WO2018113338A1 - 一种接入控制的方法及设备 - Google Patents

一种接入控制的方法及设备 Download PDF

Info

Publication number
WO2018113338A1
WO2018113338A1 PCT/CN2017/099523 CN2017099523W WO2018113338A1 WO 2018113338 A1 WO2018113338 A1 WO 2018113338A1 CN 2017099523 W CN2017099523 W CN 2017099523W WO 2018113338 A1 WO2018113338 A1 WO 2018113338A1
Authority
WO
WIPO (PCT)
Prior art keywords
user equipment
authentication
access
network
layer
Prior art date
Application number
PCT/CN2017/099523
Other languages
English (en)
French (fr)
Inventor
陈山枝
陈中林
艾明
Original Assignee
电信科学技术研究院
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 电信科学技术研究院 filed Critical 电信科学技术研究院
Priority to EP17885077.2A priority Critical patent/EP3562186A4/en
Priority to US16/472,728 priority patent/US11405783B2/en
Publication of WO2018113338A1 publication Critical patent/WO2018113338A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/04Interfaces between hierarchically different network devices
    • H04W92/12Interfaces between hierarchically different network devices between access points and access point controllers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0869Network architectures or network communication protocols for network security for authentication of entities for achieving mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/71Hardware identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/04Interfaces between hierarchically different network devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/04Interfaces between hierarchically different network devices
    • H04W92/10Interfaces between hierarchically different network devices between terminal device and access point, i.e. wireless air interface
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/20Selecting an access point
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/005Moving wireless networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/18Self-organising networks, e.g. ad-hoc networks or sensor networks

Definitions

  • the present invention relates to the field of wireless communication technologies, and in particular, to a method and an apparatus for access control.
  • UDN Ultra Dense Network
  • UDN User-centric Ultra Dense Network
  • APG Access Points Group
  • the AP In an existing mobile communication system access network, such as an E-UTRAN (Evolved Universal Terrestrial Radio Access Network), the AP is deployed and maintained by the operator in a secure and trusted environment.
  • E-UTRAN Evolved Universal Terrestrial Radio Access Network
  • MME Mobility Management Entity
  • the user equipment After the authentication is passed, the user equipment directly accesses the eNB (evolved Node B, evolved). Base station) or HeNB (Home evolved Node B).
  • the AP functions are diversified, and the deployment mode is flexible. It may even be deployed by users.
  • the physical security environment of the access network in the UDN/UUDN scenario is complex and varies greatly.
  • an AP may belong to multiple APGs, if the existing user equipment access control method is still used, it is still impossible to exclude the illegal AP from impersonating a legal APG.
  • the AP implements a security attack, the security of user equipment access cannot be guaranteed.
  • the current method in which a user equipment directly accesses an eNB or an HeNB is not applicable to a UDN/UUDN scenario.
  • the embodiment of the invention provides a method and a device for access control, which are used to solve the prior art in UDN/UUDN.
  • the user equipment cannot access the APG securely.
  • a method for access control provided by an embodiment of the present invention includes:
  • the user equipment and the local service center perform network layer two-way authentication
  • the user equipment and the corresponding access node group After the two-way authentication of the network layer is passed, the user equipment and the corresponding access node group perform two-way authentication of the access layer, so that the user equipment accesses the corresponding access after the two-way authentication of the access layer is passed. In the node group.
  • the user equipment and the corresponding access node group perform two-way authentication of the access layer, including:
  • the user equipment authenticates the network according to the access layer authentication request message that is sent by the target node in the access node group and includes the node group identifier;
  • the user equipment returns an access layer authentication request response message including the node group identifier to the target node after the authentication is passed, so that the target node responds to the access layer authentication request response message
  • the user equipment is authenticated.
  • the user equipment authenticates the network according to the access layer authentication request message that is sent by the target node in the access node group, and includes:
  • the user equipment determines to pass the network authentication.
  • the user equipment returns an access layer authentication request response message that includes the node group identifier to the target node after the authentication is passed, including:
  • the user equipment After the user equipment passes the authentication, the user equipment determines an authentication response parameter according to the random number;
  • an access layer authentication request response message that includes the node group identifier and the authentication response parameter, to the target node, according to the node group identifier and the authentication
  • the user equipment is authenticated by a response parameter.
  • a second aspect of the present invention provides a method for access control, including:
  • the local service center After receiving the access request message of the user equipment, the local service center performs network layer two-way authentication with the user equipment;
  • the local service center notifies the access node group to perform the access layer bidirectional authentication with the user equipment, so that the access node group allows the user equipment to access after the access layer is authenticated by the access layer.
  • the local service center after receiving the access request message of the user equipment, and performing network layer two-way authentication with the user equipment, further includes:
  • the local service center requests, according to the context information of the user equipment in the access request message, the network layer authentication parameter corresponding to the user equipment to the network service center;
  • the local service center and the user equipment perform network layer two-way authentication, including:
  • the local service center performs network layer bidirectional authentication with the user equipment according to the network layer authentication parameter.
  • the local service center performs network layer two-way authentication with the user equipment according to the network layer authentication parameter, including:
  • the local service center sends a network layer authentication request message including a network layer authentication parameter to the user equipment, so that the user equipment authenticates the network according to the network layer authentication request message;
  • the local service center receives the network layer authentication request response message returned by the user equipment, the user equipment is authenticated according to the network layer authentication request response message.
  • the local service center performs authentication on the user equipment according to the network layer authentication request response message returned by the user equipment, including:
  • the local service center determines to authenticate the user equipment.
  • the local service center notifies the access node group and the user equipment to perform two-way authentication of the access layer, including:
  • the local service center notifies the target node to perform two-way authentication of the access layer with the user equipment.
  • the local service center notifies the target node to perform two-way authentication of the access layer with the user equipment, including:
  • the access layer authentication parameter performs bidirectional authentication with the user equipment at the access layer.
  • the local service center determines, according to the following manner, a corresponding access layer authentication parameter corresponding to the user equipment:
  • the local service center determines an access layer authentication parameter corresponding to the user equipment according to the network layer authentication parameter corresponding to the user equipment and the node group identifier.
  • a method for access control provided by an embodiment of the present invention includes:
  • the access node receives the access layer authentication parameter corresponding to the user equipment sent by the local service center, where the access layer authentication parameter is sent by the local service center after determining that the network bidirectional authentication with the user equipment is passed;
  • the access node performs bidirectional authentication with the user equipment at the access layer, and allows the user equipment to access after determining that the access layer of the user equipment passes the two-way authentication.
