WO2016206387A1 - 一种接入孤立网络的鉴权认证方法及系统 - Google Patents

一种接入孤立网络的鉴权认证方法及系统 Download PDF

Info

Publication number
WO2016206387A1
WO2016206387A1 PCT/CN2016/073807 CN2016073807W WO2016206387A1 WO 2016206387 A1 WO2016206387 A1 WO 2016206387A1 CN 2016073807 W CN2016073807 W CN 2016073807W WO 2016206387 A1 WO2016206387 A1 WO 2016206387A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
authentication key
network identifier
authentication
correspondence
Prior art date
Application number
PCT/CN2016/073807
Other languages
English (en)
French (fr)
Inventor
彭锦
游世林
朱进国
林兆骥
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016206387A1 publication Critical patent/WO2016206387A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • This document relates to, but is not limited to, the field of mobile communications, and in particular, to an authentication authentication method and system for accessing an isolated network.
  • FIG. 1 is a schematic diagram of a network architecture of an evolved packet core network (EPC, Evolved Packet Core) in the related art.
  • EPC evolved packet core network
  • HSS Home Subscriber Server
  • MME Mobility Management Entity
  • S-GW Serving Gateway
  • P-GW PDN Gateway
  • SGSN Serving GPRS Support Node
  • PCRF Policy and Charging Rules Function
  • the HSS is set as the permanent storage location of the user subscription data, and is located in the home network that the user subscribes to;
  • the MME is set as the user subscription data in the current network storage location, and is responsible for the non-access stratum (Non-Access Stratum) signaling of the terminal to the network.
  • Non-Access Stratum Non-Access Stratum
  • S-GW is set as the gateway of the core network to the wireless system, responsible for the user plane bearer of the terminal to the core network, data buffering in the terminal idle mode, and the network side The function of initiating a service request, the lawful eavesdropping, and the packet data routing and forwarding function;
  • the P-GW is configured as an evolving packet system and a gateway of the external network of the system, and is responsible for the network protocol (IP, Internet Protocol) address allocation and charging function of the terminal, Packet packet filtering, policy application and other functions;
  • SGSN is set to Global System for Mobile Communication (GSM) and/or Enhanced Data Rate for GSM Evolution (EDGE) radio access network (GERAN) , GSM EDGE Radio Access Network) and Universal Terrestrial Radio Access Network
  • the UT Universal Terrestrial Radio Access Network accesses the service support point of the EPC network. It functions similarly to the MME and is responsible for user location update, paging management, and bearer
  • Iu is the interface between the radio network controller and the SGSN
  • Gr is the interface between the SGSN and the HSS
  • S1-MME is the interface between the base station and the MME
  • S1-U is the interface between the base station and the S-GW.
  • S3 is the interface between the MME and the SGSN
  • S4 is the interface between the SGSN and the S-GW
  • S5 is the interface between the S-GW and the P-GW
  • S6a is the interface between the MME and the HSS
  • S7 is the P.
  • S10 is the interface between the MME
  • S11 is the interface between the MME and the S-GW
  • SGi is the interface between the P-GW and the packet data network
  • Rx is the PCRF and the packet data network.
  • the base station may be disconnected from the core network or maintain a limited connection (ie, message delivery on the control plane may be guaranteed, but the transfer of user plane data may not be guaranteed). In this case, an emergency communication needs to be established quickly.
  • Network to ensure that special services are provided to some special users in the network (such as those related to national public safety) under special circumstances.
  • the network of emergency communication also known as the isolated network, adopts a network architecture that is different from the original architecture of the related technology, except that the base station may be transformed into a base station with public security capability, that is, a function with a partially evolved packet core network, that is, multiple
  • the logical functional entities are integrated in one or several entity public safety base stations.
  • the related technology uses an extended global subscriber identity module (USIM) application, that is, includes an International Mobile Subscriber Identification Number (IMSI) and multiple authentication keys Ki in the same USIM application.
  • USIM extended global subscriber identity module
  • IMSI International Mobile Subscriber Identification Number
  • the local core network specifies the authentication key used by the Universal Integrated Circuit Card (UICC) by carrying the index value of the authentication key Ki in the authentication request message.
  • UICC Universal Integrated Circuit Card
  • FIG. 2 is a flowchart of a terminal accessing an isolated network authentication authentication in the related art. As shown in Figure 2, the process includes the following steps:
  • Step 201 The universal integrated circuit card and the base station including the local core network pre-configure an isolated network authentication key (Ki) list;
  • Step 202 The connection between the base station and the core network is interrupted, and the mode is switched to the isolated network mode.
  • Step 203 The base station broadcasts a network identifier of the isolated network.
  • Step 204 The terminal detects the network identifier of the isolated network.
  • Step 205 The terminal sends a network attach request message to the base station including the local core network, where the message includes a user identifier parameter.
  • Step 206 The base station including the local core network randomly selects the isolated network authentication key Ki, adds the index value of the Ki to the authentication management function (AMF) domain, and generates an authentication and key agreement protocol (AKA, Authentication). And Key Agreement) authentication vector;
  • AMF authentication management function
  • AKA authentication and key agreement protocol
  • Step 207 The base station including the local core network sends an authentication request message to the terminal, where the message includes a random number and an authentication token (AUTN), wherein the authentication token parameter includes an AMF domain.
  • AUTN authentication token
  • Step 208 The terminal sends an authentication data request message to the universal integrated circuit card, where the message includes a random number and an authentication token parameter, where the authentication token parameter includes an AMF domain.
  • Step 209 The universal integrated circuit card obtains the authentication key Ki according to the authentication key index value in the AMF domain, verifies the authentication token, and calculates a response value (RES) and an intermediate key (K ASME );
  • RES response value
  • K ASME intermediate key
  • Step 210 The universal integrated circuit card sends back an authentication data response message to the terminal, where the message includes a response value RES and an intermediate key K ASME parameter.
  • Step 211 The terminal estimates a non-access stratum (NAS) and an access stratum (AS, Access Stratum) service key according to the intermediate key K ASME ;
  • NAS non-access stratum
  • AS Access Stratum
  • Step 212 The terminal sends back an authentication response message to the base station including the local core network, where the message includes a response value RES;
  • Step 213 The base station including the local core network verifies whether the received response value RES is equal to the expected response value XRES, and if they are equal, the verification passes;
  • Step 214 Perform a security mode command (SMC) process between the base station and the terminal of the local core network to negotiate a security algorithm to complete the establishment of the secure connection.
  • SMC security mode command
  • Step 215 The base station including the local core network sends back a network attach accept message to the terminal.
  • the above process uses the AMF field in the authentication vector to specify the authentication key to be used, which requires all operators and terminals to follow the same standard for the use of the AMF domain.
  • the current use of the AMF domain is not standardized.
  • different operators have different uses of the AMF domain, and it is difficult to standardize. Therefore, the processing flow of the related art cannot be implemented on a large scale.
  • the embodiment of the invention provides an authentication authentication method and system for accessing an isolated network, which can avoid the problem that the method of specifying an authentication key in the AMF domain of the authentication vector cannot be implemented on a large scale.
  • An embodiment of the present invention provides an authentication and authentication method for accessing an isolated network, which is applied to a universal integrated circuit card installed in a terminal, and includes: a universal integrated circuit card receives a network identifier of an isolated network from a terminal, or receives a basis from the terminal.
  • the universal integrated circuit card refers to the corresponding identifier of the network identifier or the network identifier, and refers to the correspondence between the pre-configured network identifier and the authentication key to obtain the The authentication key corresponding to the network identifier of the isolated network, wherein the correspondence between the network identifier pre-configured by the universal integrated circuit card and the authentication key and the network identifier and authentication secret pre-configured by the base station including the local core network
  • the correspondence of the keys is the same.
  • the method further includes: determining, by the universal integrated circuit card, the response value RES according to the obtained authentication key, and providing the terminal.
  • the corresponding relationship between the pre-configured network identifier and the authentication key includes:
  • the associated parameters include:
  • the embodiment of the present invention further provides an authentication and authentication method for accessing an isolated network, which is applied to a terminal for installing a universal integrated circuit card, and includes: the terminal sending the detected network identifier of the isolated network to the universal integrated circuit card or according to the The network identifier of the isolated network determines an association parameter; the terminal receives a response value RES determined by the universal integrated circuit card according to an authentication key corresponding to the network identifier; the terminal sends the response value RES to include local Base station of the core network.
  • the corresponding relationship between the network identifier and the authentication key includes:
  • the method further includes: the terminal acquiring the network identifier from the universal integrated circuit card and associating the authentication key
  • the parameter is associated with the indirect correspondence, and the corresponding relationship between the network identifier and the associated parameter is obtained and stored according to the indirect correspondence.
  • the associated parameters include:
  • the embodiment of the present invention further provides an authentication and authentication method for accessing an isolated network, including: a base station including a local core network that is switched to an isolated network mode, according to a network identifier of an isolated network, referring to a pre-configured network identifier and an authentication key. Corresponding relationship, determining an authentication key corresponding to the network identifier of the isolated network, and generating an expected response value XRES, wherein the mapping between the network identifier pre-configured by the base station of the local core network and the authentication key and the universal integration
