送的认证数据请求消息中携带的 UE支持的认证算法的信息, 结合其自身支持 的认证算法的信息选择 UE和 HSS都支持的认证算法作为对 UE认证的认证算 法(包括 Tuak算法或者 Milenage算法), 并根据上述选定的对 UE认证的认 证算法设定 AMF参数的第 X比特的值(包括 0和 1 ), 进而根据上述 AMF和 选定的认证算法确定对 UE认证的认证矢量, 将上述包括选定的对 UE认证的 认证算法的标识信息的认证矢量发送给 MME。当 HSS不支持认证算法选择时, HSS接收到 MME发送的认证数据请求消息之后默认选择 Milenage算法作为 对 UE认证的认证算法, 并根据预设的 AMF参数和上述 Milenage算法确定对 UE认证的认证矢量,进而将上述对 UE认证的认证矢量发送给 MME。在本发 明实施例中, HSS 可根据 UE支持的认证算法和其自身支持的认证算法选择 UE和 HSS都支持的认证算法作为对 UE认证的认证算法, 根据选定的认证算 法确定认证算法的标识信息及对 UE认证的认证矢量,通过认证算法的标识信 息通知 UE对其认证的认证算法, 提高了对 UE认证的认证算法的选择的多样 性和 UE和 HSS的资源利用率, 增强对 UE认证的用户体验。
参见图 5, 是本发明实施例提供的选择认证算法的方法的第二实施例流程 示意图。 本实施例中所描述的选择认证算法的方法, 包括步骤:
S201 , 用户设备向控制设备发送所述用户设备支持的认证算法的信息。 在一些可行的实施方式中, 当 UE需要向 MME发送 UE支持的认证算法 的信息时, UE可向 MME发送请求消息, 将上述 UE支持的认证算法的信息 通过上述请求消息发送给 MME; 或者, 当 MME需要得知 UE支持的认证算 法的信息时, MME可向 UE发送请求消息, 请求 UE将 UE支持的认证算法 的信息发送给 MME, UE接收到 MME发送的请求之后, 则可向 MME发送响 应消息, 将 UE支持的认证算法的信息通过上述响应消息发送给 MME。 本发 明实施例对 UE将其支持的认证算法的信息发送给 MME的发送方式不做具体 限定, 上述通过请求消息或者响应消息将其支持的认证算法的信息发送给 MME的发送方式仅是举例,而非穷举,本发明实施例将以通过请求消息将 UE 支持的认证算法的信息发送给 MME的发送方式为例, 进行具体说明。 具体实 现中, UE向 MME发送的请求消息可为依附 (Attach )请求, 或者跟踪区更 新(Tracking Area Update, TAU )请求或者注册 ( Registration )请求等, 本发 明实施例不限定上述请求消息的消息类型。 UE向 MME发送的请求消息中可 将 UE支持的认证算法的信息添加到上述请求消息中发送给 MME。 具体实现 中, 当 UE支持认证算法选择 (即 UE可支持 Tuak算法和 Milenage算法)时, UE向 MME发送请求消息时可将其可支持的认证算法(包括 Tuak算法或者 Milenage算法)信息添加在上述请求消息中发送给 MME, 如图 2或图 3, 即 此时 UE向 MME发送的请求消息中携带着 UE支持的 Tuak算法或者 Milenage 算法的信息; 当 UE不支持认证算法选择 (即 UE只支持 Milenage算法 ) 时, UE向 MME发送请求消息时则不将其支持的认证算法的信息发送给 MME,即 此时 UE向 MME发送的请求消息中携带的 UE支持的认证算法的信息为空。
5202, 所述用户设备接收所述控制设备发送的用户认证请求消息。
5203, 所述用户设备根据所述用户认证请求消息确定认证算法,并根据所 述认证算法对所述网络进行认证。
在一些可行的实施方式中, 当 UE向 MME发送请求消息之后, MME可 根据 UE发送的请求消息向 HSS发送认证数据请求消息, HSS接收到 MME 发送的认证数据请求消息之后可根据上述认证数据请求消息选择对 UE认证的 认证算法, 并根据选定的认证算法设定上述认证算法的标识信息, 确定对 UE 认证的认证矢量,进而通过 MME将上述包含上述认证算法的标识信息的认证 矢量发送给 UE。 MME接收到 HSS发送的对 UE认证的认证算法的标识信息 之后, 可保存上述对 UE认证的认证算法的标识信息(具体可为对 UE认证的 认证矢量), 并通过向 UE发送用户认证请求将上述对 UE认证的认证算法的 标识信息发送给 UE。 UE接收 MME发送的用户认证请求消息之后,则可根据 上述用户认证请求消息确定网络对其认证的认证算法,进而根据网络对其认证 的认证算法确定认证算法(即 UE对网络认证的认证算法), 并根据上述确定 的对网络的认证算法对网络进行认证。 其中, 上述 UE接收 MME发送的用户 认证请求消息中包含对 UE认证的认证参数,即包含 HSS根据 UE发送的请求 消息设定的对 UE认证的认证矢量中的参数, 包括 AUTN、 RAND参数等。
在一些可行的实施方式中, 当 UE支持认证算法选择时, UE将其支持的 认证算法的信息添加到请求消息中发送给 MME之后, 当 UE从 MME处接收 到用户认证请求消息时, UE则可对上述用户认证请求消息进行解析, 从上述 用户认证请求消息中包括的认证参数中获取网络对 UE认证的认证算法的标识 信息。 具体实现中, 当 HSS支持认证算法选择, 并且 HSS从 MME处接收到 的认证数据请求消息中携带 UE支持的认证算法的信息时, HSS可根据 UE支 持的认证算法及其自身支持的认证算法确定对 UE认证的认证算法, 并在预设 的 AMF参数中设定选定的认证算法的标识信息, 根据上述包含认证算法的标 识信息的 AMF参数计算得到对 UE认证的认证矢量。 HSS确定上述认证矢量 之后则可通过 MME将上述认证矢量中对 UE认证的认证参数发送给 UE。 UE 接收到 MME发送的用户认证请求之后,则可对上述用户认证请求消息中包含 的认证参数进行解析,从上述认证参数中获取网络对 UE认证的认证算法的标 识信息, 其中, 上述网络对 UE认证的认证算法的标识信息包括: 上述 AMF 参数中对 UE认证的认证算法的标志位(即上述 AMF参数中的第 X比特)的 第一标识符(例如 1 )或者第二标识符(例如 0 )。 如图 2, 当 UE接收到 MME 发送的用户认证请求消息之后, 则可对上述用户认证请求消息中的 AMF参数 的第 X比特进行分析,从上述 AMF参数的第 X比特中获取认证算法的标识信 息 (包括 0或 1 ), 根据获取到的标识信息确定网络对其认证的认证算法, 进 而确定其对网络进行认证的认证算法(与网络对其认证的认证算法保存一致)。 例如, 当 UE从上述 AMF参数中获取得知 AMF的第 X比特的值为 1 (即第 一标识符)时, 则可确定网络对其认证的认证算法为 Tuak算法, UE确定网络 对其认证的认证算法之后, 则可确定其对网络认证的认证算法为 Tuak算法, 进而可根据上述 Tuak算法对网络进行认证;当 UE从上述 AMF参数中获取得 知 AMF的第 X比特的值为 0 (即第二标识符 ) 时, 则可确定网络对其认证的 认证算法为 Milenage算法, UE确定网络对其认证的认证算法之后, 则可确定 其对网络认证的认证算法为 Milenage算法, 进而可根据上述 Milenage算法对 网络进行认证。