  • the user equipment that performs the access layer and the user equipment corresponding to the access layer authentication parameter perform two-way authentication of the access layer, including:
  • the access node sends an access layer authentication request message including a node group identifier and an access layer authentication parameter to the user equipment, so that the user equipment performs the network according to the access layer authentication request message.
  • the access node receives the access layer authentication request response message that includes the node group identifier returned by the user equipment, the user equipment is authenticated according to the access layer authentication request response message.
  • the access node performs authentication on the user equipment according to the access layer authentication request response message that is sent by the user equipment, and includes:
  • the access node determines to authenticate the user equipment.
  • the fourth aspect of the present invention provides a user equipment, including:
  • the first network authentication module is configured to perform network layer two-way authentication with the local service center when the network needs to be accessed;
  • the first access authentication module is configured to perform two-way authentication of the access layer with the corresponding access node group after the two-way authentication of the network layer is passed, so that the user equipment is connected after the two-way authentication of the access layer is passed. Enter the corresponding access node group.
  • the first access authentication module is specifically configured to:
  • the access layer authentication request response message is configured to enable the target node to authenticate the user equipment according to the access layer authentication request response message.
  • the first access authentication module is specifically configured to:
  • the first access authentication module is specifically configured to:
  • the target node After the authentication is passed, determining an authentication response parameter according to the random number; returning, to the target node, an access layer authentication request response message including the node group identifier and the authentication response parameter, so that the The target node authenticates the user equipment according to the node group identifier and the authentication response parameter.
  • a fifth aspect of the present invention provides a local service center, including:
  • a second network authentication module configured to perform network layer two-way authentication with the user equipment after receiving the access request message of the user equipment
  • a notification module configured to determine an access node group corresponding to the user equipment after determining that the user equipment network layer is authenticated by the two-way authentication;
  • a second access authentication module configured to notify the access node group and the user equipment to perform access layer bidirectional authentication, so that the access node group allows the User equipment access.
  • the second network authentication module is further configured to:
  • the second network authentication module is specifically configured to:
  • the second network authentication module is specifically configured to:
  • the layer authentication request response message is used to authenticate the user equipment according to the network layer authentication request response message.
  • the second network authentication module is specifically configured to:
  • the authentication response parameter included in the network layer authentication request response message is the same as the expected response parameter in the network layer authentication parameter, it is determined that the user equipment is authenticated.
  • the second access authentication module is specifically configured to:
  • the second access authentication module is specifically configured to:
  • the authentication parameter performs bidirectional authentication with the user equipment at the access layer.
  • the second access authentication module is specifically configured to:
  • the local service center determines, according to the following manner, a corresponding access layer authentication parameter corresponding to the user equipment:
  • a sixth aspect of the present invention provides an access node, including:
  • a receiving module configured to receive an access layer authentication parameter corresponding to the user equipment sent by the local service center, where the access layer authentication parameter is sent by the local service center after determining that the network bidirectional authentication with the user equipment is passed of;
  • the third access authentication module is configured to perform two-way authentication on the access layer with the user equipment, and allow the user equipment to access after determining that the access layer of the user equipment passes the two-way authentication.
  • the third access authentication module is specifically configured to:
  • an access layer authentication request message that includes a node group identifier and an access layer authentication parameter, so that the user equipment authenticates the network according to the access layer authentication request message;
  • the access layer authentication request response message that is sent by the user equipment and includes the node group identifier, and the user equipment is authenticated according to the access layer authentication request response message.
  • the third access authentication module is specifically configured to:
  • the authentication response parameter included in the access layer authentication request response message is the same as the expected response parameter in the access layer authentication parameter, it is determined that the user equipment is authenticated.
  • Another user equipment includes a memory and a processor, where
  • a processor for reading a program in the memory performing the following process:
  • the network layer is authenticated with the local service center
  • the access layer is authenticated with the corresponding access node group to enable the user equipment to access the corresponding access node group after the access layer is authenticated.
  • Another local service center provided by the embodiment of the present application includes a memory and a processor, where
  • a processor for reading a program in the memory performing the following process:
  • Another access node provided by the embodiment of the present application includes a memory and a processor, where
  • a processor for reading a program in the memory performing the following process:
  • the user equipment when the user equipment needs to access the network, the user equipment first performs network layer two-way authentication with the local service center; after the network layer two-way authentication passes, the user equipment and the corresponding access node group The target node in the access layer performs the two-way authentication of the access layer.
  • the two-way bidirectional authentication is adopted in the embodiment of the present invention, and after the two-layer bidirectional authentication is passed, the user equipment can access the corresponding access node group. Thereby, the user equipment is securely connected to the corresponding access node group.
  • FIG. 1 is a schematic structural diagram of an ultra-dense networking according to an embodiment of the present invention.
  • FIG. 2 is a schematic structural diagram of a system for access control according to an embodiment of the present invention.
  • FIG. 3 is a flowchart of bidirectional authentication of a network layer of a user equipment and a local service center according to an embodiment of the present invention
  • FIG. 4 is a schematic structural diagram of a system for performing bidirectional authentication of an access layer according to an embodiment of the present invention
  • FIG. 5 is a flowchart of bidirectional authentication of an access layer of a user equipment and a target node according to an embodiment of the present invention
  • FIG. 6 is a schematic structural diagram of a first user equipment according to an embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of a first local service center according to an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of a first access node according to an embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a second user equipment according to an embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a second local service center according to an embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of a second access node according to an embodiment of the present invention.
  • FIG. 12 is a schematic flowchart of a method for user equipment side access control according to an embodiment of the present invention.
  • FIG. 13 is a schematic flowchart of a method for assisting user equipment side access control by a local service center according to an embodiment of the present invention
  • FIG. 14 is a schematic flowchart of a method for assisting user equipment side access control on an access node side according to an embodiment of the present invention.
  • FIG. 1 is a schematic diagram of an ultra-dense networking structure.
  • the network structure mainly includes: NSC (Network Service Center), LSC (Local Service Center), and several UEs (User Equipment, a user equipment), a plurality of APGs serving the UE; wherein each APG includes a plurality of APs, and the same AP may be located in different APGs; each APG corresponds to one node group identification ID, and each APG corresponds to one UE. .
  • the AP in the APG is connected to the UE through a wireless connection, and each AP and the LSC are connected by a wired connection, and the LSC and the NSC are connected through an IP network.
  • the system for access control in the embodiment of the present invention includes: a user equipment 10, a local service center 20, and at least one access node 30.