  • the network card pre-configured network identifier has the same correspondence with the authentication key; the base station authenticates the response value RES returned by the terminal according to the expected response value XRES.
  • the corresponding relationship between the pre-configured network identifier and the authentication key includes:
  • the associated parameters include:
  • the determining, by the base station, the response value RES returned by the terminal according to the predicted response value XRES includes: when the predicted response value XRES is equal to the response value RES returned by the terminal, the terminal passes the authentication.
  • the embodiment of the present invention further provides an authentication and authentication system for accessing an isolated network, which is applied to a universal integrated circuit card installed in the terminal, and includes: a receiving module, configured to receive a network identifier of the isolated network from the terminal, or receive from the terminal Corresponding parameter determined according to the network identifier of the isolated network; the processing module is configured to refer to the corresponding relationship between the pre-configured network identifier and the authentication key according to the network identifier or the associated parameter that has a corresponding relationship with the network identifier Obtaining an authentication key corresponding to the network identifier of the isolated network, where the correspondence between the pre-configured network identifier and the authentication key and the network identifier and the authentication key pre-configured by the base station including the local core network The correspondence is the same.
  • the system further includes: a storage module, configured to store a correspondence between the pre-configured network identifier and the authentication key.
  • the corresponding relationship between the pre-configured network identifier and the authentication key includes:
  • the processing module is further configured to determine, according to the obtained authentication key, a response value RES, which is provided to the terminal.
  • the associated parameters include:
  • the embodiment of the present invention further provides an authentication and authentication system for accessing an isolated network, which is applied to a terminal for installing a universal integrated circuit card, and includes: a first sending module, configured to send the detected isolated network to the universal integrated circuit card. a network identifier or an association parameter determined according to the network identifier of the isolated network; the receiving module is configured to receive a response value RES determined by the universal integrated circuit card according to an authentication key corresponding to the network identifier; and a second sending module, It is arranged to send the response value RES to a base station comprising a local core network.
  • the corresponding relationship between the pre-configured network identifier and the authentication key includes:
  • the system further includes: a storage module, configured to obtain, from the universal integrated circuit card, an indirect correspondence between the network identifier and the authentication key through association parameters, and obtain and store the network identifier according to the indirect correspondence Correspondence with associated parameters.
  • a storage module configured to obtain, from the universal integrated circuit card, an indirect correspondence between the network identifier and the authentication key through association parameters, and obtain and store the network identifier according to the indirect correspondence Correspondence with associated parameters.
  • the associated parameters include:
  • the embodiment of the present invention further provides an authentication and authentication system for accessing an isolated network, including: a processing module, configured to determine, according to a network identifier of an isolated network, a reference to a correspondence between a pre-configured network identifier and an authentication key, The network identifier of the isolated network identifies the corresponding authentication key, and generates an expected response value XRES, wherein the correspondence between the pre-configured network identifier and the authentication key and the network identifier and authentication secret pre-configured by the universal integrated circuit card The correspondences of the keys are the same; the authentication module is configured to authenticate the response value RES returned by the terminal according to the expected response value XRES.
  • the system further includes: a storage module, configured to store a correspondence between the pre-configured network identifier and the authentication key.
  • the corresponding relationship between the pre-configured network identifier and the authentication key includes:
  • the associated parameters include:
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • the universal integrated circuit card receives the network identifier of the isolated network from the terminal, Or the associated parameter determined by the network identifier of the isolated network; the universal integrated circuit card obtains the authentication key corresponding to the network identifier of the isolated network by referring to the correspondence between the pre-configured network identifier and the authentication key according to the network identifier or the associated parameter.
  • the correspondence between the network identifier pre-configured by the universal integrated circuit card and the authentication key is the same as the correspondence between the network identifier pre-configured by the base station including the local core network and the authentication key.
  • the embodiment of the present invention avoids the problem that the AMF domain specifying the authentication key in the related art uses the authentication vector.
  • embodiments of the present invention can achieve large scale implementation.
  • FIG. 1 is a schematic diagram of a network architecture of a related EPC
  • FIG. 2 is a flowchart of a terminal accessing an isolated network authentication authentication in the related art
  • FIG. 3 is a flowchart of an authentication and authentication method for accessing an isolated network according to an embodiment of the present invention
  • FIG. 4 is a flowchart of an authentication and authentication method for accessing an isolated network according to an embodiment of the present invention
  • FIG. 5 is a flowchart of an authentication and authentication method for accessing an isolated network according to an embodiment of the present invention
  • FIG. 6 is a flowchart of an authentication and authentication method for accessing an isolated network according to Embodiment 1 of the present invention.
  • FIG. 7 is a flowchart of an authentication and authentication method for accessing an isolated network according to Embodiment 2 of the present invention.
  • FIG. 8 is a flowchart of an authentication and authentication method for accessing an isolated network according to Embodiment 3 of the present invention.
  • FIG. 9 is a schematic diagram of a component module of an authentication and authentication system applied to an isolated network installed in a universal integrated circuit card installed in a terminal according to an embodiment of the present disclosure
  • FIG. 10 is a structural diagram of a component of an authentication and authentication system for accessing an isolated network in a terminal for installing a universal integrated circuit card according to an embodiment of the present invention.
  • FIG. 3 is a flowchart of an authentication and authentication method for accessing an isolated network according to an embodiment of the present invention. As shown in FIG. 3, the authentication and authentication method for accessing an isolated network provided in this embodiment is applied to the installation end.
  • the universal integrated circuit card of the end includes the following steps:
  • Step 11 The universal integrated circuit card receives the network identifier of the isolated network from the terminal, or receives the associated parameter according to the network identifier of the isolated network from the terminal.
  • the associated parameters include:
  • Step 12 The universal integrated circuit card obtains the authentication corresponding to the network identifier of the isolated network by referring to the corresponding relationship between the network identifier and the authentication key according to the network identifier or the associated parameter that has a corresponding relationship with the network identifier. Key.
  • the corresponding relationship between the network identifier pre-configured by the universal integrated circuit card and the authentication key includes:
  • the correspondence between the network identifier pre-configured by the universal integrated circuit card and the authentication key is the same as the correspondence between the network identifier pre-configured by the base station including the local core network and the authentication key.
  • the base station including the local core network may pre-configure the direct or indirect correspondence between the network identifier and the authentication key.
  • the universal integrated circuit card refers to the authentication key determined by the pre-configured correspondence relationship according to the network identifier of the isolated network or the corresponding associated parameter
  • the base station including the local core network refers to the pre-predetermined network according to the network identifier of the isolated network.
  • the authentication key determined by the configured correspondence relationship may be the same.
  • the method further includes: determining, by the universal integrated circuit card, the response value RES according to the obtained authentication key, and providing the response value to the terminal.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • FIG. 4 is a flowchart of an authentication and authentication method for accessing an isolated network according to an embodiment of the present invention. As shown in FIG. 4, the authentication and authentication method for accessing an isolated network provided in this embodiment is applied to a terminal for installing a universal integrated circuit card, and includes the following steps:
  • Step 21 The terminal sends the detected network identifier of the isolated network to the universal integrated circuit card or the associated parameter determined according to the network identifier of the isolated network.
  • the associated parameters include:
  • the method further includes: obtaining, by the terminal from the universal integrated circuit card, an indirect correspondence between the network identifier and the authentication key through association parameters, and acquiring and storing the correspondence between the network identifier and the associated parameter according to the indirect correspondence relationship.
  • the universal integrated circuit card is pre-configured with a correspondence between a network identifier and an authentication key, and the corresponding relationship includes:
  • the correspondence between the network identifier pre-configured by the universal integrated circuit card and the authentication key is the same as the correspondence between the network identifier pre-configured by the base station including the local core network and the authentication key.
  • the base station including the local core network can pre-configure the direct or indirect correspondence between the network identifier and the authentication key.
  • the base station including the local core network refers to the pre-configured according to the network identifier of the isolated network.
  • the authentication keys determined by the correspondence relationship may be identical.