在一些可行的实施方式中, 当 UE不支持认证算法选择时, UE向 MME 发送请求消息中携带的 UE支持的认证算法的信息为空, HSS通过 MME接收 到的认证数据请求消息中携带的 UE支持的认证算法的信息也为空,此时 HSS 选择默认认证算法(Milenage算法), HSS根据选定的认证算法确定的认证矢 量中包含的对 UE认证的认证算法的标识信息为 AMF参数的第 X比特的第二 标识符(0 ), 如图 4。 UE接收到 MME发送的用户认证请求之后, 则根据默 认认证算法 (即 Milenage算法 )对网络进行认证, 即此时网络对 UE认证的认 证算法和 UE对网络认证的认证算法均为 Milenage算法。 具体实现中, UE确 定对网络认证的认证算法之后,则可将上述对网络认证的认证算法的信息通过 用户认证响应发送给 MME, 以通过 MME完成网络对 UE的认证, 允许 UE 接入网络。具体实现中,上述 HSS通过 MME接收到 UE发送的请求消息中包 含的信息后根据上述信息确定对 UE认证的认证算法及认证算法的标识信息, 并通过 MME将上述认证算法的标识信息等信息发送给 UE的具体实现过程可 参见本发明实施例提供的选择认证算法的第一实施例, 在此不再赘述。
在本发明实施例中, 当 UE支持认证算法选择时, UE可将其支持的认证 算法通过请求消息发送给 MME, 还可根据 MME发送的用户认证请求获取网 络对其认证的认证算法的信息,进而将网络对其认证的认证算法设定为其对网 络认证的认证算法, 根据上述认证算法对网络进行认证; 当 UE不支持认证算 法选择时, UE向 MME发送的请求消息, 网络接收到其发送的请求消息之后 将选择默认的 Milenage算法作为对 UE认证的认证算法, 当 UE接收到 MME 发送的用户认证请求时, 则可将默认算法 Milenage算法设定为对网络认证的 认证算法, 从而实现认证算法的统一, 通过 MME完成 UE的认证, 允许 UE 接入到网络。本发明实施例提高了 UE认证的认证算法选择的多样性和终端的 资源利用率, 增强了 UE认证的用户体验。
参见图 6, 是本发明实施例提供的选择认证算法的方法的第三实施例流程 示意图。 本实施例中所描述的选择认证算法的方法, 包括步骤:
5301 , 控制设备接收用户设备发送的所述用户设备支持的认证算法的信 息。
5302, 所述控制设备向服务设备发送认证数据请求消息。
5303, 所述控制设备接收所述服务设备发送的认证算法的标识信息。
5304, 所述控制设备向所述用户设备发送用户认证请求消息。
在一些可行的实施方式中, 当 UE需要向 MME发送 UE支持的认证算法 的信息时, UE可向 MME发送请求消息, 将上述 UE支持的认证算法的信息 通过上述请求消息发送给 MME; 或者, 当 MME需要得知 UE支持的认证算 法的信息时, MME可向 UE发送请求消息, 请求 UE将 UE支持的认证算法 的信息发送给 MME, UE接收到 MME发送的请求之后, 则可向 MME发送响 应消息, 将 UE支持的认证算法的信息通过上述响应消息发送给 MME。 本发 明实施例对 UE将其支持的认证算法的信息发送给 MME的发送方式不做具体 限定, 上述通过请求消息或者响应消息将其支持的认证算法的信息发送给 MME的发送方式仅是举例,而非穷举,本发明实施例将以通过请求消息将 UE 支持的认证算法的信息发送给 MME的发送方式为例, 进行具体说明。 具体实 现中, 上述 UE支持的认证算法的信息, 包括: UE支持的 Tuak算法, 或者 UE支持的 Milenage算法, 或者为空。 即当 UE支持认证算法选择(即 UE支 持 Tuak算法和 Milenage算法) 时, UE向 MME发送请求消息时可将其支持 的认证算法的信息通过上述请求消息发送给 MME; 当 UE不支持认证算法选 择(即 UE只支持 Milenage算法) 时, UE向 MME发送的请求消息中携带的 UE支持的认证算法的信息则为空。 MME接收到 UE发送的请求消息之后, 则 可根据上述请求消息向 HSS发送认证数据请求消息。 当 UE发送的请求消息 中携带 UE支持的认证算法的信息时, MME向 HSS发送认证数据请求消息时 则可将上述 UE 支持的认证算法的信息通过上述认证数据请求消息发送给 HSS;当 UE发送的请求消息中携带的 UE支持的认证算法的信息为空时, MME 向 HSS发送认证数据请求消息时, 上述认证数据请求消息中携带的 UE支持 的认证算法的信息则为空。
在一些可行的实施方式中, MME向 HSS发送认证数据请求消息之后, HSS则可根据上述认证数据请求消息确定对 UE认证的认证算法,并根据上述 确定的认证算法计算得到对 UE认证的认证算法的标识信息 (具体可为对 UE 认证的认证矢量)。 HSS根据 MME发送的认证数据请求消息确定对 UE认证 的认证算法, 并根据上述认证算法确定对 UE认证的认证矢量之后, 则可将上 述认证矢量通过认证数据响应消息发送给 MME。 MME接收到 HSS发送的认 证数据响应消息之后, 则可保存上述认证数据响应消息中包含的认证矢量, 进 而向 UE发送用户认证请求消息, 将上述对 UE认证的认证矢量中包含的对 UE认证的认证参数发送给 UE, 如图 2、 图 3或图 4。 UE接收到 MME发送 的用户认证请求消息之后, 则可从中获取网络对其认证的认证参数等信息, 进 而根据上述认证参数确定对网络认证的认证算法。 具体实现中, 上述 HSS根 据 MME发送的认证数据请求消息确定对 UE认证的认证算法及认证矢量, 并 通过认证数据响应消息将上述认证矢量等信息发送给 MME 的具体实现过程 可参见本发明实施例提供的选择认证算法的方法的第一实施例, 在此不再赘 述。 上述 UE向 MME发送请求消息并根据 MME发送的用户认证请求确定对 网络认证的认证算法的具体实现过程可参见本发明实施例提供的选择认证算 法的方法的第二实施例, 在此不再赘述。
在一些可行的实施方式中, 当 MME支持 UE支持的认证算法的信息的保 存和转发时, 若 UE发送给 MME的请求消息中携带 UE支持的认证算法的信 息 (即 UE支持 Tuak算法和 Milenage算法), MME接收到 UE发送的请求消 息之后则可保存 UE支持的认证算法的信息, 并将上述 UE支持的认证算法的 信息通过认证数据请求消息发送给 HSS, 如图 2或图 3; 若 UE发送给 MME 的请求消息中携带的 UE支持的认证算法的信息为空, MME接收到上述请求 消息之后则可向 HSS发送认证数据请求消息, 其中上述认证数据请求消息中 携带的 UE支持的认证算法的信息则为空, 如图 4。 当 MME不支持 UE支持 的认证算法的信息的保存和转发时, 若 UE发送给 MME 的请求消息中携带 UE支持的认证算法的信息 (即 UE支持 Tuak算法和 Milenage算法), MME 接收到 UE发送的请求消息之后无法保存 UE 支持的认证算法的信息, 此时 MME向 HSS发送认证数据请求消息时, 上述认证数据请求消息中携带的 UE 支持的认证算法的信息则为空, 如图 7或者图 8; 若 UE发送给 MME的请求 消息中携带的 UE支持的认证算法的信息为空, 则 MME接收到 UE发送的请 求消息之后则可向 HSS发送认证数据请求消息, 其中, 上述认证数据请求消 息中携带的 UE支持的认证算法的信息为空, 如图 9。
在一些可行的实施方式中, MME向 UE发送用户认证请求消息之后, 还 可从 UE处获取用户认证响应消息,并根据其保存的 HSS发送的对 UE认证的 认证矢量完成对 UE的认证, 进而允许 UE接入到网络。
在本发明实施例中, MME可接收 UE发送的 UE支持的认证算法的信息, 根据 UE支持的认证算法的信息向 HSS发送认证数据请求消息, 并从 HSS处 获取 HSS根据上述认证数据请求消息确定的对 UE认证的认证算法的标识信 息(具体可为对 UE认证的认证矢量)等信息, 进而向 UE发送用户认证请求, 将上述 HSS对 UE认证的认证算法的标识信息等信息发送给 UE, 以供 UE确 定其对网络认证的认证算法; MME还可从 UE处获取用户认证响应消息, 结 合 HSS发送的对 UE认证的认证矢量等信息完成 UE接入网络的认证,进而允 许 UE接入到网络; MME还可根据其自身配置 (即是否支持 UE支持的认证 算法的信息的保存和转发) 向 HSS发送认证数据请求消息, 丰富了 UE认证 的认证算法的多样性, 提高了 UE认证的终端利用率, 增强了 UE认证的用户 体验。