  • the user equipment 10 is configured to perform network layer two-way authentication with the local service center when the network needs to be accessed; and perform two-way authentication of the access layer with the corresponding access node group after the two-way authentication of the network layer is passed, so that After the two-way authentication of the access layer is passed, the user equipment is accessed into the corresponding access node group.
  • the local service center 20 is configured to perform network layer two-way authentication with the user equipment after receiving the access request message of the user equipment, and determine the user after determining that the user equipment network layer is authenticated by the two-way authentication Equipment corresponding
  • the access node group is configured to notify the access node group and the user equipment to perform the access layer bidirectional authentication, so that the access node group allows the user equipment to access after the access layer is authenticated by the access layer.
  • the access node 30 is configured to receive an access layer authentication parameter corresponding to the user equipment sent by the local service center, where the access layer authentication parameter is that the local service center determines to perform bidirectional authentication with the network of the user equipment. After being sent, the access layer is authenticated by the user equipment, and after the two-way authentication with the access layer of the user equipment is determined, the user equipment is allowed to access.
  • the user equipment when the user equipment needs to access the network, the user equipment first performs network layer two-way authentication with the local service center; after the network layer two-way authentication passes, the user equipment accesses the target node in the corresponding access node group. Layer two-way authentication; the user equipment can access the corresponding access node group after the two-layer two-way authentication is adopted in the embodiment of the present invention. Thereby, the user equipment is securely connected to the corresponding access node group.
  • the time when the user equipment needs to access the network may be that the user equipment starts up.
  • the user equipment When the user equipment needs to access the network, the user equipment sends an access request message to the local service center through the access node;
  • the method for determining the access node that forwards the access request message includes some or all of the following:
  • the user equipment sends an access request message by using the nearest access node
  • the user equipment sends an access request message through the access node with the strongest signal strength
  • the user equipment sends an access request message through the specified.
  • the local service center After receiving the access request message sent by the user equipment, the local service center requests the network layer corresponding to the user equipment from the network service center according to the context information of the user equipment in the access request message. Weight parameter.
  • the local service center sends a request authentication parameter message to the network service center, and the request authentication parameter message includes the identifier information of the user equipment.
  • the network service center receives the request authentication parameter message sent by the local service center, and generates the network layer authentication parameter corresponding to the user equipment according to the identifier information of the user equipment in the request authentication parameter message.
  • Network layer authentication parameters include: RAND (random number), XRES (expected response parameter), AUTN (authentication flag), K LSC (temporary key);
  • the K LSC is determined according to the root key k corresponding to the user equipment stored in the network service center, and the RAND in the network layer authentication parameter; and the role of the K LSC is to enable the local service center to derive the UE according to the K LSC The communication key when communicating with the network.
  • the network service center sends the network layer authentication parameter corresponding to the user equipment to the local service center, and the local service center locally stores the network layer authentication parameter corresponding to the received user equipment.
  • the user equipment and the network are required to perform dual bidirectional authentication. That is, the authentication is performed twice, which is: two-way authentication of the network layer of the user equipment and the local service center, and two-way authentication of the access layer of the user equipment and the access node group. After the two authentications are respectively passed, the user equipment accesses the corresponding access node group.
  • the two-way authentication of the network layer and the two-way authentication of the access layer are respectively described below.
  • the local service center performs network layer bidirectional authentication with the user equipment according to the network layer authentication parameter.
  • the local service center sends a network layer authentication request message including a network layer authentication parameter to the user equipment, so that the user equipment authenticates the network side according to the network layer authentication request message; After receiving the network layer authentication request response message returned by the user equipment, the local service center authenticates the user equipment according to the network layer authentication request response message.
  • the network layer authentication request message that is sent by the local service center to the user equipment and includes the network layer authentication parameter is forwarded by the access node that forwards the access request message; and the network returned by the user equipment
  • the layer authentication request response message is also forwarded by the access node.
  • FIG. 1 a flow chart of bidirectional authentication of the user equipment and the network layer of the local service center as shown in FIG.
  • Step 301 The local service center sends a network layer authentication request message including a network layer authentication parameter to the user equipment.
  • Step 302 The user equipment receives and saves the network layer authentication parameter in the network layer authentication request message.
  • Step 303 The user equipment determines the AUTN according to the RAND in the network layer authentication parameter.
  • Step 304 If the determined AUTN is the same as the AUTN in the network layer authentication parameter, the user equipment determines to pass the network layer authentication of the network.
  • Step 305 The user equipment determines RES (authentication response parameter) according to RAND in the network layer authentication parameter.
  • Step 306 The user equipment returns a network layer authentication request response message including the RES to the local service center.
  • Step 307 If the RES in the network layer authentication request response message is the same as the XRES in the network layer authentication parameter, the local service center determines that the network layer authentication of the user equipment passes.
  • the user equipment fails to pass the network layer authentication of the network, or the local service center fails to pass the network layer authentication of the user equipment, the user equipment cannot access the network.
  • the local service center of the embodiment of the present invention determines the two-way authentication with the network layer of the user equipment, the local service center applies to the network service center, and requests the network service center to allocate the node group identifier for the user equipment.
  • the local service center applies to the network service center, and requests the network service center to allocate a node group identifier to the access node group corresponding to the user equipment;
  • the network service center may only Sending the node group identifier assigned to the access node group to the local service center;
  • the network service center sends a group node identifier to the local service center in advance, and after the local service center determines to perform bidirectional authentication with the network layer of the user equipment, selects a node group identifier that is not allocated from the group node group identifier. Assigned to user devices.
  • the local service center After determining the node group identifier corresponding to the user equipment, the local service center notifies the user equipment of the node group identifier assigned to the user equipment.
  • the local service center After determining the node group identifier corresponding to the user equipment, the local service center generates an access node group that provides communication services for the user equipment.
  • the N access nodes with the strongest reference signal strength are formed into the access node group corresponding to the user equipment;
  • the N access nodes with the largest communication cooperation gain are formed into the access node group corresponding to the user equipment;
  • the designated N access nodes form an access node group corresponding to the user equipment.
  • the manner of determining the access node group that provides the communication service for the user equipment is only an example of the embodiment of the present invention.
  • the manner of determining the access node group corresponding to the user equipment that is to be protected by the embodiment of the present invention is not Limited to the above examples, any manner of determining an access node group that can provide communication services for user equipment is applicable to the present invention.
  • the user equipment and the access layer of the access node group are authenticated in both directions.
  • the user equipment and the access layer of the access node group are authenticated in both directions.
  • the user equipment and the target node in the access node group perform two-way authentication at the access layer.
  • the local service center determines a target node in the access node group; and the local service center notifies the target node to perform access layer bidirectional authentication with the user equipment.