  • Step 22 The terminal receives the response value RES determined by the universal integrated circuit card.
  • the response value RES is determined by the universal integrated circuit card according to the network identifier or the associated parameter, and the corresponding relationship between the pre-configured network identifier and the authentication key is obtained, and the authentication key corresponding to the obtained network identifier of the isolated network is determined. .
  • Step 23 The terminal sends the response value RES to the base station including the local core network.
  • the base station that includes the local core network that is switched to the isolated network mode refers to the network identifier of the isolated network, refers to the correspondence between the pre-configured network identifier and the authentication key in the base station, or determines the corresponding identifier of the network identifier of the isolated network.
  • a weight key and an expected response value XRES is generated based on the authentication key. When the response value RES is equal to the expected response value XRES, the terminal passes the authentication and accesses Isolated network.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • FIG. 5 is a flowchart of an authentication and authentication method for an access authentication network according to an embodiment of the present invention. As shown in FIG. 5, the authentication and authentication method for the access authentication network provided by this embodiment includes the following steps:
  • Step 31 The base station including the local core network that is switched to the isolated network mode determines the authentication key corresponding to the network identifier of the isolated network according to the network identifier of the isolated network and the corresponding relationship between the pre-configured network identifier and the authentication key. And generate the expected response value XRES.
  • the associated parameters include:
  • the mapping between the network identifier of the local core network and the authentication key is performed by the base station, and the corresponding relationship includes:
  • the correspondence between the network identifier pre-configured by the base station including the local core network and the authentication key is the same as the correspondence between the network identifier pre-configured by the universal integrated circuit card and the authentication key.
  • the universal integrated circuit card may pre-configure the direct or indirect correspondence between the network identifier and the authentication key.
  • the universal integrated circuit card refers to the authentication key determined by the pre-configured correspondence relationship according to the network identifier of the isolated network or the corresponding associated parameter
  • the base station including the local core network refers to the pre-predetermined network according to the network identifier of the isolated network.
  • the authentication key determined by the configured correspondence relationship may be the same.
  • Step 32 The base station authenticates the response value RES returned by the terminal according to the expected response value XRES.
  • the terminal accesses the isolated network by using the authentication.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • FIG. 6 is a flowchart of an authentication and authentication method for accessing an isolated network according to Embodiment 1 of the present invention.
  • the terminal does not store the correspondence between the network identifier and the authentication key index value, and directly transmits the network identifier of the isolated network to the universal integrated circuit card.
  • the embodiment specifically includes the following steps:
  • Step 301 The universal integrated circuit card and the base station including the local core network pre-configure the authentication key Ki of the isolated network and its corresponding network identifier list.
  • the universal integrated circuit card for example, the pre-configured network identifier and the authentication key
  • the indirect correspondence of the association by the authentication key index value including the indirect correspondence of the base station of the local core network, for example, the pre-configured network identifier and the authentication key by the authentication key index value, or the network identifier and the authentication secret Direct correspondence of keys;
  • the universal integrated circuit card saves the list in an element file (EF, Elementary File), for example, can be saved in the EF OPLMNwACT file, and the format is as shown in Table 1.
  • EF Elementary File
  • the authentication key index value corresponds to the network identifier (N th PLMN).
  • N th PLMN the network identifier
  • the universal integrated circuit card saves the authentication key in the secure storage area, only the authentication key index value is saved in the EF.
  • the universal integrated circuit card can also store a direct correspondence list of network identifications and authentication keys.
  • the base station including the local core network saves the authentication key Ki of the isolated network and its corresponding network identifier list in the database.
  • the base station including the local core network can store, for example, an authentication key and an authentication secret.
  • a relationship list of the key index values and a correspondence list of the authentication key index values and the network identifiers; or, a direct correspondence list of the network identifiers and the authentication keys may be stored.
  • Step 302 The connection between the base station and the core network is interrupted, and the mode is switched to the isolated network mode.
  • Step 303 The base station broadcasts a network identifier of the isolated network.
  • Step 304 The terminal detects the network identifier of the isolated network.
  • Step 305 The terminal sends a network attach request message to the base station including the local core network, where the message includes a user identifier parameter.
  • Step 306 The base station including the local core network obtains the corresponding authentication key Ki and generates an AKA authentication vector according to the network identifier broadcasted in step 303 by referring to the list saved in step 301.
  • Step 307 The base station including the local core network sends an authentication request message to the terminal, where the message includes a random number and an authentication token (AUTN) parameter.
  • AUTN authentication token
  • Step 308 The terminal sends an authentication data request message to the universal integrated circuit card, where the message includes a random number, an authentication token, and a detected network identification parameter of the isolated network.
  • Step 309 The universal integrated circuit card refers to the list saved in step 301, obtains the corresponding authentication key index value according to the received network identification parameter, and obtains the authentication key Ki according to the authentication key index value. Weight token, and calculate response value RES and intermediate key K ASME ;
  • Step 310 The universal integrated circuit card returns an authentication data response message to the terminal, where the message carries an authentication response parameter, including a response value RES and an intermediate key K ASME parameter;
  • Step 311 The terminal estimates the NAS and AS service keys according to the intermediate key K ASME .
  • Step 312 The terminal sends back an authentication response message to the base station including the local core network, where the message includes a response value RES parameter.
  • Step 313 The base station including the local core network verifies whether the received response value RES is equal to the expected response value XRES, and if they are equal, the verification passes;
  • Step 314 Perform an SMC process between the base station and the terminal that includes the local core network to negotiate a security algorithm to complete the establishment of the secure connection.
  • Step 315 The base station including the local core network sends back a network attach accept message to the terminal.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • FIG. 7 is a flowchart of an authentication and authentication method for accessing an isolated network according to Embodiment 2 of the present invention.
  • the terminal stores the correspondence between the network identifier and the authentication key index value, and transmits the authentication key index value determined according to the network identifier of the isolated network to the universal integrated circuit card.
  • the embodiment specifically includes the following steps:
  • Step 401 The universal integrated circuit card and the base station including the local core network pre-configure the authentication key Ki of the isolated network and the corresponding network identifier list.
  • the universal integrated circuit card and the base station pre-configured network identifier including the local core network An indirect correspondence relationship with the authentication key through the authentication key index value;
  • the universal integrated circuit card saves the list in an EF file, for example, it can be saved in the EF OPLMNwACT file, and the format is as shown in Table 2.
  • the base station including the local core network stores, for example, the authentication key Ki of the isolated network and its corresponding authentication key index value list, the network identifier, and its corresponding authentication key index value list in the database.
  • Step 402 The terminal reads the EF file on the universal integrated circuit card, and stores the network identifier and a list of corresponding authentication key index values.
  • Step 403 The connection between the base station and the core network is interrupted, and the mode is switched to the isolated network mode.
  • Step 404 The base station broadcasts a network identifier of the isolated network.
  • Step 405 The terminal detects the network identifier of the isolated network.
  • Step 406 The terminal sends a network attach request message to the base station including the local core network, where the message includes a user identifier parameter.
  • Step 407 The base station including the local core network obtains the corresponding authentication key Ki and generates an AKA authentication vector according to the network identifier broadcasted in step 404 by referring to the list saved in step 401.
  • Step 408 The base station including the local core network sends an authentication request message to the terminal, where the message includes a random number and an authentication token (AUTN) parameter.
  • AUTN authentication token
  • Step 409 The terminal obtains the corresponding authentication key index value by referring to the network identifier stored in step 402 and the corresponding authentication key index value list according to the network identifier detected in step 405;
  • the card sends an authentication data request message, where the message includes a random number, an authentication token, and an authentication key index value parameter;
  • Step 410 The universal integrated circuit card refers to the list saved in step 401 according to the received authentication key index value parameter, acquires the corresponding authentication key Ki, verifies the authentication token, and calculates the response value RES and Intermediate key K ASME ;
  • Step 411 The universal integrated circuit card returns an authentication data response message to the terminal, where the message includes a response value RES and an intermediate key K ASME parameter;
  • Step 412 The terminal estimates the NAS and AS service keys according to the intermediate key K ASME .
  • Step 413 The terminal sends back an authentication response message to the base station including the local core network, where the message includes a response value RES parameter.