参见图 10, 是本发明实施例提供的选择认证算法的服务设备的实施例结 构示意图。 本实施例中所描述的服务设备, 包括:
接收模块 10, 用于接收控制设备发送的认证数据请求消息, 所述认证数 据请求消息中携带用户设备支持的认证算法的信息。
选择模块 20, 用于根据所述接收模块接收的所述认证数据请求消息, 和 所述服务设备支持的认证算法的信息选定认证算法。
处理模块 30, 用于根据所述选择模块选定的所述认证算法确定所述认证 算法的标识信息。
发送模块 40, 用于将所述认证算法的标识信息发送给所述控制设备, 以 通过所述控制设备发送给所述用户设备。
在一些可行的实施方式中, 上述接收模块 10接收的所述认证数据请求消 息中携带的所述认证算法的标识信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法;
所述选择模块 20, 具体用于:
从所述用户设备支持的认证算法和所述服务设备支持的认证算法中选择 一种所述用户设备和所述服务设备都支持的认证算法,并将所述认证算法设定 为所述选定的所述认证算法;
其中, 所述服务设备支持的认证算法包括: Tuak算法, 和 /或 Milenage 算法。
在一些可行的实施方式中, 上述接收模块 10接收的所述认证数据请求消 息中携带的用户设备支持的认证算法的信息为空;
所述服务设备支持的认证算法信息中包括: 所述服务设备支持的 Tuak算 法, 和 /或所述服务设备支持的 Milenage算法;
所述选择模块 20, 具体用于:
所述服务设备从其支持的认证算法中选择 Milenage 算法, 并将所述 Milenage算法设定为所述选定的所述认证算法。 在一些可行的实施方式中, HSS的接收模块 10从 MME接收到的认证数 据请求消息中携带用户设备支持的认证算法的信息, 其中, 上述用户设备支持 的认证算法的信息可包括: UE支持的 Tuak算法, 或者 UE支持的 Milenage 算法等。 具体实现中, 当接收模块 10从 MME接收到的认证数据请求消息中 包含 UE支持的认证算法的信息, 并且 HSS支持认证算法选择 (即 HSS可支 持 Tuak算法和 Milenage算法 ) 时, 选择模块 20可根据上述认证数据请求消 息中所包含的 UE支持的认证算法的信息, 从中选择 HSS也支持的认证算法 (即 UE和 HSS都支持的认证算法), 并将上述选定的认证算法设定为对 UE 认证的认证算法。 例如, 如图 2, 当接收模块 10从 MME接收到的认证数据 请求消息中包括 UE支持的认证算法(包括 Tuak算法和 Milenage算法), 并 且 HSS支持认证算法选择时, 选择模块 20则可根据 HSS支持的认证算法从 UE支持的认证算法中选择 HSS也支持的认证算法作为对 UE认证的认证算 法, 例如, 当 HSS支持 Tuak算法时, 选择模块 20则可从 UE支持的认证算 法中选择 Tuak算法作为对 UE认证的认证算法;当 HSS支持 Milenage算法时, 选择模块 20则可从 UE支持的认证算法中选择 Milenage算法作为对 UE认证 的认证算法; 当 HSS支持 Tuak算法, 也支持 Milenage算法时, 选择模块 20 则可从 UE支持的认证算法中任选一种作为对 UE认证的认证算法。
在一些可行的实施方式中, 若 HSS不支持认证算法选择 (即 HSS只支持 Milenage算法),则当接收模块 10从 MME接收到的认证数据请求消息中包含 UE支持的认证算法的信息 (包括 UE支持 Tuak算法和 Milenage算法 ) 时, 选择模块 20选择默认认证算法作为对 UE认证的认证算法, 即选择模块 20默 认选择 Milenage算法,并将上述 Milenage算法设定为对 UE认证的认证算法, 如图 3。
在一些可行的实施方式中, 当接收模块 10从 MME处接收到的认证数据 请求消息中携带的 UE支持的认证算法的信息为空, 即上述认证数据请求消息 中不包含 UE支持的认证算法信息时, 选择模块 20选择 Milenage算法并将上 述 Milenage算法设定为对 UE认证的认证算法。 即, 如图 4, 若 HSS支持认 证算法选择 (即 HSS可支持 Tuak算法和 Milenage算法), 则当接收模块 10 从 MME处接收到的认证数据请求消息中携带的 UE支持的认证算法的信息为 空, 选择模块 20选择默认认证算法, 即选择模块 20选择 Milenage算法作为 对 UE认证的认证算法。 具体实现中, 上述 HSS的接收模块和选择模块根据 接收到的 MME发送的认证数据请求消息选定对 UE认证的认证算法的具体实 现过程可参见本发明实施例提供的选择认证算法的第一实施例的步骤 S101-S102, 在此不再赘述。
在一些可行的实施方式中, 上述处理模块 30确定的认证算法的标识信息 具体为对所述用户设备认证的认证矢量;
当上述选择模块 20将所述 Tuak算法设定为所述选定的所述认证算法时, 所述处理模块 30, 具体用于:
在预设的 AMF参数中选定对所述用户设备认证的认证算法的标志位, 并 将所述标志位设定为第一标识符, 作为所述 Tuak算法的标识信息;
根据所述 AMF参数和所述 Tuak算法生成对所述用户设备认证的认证矢 量。
在一些可行的实施方式中, 上述处理模块 30确定的认证算法的标识信息 具体为对所述用户设备认证的认证矢量;
当上述选择模块 20将所述 Milenage算法设定为所述选定的所述认证算法 时, 所述处理模块 30, 具体用于:
在预设的 AMF参数中选定对所述用户设备认证的认证算法的标志位, 并 将所述标志位设定为第二标识符, 作为所述 Milenage算法的标识信息;
根据所述 AMF参数和所述 Milenage算法生成对所述用户设备认证的认证 矢量。
在一些可行的实施方式中, HSS的选择模块 20根据 MME发送的认证数 据请求消息选定对 UE认证的认证算法之后, 处理模块 30则可在预设的 AMF 参数中设定上述选定的认证算法的标识信息, 进而根据上述 AMF参数和上述 选定的认证算法确定对 UE认证的认证矢量。 具体实现中, 如图 2, 若 HSS支 持认证算法选择, 则当选择模块 20选择对 UE认证的认证算法之后, 处理模 块 30则可在预设的 AMF参数中设定上述选定的认证算法的标识信息, 并根 据上述 AMF参数和选定的认证算法计算得到对 UE认证的认证矢量, 其中, 上述处理模块 30根据选择模块 20选定的认证算法计算得到的认证矢量中包括 对 UE认证的认证参数 AUTN、 MAC, XRES以及密钥 CK、 ΙΚ、 ΑΚ等。 例 如, 当 HSS的选择模块 20选择 Tuak算法作为对 UE认证的认证算法时, HSS 的处理模块 30则可在预设的 AMF参数中选择第 X比特作为对 UE认证的标 志位, 进而可将 AMF参数的第 X比特设定为 1 (即第一标识符), 用以作为 对 UE认证的 Tuak算法的标识信息; 当 HSS的选择模块 20选择 Milenage算 法作为对 UE认证的认证算法时, HSS的处理模块 30则可在预设的 AMF参数 中选择第 X比特作为对 UE认证的标志位,进而可将 AMF参数的第 X比特设 定为 0(即第二标识符),用以作为 Milenage算法的标识信息,其中,上述 AMF 参数的第 X比特可为 AMF参数中空闲的 8个比特位中的任意一个, 即 1 X 7。