  • the manner in which the local service center determines the target node in the access node group includes some or all of the following:
  • the access node with the strongest reference signal strength in the access node group received by the user equipment is used as the target node;
  • the access node with the largest communication cooperation gain generated by the user equipment in the access node group is used as the target node;
  • Manner 3 The access node that is the first request in the access node group to join the access node group is used as the target node;
  • Mode 4 arbitrarily designate one access node as a target node in the access node group.
  • the manner of determining the target node is only an example of the embodiment of the present invention.
  • the manner in which the target node is determined to be protected by the embodiment is not limited to the above examples, and any manner in which the target node can be determined is applicable to the present invention.
  • the local service center After determining the target node from the access node group, the local service center notifies the target node to perform access layer bidirectional authentication with the user equipment.
  • the local service center sends the node group identifier corresponding to the access node group and the access layer authentication parameter corresponding to the user equipment to the target node, so that the target node is configured according to the The node group identifier and the access layer authentication parameter perform bidirectional authentication with the user equipment at the access layer.
  • the local service center determines the corresponding access layer authentication parameter corresponding to the user equipment according to the following manner:
  • the local service center obtains the access layer authentication parameter corresponding to the user equipment from the network service center.
  • the local service center sends a request access layer authentication parameter message to the network service center, and requests the access layer authentication parameter message to include the node group identifier;
  • the network service center receives the request access layer authentication parameter message sent by the local service center, and generates an access layer authentication parameter corresponding to the user equipment according to the node group identifier included in the access layer authentication parameter message.
  • the access layer authentication parameters include: RAND (random number), XRES (expected response parameter), AUTN (authentication flag), K APG (intermediate key);
  • the K APG is determined according to the root key k corresponding to the user equipment stored in the network service center, and the access layer authentication parameter message includes the node group identifier APG_ID and the RAND in the network layer authentication parameter; and, K The role of the APG is to enable the local service center to derive the communication key when the UE communicates with the network based on the K APG .
  • the local service center determines the access layer authentication parameter corresponding to the user equipment according to the network layer authentication parameter corresponding to the user equipment and the node group identifier.
  • the local service center determines the access layer authentication parameter corresponding to the user equipment according to the RAND, the XRES, the AUTN, the K LSC , and the node group identifier APG_ID in the network layer authentication parameter obtained from the network service center.
  • K APG is determined, and RAND, XRES, AUTN, and K APG are used as access layer authentication parameters.
  • each access node may belong to different access node groups at the same time, that is, one access node may simultaneously provide communication services for multiple user equipments. Therefore, when the target node in the access node group and the user equipment perform the access layer bidirectional authentication, the message sent during the authentication process between the target node and the user equipment needs to include the node group identifier, so that the target node and the user equipment Conduct secure and accurate authentication.
  • the local service center of the embodiment of the present invention sends the determined access layer authentication parameter to the target node
  • the identifier information of the user equipment corresponding to the access layer authentication parameter needs to be sent to the target node, so that the target node Determine the user equipment that needs to perform access layer authentication.
  • the system for performing bidirectional authentication of the access layer in the embodiment of the present invention includes: a user equipment 20 and a target node 40.
  • the target node 40 is configured to send, to the user equipment, an access layer authentication request message that includes a node group identifier and an access layer authentication parameter, so that the user equipment uses the access layer authentication request message to the network. Performing authentication; if receiving an access layer authentication request response message that includes the node group identifier returned by the user equipment, authenticating the user equipment according to the access layer authentication request response message.
  • the user equipment 10 is configured to authenticate the network according to the access layer authentication request message that includes the node group identifier sent by the target node in the access node group, and return the content to the target node after the authentication is passed.
  • the access layer authentication request response message that is identified by the node group, so that the target node authenticates the user equipment according to the access layer authentication request response message.
  • the node group identifier APG_ID included in the access layer authentication request message sent by the target node to the user equipment, and the access layer authentication parameter include RAND and AUTN.
  • the node group identifier APG_ID may be added as a separate parameter in the access layer authentication request message; or the node group identifier APG_ID may be exclusive or hidden in the access layer authentication parameter to be added in the access layer authentication.
  • the APG_ID is XORed with the AUTN.
  • the user equipment receives the access layer authentication. After requesting the message, the node group identifier APG_ID is parsed from the access layer authentication parameter.
  • the two-way authentication of the access layer of the user equipment and the target node includes: the user equipment performs network authentication on the target node, and the target node authenticates the user equipment.
  • the user equipment performs network authentication on the target node.
  • the user equipment authenticates the network according to the access layer authentication request message that is sent by the target node in the access node group and includes the node group identifier;
  • the user equipment determines, according to the random number in the access layer authentication request message, a second authentication token; if the second authentication token and the first authentication in the access layer authentication request message If the tags are the same, the user equipment determines to pass the network authentication.
  • the user equipment determines the AUTN according to the RAND in the access layer authentication request message. If the AUTN determined by the user equipment is the same as the AUTN in the access layer authentication request message, the access node determines to pass the network authentication.
  • the user equipment After the user passes the authentication, the user equipment returns an access layer authentication request response message that includes the node group identifier, so that the target node sends the response message to the user according to the access layer authentication request response message.
  • the device is authenticated.
  • the user equipment determines an authentication response parameter according to the random number; the user equipment returns an access layer that includes the node group identifier and the authentication response parameter to the target node.
  • the target node is configured to authenticate the user equipment according to the node group identifier and the authentication response parameter.
  • the user equipment determines an RES (authentication response parameter) according to the RAND in the access layer authentication parameter, and returns an access layer authentication response including the APG_ID and the RES to the local service center. Message.
  • the node group identifier APG_ID may be added to the access layer authentication response message as a separate parameter; or the XOR_ID of the node group identifier and the authentication response parameter may be XORed in the access layer authentication response message, for example, APG_ID is XORed with RES.
  • the local service center will receive the access layer authentication response message after receiving the access layer authentication response message.
  • the node group identifier APG_ID is parsed from the authentication response parameter.
  • the target node authenticates the user equipment.
  • the target node receives the access layer authentication request response message that is sent by the user equipment and includes the node group identifier, and then authenticates the user equipment according to the access layer authentication request response message.
  • the target node determines to authenticate the user equipment.
  • the target node determines whether the RES in the access layer authentication response message is the same as the XRES in the access layer authentication parameter, and if the same, determines that the user equipment is authenticated.
  • FIG. 5 A flowchart of bidirectional authentication of the access layer of the user equipment and the target node as shown in FIG. 5.