  • Step 414 The base station including the local core network verifies whether the received response value RES is equal to the expected response value XRES, and if they are equal, the verification passes;
  • Step 415 Perform an SMC process between the base station and the terminal that includes the local core network to negotiate a security algorithm to complete establishment of a secure connection.
  • Step 416 The base station including the local core network sends back a network attach accept message to the terminal.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • FIG. 8 is a flowchart of an authentication and authentication method for accessing an isolated network according to Embodiment 3 of the present invention.
  • the terminal stores the correspondence between the network identifier and the network mode indicator parameter, and transmits the network mode indicator parameter determined according to the network identifier of the isolated network to the general-purpose integrated circuit. card.
  • This embodiment applies to the case where all ordinary networks use the same authentication key and all isolated networks use the same authentication key.
  • the embodiment specifically includes the following steps:
  • Step 501 The universal integrated circuit card and the base station including the local core network pre-configure the network identifier and the corresponding network mode list; wherein the network mode includes, for example, a normal network mode and an isolated network mode; and the common network mode is configured with a common network authentication key.
  • the isolated network mode is configured with an isolated network authentication key.
  • the universal integrated circuit card and the base station pre-configured network identifier including the local core network and the indirect correspondence relationship between the authentication key and the authentication mode key are configured by the network mode indicator parameter;
  • the universal integrated circuit card saves the list in an EF file, for example, it can be saved in the EF OPLMNwACT file, and the format is as shown in Table 3.
  • the network mode indicator (Mode Indicator) has a correspondence with the network identifier (N th PLMN).
  • N th PLMN When the network is a normal network, its Mode Indicator value is 0; when the network is an isolated network, its Mode Indicator value is 1.
  • the common network configuration has a corresponding common network authentication key, and the isolated network is configured with a corresponding isolated network authentication key. That is, the association between the network identifier and the authentication key is implemented by the network mode indicator parameter.
  • the base station including the local core network stores, for example, a network identifier and its corresponding network mode indicator parameter list, network mode indicator parameters, and their corresponding authentication key lists in a database.
  • Step 502 The terminal reads the EF file on the universal integrated circuit card, and stores a network identifier and a corresponding list of network mode indicators.
  • Step 503 The connection between the base station and the core network is interrupted, and the mode is switched to the isolated network mode.
  • Step 504 The base station broadcasts a network identifier of the isolated network.
  • Step 505 The terminal detects the network identifier of the isolated network.
  • Step 506 The terminal sends a network attach request message to the base station including the local core network, where the message includes a user identifier parameter.
  • Step 507 The local core network obtains the corresponding network mode indicator parameter according to the network identifier broadcasted in step 504, and refers to the list saved in step 501, and obtains the corresponding authentication key Ki to generate the AKA authentication. vector;
  • Step 508 The base station including the local core network sends an authentication request message to the terminal, where the message includes a random number and an authentication token (AUTN) parameter.
  • AUTN authentication token
  • Step 509 The terminal acquires a corresponding network mode indicator parameter according to the network identifier detected in step 505 by referring to the list stored in step 502; the terminal sends an authentication data request message to the universal integrated circuit card, the message Include random numbers, authentication tokens, and network mode indicator parameters;
  • Step 510 The universal integrated circuit card refers to the list saved in step 501 according to the received network mode indicator parameter, obtains the corresponding authentication key Ki, verifies the authentication token, and calculates the response value RES and the intermediate density.
  • Key K ASME the universal integrated circuit card refers to the list saved in step 501 according to the received network mode indicator parameter, obtains the corresponding authentication key Ki, verifies the authentication token, and calculates the response value RES and the intermediate density.
  • Key K ASME Key
  • Step 511 The universal integrated circuit card sends a response data response message to the terminal, and the message includes a response value RES and an intermediate key K ASME parameter.
  • Step 512 The terminal estimates the NAS and AS service keys according to the intermediate key K ASME .
  • Step 513 The terminal sends back an authentication response message to the base station including the local core network, where the message includes a response value RES parameter.
  • Step 514 The base station including the local core network verifies whether the received response value RES is equal to the expected response value XRES, and if they are equal, the verification passes;
  • Step 515 Perform an SMC process between the base station and the terminal that includes the local core network to negotiate a security algorithm to complete the establishment of the secure connection.
  • Step 516 The base station including the local core network sends back a network attach accept message to the terminal.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the above method.
  • the embodiment of the present invention further provides an authentication and authentication system for accessing an isolated network, which is applied to a universal integrated circuit card installed in a terminal, as shown in FIG. 9, comprising: a receiving module, configured to receive an isolated network from the terminal.
  • the network identifier, or the association parameter determined according to the network identifier of the isolated network is received from the terminal;
  • the processing module is configured to refer to the correspondence between the pre-configured network identifier and the authentication key according to the network identifier or the associated parameter a relationship, the authentication key corresponding to the network identifier of the isolated network, where the correspondence between the pre-configured network identifier and the authentication key and the pre-configured network identifier and authentication secret of the base station including the local core network
  • the correspondence of the keys is the same.
  • system further includes: a storage module, configured to store a correspondence between the pre-configured network identifier and the authentication key.
  • the processing module is further configured to determine the response value RES according to the obtained authentication key, and provide the data to the terminal.
  • the correspondence between the pre-configured network identifier and the authentication key includes:
  • the associated parameters include:
  • the embodiment of the present invention further provides an authentication and authentication system for accessing an isolated network, which is applied to a terminal for installing a universal integrated circuit card, as shown in FIG. 10, including: a first sending module, configured to be a general-purpose integrated circuit The card sends the detected network identifier of the isolated network or the associated parameter determined according to the network identifier of the isolated network; the receiving module is configured to receive the response value RES determined by the universal integrated circuit card, wherein the response value RES is The universal integrated circuit card determines, according to the network identifier or the associated parameter, the authentication key corresponding to the network identifier of the isolated network obtained by referring to the correspondence between the pre-configured network identifier and the authentication key, Corresponding relationship between the pre-configured network identifier and the authentication key is the same as the corresponding relationship between the network identifier of the base station including the local core network and the authentication key; the second sending module is configured to send the response value RES to A base station including a local core network.
  • a first sending module configured
  • the correspondence between the pre-configured network identifier and the authentication key includes:
  • system further includes: a storage module, configured to acquire, from the universal integrated circuit card, an indirect correspondence between the network identifier and the authentication key through association parameters, and obtain and store the network identifier according to the indirect correspondence Correspondence with associated parameters.
  • a storage module configured to acquire, from the universal integrated circuit card, an indirect correspondence between the network identifier and the authentication key through association parameters, and obtain and store the network identifier according to the indirect correspondence Correspondence with associated parameters.
  • the associated parameters include:
  • the embodiment of the present invention further provides an authentication and authentication system for accessing an isolated network, including: a processing module, configured to determine, according to a network identifier of an isolated network, a reference to a correspondence between a pre-configured network identifier and an authentication key.
  • the network identifier of the isolated network identifies the corresponding authentication key, and generates an expected response value XRES, wherein the correspondence between the pre-configured network identifier and the authentication key and the pre-configured network identifier and the common integrated circuit card
  • the correspondences of the weight keys are the same;
  • the authentication module is configured to authenticate the response value RES returned by the terminal according to the expected response value XRES.
  • system further includes: a storage module, configured to store a correspondence between the pre-configured network identifier and the authentication key.
  • the correspondence between the pre-configured network identifier and the authentication key includes:
  • the associated parameters include:
  • each module/unit in the above embodiment may be implemented in the form of hardware, for example, by implementing an integrated circuit to implement its corresponding function, or may be implemented in the form of a software function module, for example, executing a program stored in the memory by a processor. / instruction to achieve its corresponding function.
  • the invention is not limited to any specific form of combination of hardware and software.
  • the above technical solution avoids the problem that the AMF domain specifying the authentication key in the related art uses the authentication vector. Moreover, the above technical solution can achieve large-scale implementation.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种接入孤立网络的鉴权认证方法及系统,包括:通用集成电路卡从终端接收孤立网络的网络标识,或者根据孤立网络的网络标识确定的关联参数;通用集成电路卡根据网络标识或关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取孤立网络的网络标识对应的鉴权密钥,其中,通用集成电路卡预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系。上述技术方案能够解决相关技术中使用鉴权向量的AMF域指定鉴权密钥的方式无法大规模实施的问题。