在一些可行的实施方式中, 如图 3, 若 HSS不支持认证算法选择, 则当 HSS的选择模块 30选定对 UE认证的认证算法之后, HSS的处理模块 30不对 上述预设的 AMF参数设置对 UE认证的认证算法的标识信息, HSS的处理模 块 30可根据预设的 AMF参数和选定的认证算法计算对 UE认证的认证矢量。 如图 3, 由于 HSS不支持认证算法选择, 处理模块 30无法在 AMF参数中设 置对 UE认证的认证算法的标识信息, 故此, 当 HSS的接收模块 10接收到 MEE发送的认证数据请求消息并通过选择模块 20选择默认算法( Milenage算 法)作为对 UE认证的认证算法之后, HSS的处理模块 30可根据预设的 AMF 参数和上述 Milenage算法计算得到对 UE认证的认证矢量,此时上述认证矢量 中的 AMF参数的第 X比特为默认值 0, 上述 AMF的第 X比特的默认值则作 为对 UE认证的 Milenage算法的标识信息。
在一些可行的实施方式中, 当 HSS的处理模块 30根据接收模块 10接收 到的 MME发送的认证数据请求消息确定了对 UE认证的认证算法, 并根据选 定的认证算法确定对 UE认证的认证算法的标识信息(具体可为认证矢量)之 后, 发送模块 40则可将上述处理模块 30确定的认证矢量发送给 MME。 具体 实现中, HSS可通过的发送模块 40向 MME发送的认证数据响应消息将上述 认证矢量发送给 MME,上述发送模块 40发送给 MME的认证矢量消息中包含 对 UE认证的认证算法的标识信息。 如图 2或者图 4, 当 HSS的选择模块 20 根据接收模块 10接收到的 MEE发送的认证数据请求消息选定 Tuak算法或者 Milenage算法作为对 UE认证的认证算法, 并通过处理模块 30在预设的 AMF 参数的第 X比特中设定对上述 Tuak算法或者 Milenage算法的标识信息之后, 即将上述认证矢量中的 AMF参数的第 X比特设定为 0或 1之后, 处理模块 30则可根据上述 AMF参数和上述选定的认证算法确定对 UE认证的认证矢 量, 进而通过发送模块 40将包含上述 AMF参数的第 X比特的信息的认证矢 量消息发送给 MEE, MME接收到上述认证矢量消息之后, 可保存上述认证矢 量消息并将上述认证矢量消息中对 UE认证的认证参数信息发送给 UE。 如图 3, 当 HSS不支持认证算法选择时, HSS的选择模块 20默认选择 Milenage算 法作为对 UE认证的认证算法并通过处理模块 30根据上述选择模块 20选择的 Milenage算法确定对 UE认证的认证矢量之后, 发送模块 40则可将上述认证 矢量发送给 MME, 其中, 上述认证矢量消息中包含的对 UE认证的认证算法 的标识信息为预设的 AMF参数中默认设置的标识信息, 即上述认证矢量中的 AMF参数的第 X比特默认设定为 0, HSS的发送模块 40可将包含上述 AMF 参数的第 X比特的信息的认证矢量发送给 MME, MME接收到上述认证矢量 消息之后,可保存上述认证矢量消息并将上述认证矢量消息中对 UE认证的认 证参数信息发送给 UE。 具体实现中, 上述 HSS的处理模块和发送模块根据选 择模块选择的认证算法确定对 UE认证的认证矢量并向 MME发送上述认证矢 量的具体实现过程可参见本发明实施例提供的选择认证算法的方法的第一实 施例中的步骤 S103-S104, 在此不再赘述。
本发明实施例中所描述的 HSS若支持认证算法选择, HSS可根据 MME 发送的认证数据请求消息中携带的 UE支持的认证算法的信息,结合其自身支 持的认证算法的信息选择对 UE认证的认证算法(包括 Tuak算法或者 Milenage 算法), 并根据上述选定的对 UE认证的认证算法设定 AMF参数的第 X比特 的值(包括 0和 1 ), 进而根据上述 AMF和选定的认证算法确定对 UE认证的 认证矢量,将上述包括选定的对 UE认证的认证算法的标识信息的认证矢量发 送给 MME。 若 HSS不支持认证算法选择, HSS接收到 MME发送的认证数据 请求消息之后默认选择 Milenage算法作为对 UE认证的认证算法,并根据预设 的 AMF参数和上述 Milenage算法确定对 UE认证的认证矢量, 进而将上述对 UE认证的认证矢量发送给 MME。 本发明实施例中所描述的 HSS可根据 UE 支持的认证算法和其自身支持的认证算法选择对 UE认证的认证算法,根据选 定的认证算法确定 UE认证的认证矢量并在上述认证矢量中添加对 UE认证的 认证算法的标识信息, 用于通知 UE对其认证的认证算法, 提高了对 UE认证 的认证算法的选择的多样性和 UE和 HSS的资源利用率,增强对 UE认证的用 户体验。 参见图 11, 是本发明实施例提供的选择认证算法的用户设备的实施例结 构示意图。 本实施例中所描述的用户设备, 包括:
发送模块 50, 用于向控制设备发送所述用户设备支持的认证算法的信息。 接收模块 60, 用于接收所述控制设备发送的用户认证请求消息。
处理模块 70, 用于根据所述用户认证请求消息确定认证算法, 并根据所 述认证算法对所述网络进行认证。
在一些可行的实施方式中, 当 UE需要向 MME发送 UE支持的认证算法 的信息时, UE可向 MME发送请求消息, 将上述 UE支持的认证算法的信息 通过上述请求消息发送给 MME; 或者, 当 MME需要得知 UE支持的认证算 法的信息时, MME可向 UE发送请求消息, 请求 UE将 UE支持的认证算法 的信息发送给 MME, UE接收到 MME发送的请求之后, 则可向 MME发送响 应消息, 将 UE支持的认证算法的信息通过上述响应消息发送给 MME。 本发 明实施例对 UE将其支持的认证算法的信息发送给 MME的发送方式不做具体 限定, 上述通过请求消息或者响应消息将其支持的认证算法的信息发送给 MME的发送方式仅是举例,而非穷举,本发明实施例将以通过请求消息将 UE 支持的认证算法的信息发送给 MME的发送方式为例, 进行具体说明。 具体实 现中, UE的发送模块 50向 MME发送的请求消息可为 Attach请求,或者 TAU 请求或者 Registration请求等,本发明实施例不限定上述请求消息的消息类型。 UE向 MME发送的请求消息中可将 UE支持的认证算法的信息添加到上述请 求消息中发送给 MME。 具体实现中, 当 UE支持认证算法选择 (即 UE可支 持 Tuak算法和 Milenage算法)时, UE的发送模块 50向 MME发送请求消息 时可将其可支持的认证算法(包括 Tuak算法或者 Milenage算法 )信息添加在 上述请求消息中发送给 MME, 如图 2或图 3, 即此时 UE的发送模块 50向 MME发送的请求消息中携带着 UE支持的 Tuak算法或者 Milenage算法的信 息; 当 UE不支持认证算法选择 (即 UE只支持 Milenage算法 ) 时, UE的发 送模块 50 向 MME发送请求消息时则不将其支持的认证算法的信息发送给 MME, 即此时 UE的发送模块 50向 MME发送的请求消息中携带的 UE支持 的认证算法的信息为空。 具体实现中, 上述 UE的发送模块向 MME发送请求 消息的具体实现过程可参见本发明实施例提供的选择认证算法的第二实施例 中的步骤 S201, 在此不再赘述。
在一些可行的实施方式中, 上述发送模块 50发送的所述用户设备支持的 认证算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支 持的 Milenage算法;
所述处理模块 70, 具体用于:
对所述用户认证请求消息进行解析,获取所述用户认证请求消息中包含的 认证算法的标识信息;
根据所述标识信息确定认证算法。
在一些可行的实施方式中, 上述接收模块 60接收到的所述用户认证请求 消息中包含对所述用户设备认证的认证参数;
上述接收模块 60接收的所述对所述用户设备认证的所述认证参数中包含 AUTN参数, 所述 AUTN参数中包含 AMF参数;
所述认证算法的标识信息包括: 所述 AMF参数中包含的所述认证算法的 标志位的第一标识符, 或第二标识符。