  • Step 501 The target node sends an access layer authentication request message that includes a node group identifier and an access layer authentication parameter to the user equipment.
  • Step 502 The user equipment receives and saves an access layer authentication parameter in the access layer authentication request message.
  • Step 503 The user equipment determines the AUTN according to the RAND in the access layer authentication request message.
  • Step 504 If the determined AUTN is the same as the AUTN in the access layer authentication parameter, the user equipment determines to pass the network authentication.
  • Step 505 The user equipment determines the RES according to the RAND in the access layer authentication parameter.
  • Step 506 The user equipment user equipment returns an access layer authentication request response message including the node group identifier and the RES to the target node.
  • Step 507 After determining that the authentication response parameter included in the access layer authentication request response message is the same as the expected response parameter in the access layer authentication parameter, the target node determines to pass the authentication of the user equipment.
  • the access node in the embodiment of the present invention may be a base station (such as a macro base station, a home base station, etc.), and may also be other nodes.
  • a base station such as a macro base station, a home base station, etc.
  • a user equipment includes:
  • the first network authentication module 601 is configured to perform network layer bidirectional authentication with the local service center when the network needs to be accessed. right;
  • the first access authentication module 602 is configured to perform bidirectional authentication of the access layer with the corresponding access node group after the bidirectional authentication of the network layer is passed, so that the user equipment is enabled after the access layer is authenticated by the access layer. Access to the corresponding access node group.
  • the first access authentication module 602 is specifically configured to:
  • the access layer authentication request response message is configured to enable the target node to authenticate the user equipment according to the access layer authentication request response message.
  • the first access authentication module 602 is specifically configured to:
  • the first access authentication module 602 is specifically configured to:
  • the target node After the authentication is passed, determining an authentication response parameter according to the random number; returning, to the target node, an access layer authentication request response message including the node group identifier and the authentication response parameter, so that the The target node authenticates the user equipment according to the node group identifier and the authentication response parameter.
  • a local service center includes:
  • the second network authentication module 701 is configured to perform network layer two-way authentication with the user equipment after receiving the access request message of the user equipment;
  • the notification module 702 is configured to determine, according to the bidirectional authentication of the user equipment network layer, the access node group corresponding to the user equipment;
  • the second access authentication module 703 is configured to notify the access node group and the user equipment to perform access layer bidirectional authentication, so that the access node group allows the access layer to pass through after the two-way authentication of the access layer User equipment access.
  • the second network authentication module 701 is further configured to:
  • the network service center After receiving the access request message of the user equipment, before performing the network layer bidirectional authentication with the user equipment, requesting, according to the context information of the user equipment in the access request message, the network service center to request the user equipment to correspond to Network layer authentication parameters;
  • the second network authentication module 701 is specifically configured to:
  • the second network authentication module 701 is specifically configured to:
  • the layer authentication request response message is used to authenticate the user equipment according to the network layer authentication request response message.
  • the second network authentication module 701 is specifically configured to:
  • the authentication response parameter included in the network layer authentication request response message is the same as the expected response parameter in the network layer authentication parameter, it is determined that the user equipment is authenticated.
  • the second access authentication module 703 is specifically configured to:
  • the second access authentication module 703 is specifically configured to:
  • the authentication parameter performs bidirectional authentication with the user equipment at the access layer.
  • the second access authentication module 703 is specifically configured to:
  • the local service center determines, according to the following manner, a corresponding access layer authentication parameter corresponding to the user equipment:
  • an access node includes:
  • the receiving module 801 is configured to receive an access layer authentication parameter corresponding to the user equipment sent by the local service center, where the access layer authentication parameter is that the local service center determines the two-way authentication with the network of the user equipment Sent
  • the third access authentication module 802 is configured to perform access layer bidirectional authentication with the user equipment, and allow the user equipment to access after determining that the access layer of the user equipment passes the bidirectional authentication.
  • the third access authentication module 802 is specifically configured to:
  • an access layer authentication request message that includes a node group identifier and an access layer authentication parameter, so that the user equipment authenticates the network according to the access layer authentication request message;
  • the access layer authentication request response message that is sent by the user equipment and includes the node group identifier, and the user equipment is authenticated according to the access layer authentication request response message.
  • the third access authentication module 802 is specifically configured to:
  • the authentication response parameter included in the access layer authentication request response message is the same as the expected response parameter in the access layer authentication parameter, it is determined that the user equipment is authenticated.
  • the second user equipment in the embodiment of the present invention includes:
  • the processor 901 is configured to read a program in the memory 904 and perform the following process:
  • the network layer When the network needs to be accessed, the network layer is authenticated with the local service center. After the two-way authentication of the network layer is passed, the access layer is authenticated by the access layer in both directions, so that the access layer can be authenticated in both directions. Passing the user equipment Access to the corresponding access node group.
  • the transceiver 902 is configured to receive and transmit data under the control of the processor 901.
  • the processor 901 is specifically configured to:
  • the processor 901 is specifically configured to:
  • the processor 901 is specifically configured to:
  • the target node is configured to authenticate the user equipment according to the node group identifier and the authentication response parameter.
  • the interaction between the processor 901 and the local service center and the access node is implemented by the transceiver 902, and is not separately described herein.
  • bus 900 may include any number of interconnected buses and bridges, and bus 900 will include one or more processors and memory 904 represented by general purpose processor 901. The various circuits of the memory are linked together.
  • the bus 900 can also link various other circuits, such as peripherals, voltage regulators, and power management circuits, as is known in the art, and therefore, will not be further described herein.
  • Bus interface 903 provides an interface between bus 900 and transceiver 902.
  • Transceiver 902 can be an element or a plurality of elements, such as a plurality of receivers and transmitters, providing means for communicating with various other devices on a transmission medium.
  • transceiver 902 receives external data from other devices.
  • the transceiver 902 is configured to send the processed data of the processor 901 to other devices.
  • a user interface 905 can also be provided, such as a keypad, display, speaker, microphone, joystick.
  • the processor 901 is responsible for managing the bus 900 and the usual processing, running a general purpose operating system as described above.
  • the memory 904 can be used to store data used by the processor 901 in performing operations.
  • the processor 901 may be a CPU (Central Embedded Device), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a CPLD (Complex Programmable Logic Device). , complex programmable logic devices).
  • CPU Central Embedded Device
  • ASIC Application Specific Integrated Circuit
  • FPGA Field-Programmable Gate Array
  • CPLD Complex Programmable Logic Device
  • the second local service center in the embodiment of the present invention includes:
  • the processor 1001 is configured to read a program in the memory 1004 and perform the following process:
  • the access node group corresponding to the user equipment is determined; and the access node 100 is notified by the transceiver 1002 to perform two-way authentication of the access layer with the user equipment, so that The access node group allows the user equipment to access after the access layer has passed the two-way authentication.