Description

一种接入孤立网络的鉴权认证方法及系统 技术领域
本文涉及但不限于移动通信领域,尤其涉及一种接入孤立网络的鉴权认证方法及系统。
背景技术
为了保持第三代移动通信系统在通信领域的竞争力,为用户提供速率更快、时延更低、更加个性化的移动通信服务,同时,降低运营商的运营成本,第三代合作伙伴计划(3GPP,3rd Generation Partnership Project)标准工作组正致力于演进分组系统(EPS,Evolved Packet System)的研究。
图1为相关技术中演进的分组核心网(EPC,Evolved Packet Core)的网络架构示意图。如图1所示,在EPC中,包含了归属用户数据服务器(HSS,Home Subscriber Server)、移动性管理实体(MME,Mobility Management Entity)、服务网关(S-GW,Serving Gateway)、分组数据网络网关(P-GW,PDN Gateway)、服务GPRS支持节点(SGSN,Serving GPRS Support Node)以及策略与计费规则功能实体(PCRF,Policy and Charging Rules Function)。
其中,HSS设置为用户签约数据的永久存放地点,位于用户签约的归属网;MME设置为用户签约数据在当前网络的存放地点,负责终端到网络的非接入层(Non-Access Stratum)信令管理、用户空闲模式下的跟踪和寻呼管理功能和承载管理;S-GW设置为核心网到无线系统的网关,负责终端到核心网的用户面承载、终端空闲模式下的数据缓存、网络侧发起业务请求的功能、合法窃听和分组数据路由和转发功能;P-GW设置为演进分组系统和该系统外部网络的网关,负责终端的网络协议(IP,Internet Protocol)地址分配、计费功能、分组包过滤、策略应用等功能;SGSN设置为全球移动通信系统(GSM,Global System for Mobile Communication)和/或增强型数据速率GSM演进(EDGE,Enhanced Data Rate for GSM Evolution)无线接入网(GERAN,GSM EDGE Radio Access Network)和通用陆地无线接入网络 (UTRAN,Universal Terrestrial Radio Access Network)用户接入EPC网络的业务支持点,功能上与MME类似,负责用户的位置更新、寻呼管理和承载管理等功能;PCRF设置为负责向策略与计费执行功能实体(PCEF,Policy and Charging Enforcement Function)提供策略控制与计费规则。
其中,Iu为无线网络控制器与SGSN之间的接口,Gr为SGSN与HSS之间的接口,S1-MME为基站与MME之间的接口,S1-U为基站与S-GW之间的接口,S3为MME与SGSN之间的接口,S4为SGSN与S-GW之间的接口,S5为S-GW与P-GW之间的接口,S6a为MME与HSS之间的接口,S7为P-GW与PCRF之间的接口,S10为MME之间的接口,S11为MME与S-GW之间的接口,SGi为P-GW与分组数据网络之间的接口,Rx为PCRF与分组数据网络之间的参考点接口。
在一些应急情况下,基站可能与核心网断开连接或者保持有限的连接(即控制面的消息传递可以保证,但是用户面数据的传递可能无法保证),此时,需要快速建立一个应急通信的网络,以保证在特殊情况下为网络中部分特殊用户(例如跟国家公共安全相关的人员)提供特殊的业务。应急通信的网络,又称为孤立网络,采用的网络架构与相关技术本来的架构并无不同,只是基站可能转变为具有公共安全能力的基站,即具有部分演进分组核心网的功能,也即多个逻辑功能实体集成在一个或者几个实体公共安全基站中。
由于公共安全基站进入了公共安全模式,如果公共终端需要接入公共安全基站进行公共安全业务,则公共安全基站和公共安全终端需要相互认证。相关技术使用扩展的全球用户身份模块(USIM,Universal Subscriber Identity Module)应用,即在同一个USIM应用中包括一个国际移动用户识别码(IMSI,International Mobile Subscriber Identification Number)和多个鉴权密钥Ki。本地核心网通过在鉴权请求消息中携带鉴权密钥Ki的索引值的方式,向通用集成电路卡(UICC,Universal Integrated Circuit Card)指定使用的鉴权密钥。
图2为相关技术中终端接入孤立网络鉴权认证的流程图。如图2所示,该过程包括以下步骤:
步骤201:通用集成电路卡和包括本地核心网的基站预配置孤立网络鉴权密钥(Ki)列表;
步骤202:基站与核心网的连接中断,切换到孤立网络模式;
步骤203:基站广播孤立网络的网络标识;
步骤204:终端检测到该孤立网络的网络标识;
步骤205:终端向包括本地核心网的基站发送网络附着请求消息,其中,该消息中包括用户标识参数;
步骤206:包括本地核心网的基站随机选择孤立网络鉴权密钥Ki,将Ki的索引值加入认证管理功能(AMF,Authentication Management Function)域中,并生成认证与密钥协商协议(AKA,Authentication and Key Agreement)鉴权向量;
步骤207:包括本地核心网的基站向终端发送鉴权请求消息,该消息中包括随机数和鉴权令牌(AUTN,Authentication Token)参数,其中,鉴权令牌参数包括AMF域;
步骤208:终端向通用集成电路卡发送鉴权数据请求消息,该消息中包括随机数和鉴权令牌参数,其中,鉴权令牌参数包括AMF域;
步骤209:通用集成电路卡根据AMF域中的鉴权密钥索引值获取鉴权密钥Ki,验证鉴权令牌,并计算响应值(RES)和中间密钥(KASME);
步骤210:通用集成电路卡向终端回送鉴权数据响应消息,该消息中包括响应值RES和中间密钥KASME参数;
步骤211:终端根据中间密钥KASME推算非接入层(NAS)和接入层(AS,Access Stratum)业务密钥;
步骤212:终端向包括本地核心网的基站回送鉴权响应消息,该消息中包括响应值RES;
步骤213:包括本地核心网的基站验证接收到的响应值RES是否跟预计响应值XRES相等,如果相等则验证通过;
步骤214:包括本地核心网的基站与终端之间执行安全模式命令(SMC,Safe Mode Command)过程,以协商安全算法,完成安全连接的建立;
步骤215:包括本地核心网的基站向终端回送网络附着接受消息。
其中,上述流程使用鉴权向量中的AMF域来指定使用的鉴权密钥,这就要求所有的运营商和终端对AMF域的使用遵循同样的标准。但是,目前对AMF域的使用是没有被标准化的。而且,在现网中,不同的运营商对AMF域已经有了不同的使用,也很难进行标准化。因此,相关技术的处理流程无法大规模实施。
发明内容
以下是对本文详细描述的主题的概述。本概述并非是为了限制权利要求的保护范围。
本发明实施例提供一种接入孤立网络的鉴权认证方法及系统,可避免使用鉴权向量的AMF域指定鉴权密钥的方式无法大规模实施的问题。
本发明实施例提供一种接入孤立网络的鉴权认证方法,应用于安装在终端的通用集成电路卡中,包括:通用集成电路卡从终端接收孤立网络的网络标识,或者从终端接收根据所述孤立网络的网络标识确定的关联参数;通用集成电路卡根据所述网络标识或所述与网络标识存在对应关系的关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取所述孤立网络的网络标识对应的鉴权密钥,其中,所述通用集成电路卡预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。
可选地,所述获取所述孤立网络的网络标识对应的鉴权密钥之后,该方法还包括:所述通用集成电路卡根据获取的鉴权密钥,确定响应值RES,提供给所述终端。
可选地,所述预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
可选地,所述关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
本发明实施例还提供一种接入孤立网络的鉴权认证方法,应用于安装通用集成电路卡的终端中,包括:终端向通用集成电路卡发送检测到的孤立网络的网络标识或者根据所述孤立网络的网络标识确定的关联参数;所述终端接收由所述通用集成电路卡根据与网络标识对应的鉴权密钥确定的响应值RES;所述终端将所述响应值RES发送至包括本地核心网的基站。
可选地,所述网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
可选地,所述终端向通用集成电路卡发送根据孤立网络的网络标识确定的关联参数之前,该方法还包括:所述终端从所述通用集成电路卡获取网络标识与鉴权密钥通过关联参数进行关联的间接对应关系,根据所述间接对应关系获取并存储网络标识与关联参数的对应关系。
可选地,所述关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
本发明实施例还提供一种接入孤立网络的鉴权认证方法,包括:切换为孤立网络模式的包括本地核心网的基站根据孤立网络的网络标识,参照预配置的网络标识与鉴权密钥的对应关系,确定所述孤立网络的网络标识对应的鉴权密钥,并生成预计响应值XRES,其中,包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系与通用集成电路卡预配置的网络标识与鉴权密钥的对应关系相同;所述基站根据所述预计响应值XRES对终端返回的响应值RES进行认证。
可选地,所述预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
可选地,所述关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
可选地,所述基站根据所述预计响应值XRES对终端返回的响应值RES进行认证包括:当所述预计响应值XRES与终端返回的响应值RES相等时,所述终端通过认证。
本发明实施例还提供一种接入孤立网络的鉴权认证系统,应用于安装在终端的通用集成电路卡中,包括:接收模块,设置为从终端接收孤立网络的网络标识,或者从终端接收根据所述孤立网络的网络标识确定的关联参数;处理模块,设置为根据所述网络标识或所述与网络标识存在对应关系的关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取所述孤立网络的网络标识对应的鉴权密钥,其中,所述预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。
可选地,该系统还包括:存储模块,设置为存储预配置的网络标识与鉴权密钥的对应关系。
可选地,所述预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
可选地,所述处理模块,还设置为根据获取的鉴权密钥,确定响应值RES,提供给所述终端。
可选地,所述关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
本发明实施例还提供一种接入孤立网络的鉴权认证系统,应用于安装通用集成电路卡的终端中,包括:第一发送模块,设置为向通用集成电路卡发送检测到的孤立网络的网络标识或者根据所述孤立网络的网络标识确定的关联参数;接收模块,设置为接收由所述通用集成电路卡根据与网络标识对应的鉴权密钥确定的响应值RES;第二发送模块,设置为将所述响应值RES发送至包括本地核心网的基站。
可选地,所述预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