上述处理模块 70, 具体用于:
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第一标识符时, 将所述用户设备支持的 Tuak算法设定为认证算法; 或 者
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第二标识符时, 将所述用户设备支持的 Milenage算法设定为认证算法。
在一些可行的实施方式中, 上述发送模块 50发送的所述用户设备支持的 认证算法的信息为空;
所述处理模块 70, 具体用于: 根据所述用户认证请求消息将其支持的 Milenage算法设定为认证算法。 在一些可行的实施方式中, 当 UE的发送模块 50向 MME发送请求消息 之后, MME可根据 UE发送的请求消息向 HSS发送认证数据请求消息, HSS 接收到 MME发送的认证数据请求消息之后可根据上述认证数据请求消息选 择对 UE认证的认证算法, 并根据选定的认证算法设定上述认证算法的标识信 息, 确定对 UE认证的认证矢量, 进而通过 MME将上述包含上述认证算法的 标识信息的认证矢量发送给 UE。 MME接收到 HSS发送的对 UE认证的认证 算法的标识信息之后, 可保存上述对 UE认证的认证算法的标识信息(具体可 的认证算法的标识信息发送给 UE。 UE的接收模块 60接收 MME发送的用户 认证请求消息之后,处理模块 70则可根据上述接收模块 60接收到的用户认证 请求消息确定网络对其认证的认证算法,进而根据网络对其认证的认证算法确 定其对网络认证的认证算法,并根据上述确定的对网络的认证算法对网络进行 认证。 其中, 上述 UE的接收模块 60接收到的 MME发送的用户认证请求消 息中包含对 UE认证的认证参数,即包含 HSS根据 UE发送的请求消息设定的 对 UE认证的认证矢量中的参数, 包括 AUTN、 RAND参数等。
在一些可行的实施方式中, 当 UE支持认证算法选择时, UE的发送模块 50将 UE支持的认证算法的信息添加到请求消息中发送给 MME之后, 当 UE 的接收模块 60从 MME处接收到用户认证请求消息时,处理模块 70则可对上 述接收模块 60接收到的用户认证请求消息进行解析, 从上述用户认证请求消 息中包含的上述认证参数中获取对 UE认证的认证算法的标识信息。具体实现 中, 当 HSS支持认证算法选择, 并且 HSS从 MME处接收到的认证数据请求 消息中携带 UE支持的认证算法的信息时, HSS可根据 UE支持的认证算法及 其自身支持的认证算法确定对 UE认证的认证算法, 并在预设的 AMF参数中 设定选定的认证算法的标识信息, 根据上述包含认证算法的标识信息的 AMF 参数计算得到对 UE认证的认证矢量。 HSS确定上述认证矢量之后则可通过 MME将上述认证矢量中对 UE认证的认证参数发送给 UE。 UE的接收模块 60 接收到 MME发送的用户认证请求之后, 处理模块 70则可对上述用户认证请 求消息进行解析, 从上述用户认证请求消息中包含的认证参数中获取网络对 UE认证的认证算法的标识信息, 其中, 上述网络对 UE认证的认证算法的标 识信息包括: 上述 AMF参数中对 UE认证的标志位(即上述 AMF参数中的 第 X比特) 的第一标识符 (例如 1 )或者第二标识符(例如 0 )。 如图 2, 当 UE的接收模块 60接收到 MME发送的用户认证请求消息之后, 处理模块 70 则可对上述用户认证请求消息中的 AMF参数的第 X比特进行分析, 从上述 AMF参数的第 X比特中获取认证算法的标识信息(包括 0或 1 ), 根据获取到 的标识信息确定网络对其认证的认证算法,进而确定其对网络进行认证的认证 算法(与网络对其认证的认证算法保存一致)。 例如, 当 UE的处理模块 70从 上述 AMF参数中获取得知 AMF的第 X比特的值为 1 (即第一标识符) 时, 则可确定网络对其认证的认证算法为 Tuak算法, 处理模块 70确定网络对 UE 认证的认证算法之后,则可确定 UE对网络认证的认证算法为 Tuak算法 Tuak; 当处理模块 70从上述 AMF参数中获取得知 AMF的第 X比特的值为 0 (即第 二标识符)时, 则可确定网络对 UE认证的认证算法为 Milenage算法, 处理模 块 70确定网络对 UE认证的认证算法之后, 则可确定 UE对网络认证的认证 算法为 Milenage算法。
在一些可行的实施方式中, 当 UE不支持认证算法选择时, UE的发送模 块 50向 MME发送请求消息中携带的 UE支持的认证算法的信息为空, HSS 通过 MME接收到的认证数据请求消息中携带的 UE支持的认证算法的信息也 为空, 此时 HSS选择默认认证算法(Milenage算法), HSS根据选定的认证算 法确定的认证矢量中包含的对 UE认证的认证算法的标识信息为 AMF参数的 第 X比特的第二标识符(0 ), 如图 4。 UE的接收模块 60接收到 MME发送的 用户认证请求之后, 处理模块 70则根据默认认证算法(即 Milenage算法 )确 定对网络认证的认证算法, 即此时网络对 UE认证的认证算法和 UE对网络认 证的认证算法均为 Milenage算法。 具体实现中, 处理模块 70确定对网络认证 的认证算法之后,则可将上述对网络认证的认证算法的信息通过用户认证响应 发送给 MME, 以通过 MME完成网络对 UE的认证, 允许 UE接入网络。 具 体实现中,上述 HSS通过 MME接收到 UE发送的请求消息中包含的信息后根 据上述信息确定对 UE认证的认证算法及认证矢量, 并通过 MME将上述认证 矢量等信息发送给 UE的具体实现过程可参见本发明实施例提供的选择认证算 法的第一实施例, 在此不再赘述。
具体实现中, 上述 UE的接收模块和处理模块接收 MME发送的用户认证 请求,并根据上述接收用户认证请求确定对网络认证的认证算法的具体实现过 程可参见本发明实施例提供的选择认证算法的第二实施例中的步骤 S202-S203, 在此不再赘述。
本发明实施例中所描述的 UE若支持认证算法选择, UE可将其支持的认 证算法通过请求消息发送给 MME, 还可根据 MME发送的用户认证请求获取 网络对其认证的认证算法的信息,进而将网络对其认证的认证算法设定为其对 网络认证的认证算法; 若 UE不支持认证算法选择, UE向 MME发送的请求 消息, 网络接收到其发送的请求消息之后将选择默认的 Milenage算法作为对 UE认证的认证算法, 当 UE接收到 MME发送的用户认证请求时, 则可将默 认算法 Milenage算法设定为对网络认证的认证算法, 从而实现认证算法的统 一, 通过 MME完成 UE的认证, 允许 UE接入到网络。 本发明实施例提高了 UE认证的认证算法选择的多样性和终端的资源利用率, 增强了 UE认证的用 户体验。 参见图 12, 是本发明实施例提供的选择认证算法的控制设备的实施例结 构示意图。 本实施例中所描述的控制设备, 包括:
接收模块 80, 用于接收用户设备发送的所述用户设备支持的认证算法的 信息。
发送模块 90, 用于向服务设备发送认证数据请求消息, 所述认证数据请 求消息中携带所述用户设备支持的认证算法的信息。
所述接收模块 80, 用于接收所述服务设备发送的认证算法的标识信息, 所述认证算法的标识信息对应于所述认证数据请求消息。
所述发送模块 90, 用于向所述用户设备发送用户认证请求消息, 所述用 户认证请求消息中携带所述认证算法的标识信息。
在一些可行的实施方式中, 上述接收模块 80接收的所述用户设备支持的 认证算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支 持的 Milenage算法, 或者为空。 在一些可行的实施方式中, 上述接收模块 80接收的所述认证算法的标识 信息, 包括: 所述服务设备选定的 Tuak算法对应的标识信息, 和 /或所述服务 设备选定的 Milenage算法对应的标识信息, 或者为空。