  • the transceiver 1002 is configured to receive and transmit data under the control of the processor 1001.
  • the processor 1001 is further configured to:
  • the network service center After receiving the access request message of the user equipment, before performing the network layer bidirectional authentication with the user equipment, requesting, according to the context information of the user equipment in the access request message, the network service center to request the user equipment to correspond to Network layer authentication parameters;
  • the processor 1001 is specifically configured to:
  • the processor 1001 is specifically configured to:
  • the layer authentication request response message is used to authenticate the user equipment according to the network layer authentication request response message.
  • the processor 1001 is specifically configured to:
  • the authentication response parameter included in the network layer authentication request response message is the same as the expected response parameter in the network layer authentication parameter, it is determined that the user equipment is authenticated.
  • the processor 1001 is specifically configured to:
  • the processor 1001 is specifically configured to:
  • the authentication parameter performs bidirectional authentication with the user equipment at the access layer.
  • the processor 1001 is specifically configured to:
  • the local service center determines, according to the following manner, a corresponding access layer authentication parameter corresponding to the user equipment:
  • the interaction between the processor 1001 and the user equipment is implemented by the transceiver 1002 and the access node, that is, the processor 1001 sends the information that needs to be sent to the user equipment to the access node through the transceiver 1002.
  • the ingress node sends the information to the user equipment; after receiving the information from the user equipment that needs to be sent to the local service center, the access node sends the information to the local service center, and the processor 1001 receives the information through the transceiver 1002.
  • the local service center and the access node may be connected by wired or wireless means.
  • bus 1000 may include any number of interconnected buses and bridges, and bus 1000 will include one or more processors represented by processor 1001 and memory represented by memory 1004. The various circuits are linked together. The bus 1000 can also link various other circuits, such as peripherals, voltage regulators, and power management circuits, as is known in the art, and therefore, will not be further described herein.
  • Bus interface 1003 provides an interface between bus 1000 and transceiver 1002.
  • the transceiver 1002 can be an element or a plurality of elements, such as a plurality of receivers and transmitters, providing means for communicating with various other devices on a transmission medium.
  • the data processed by the processor 1001 is transmitted over the wireless medium via the antenna 1005. Further, the antenna 1005 also receives the data and transmits the data to the processor 1001.
  • the processor 1001 is responsible for managing the bus 1000 and the usual processing, and can also provide various functions including timing, peripheral interfaces, voltage regulation, power management, and other control functions.
  • the memory 1004 can be used to store data used by the processor 1001 in performing operations.
  • the processor 1001 may be a CPU, an ASIC, an FPGA, or a CPLD.
  • the second access node in the embodiment of the present invention includes:
  • the processor 1101 is configured to read a program in the memory 1104 and perform the following process:
  • an access layer authentication parameter corresponding to the user equipment sent by the local service center where the access layer authentication parameter is sent by the local service center after determining that the network bidirectional authentication with the user equipment is passed Performing bidirectional authentication of the access layer with the user equipment, and allowing the user equipment to access after determining that the access layer of the user equipment passes the two-way authentication.
  • the transceiver 1102 is configured to receive and transmit data under the control of the processor 1101.
  • the processor 1101 is specifically configured to:
  • the access layer authentication request message including the node group identifier and the access layer authentication parameter is sent to the user equipment by the transceiver 1102, so that the user equipment performs the network identification according to the access layer authentication request message. If the access layer authentication request response message including the node group identifier returned by the user equipment is received by the transceiver 1102, the user equipment is performed according to the access layer authentication request response message. Authentication.
  • the third access authentication module 802 is specifically configured to:
  • the authentication response parameter included in the access layer authentication request response message is the same as the expected response parameter in the access layer authentication parameter, it is determined that the user equipment is authenticated.
  • the interaction between the processor 1101 and the user equipment is implemented by the transceiver 1102, and the interaction between the processor 1101 and the local service center can also be implemented by the transceiver 1102.
  • the transceiver 1102 has at least two sets of transmission modes, one of which is a method of interacting with the user equipment, such as a wireless mode, and the other is a method of interacting with the local service center, such as a wireless mode or a wired mode. .
  • the local service center and the access node may be connected by wired or wireless means. Access node and use The devices are connected wirelessly.
  • bus 1100 can include any number of interconnected buses and bridges, and bus 1100 will include one or more processors represented by processor 1101 and memory represented by memory 1104. The various circuits are linked together. The bus 1100 can also link various other circuits, such as peripherals, voltage regulators, and power management circuits, as is known in the art and, therefore, will not be further described herein.
  • Bus interface 1103 provides an interface between bus 1100 and transceiver 1102.
  • the transceiver 1102 can be an element or a plurality of elements, such as a plurality of receivers and transmitters, providing means for communicating with various other devices on a transmission medium.
  • the data processed by the processor 1101 is transmitted over the wireless medium via the antenna 1105. Further, the antenna 1105 also receives the data and transmits the data to the processor 1101.
  • the processor 1101 is responsible for managing the bus 1100 and the usual processing, and can also provide various functions including timing, peripheral interfaces, voltage regulation, power management, and other control functions.
  • the memory 1104 can be used to store data used by the processor 1101 when performing operations.
  • the processor 1101 may be a CPU, an ASIC, an FPGA, or a CPLD.
  • the embodiment of the present invention further provides a method for access control.
  • the device corresponding to the method is a user equipment in the system for access control according to the embodiment of the present invention, and the method solves the problem and
  • the device is similar, so the implementation of the method can be referred to the implementation of the device, and the repeated description will not be repeated.
  • a method for access control includes:
  • Step 1201 The user equipment performs network layer bidirectional authentication with the local service center when the user equipment needs to access the network.
  • the user equipment and the corresponding access node group perform two-way authentication of the access layer, including:
  • the user equipment authenticates the network according to the access layer authentication request message that is sent by the target node in the access node group and includes the node group identifier;
  • the user equipment returns an access layer authentication request response message including the node group identifier to the target node after the authentication is passed, so that the target node responds to the access layer authentication request response message
  • the user equipment is authenticated.
  • the user equipment authenticates the network according to the access layer authentication request message that is sent by the target node in the access node group, and includes:
  • the user equipment determines to pass the network authentication.