可选地,该系统还包括:存储模块,设置为从所述通用集成电路卡获取网络标识与鉴权密钥通过关联参数进行关联的间接对应关系,根据所述间接对应关系获取并存储网络标识与关联参数的对应关系。
可选地,所述关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
本发明实施例还提供一种接入孤立网络的鉴权认证系统,包括:处理模块,设置为根据孤立网络的网络标识,参照预配置的网络标识与鉴权密钥的对应关系,确定所述孤立网络的网络标识对应的鉴权密钥,并生成预计响应值XRES,其中,所述预配置的网络标识与鉴权密钥的对应关系与通用集成电路卡预配置的网络标识与鉴权密钥的对应关系相同;认证模块,设置为根据所述预计响应值XRES对终端返回的响应值RES进行认证。
可选地,该系统还包括:存储模块,设置为存储预配置的网络标识与鉴权密钥的对应关系。
可选地,所述预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
可选地,所述关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
在本发明实施例中,通用集成电路卡从终端接收孤立网络的网络标识, 或者根据孤立网络的网络标识确定的关联参数;通用集成电路卡根据网络标识或关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取孤立网络的网络标识对应的鉴权密钥,其中,通用集成电路卡预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。如此,本发明实施例避免了相关技术中使用鉴权向量的AMF域指定鉴权密钥存在的问题。而且,本发明实施例可以实现大规模实施。
在阅读并理解了附图和详细描述后,可以明白其他方面。
附图概述
图1为相关EPC的网络架构示意图;
图2为相关技术中终端接入孤立网络鉴权认证的流程图;
图3为本发明实施例提供的接入孤立网络的鉴权认证方法的流程图;
图4为本发明实施例提供的接入孤立网络的鉴权认证方法的流程图;
图5为本发明实施例提供的接入孤立网络的鉴权认证方法的流程图;
图6为本发明实施例一提供的接入孤立网络的鉴权认证方法的流程图;
图7为本发明实施例二提供的接入孤立网络的鉴权认证方法的流程图;
图8为本发明实施例三提供的接入孤立网络的鉴权认证方法的流程图;
图9为本发明实施例提供的一种应用于安装在终端的通用集成电路卡中的接入孤立网络的鉴权认证系统组成模块图;
图10为本发明实施例提供的一种应用于安装通用集成电路卡的终端中的接入孤立网络的鉴权认证系统组成模块图。
本发明的实施方式
以下结合附图对本发明的实施例进行详细说明,应当理解,以下所说明的实施例仅用于说明和解释本发明,并不用于限定本发明。
图3为本发明实施例提供的接入孤立网络的鉴权认证方法的流程图。如图3所示,本实施例提供的接入孤立网络的鉴权认证方法,应用于安装在终 端的通用集成电路卡中,包括以下步骤:
步骤11:通用集成电路卡从终端接收孤立网络的网络标识,或者从终端接收根据所述孤立网络的网络标识确定关联参数。
其中,关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
步骤12:通用集成电路卡根据所述网络标识或所述与网络标识存在对应关系的关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取孤立网络的网络标识对应的鉴权密钥。
其中,通用集成电路卡预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
而且,通用集成电路卡预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。可选的,当通用集成电路卡预配置网络标识与鉴权密钥的直接对应关系或间接对应关系时,包括本地核心网的基站可预配置网络标识与鉴权密钥的直接或间接对应关系,仅需满足,通用集成电路卡根据孤立网络的网络标识或相应的关联参数参照其预配置的对应关系确定的鉴权密钥,与包括本地核心网的基站根据孤立网络的网络标识参照其预配置的对应关系确定的鉴权密钥一致即可。
于步骤12之后,该方法还包括:通用集成电路卡根据获取的鉴权密钥,确定响应值RES,提供给终端。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
图4为本发明实施例提供的接入孤立网络的鉴权认证方法的流程图。如图4所示,本实施例提供的接入孤立网络的鉴权认证方法,应用于安装通用集成电路卡的终端中,包括以下步骤:
步骤21:终端向通用集成电路卡发送检测到的孤立网络的网络标识或者根据孤立网络的网络标识确定的关联参数。
其中,关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
于步骤21之前,该方法还包括:终端从通用集成电路卡获取网络标识与鉴权密钥通过关联参数进行关联的间接对应关系,根据所述间接对应关系获取并存储网络标识与关联参数的对应关系。
其中,通用集成电路卡预配置有网络标识与鉴权密钥的对应关系,该对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
而且,通用集成电路卡预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。具体而言,当通用集成电路卡预配置网络标识与鉴权密钥的直接对应关系或间接对应关系时,包括本地核心网的基站可预配置网络标识与鉴权密钥的直接或间接对应关系,仅需满足通用集成电路卡根据孤立网络的网络标识或相应的关联参数参照其预配置的对应关系确定的鉴权密钥与包括本地核心网的基站根据孤立网络的网络标识参照其预配置的对应关系确定的鉴权密钥一致即可。
步骤22:终端接收由通用集成电路卡确定的响应值RES。
其中,响应值RES由通用集成电路卡根据所述网络标识或所述关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取的孤立网络的网络标识对应的鉴权密钥确定。
步骤23:终端将响应值RES发送至包括本地核心网的基站。
可选的,切换为孤立网络模式的包括本地核心网的基站根据孤立网络的网络标识,参照基站内预配置的网络标识与鉴权密钥的对应关系或,确定孤立网络的网络标识对应的鉴权密钥,并根据所述鉴权密钥生成预计响应值XRES。当响应值RES与预计响应值XRES相等时,则终端通过认证,接入 孤立网络。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
图5为本发明实施例提供的接入鉴权网络的鉴权认证方法的流程图。如图5所示,本实施例提供的接入鉴权网络的鉴权认证方法,包括以下步骤:
步骤31:切换为孤立网络模式的包括本地核心网的基站根据孤立网络的网络标识,参照预配置的网络标识与鉴权密钥的对应关系,确定孤立网络的网络标识对应的鉴权密钥,并生成预计响应值XRES。
其中,关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
其中,包括本地核心网的基站预配置网络标识与鉴权密钥的对应关系,该对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
而且,包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系与通用集成电路卡预配置的网络标识与鉴权密钥的对应关系相同。可选的,当包括本地核心网的基站预配置网络标识与鉴权密钥的直接对应关系或间接对应关系时,通用集成电路卡可预配置网络标识与鉴权密钥的直接或间接对应关系,仅需满足,通用集成电路卡根据孤立网络的网络标识或相应的关联参数参照其预配置的对应关系确定的鉴权密钥,与包括本地核心网的基站根据孤立网络的网络标识参照其预配置的对应关系确定的鉴权密钥一致即可。
步骤32:基站根据预计响应值XRES对终端返回的响应值RES进行认证。
可选的,当响应值RES与预计响应值XRES相等时,则终端通过认证,接入孤立网络。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
图6为本发明实施例一提供的接入孤立网络的鉴权认证方法的流程图。于本实施例中,终端不存储网络标识与鉴权密钥索引值的对应关系,直接将孤立网络的网络标识传递给通用集成电路卡。如图6所示,本实施例具体包括以下步骤:
步骤301:通用集成电路卡和包括本地核心网的基站,预配置孤立网络的鉴权密钥Ki及其对应的网络标识列表,于此,通用集成电路卡例如预配置网络标识与鉴权密钥通过鉴权密钥索引值进行关联的间接对应关系,包括本地核心网的基站例如预配置网络标识与鉴权密钥通过鉴权密钥索引值进行关联的间接对应关系或网络标识与鉴权密钥的直接对应关系;
可选的,通用集成电路卡将该列表保存在某个基本文件(EF,Elementary File)中,比如可以保存在EFOPLMNwACT文件中,格式如表1所示。
表1 EFOPLMNwACT文件格式
Figure PCTCN2016073807-appb-000001
Figure PCTCN2016073807-appb-000002
由表1可见,鉴权密钥索引值(Key Index)与网络标识(Nth PLMN)对应。可选的,由于通用集成电路卡将鉴权密钥保存在安全存储区中,因此,EF中只保存鉴权密钥索引值即可。然而,本发明对此并不限定。通用集成电路卡亦可存储网络标识与鉴权密钥的直接对应列表。
另外,包括本地核心网的基站将孤立网络的鉴权密钥Ki及其对应的网络标识列表保存在数据库中,可选的,包括本地核心网的基站例如可存储鉴权密钥与鉴权密钥索引值的关系列表以及鉴权密钥索引值与网络标识的对应关系列表;或者,可存储网络标识与鉴权密钥的直接对应列表。
步骤302:基站与核心网的连接中断,切换到孤立网络模式;
步骤303:基站广播孤立网络的网络标识;
步骤304:终端检测到该孤立网络的网络标识;
步骤305:终端向包括本地核心网的基站发送网络附着请求消息,其中,该消息中包括用户标识参数;
步骤306:包括本地核心网的基站根据在步骤303中所广播的网络标识,参照其在步骤301中保存的列表,获取对应的鉴权密钥Ki,并生成AKA鉴权向量;
步骤307:包括本地核心网的基站向终端发送鉴权请求消息,其中,该消息中包括随机数和鉴权令牌(AUTN)参数;
步骤308:终端向通用集成电路卡发送鉴权数据请求消息,其中,该消息中包括随机数、鉴权令牌和检测到的孤立网络的网络标识参数;
步骤309:通用集成电路卡参照其在步骤301中保存的列表,根据接收到的网络标识参数获取对应的鉴权密钥索引值,根据鉴权密钥索引值获取鉴权密钥Ki,验证鉴权令牌,并计算响应值RES和中间密钥KASME
步骤310:通用集成电路卡向终端返回鉴权数据响应消息,其中,该消息中携带鉴权响应参数,包括响应值RES和中间密钥KASME参数;
步骤311:终端根据中间密钥KASME推算NAS和AS业务密钥;
步骤312:终端向包括本地核心网的基站回送鉴权响应消息,该消息中包括响应值RES参数;
步骤313:包括本地核心网的基站验证接收到的响应值RES是否跟预计响应值XRES相等,如果相等则验证通过;
步骤314:包括本地核心网的基站与终端之间执行SMC过程,以协商安全算法,完成安全连接的建立;
步骤315:包括本地核心网的基站向终端回送网络附着接受消息。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
图7为本发明实施例二提供的接入孤立网络的鉴权认证方法的流程图。于本实施例中,终端存储网络标识和鉴权密钥索引值的对应关系,并将根据孤立网络的网络标识确定的鉴权密钥索引值传递给通用集成电路卡。如图7所示,本实施例具体包括以下步骤:
步骤401:通用集成电路卡和包括本地核心网的基站预配置孤立网络的鉴权密钥Ki及其对应的网络标识列表,于此,通用集成电路卡和包括本地核心网的基站预配置网络标识与鉴权密钥通过鉴权密钥索引值进行关联的间接对应关系;
可选的,通用集成电路卡将该列表保存在某个EF文件中,比如可以保存在EFOPLMNwACT文件中,格式如表2所示。
表2 EFOPLMNwACT文件格式
Figure PCTCN2016073807-appb-000003
Figure PCTCN2016073807-appb-000004
由表2可见,鉴权密钥索引值(Key Index)与网络标识(Nth PLMN)存在对应关系。可选的,由于通用集成电路卡将鉴权密钥保存在安全存储区中,因此,EF中只保存鉴权密钥索引值即可,即通过鉴权密钥索引值实现网络标识与鉴权密钥的关联对应。
另外,包括本地核心网的基站例如将孤立网络的鉴权密钥Ki及其对应的鉴权密钥索引值列表、网络标识及其对应的鉴权密钥索引值列表保存在数据库中。
步骤402:终端读取通用集成电路卡上的EF文件,存储网络标识及其对应的鉴权密钥索引值列表;
步骤403:基站与核心网的连接中断,切换到孤立网络模式;
步骤404:基站广播孤立网络的网络标识;
步骤405:终端检测到该孤立网络的网络标识;
步骤406:终端向包括本地核心网的基站发送网络附着请求消息,该消息中包括用户标识参数;
步骤407:包括本地核心网的基站根据在步骤404中所广播的网络标识,参照其在步骤401中保存的列表,获取对应的鉴权密钥Ki,生成AKA鉴权向量;
步骤408:包括本地核心网的基站向终端发送鉴权请求消息,该消息中包括随机数和鉴权令牌(AUTN)参数;
步骤409:终端根据在步骤405中所检测到的网络标识,参照步骤402存储的网络标识及其对应的鉴权密钥索引值列表,获取对应的鉴权密钥索引值;终端向通用集成电路卡发送鉴权数据请求消息,其中,该消息中包括随机数、鉴权令牌和鉴权密钥索引值参数;
步骤410:通用集成电路卡根据接收到的鉴权密钥索引值参数,参照其在步骤401中保存的列表,获取对应的鉴权密钥Ki,验证鉴权令牌,并计算响应值RES和中间密钥KASME
步骤411:通用集成电路卡向终端返回鉴权数据响应消息,该消息中包括响应值RES和中间密钥KASME参数;
步骤412:终端根据中间密钥KASME推算NAS和AS业务密钥;
步骤413:终端向包括本地核心网的基站回送鉴权响应消息,消息中包括响应值RES参数;
步骤414:包括本地核心网的基站验证接收到的响应值RES是否跟预计响应值XRES相等,如果相等则验证通过;
步骤415:包括本地核心网的基站与终端之间执行SMC过程,以协商安全算法,完成安全连接的建立;
步骤416:包括本地核心网的基站向终端回送网络附着接受消息。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
图8为本发明实施例三提供的接入孤立网络的鉴权认证方法的流程图。于本实施例中,终端存储网络标识和网络模式指示符参数的对应关系,并将根据孤立网络的网络标识确定的网络模式指示符参数传递给通用集成电路 卡。本实施例应用于所有普通网络使用同样的鉴权密钥和所有孤立网络使用同样的鉴权密钥的情况。如图8所示,本实施例具体包括以下步骤:
步骤501:通用集成电路卡和包括本地核心网的基站预配置网络标识及其对应的网络模式列表;其中网络模式例如包括普通网络模式、孤立网络模式;普通网络模式配置有普通网络鉴权密钥,孤立网络模式配置有孤立网络鉴权密钥,于此,通用集成电路卡和包括本地核心网的基站预配置网络标识与鉴权密钥通过网络模式指示符参数进行关联的间接对应关系;
可选的,通用集成电路卡将该列表保存在某个EF文件中,比如可以保存在EFOPLMNwACT文件中,格式如表3所示。
表3 EFOPLMNwACT文件格式
Bytes Description M/O Length
1 to 3 1st PLMN(highest priority) M 3 bytes
4 to 5 1st PLMN Access Technology Identifier M 2 bytes
6 1st PLMN Mode Indicator M 1 byte
: :    
43 to 45 8th PLMN M 3 bytes
46 to 47 8th PLMN Access Technology Identifier M 2 bytes
48 8th PLMN Mode Indicator M 1 byte
49 to 51 9th PLMN O 3 bytes
52 to 53 9th PLMN Access Technology Identifier O 2 bytes
54 9th PLMN Mode Indicator O 1 byte
: :    
(6n-5)to(6n-3) Nth PLMN(lowest priority) O 3 bytes
(6n-2)to(6n-1) Nth PLMN Access Technology Identifier O 2 bytes
6n Nth PLMN Mode Indicator O 1 byte
由表3可见,网络模式指示符(Mode Indicator)与网络标识(Nth PLMN) 存在对应关系。当网络为普通网络时,其Mode Indicator的值为0;当网络为孤立网络时,其Mode Indicator的值为1。普通网络配置有对应的普通网络鉴权密钥,孤立网络配置有对应的孤立网络鉴权密钥。即,通过网络模式指示符参数实现网络标识与鉴权密钥的关联对应。
另外,包括本地核心网的基站例如将网络标识及其对应的网络模式指示符参数列表、网络模式指示符参数及其对应的鉴权密钥列表保存在数据库中。
步骤502:终端读取通用集成电路卡上的EF文件,存储网络标识及其对应的网络模式指示符列表;
步骤503:基站与核心网的连接中断,切换到孤立网络模式;
步骤504:基站广播孤立网络的网络标识;
步骤505:终端检测到该孤立网络的网络标识;
步骤506:终端向包括本地核心网的基站发送网络附着请求消息,消息中包括用户标识参数;
步骤507:本地核心网根据在步骤504中所广播的网络标识,参照其在步骤501中保存的列表,获取对应的网络模式指示符参数,并获取对应的鉴权密钥Ki,生成AKA鉴权向量;
步骤508:包括本地核心网的基站向终端发送鉴权请求消息,消息中包括随机数和鉴权令牌(AUTN)参数;
步骤509:终端根据在步骤505中所检测到的网络标识,参照其在步骤502中存储的列表,获取对应的网络模式指示符参数;终端向通用集成电路卡发送鉴权数据请求消息,该消息中包括随机数、鉴权令牌和网络模式指示符参数;
步骤510:通用集成电路卡根据接收到的网络模式指示符参数,参照其在步骤501中保存的列表,获取对应的鉴权密钥Ki,验证鉴权令牌,并计算响应值RES和中间密钥KASME
步骤511:通用集成电路卡向终端或送鉴权数据响应消息,消息中包括响应值RES和中间密钥KASME参数;
步骤512:终端根据中间密钥KASME推算NAS和AS业务密钥;
步骤513:终端向包括本地核心网的基站回送鉴权响应消息,消息中包括响应值RES参数;
步骤514:包括本地核心网的基站验证接收到的响应值RES是否跟预计响应值XRES相等,如果相等则验证通过;
步骤515:包括本地核心网的基站与终端之间执行SMC过程,以协商安全算法,完成安全连接的建立;
步骤516:包括本地核心网的基站向终端回送网络附着接受消息。
本发明实施例还提供了一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行上述的方法。
此外,本发明实施例还提供一种接入孤立网络的鉴权认证系统,应用于安装在终端的通用集成电路卡中,如图9所示,包括:接收模块,设置为从终端接收孤立网络的网络标识,或者从终端接收根据所述孤立网络的网络标识确定的关联参数;处理模块,设置为根据所述网络标识或所述关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取所述孤立网络的网络标识对应的鉴权密钥,其中,所述预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。
于一实施例中,上述系统还包括:存储模块,设置为存储预配置的网络标识与鉴权密钥的对应关系。
于一实施例中,处理模块,还设置为根据获取的鉴权密钥,确定响应值RES,提供给终端。
其中,预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
其中,关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
此外,本发明实施例还提供一种接入孤立网络的鉴权认证系统,应用于安装通用集成电路卡的终端中,如图10所示,包括:第一发送模块,设置为向通用集成电路卡发送检测到的孤立网络的网络标识或者根据所述孤立网络的网络标识确定的关联参数;接收模块,设置为接收由所述通用集成电路卡确定的响应值RES,其中,响应值RES由所述通用集成电路卡根据所述网络标识或所述关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取的所述孤立网络的网络标识对应的鉴权密钥确定,所述预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同;第二发送模块,设置为将所述响应值RES发送至包括本地核心网的基站。
其中,预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
于一实施例中,该系统还包括:存储模块,设置为从通用集成电路卡获取网络标识与鉴权密钥通过关联参数进行关联的间接对应关系,根据所述间接对应关系获取并存储网络标识与关联参数的对应关系。
其中,关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
此外,本发明实施例还提供一种接入孤立网络的鉴权认证系统,包括:处理模块,设置为根据孤立网络的网络标识,参照预配置的网络标识与鉴权密钥的对应关系,确定所述孤立网络的网络标识对应的鉴权密钥,并生成预计响应值XRES,其中,所述预配置的网络标识与鉴权密钥的对应关系与通用集成电路卡预配置的网络标识与鉴权密钥的对应关系相同;认证模块,设置为根据所述预计响应值XRES对终端返回的响应值RES进行认证。
于一实施例中,上述系统还包括:存储模块,设置为存储预配置的网络标识与鉴权密钥的对应关系。
其中,预配置的网络标识与鉴权密钥的对应关系包括:
网络标识与鉴权密钥的直接对应关系;或者,
网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
其中,关联参数包括:
鉴权密钥索引值;或者,
网络模式指示符参数。
此外,关于上述系统的具体处理流程同上述方法所述,故于此不再赘述。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序来指令相关硬件(例如处理器)完成,所述程序可以存储于计算机可读存储介质中,如只读存储器、磁盘或光盘等。可选地,上述实施例的全部或部分步骤也可以使用一个或多个集成电路来实现。相应地,上述实施例中的各模块/单元可以采用硬件的形式实现,例如通过集成电路来实现其相应功能,也可以采用软件功能模块的形式实现,例如通过处理器执行存储于存储器中的程序/指令来实现其相应功能。本发明不限制于任何特定形式的硬件和软件的结合。
本领域的普通技术人员应当理解,可以对本发明的技术方案进行修改或者等同替换,而不脱离本发明技术方案的精神和范围,均应涵盖在本发明的权利要求范围当中。
工业实用性
上述技术方案避免了相关技术中使用鉴权向量的AMF域指定鉴权密钥存在的问题。而且,上述技术方案可以实现大规模实施。