在一些可行的实施方式中, 当 UE需要向 MME发送 UE支持的认证算法 的信息时, UE可向 MME发送请求消息, 将上述 UE支持的认证算法的信息 通过上述请求消息发送给 MME; 或者, 当 MME需要得知 UE支持的认证算 法的信息时, MME可向 UE发送请求消息, 请求 UE将 UE支持的认证算法 的信息发送给 MME, UE接收到 MME发送的请求之后, 则可向 MME发送响 应消息, 将 UE支持的认证算法的信息通过上述响应消息发送给 MME。 本发 明实施例对 UE将其支持的认证算法的信息发送给 MME的发送方式不做具体 限定, 上述通过请求消息或者响应消息将其支持的认证算法的信息发送给 MME的发送方式仅是举例,而非穷举,本发明实施例将以通过请求消息将 UE 支持的认证算法的信息发送给 MME的发送方式为例, 进行具体说明。 具体实 现中, MME的接收模块 80从 UE处接收到的 UE发送的请求消息中可携带 UE支持的认证算法的信息, 包括: UE支持的 Tuak算法, 或者 UE支持的 Milenage算法, 或者为空。 即当 UE支持认证算法选择 (即 UE支持 Tuak算 法和 Milenage算法)时, UE向 MME发送请求消息时可将其支持的认证算法 的信息通过上述请求消息发送给 MME; 当 UE不支持认证算法选择 (即 UE 只支持 Milenage算法) 时, UE向 MME发送的请求消息中携带的 UE支持的 认证算法的信息则为空。 MME的接收模块 80接收到 UE发送的请求消息之后, 发送模块 90则可根据上述接收模块 80接收到的请求消息向 HSS发送认证数 据请求消息。当 UE发送的请求消息中携带 UE支持的认证算法的信息时, MME 的发送模块 90向 HSS发送认证数据请求消息时则可将上述 UE支持的认证算 法的信息通过上述认证数据请求消息发送给 HSS; 当 UE发送的请求消息中携 带的 UE支持的认证算法的信息为空时, MME的发送模块 90向 HSS发送认 证数据请求消息时,上述认证数据请求消息中携带的 UE支持的认证算法的信 息则为空。
在一些可行的实施方式中, MME的发送模块 90向 HSS发送认证数据请 求消息之后, HSS则可根据上述认证数据请求消息确定对 UE认证的认证算法, 并根据上述确定的认证算法计算得到对 UE认证的认证矢量。 HSS根据 MME 发送的认证数据请求消息确定对 UE认证的认证算法,并根据上述认证算法确 定对 UE认证的认证矢量之后, 则可将上述认证矢量通过认证数据响应消息发 送给 MME。 MME通过接收模块 80接收到 HSS发送的认证数据响应消息之后, 则可保存上述认证数据响应消息中包含的认证矢量, 进而通过发送模块 90向 UE发送用户认证请求消息, 将上述对 UE认证的认证矢量中包含的对 UE认 证的认证参数发送给 UE, 如图 2、 图 3或图 4。 UE接收到 MME发送的用户 认证请求消息之后, 则可从中获取网络对其认证的认证参数等信息, 进而根据 上述认证参数确定对网络认证的认证算法。 具体实现中, 上述 HSS根据 MME 发送的认证数据请求消息确定对 UE认证的认证算法及认证矢量, 并通过认证 数据响应消息将上述认证矢量等信息发送给 MME 的具体实现过程可参见本 发明实施例提供的选择认证算法的方法的第一实施例, 在此不再赘述。 上述 UE向 MME发送请求消息并根据 MME发送的用户认证请求确定对网络认证 的认证算法的具体实现过程可参见本发明实施例提供的选择认证算法的方法 的第二实施例, 在此不再赘述。
在一些可行的实施方式中, 当 MME支持 UE支持的认证算法的信息的保 存和转发时, 若 UE发送给 MME的请求消息中携带 UE支持的认证算法的信 息(即 UE支持 Tuak算法和 Milenage算法), MME的接收模块 80接收到 UE 发送的请求消息之后则可保存 UE支持的认证算法的信息,并通过发送模块 90 将上述 UE支持的认证算法的信息通过认证数据请求消息发送给 HSS, 如图 2 或图 3; 若 UE发送给 MME的请求消息中携带的 UE支持的认证算法的信息 为空, MME的接收模块 80接收到上述请求消息之后则可通过发送模块 90向 HSS发送认证数据请求消息,其中上述认证数据请求消息中携带的 UE支持的 认证算法的信息则为空, 如图 4。 当 MME不支持 UE支持的认证算法的信息 的保存和转发时, 若 UE发送给 MME的请求消息中携带 UE支持的认证算法 的信息 (即 UE支持 Tuak算法和 Milenage算法), MME通过接收模块 80接 收到 UE发送的请求消息之后无法保存 UE支持的认证算法的信息,此时 MME 的发送模块 90向 HSS发送认证数据请求消息时,上述认证数据请求消息中携 带的 UE支持的认证算法的信息则为空,如图 7或者图 8; 若 UE发送给 MME 的请求消息中携带的 UE支持的认证算法的信息为空,则 MME的接收模块 80 接收到 UE发送的请求消息之后, 发送模块 90则可向 HSS发送认证数据请求 消息,其中,上述认证数据请求消息中携带的 UE支持的认证算法的信息为空, 如图 9。 具体实现中, 本发明实施例中所描述的控制设备的具体实现过程可参 见本发明实施例提供的选择认证算法的方法的第三实施例中的步骤 S301-S304, 在此不再赘述。
在一些可行的实施方式中, MME向 UE发送用户认证请求消息之后, 还 可从 UE处获取用户认证响应消息,并根据其保存的 HSS发送的对 UE认证的 认证矢量完成对 UE的认证, 进而允许 UE接入到网络。
本发明实施例中, MME可接收 UE发送的请求消息, 根据 UE发送的请 求消息向 HSS发送认证数据请求消息,并从 HSS处获取 HSS根据上述认证数 据请求消息确定的对 UE认证的认证矢量等信息, 进而向 UE发送用户认证请 求, 将上述 HSS对 UE认证的认证矢量等信息发送给 UE, 以供 UE确定其对 网络认证的认证算法; MME还可从 UE处获取用户认证响应消息, 结合 HSS 发送的对 UE认证的认证矢量等信息完成 UE接入网络的认证, 进而允许 UE 接入到网络; 此外, MME还可根据其自身配置 (即是否支持 UE支持的认证 算法的信息的保存和转发) 向 HSS发送认证数据请求消息, 丰富了 UE认证 的认证算法的多样性, 提高了 UE认证的终端利用率, 增强了 UE认证的用户 体验。
参见图 13, 是本发明实施例提供的选择认证算法的系统的实施例结构示 意图。 本实施例中所描述的选择认证算法的系统, 包括:
上述本发明实施例提供的选择认证算法的用户设备 100、 上述本发明实施 例中提供的选择认证算法的控制设备 200和上述本发明实施例提供的选择认 证算法的服务设备 300。 具体实现中, 上述用户设备 100、 控制设备 200和服 务设备 300在选择认证算法的过程中的具体交互过程可参见本发明实施例提 供的选择认证算法的方法的第一实施例、第二实施例和第三实施例中所描述的 具体实现过程, 在此不再赘述。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程, 是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于计算机 可读取存储介质中, 该程序在执行时, 可包括如上述各方法的实施例的流程。 其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory, ROM )或随机存储记忆体(Random Access Memory, RAM )等。
以上所揭露的仅为本发明较佳实施例而已,当然不能以此来限定本发明之 权利范围,因此依本发明权利要求所作的等同变化,仍属本发明所涵盖的范围。