  • the user equipment returns an access including the node group identifier to the target node after the authentication succeeds Layer authentication request response message, including:
  • the user equipment After the user equipment passes the authentication, the user equipment determines an authentication response parameter according to the random number;
  • an access layer authentication request response message that includes the node group identifier and the authentication response parameter, to the target node, according to the node group identifier and the authentication
  • the user equipment is authenticated by a response parameter.
  • the embodiment of the present invention further provides a method for access control, where the device corresponding to the method is a local service center in the system for access control according to the embodiment of the present invention, and the method solves the problem. Similar to the device, the implementation of the method can be referred to the implementation of the device, and the repeated description is not repeated.
  • a method for access control includes:
  • Step 1301 After receiving the access request message of the user equipment, the local service center performs network layer two-way authentication with the user equipment.
  • Step 1302 After determining that the two-way authentication with the user equipment network layer passes, the local service center determines an access node group corresponding to the user equipment;
  • Step 1303 The local service center notifies the access node group and the user equipment to perform two-way authentication of the access layer, so that the access node group allows the user equipment after the access layer performs two-way authentication. Access.
  • the local service center after receiving the access request message of the user equipment, and performing network layer two-way authentication with the user equipment, further includes:
  • the local service center requests, according to the context information of the user equipment in the access request message, the network layer authentication parameter corresponding to the user equipment to the network service center;
  • the local service center and the user equipment perform network layer two-way authentication, including:
  • the local service center performs network layer bidirectional authentication with the user equipment according to the network layer authentication parameter.
  • the local service center performs network layer two-way authentication with the user equipment according to the network layer authentication parameter, including:
  • the local service center sends a network layer authentication request message including a network layer authentication parameter to the user equipment, so that the user equipment authenticates the network according to the network layer authentication request message;
  • the local service center receives the network layer authentication request response message returned by the user equipment, the user equipment is authenticated according to the network layer authentication request response message.
  • the local service center performs authentication on the user equipment according to the network layer authentication request response message returned by the user equipment, including:
  • the local service center determines to authenticate the user equipment.
  • the local service center notifies the access node group and the user equipment to perform two-way authentication of the access layer, including:
  • the local service center notifies the target node to perform two-way authentication of the access layer with the user equipment.
  • the local service center notifies the target node to perform two-way authentication of the access layer with the user equipment, including:
  • the access layer authentication parameter performs bidirectional authentication with the user equipment at the access layer.
  • the local service center determines, according to the following manner, a corresponding access layer authentication parameter corresponding to the user equipment:
  • the local service center determines an access layer authentication parameter corresponding to the user equipment according to the network layer authentication parameter corresponding to the user equipment and the node group identifier.
  • an embodiment of the present invention provides a method for access control.
  • the device corresponding to the method is an access node in the system for access control according to the embodiment of the present invention, and the method solves the problem. Similar to the device, the implementation of the method can be referred to the implementation of the device, and the repeated description is not repeated.
  • a method for access control includes:
  • Step 1401 The access node receives an access layer authentication parameter corresponding to the user equipment sent by the local service center, where the access layer authentication parameter is determined by the local service center after determining the network bidirectional authentication with the user equipment.
  • Step 1402 The access node performs bidirectional authentication with the user equipment at the access layer, and allows the user equipment to access after determining that the access layer of the user equipment passes the two-way authentication.
  • the user equipment that performs the access layer and the user equipment corresponding to the access layer authentication parameter perform two-way authentication of the access layer, including:
  • the access node sends an access layer authentication request message including a node group identifier and an access layer authentication parameter to the user equipment, so that the user equipment performs the network according to the access layer authentication request message.
  • the access node receives the access layer authentication request response message that includes the node group identifier returned by the user equipment, the user equipment is authenticated according to the access layer authentication request response message.
  • the access node performs authentication on the user equipment according to the access layer authentication request response message that is sent by the user equipment, and includes:
  • the access node determines to authenticate the user equipment.
  • embodiments of the present invention can be provided as a method, system, or computer program product.
  • the present invention can be implemented in an entirely hardware embodiment, an entirely software embodiment, or in combination with software and hardware.