Claims (25)

  1. 一种接入孤立网络的鉴权认证方法,应用于安装在终端的通用集成电路卡中,包括:
    通用集成电路卡从终端接收孤立网络的网络标识,或者从终端接收根据所述孤立网络的网络标识确定的关联参数;
    所述通用集成电路卡根据所述网络标识或所述与网络标识存在对应关系的关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取所述孤立网络的网络标识对应的鉴权密钥,其中,所述通用集成电路卡预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。
  2. 如权利要求1所述的方法,还包括:
    所述获取所述孤立网络的网络标识对应的鉴权密钥之后,所述通用集成电路卡根据获取的鉴权密钥,确定响应值RES,提供给所述终端。
  3. 如权利要求1所述的方法,其中,所述预配置的网络标识与鉴权密钥的对应关系包括:
    网络标识与鉴权密钥的直接对应关系;或者,
    网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
  4. 如权利要求1或3所述的方法,其中,所述关联参数包括:
    鉴权密钥索引值;或者,
    网络模式指示符参数。
  5. 一种接入孤立网络的鉴权认证方法,应用于安装通用集成电路卡的终端中,包括:
    终端向通用集成电路卡发送检测到的孤立网络的网络标识或者根据所述孤立网络的网络标识确定的关联参数;
    所述终端接收由所述通用集成电路卡根据与网络标识对应的鉴权密钥确定的响应值RES;
    所述终端将所述响应值RES发送至包括本地核心网的基站。
  6. 如权利要求5所述的方法,其中,所述网络标识与鉴权密钥的对应关系包括:
    网络标识与鉴权密钥的直接对应关系;或者,
    网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
  7. 如权利要求5所述的方法,还包括:
    所述终端向通用集成电路卡发送根据孤立网络的网络标识确定的关联参数之前,所述终端从所述通用集成电路卡获取网络标识与鉴权密钥通过关联参数进行关联的间接对应关系,根据所述间接对应关系获取并存储网络标识与关联参数的对应关系。
  8. 如权利要求5至7任一项所述的方法,其中,所述关联参数包括:
    鉴权密钥索引值;或者,
    网络模式指示符参数。
  9. 一种接入孤立网络的鉴权认证方法,包括:
    切换为孤立网络模式的包括本地核心网的基站根据孤立网络的网络标识,参照预配置的网络标识与鉴权密钥的对应关系,确定所述孤立网络的网络标识对应的鉴权密钥,并生成预计响应值XRES,其中,包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系与通用集成电路卡预配置的网络标识与鉴权密钥的对应关系相同;
    所述基站根据所述预计响应值XRES对终端返回的响应值RES进行认证。
  10. 如权利要求9所述的方法,其中,所述预配置的网络标识与鉴权密钥的对应关系包括:
    网络标识与鉴权密钥的直接对应关系;或者,
    网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
  11. 如权利要求9或10所述的方法,其中,所述关联参数包括:
    鉴权密钥索引值;或者,
    网络模式指示符参数。
  12. 如权利要求9所述的方法,其中,所述基站根据所述预计响应值XRES对终端返回的响应值RES进行认证包括:当所述预计响应值XRES与终端返回的响应值RES相等时,所述终端通过认证。
  13. 一种接入孤立网络的鉴权认证系统,应用于安装在终端的通用集成电路卡中,包括:
    接收模块,设置为从终端接收孤立网络的网络标识,或者从终端接收根据所述孤立网络的网络标识确定的关联参数;
    处理模块,设置为根据所述网络标识或所述与网络标识存在对应关系的关联参数,参照预配置的网络标识与鉴权密钥的对应关系,获取所述孤立网络的网络标识对应的鉴权密钥,其中,所述预配置的网络标识与鉴权密钥的对应关系与包括本地核心网的基站预配置的网络标识与鉴权密钥的对应关系相同。
  14. 如权利要求13所述的系统,还包括:存储模块,设置为存储预配置的网络标识与鉴权密钥的对应关系。
  15. 如权利要求13或14所述的系统,其中,所述预配置的网络标识与鉴权密钥的对应关系包括:
    网络标识与鉴权密钥的直接对应关系;或者,
    网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
  16. 如权利要求13所述的系统,所述处理模块,还设置为根据获取的鉴权密钥,确定响应值RES,提供给所述终端。
  17. 如权利要求13所述的系统,其中,所述关联参数包括:
    鉴权密钥索引值;或者,
    网络模式指示符参数。
  18. 一种接入孤立网络的鉴权认证系统,应用于安装通用集成电路卡的终端中,包括:
    第一发送模块,设置为向通用集成电路卡发送检测到的孤立网络的网络标识或者根据所述孤立网络的网络标识确定的关联参数;
    接收模块,设置为接收由所述通用集成电路卡根据与网络标识对应的鉴权密钥确定的响应值RES;
    第二发送模块,设置为将所述响应值RES发送至包括本地核心网的基站。
  19. 如权利要求18所述的系统,其中,所述网络标识与鉴权密钥的对应关系包括:
    网络标识与鉴权密钥的直接对应关系;或者,
    网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
  20. 如权利要求19所述的系统,还包括:存储模块,设置为从所述通用集成电路卡获取网络标识与鉴权密钥通过关联参数进行关联的间接对应关系,根据所述间接对应关系获取并存储网络标识与关联参数的对应关系。
  21. 如权利要求18至20任一项所述的系统,其中,所述关联参数包括:
    鉴权密钥索引值;或者,
    网络模式指示符参数。
  22. 一种接入孤立网络的鉴权认证系统,包括:
    处理模块,设置为根据孤立网络的网络标识,参照预配置的网络标识与鉴权密钥的对应关系,确定所述孤立网络的网络标识对应的鉴权密钥,并生成预计响应值XRES,其中,所述预配置的网络标识与鉴权密钥的对应关系与通用集成电路卡预配置的网络标识与鉴权密钥的对应关系相同;
    认证模块,设置为根据所述预计响应值XRES对终端返回的响应值RES进行认证。
  23. 如权利要求22所述的系统,还包括:存储模块,设置为存储预配置的网络标识与鉴权密钥的对应关系。
  24. 如权利要求22或23所述的系统,其中,所述预配置的网络标识与鉴权密钥的对应关系包括:
    网络标识与鉴权密钥的直接对应关系;或者,
    网络标识与鉴权密钥通过关联参数进行关联的间接对应关系。
  25. 如权利要求22所述的系统,其中,所述关联参数包括:
    鉴权密钥索引值;或者,
    网络模式指示符参数。
PCT/CN2016/073807 2015-06-26 2016-02-15 一种接入孤立网络的鉴权认证方法及系统 WO2016206387A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510364243.8 2015-06-26
CN201510364243.8A CN106332077B (zh) 2015-06-26 2015-06-26 一种接入孤立网络的鉴权认证方法及系统

Publications (1)

Publication Number Publication Date
WO2016206387A1 true WO2016206387A1 (zh) 2016-12-29

Family

ID=57584617

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/073807 WO2016206387A1 (zh) 2015-06-26 2016-02-15 一种接入孤立网络的鉴权认证方法及系统

Country Status (2)

Country Link
CN (1) CN106332077B (zh)
WO (1) WO2016206387A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI675570B (zh) * 2017-10-03 2019-10-21 盛星雲端控股股份有限公司 連網裝置、連網周邊裝置及一種網路連接方法與系統

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101123778A (zh) * 2007-09-29 2008-02-13 大唐微电子技术有限公司 网络接入鉴权方法及其usim卡
CN101132649A (zh) * 2007-09-29 2008-02-27 大唐微电子技术有限公司 一种网络接入鉴权方法及其usim卡
WO2011115407A2 (en) * 2010-03-15 2011-09-22 Samsung Electronics Co., Ltd. Method and system for secured remote provisioning of a universal integrated circuit card of a user equipment
CN102905266A (zh) * 2012-10-11 2013-01-30 大唐移动通信设备有限公司 一种实现移动设备附着的方法及装置

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB0600601D0 (en) * 2006-01-12 2006-02-22 Vodafone Plc Telecommunications networks and devices
CN102118721A (zh) * 2010-01-04 2011-07-06 中兴通讯股份有限公司 演进的分组系统及其紧急呼叫的附着处理方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101123778A (zh) * 2007-09-29 2008-02-13 大唐微电子技术有限公司 网络接入鉴权方法及其usim卡
CN101132649A (zh) * 2007-09-29 2008-02-27 大唐微电子技术有限公司 一种网络接入鉴权方法及其usim卡
WO2011115407A2 (en) * 2010-03-15 2011-09-22 Samsung Electronics Co., Ltd. Method and system for secured remote provisioning of a universal integrated circuit card of a user equipment
CN102905266A (zh) * 2012-10-11 2013-01-30 大唐移动通信设备有限公司 一种实现移动设备附着的方法及装置

Also Published As

Publication number Publication date
CN106332077A (zh) 2017-01-11
CN106332077B (zh) 2021-01-22

Similar Documents

Publication Publication Date Title
US11973746B2 (en) Connecting IMSI-less devices to the EPC
US10805473B2 (en) Triggering a usage of a service of a mobile packet core network
US20170171752A1 (en) Securing signaling interface between radio access network and a service management entity to support service slicing
US20200374698A1 (en) Communication method and communications apparatus
JP7066746B2 (ja) 認証要求を制御するためのプライバシインジケータ
US9473877B2 (en) Uplink/downlink transmission method for small amount of data, and corresponding terminal and mobility management unit
US20150280927A1 (en) Method, system, and controller for routing forwarding
US11849318B2 (en) Wireless communication network authentication
CN105828413B (zh) 一种d2d模式b发现的安全方法、终端和系统
CN109964453A (zh) 统一安全性架构
WO2011060709A1 (zh) 校验国际移动用户识别码与国际移动设备身份码绑定关系的方法和装置
EP2317694B1 (en) Method and system and user equipment for protocol configuration option transmission
US10484396B2 (en) Method and device for examining message integrity check
US20150023350A1 (en) Network connection via a proxy device using a generic access point name
CN108307296A (zh) 对国际位置中的用户设备提供服务的系统和方法
EP3114865A1 (en) Using services of a mobile packet core network
US10219309B2 (en) D2D service authorizing method and device and home near field communication server
US9426721B2 (en) Temporary access to wireless networks
WO2016206387A1 (zh) 一种接入孤立网络的鉴权认证方法及系统
US20230171598A1 (en) Secondary or Splice-Specific Access Control in a Wireless Communication Network
WO2017129101A1 (zh) 路由控制方法、装置及系统
WO2016184057A1 (zh) 一种接入认证方法、设备、系统及计算机存储介质
JP6732794B2 (ja) モバイル無線通信ネットワーク及び通信ネットワークデバイスへのモバイル端末の接続を確立するための方法
US9801050B2 (en) Formatting an endpoint as a private entity
WO2015158055A1 (zh) 一种实现设备到设备发现业务的方法、终端、存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16813503

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16813503

Country of ref document: EP

Kind code of ref document: A1