Claims

权 利 要 求
1、 一种选择认证算法的方法, 其特征在于, 包括:
服务设备接收控制设备发送的认证数据请求消息,所述认证数据请求消息 中携带用户设备支持的认证算法的信息;
所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算 法的信息选定认证算法;
所述服务设备根据选定的所述认证算法确定所述认证算法的标识信息; 所述服务设备将所述认证算法的标识信息发送给所述控制设备,以通过所 述控制设备发送给所述用户设备。
2、 如权利要求 1所述的方法, 其特征在于, 所述认证数据请求消息中携 带的所述认证算法的标识信息包括: 所述用户设备支持的 Tuak算法, 和 /或所 述用户设备支持的 Milenage算法;
所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算 法的信息选定认证算法, 包括:
所述服务设备从所述用户设备支持的认证算法和所述服务设备支持的认 证算法中选择一种所述用户设备和所述服务设备都支持的认证算法,并将所述 认证算法设定为所述选定的所述认证算法;
其中, 所述服务设备支持的认证算法包括: Tuak算法, 和 /或 Milenage 算法。
3、 如权利要求 1所述的方法, 其特征在于, 所述认证数据请求消息中携 带的用户设备支持的认证算法的信息为空;
所述服务设备支持的认证算法信息中包括: 所述服务终端支持的 Tuak算 法, 和 /或所述服务终端支持的 Milenage算法;
所述服务设备根据所述认证数据请求消息,和所述服务设备支持的认证算 法的信息选定认证算法, 包括:
所述服务设备从其支持的认证算法中选择 Milenage 算法, 并将所述 Milenage算法设定为所述选定的所述认证算法。
4、 如权利要求 1所述的方法, 其特征在于, 所述认证算法的标识信息具 体为对所述用户设备认证的认证矢量;
当所述服务设备将所述 Tuak算法设定为所述选定的所述认证算法时, 所 述服务设备根据选定的所述认证算法确定所述认证算法的标识信息, 包括: 所述服务设备在预设的认证管理域 AMF参数中选定对所述用户设备认证 的认证算法的标志位, 并将所述标志位设定为第一标识符, 作为所述 Tuak算 法的标识信息;
所述服务设备根据所述 AMF参数和所述 Tuak算法生成对所述用户设备 认证的认证矢量。
5、 如权利要求 2或 3所述的方法, 其特征在于, 所述认证算法的标识信 息具体为对所述用户设备认证的认证矢量;
当所述服务设备将所述 Milenage算法设定为所述选定的所述认证算法时, 所述服务设备根据选定的所述认证算法确定所述认证算法的标识信息, 包括: 所述服务设备在预设的 AMF参数中选定对所述用户设备认证的认证算法 的标志位, 并将所述标志位设定为第二标识符, 作为所述 Milenage算法的标 识信息;
所述服务设备根据所述 AMF参数和所述 Milenage算法生成对所述用户设 备认证的认证矢量。
6、 一种选择认证算法的方法, 其特征在于, 包括:
用户设备向控制设备发送所述用户设备支持的认证算法的信息;
所述用户设备接收所述控制设备发送的用户认证请求消息;
所述用户设备根据所述用户认证请求消息确定认证算法,并根据所述认证 算法对所述网络进行认证。
7、 如权利要求 6所述的方法, 其特征在于, 所述用户设备支持的认证算 法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法;
所述用户设备根据所述用户认证请求消息确定认证算法, 包括: 所述用户设备对所述用户认证请求消息进行解析,获取所述用户认证请求 消息中包含的认证算法的标识信息;
所述用户设备根据所述标识信息确定认证算法。
8、 如权利要求 7所述的方法, 其特征在于, 所述用户认证请求消息中包 含对所述用户设备认证的认证参数;
所述对所述用户设备认证的所述认证参数中包含 AUTN参数,所述 AUTN 参数中包含 AMF参数;
所述认证算法的标识信息包括: 所述 AMF参数中包含的所述认证算法的 标志位的第一标识符, 或第二标识符。
9、 如权利要求 8所述的方法, 其特征在于, 所述用户设备根据所述标识 信息确定认证算法, 包括:
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第一标识符时, 所述用户设备将其支持的 Tuak算法设定为认证算法; 或者
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第二标识符时, 所述用户设备将其支持的 Milenage算法设定为认证算 法。
10、 如权利要求 6所述的方法, 其特征在于, 所述用户设备支持的认证算 法的信息为空;
所述用户设备根据所述用户认证请求消息确定认证算法, 包括: 所述用户设备根据所述用户认证请求消息将其支持的 Milenage算法设定 为认证算法。 -sel l . 一种选择认证算法的方法, 其特征在于, 包括:
控制设备接收用户设备发送的所述用户设备支持的认证算法的信息; 所述控制设备向服务设备发送认证数据请求消息,所述认证数据请求消息 中携带所述用户设备支持的认证算法的信息;
所述控制设备接收所述服务设备发送的认证算法的标识信息,所述认证算 法的标识信息对应于所述认证数据请求消息;
所述控制设备向所述用户设备发送用户认证请求消息,所述用户认证请求 消息中携带所述认证算法的标识信息。
12、 如权利要求 11所述的方法, 其特征在于, 所述用户设备支持的认证 算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法, 或者为空。
13、 如权利要求 11或 12所述的方法, 其特征在于, 所述服务设备发送的 认证算法的标识信息, 包括: 所述服务设备选定的 Tuak算法对应的标识信息, 和 /或所述服务设备选定的 Milenage算法对应的标识信息, 或者为空。
14、 一种选择认证算法的服务设备, 其特征在于, 包括:
接收模块, 用于接收控制设备发送的认证数据请求消息, 所述认证数据请 求消息中携带用户设备支持的认证算法的信息;
选择模块, 用于根据所述接收模块接收的所述认证数据请求消息, 和所述 服务设备支持的认证算法的信息选定认证算法;
处理模块,用于根据所述选择模块选定的所述认证算法确定所述认证算法 的标识信息;
发送模块, 用于将所述认证算法的标识信息发送给所述控制设备, 以通过 所述控制设备发送给所述用户设备。
15、 如权利要求 14所述的服务设备, 其特征在于, 所述接收模块接收的 所述认证数据请求消息中携带的所述认证算法的标识信息包括:所述用户设备 支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法;
所述选择模块, 具体用于:
从所述用户设备支持的认证算法和所述服务设备支持的认证算法中选择 一种所述用户设备和所述服务设备都支持的认证算法,并将所述认证算法设定 为所述选定的所述认证算法;
其中, 所述服务设备支持的认证算法包括: Tuak算法, 和 /或 Milenage 算法。
16、 如权利要求 15所述的服务设备, 其特征在于, 所述接收模块接收的 所述认证数据请求消息中携带的用户设备支持的认证算法的信息为空;
所述服务设备支持的认证算法信息中包括: 所述服务设备支持的 Tuak算 法, 和 /或所述服务设备支持的 Milenage算法;
所述选择模块, 具体用于:
所述服务设备从其支持的认证算法中选择 Milenage 算法, 并将所述 Milenage算法设定为所述选定的所述认证算法。
17、 如权利要求 15所述的服务设备, 其特征在于, 所述处理模块确定的 所述认证算法的标识信息具体为对所述用户设备认证的认证矢量;
当所述选择模块将所述 Tuak算法设定为所述选定的所述认证算法时, 所 述处理模块, 具体用于:
在预设的 AMF参数中选定对所述用户设备认证的认证算法的标志位, 并 将所述标志位设定为第一标识符, 作为所述 Tuak算法的标识信息;
根据所述 AMF参数和所述 Tuak算法生成对所述用户设备认证的认证矢 量。
18、 如权利要求 15或 16所述的服务设备, 其特征在于, 所述处理模块确 定的所述认证算法的标识信息具体为对所述用户设备认证的认证矢量;
当所述选择模块将所述 Milenage算法设定为所述选定的所述认证算法时, 所述处理模块, 具体用于: 在预设的 AMF参数中选定对所述用户设备认证的认证算法的标志位, 并 将所述标志位设定为第二标识符, 作为所述 Milenage算法的标识信息;
根据所述 AMF参数和所述 Milenage算法生成对所述用户设备认证的认证 矢量。
19、 一种选择认证算法的用户设备, 其特征在于, 包括:
发送模块, 用于向控制设备发送所述用户设备支持的认证算法的信息; 接收模块, 用于接收所述控制设备发送的用户认证请求消息;
处理模块, 用于根据所述用户认证请求消息确定认证算法, 并根据所述认 证算法对所述网络进行认证。
20、 如权利要求 19所述的用户设备, 其特征在于, 所述发送模块发送的 所述用户设备支持的认证算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法;
所述处理模块, 具体用于:
对所述用户认证请求消息进行解析,获取所述用户认证请求消息中包含的 认证算法的标识信息;
根据所述标识信息确定认证算法。
21、 如权利要求 20所述的用户设备, 其特征在于, 所述接收模块接收到 的所述用户认证请求消息中包含对所述用户设备认证的认证参数;
所述接收模块接收的所述对所述用户设备认证的所述认证参数中包含 AUTN参数, 所述 AUTN参数中包含 AMF参数;
所述认证算法的标识信息包括: 所述 AMF参数中包含的所述认证算法的 标志位的第一标识符, 或第二标识符。
22、 如权利要求 21所述的用户设备, 其特征在于, 所述处理模块, 具体 用于:
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第一标识符时, 将所述用户设备支持的 Tuak算法设定为认证算法; 或 者
当所述标识信息为所述 AMF参数中对所述用户设备认证的认证算法的标 志位的第二标识符时, 将所述用户设备支持的 Milenage算法设定为认证算法。
23、 如权利要求 19所述的用户设备, 其特征在于, 所述发送模块发送的 所述用户设备支持的认证算法的信息为空;
所述处理模块, 具体用于:
根据所述用户认证请求消息将所述用户设备支持的 Milenage算法设定为 认证算法。
24、 一种选择认证算法的控制设备, 其特征在于, 包括:
接收模块, 用于接收用户设备发送的所述用户设备支持的认证算法的信 息;
发送模块, 用于向服务设备发送认证数据请求消息, 所述认证数据请求消 息中携带所述用户设备支持的认证算法的信息;
所述接收模块, 用于接收所述服务设备发送的认证算法的标识信息, 所述 认证算法的标识信息对应于所述认证数据请求消息;
所述发送模块, 用于向所述用户设备发送用户认证请求消息, 所述用户认 证请求消息中携带所述认证算法的标识信息。
25、 如权利要求 24所述的控制设备, 其特征在于, 所述接收模块接收的 所述用户设备支持的认证算法的信息包括: 所述用户设备支持的 Tuak算法, 和 /或所述用户设备支持的 Milenage算法, 或者为空。
26、 如权利要求 24或 25所述的控制设备, 其特征在于, 所述接收模块接 收的所述认证算法的标识信息, 包括: 所述服务设备选定的 Tuak算法对应的 标识信息, 和 /或所述服务设备选定的 Milenage算法对应的标识信息, 或者为 27、 一种选择认证算法的系统, 其特征在于, 包括: 如权利要求 14-18所 述的服务设备、 如权利要求 19-23所述的用户设备、 以及如权利要求 24-26所 述的控制设备。
PCT/CN2014/080736 2013-12-31 2014-06-25 一种选择认证算法的方法、装置及系统 WO2015100975A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
EP14876188.5A EP3079392A1 (en) 2013-12-31 2014-06-25 Method, apparatus and system for selecting authentication algorithm
KR1020167020662A KR20160103115A (ko) 2013-12-31 2014-06-25 인증 알고리즘을 선택하는 방법, 장치 및 시스템
US15/197,343 US20160316368A1 (en) 2013-12-31 2016-06-29 Method, apparatus, and system for selecting authentication algorithm

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310754492.9 2013-12-31
CN201310754492.9A CN104754577B (zh) 2013-12-31 2013-12-31 一种选择认证算法的方法、装置及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/197,343 Continuation US20160316368A1 (en) 2013-12-31 2016-06-29 Method, apparatus, and system for selecting authentication algorithm

Publications (1)

Publication Number Publication Date
WO2015100975A1 true WO2015100975A1 (zh) 2015-07-09

Family

ID=53493111

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/080736 WO2015100975A1 (zh) 2013-12-31 2014-06-25 一种选择认证算法的方法、装置及系统

Country Status (5)

Country Link
US (1) US20160316368A1 (zh)
EP (1) EP3079392A1 (zh)
KR (1) KR20160103115A (zh)
CN (1) CN104754577B (zh)
WO (1) WO2015100975A1 (zh)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10390224B2 (en) 2014-05-20 2019-08-20 Nokia Technologies Oy Exception handling in cellular authentication
CN106465109A (zh) * 2014-05-20 2017-02-22 诺基亚技术有限公司 蜂窝网络认证
US10785645B2 (en) * 2015-02-23 2020-09-22 Apple Inc. Techniques for dynamically supporting different authentication algorithms
CN110891270B (zh) * 2018-09-10 2021-08-27 大唐移动通信设备有限公司 一种鉴权算法的选择方法和装置
US11539684B2 (en) * 2020-03-16 2022-12-27 Microsoft Technology Licensing, Llc Dynamic authentication scheme selection in computing systems
CN114245376A (zh) * 2020-09-07 2022-03-25 中国移动通信有限公司研究院 一种数据传输方法、用户设备、相关网络设备和存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102083064A (zh) * 2009-11-26 2011-06-01 大唐移动通信设备有限公司 用于增强密钥推衍算法灵活性的方法和系统
CN102256234A (zh) * 2010-05-19 2011-11-23 电信科学技术研究院 一种对用户鉴权过程进行处理的方法及设备
US20130013923A1 (en) * 2011-07-08 2013-01-10 Motorola Solutions, Inc. Methods for obtaining authentication credentials for attaching a wireless device to a foreign 3gpp wireless domain

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2394143B (en) * 2002-10-08 2006-04-05 Ipwireless Inc System and method for use of internet authentication technology to provide umts authentication
CN1767430B (zh) * 2004-10-27 2010-04-21 华为技术有限公司 鉴权方法
CN101247356B (zh) * 2007-02-13 2011-02-16 华为技术有限公司 Dhcp消息传送的方法及系统
CN101378591B (zh) * 2007-08-31 2010-10-27 华为技术有限公司 终端移动时安全能力协商的方法、系统及装置
CN101605324B (zh) * 2008-06-13 2011-06-01 华为技术有限公司 算法协商的方法、装置及系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102083064A (zh) * 2009-11-26 2011-06-01 大唐移动通信设备有限公司 用于增强密钥推衍算法灵活性的方法和系统
CN102256234A (zh) * 2010-05-19 2011-11-23 电信科学技术研究院 一种对用户鉴权过程进行处理的方法及设备
US20130013923A1 (en) * 2011-07-08 2013-01-10 Motorola Solutions, Inc. Methods for obtaining authentication credentials for attaching a wireless device to a foreign 3gpp wireless domain

Also Published As

Publication number Publication date
EP3079392A4 (en) 2016-10-12
US20160316368A1 (en) 2016-10-27
EP3079392A1 (en) 2016-10-12
KR20160103115A (ko) 2016-08-31
CN104754577A (zh) 2015-07-01
CN104754577B (zh) 2019-05-03

Similar Documents

Publication Publication Date Title
US11272365B2 (en) Network authentication method, and related device and system
US10313449B2 (en) Online signup provisioning techniques for hotspot connections
US9386004B2 (en) Peer based authentication
KR101475349B1 (ko) 이동 통신 시스템에서 단말 보안 능력 관련 보안 관리 방안및 장치
US9439069B2 (en) Subscriber identity module provider apparatus for over-the-air provisioning of subscriber identity module containers and methods
US10798082B2 (en) Network authentication triggering method and related device
WO2015100975A1 (zh) 一种选择认证算法的方法、装置及系统
WO2019017837A1 (zh) 网络安全管理的方法及装置
WO2017024671A1 (zh) 一种网络切换方法及终端
KR20130029103A (ko) 통신 시스템들에서 가입자 인증과 디바이스 인증을 바인딩하는 방법 및 장치
JP2024029170A (ja) 通信システムにおける統合サブスクリプション識別子管理
JP6962432B2 (ja) 通信方法、コントロールプレーン装置、コントロールプレーン装置もしくは通信端末のための方法、及び通信端末
WO2015100974A1 (zh) 一种终端认证的方法、装置及系统
US20190274039A1 (en) Communication system, network apparatus, authentication method, communication terminal, and security apparatus
JP2015502701A (ja) ワイヤレスリンクのセットアップのために鍵のライフタイムへのアクセスを可能にすること
KR101460766B1 (ko) 무선 네트워크 시스템에서 클러스터 기능을 이용한 보안설정 시스템 및 그 제어방법
WO2013152740A1 (zh) 用户设备的认证方法、装置及系统
EP3637815B1 (en) Data transmission method, and device and system related thereto
JP2017513412A (ja) Sim及びsipクライアントが同じモバイル機器に配置されていることを判断する方法及びシステム
KR101485801B1 (ko) 이동 통신 시스템의 인증과 비계층 프로토콜 보안 운영을 효율적으로 지원하는 관리 방법 및 시스템
KR20130033691A (ko) 네트워크 접속 보안 강화 시스템을 위한 단말장치 및 인증지원장치
WO2020208295A1 (en) Establishing secure communication paths to multipath connection server with initial connection over private network
EP4203392A1 (en) Authentication support for an electronic device to connect to a telecommunications network
WO2022067827A1 (zh) 一种密钥推衍方法及其装置、系统
WO2024067619A1 (zh) 通信方法和通信装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14876188

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2014876188

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2014876188

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20167020662

Country of ref document: KR

Kind code of ref document: A