  • the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Power Engineering (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明实施例涉及无线通信技术领域,特别涉及一种接入控制的方法及设备,用以解决现有技术中存在用户设备无法安全地接入APG的问题。本发明实施例用户设备在需要接入网络时,用户设备与本地服务中心进行网络层双向鉴权;在网络层双向鉴权通过后,用户设备与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。由于本发明实施例采用双层双向鉴权,并在双层双向鉴权通过后,该用户设备能够接入对应的接入节点组。从而使用户设备安全地接入对应的接入节点组。

Description

一种接入控制的方法及设备
本申请要求在2016年12月21日提交中国专利局、申请号为201611193853.7、发明名称为“一种接入控制的方法及设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及无线通信技术领域,特别涉及一种接入控制的方法及设备。
背景技术
在未来的网络中,传统的大功率宏基站与大量部署的低功率小基站组成了UDN(Ultra Dense Network,超密集组网),这是解决未来无线移动通信数据速率需求问题的一种很有前景的选择。
在UDN场景中,海量的AP(Access Point,接入节点)的数量甚至可能与用户具有相当的密度。为更好的提升用户体验,提出一种UUDN(User-centric Ultra Dense Network,以用户为中心的超密集组网)方案。在UUDN场景中,将组织动态变化的APG(Access Points Group,接入节点组),跟随用户的移动无感知地为用户提供服务,即UDN/UUDN场景中每一个用户设备对应的一个APG。
在现有的移动通信系统接入网,如E-UTRAN(Evolved Universal Terrestrial Radio Access Network,演进的通用陆地无线接入网),AP由运营商在安全可信的环境中部署和维护。在用户设备需要接入E-UTRAN时,该用户设备与MME(Mobility Management Entity,移动管理实体)进行双向鉴权,在鉴权通过后,该用户设备直接接入eNB(evolved Node B,演进型基站)或HeNB(Home evolved Node B,家庭基站)。但是在UDN/UUDN场景中,AP功能多样化,部署方式灵活多样,甚至可能是用户自行部署,UDN/UUDN场景中接入网物理安全环境复杂且差异巨大。由于为用户设备提供服务的APG成员的动态性,并且一个AP可能归属于多个APG,因此,若仍然使用现有的用户设备接入控制的方法,仍不能排除非法AP假冒一个合法APG中的AP实施安全攻击地情况,将不能保证用户设备接入的安全性。显然目前用户设备直接接入eNB或HeNB的方法并不适用于UDN/UUDN场景。
综上所述,目前针对UDN/UUDN场景,还没有一种用户设备接入APG的方法。
发明内容
本发明实施例提供一种接入控制的方法及设备,用以解决现有技术中在UDN/UUDN 场景中,用户设备无法安全地接入APG的问题。
第一方面,本发明实施例提供的一种接入控制的方法,包括:
用户设备在需要接入网络时,所述用户设备与本地服务中心进行网络层双向鉴权;
在网络层双向鉴权通过后,所述用户设备与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
可选的,所述用户设备与对应的接入节点组进行接入层双向鉴权,包括:
所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;
所述用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权,包括:
所述用户设备根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;
若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则所述用户设备确定对网络鉴权通过。
可选的,所述用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,包括:
所述用户设备在鉴权通过后,根据所述随机数确定鉴权响应参数;
所述用户设备向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
第二方面,本发明实施例提供的一种接入控制的方法,包括:
本地服务中心在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
所述本地服务中心在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
所述本地服务中心通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
可选的,所述本地服务中心在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前,还包括:
所述本地服务中心根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
所述本地服务中心与所述用户设备进行网络层双向鉴权,包括:
所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
可选的,所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权,包括:
所述本地服务中心向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;
若所述本地服务中心接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述本地服务中心根据所述用户设备返回的网络层鉴权请求响应消息,对所述用户设备进行鉴权,包括:
若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,所述本地服务中心确定对所述用户设备鉴权通过。
可选的,所述本地服务中心通知所述接入节点组与所述用户设备进行接入层双向鉴权,包括:
所述本地服务中心确定所述接入节点组中的目标节点;
所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权。
可选的,所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权,包括:
所述本地服务中心将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
可选的,所述本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
所述本地服务中心从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
所述本地服务中心根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
第三方面,本发明实施例提供的一种接入控制的方法,包括:
接入节点接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
所述接入节点与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
可选的,所述接入节点与所述接入层鉴权参数对应的用户设备进行接入层双向鉴权,包括:
所述接入节点向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;
若所述接入节点接收到所述用户设备返回的包含节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
可选的,所述接入节点根据所述用户设备返回的包含节点组标识的接入层鉴权请求响应消息,对所述用户设备进行鉴权,包括:
若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,所述接入节点确定对所述用户设备鉴权通过。
第四方面、本发明实施例一种用户设备,包括:
第一网络鉴权模块,用于在需要接入网络时,与本地服务中心进行网络层双向鉴权;
第一接入鉴权模块,用于在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
可选的,所述第一接入鉴权模块,具体用于:
根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述第一接入鉴权模块,具体用于:
根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则确定对网络鉴权通过。
可选的,所述第一接入鉴权模块,具体用于:
在鉴权通过后,根据所述随机数确定鉴权响应参数;向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
第五方面、本发明实施例一种本地服务中心,包括:
第二网络鉴权模块,用于在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
通知模块,用于在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
第二接入鉴权模块,用于通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
可选的,所述第二网络鉴权模块,还用于:
在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前, 根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
所述第二网络鉴权模块,具体用于:
根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
可选的,所述第二网络鉴权模块,具体用于:
向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述第二网络鉴权模块,具体用于:
若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,确定对所述用户设备鉴权通过。
可选的,所述第二接入鉴权模块,具体用于:
确定所述接入节点组中的目标节点;通知所述目标节点与所述用户设备进行接入层双向鉴权。
可选的,所述第二接入鉴权模块,具体用于:
将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
可选的,所述第二接入鉴权模块,具体用于:
所述本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
第六方面、本发明实施例一种接入节点,包括:
接收模块,用于接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
第三接入鉴权模块,用于与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
可选的,所述第三接入鉴权模块,具体用于:
向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;若接收到所述用户设备返回的包含所述节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
可选的,所述第三接入鉴权模块,具体用于:
若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,则确定对所述用户设备鉴权通过。
本发明实施例提供的另一种用户设备,包括存储器和处理器,其中,
处理器,用于读取存储器中的程序,执行下列过程:
在需要接入网络时,与本地服务中心进行网络层双向鉴权;
在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
本申请实施例提供的另一种本地服务中心,包括存储器和处理器,其中,
处理器,用于读取存储器中的程序,执行下列过程:
接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
本申请实施例提供的另一种接入节点,包括存储器和处理器,其中,
处理器,用于读取存储器中的程序,执行下列过程:
接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
本发明实施例的接入控制的方法,用户设备在需要接入网络时,首先与本地服务中心进行网络层双向鉴权;在网络层双向鉴权通过后,用户设备与对应的接入节点组中的目标节点进行接入层双向鉴权;由于本发明实施例采用双层双向鉴权,并在双层双向鉴权通过后,该用户设备能够接入对应的接入节点组。从而使用户设备安全地接入对应的接入节点组。
附图说明
图1为本发明实施例超密集组网结构示意图;
图2为本发明实施例接入控制的系统结构示意图;
图3为本发明实施例用户设备与本地服务中心的网络层双向鉴权的流程图;
图4为本发明实施例进行接入层双向鉴权的系统结构示意图;
图5为本发明实施例用户设备与目标节点的接入层双向鉴权的流程图;
图6为本发明实施例第一种用户设备的结构示意图;
图7为本发明实施例第一种本地服务中心的结构示意图;
图8为本发明实施例第一种接入节点的结构示意图;
图9为本发明实施例第二种用户设备的结构示意图;
图10为本发明实施例第二种本地服务中心的结构示意图;
图11为本发明实施例第二种接入节点的结构示意图;
图12为本发明实施例用户设备侧接入控制的方法流程示意图;
图13为本发明实施例本地服务中心辅助用户设备侧接入控制的方法流程示意图;
图14为本发明实施例接入节点侧辅助用户设备侧接入控制的方法流程示意图。
具体实施方式
为了使本发明的目的、技术方案和优点更加清楚,下面将结合附图对本发明作进一步地详细描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本发明保护的范围。
首先对本发明实施例提供的技术方案的实施环境进行说明。
图1为超密集组网结构示意图,如图所示,网络结构中主要包括:NSC(Network Service Center,网络服务中心)、LSC(Local Service Center,本地服务中心)、若干个UE(User Equipment,用户设备)、为UE提供服务的若干个APG;其中,每个APG中包括若干个AP,同一个AP可以位于不同的APG中;每个APG对应一个节点组标识ID,每个APG对应一个UE。APG中的AP与UE通过无线连接,各AP与LSC之间通过有线连接,LSC与NSC之间通过IP网络相连。
在下面的说明过程中,先从网络侧和用户设备侧的配合实施进行说明,最后分别从网络侧与用户设备侧的实施进行说明,但这并不意味着二者必须配合实施,实际上,当网络侧与用户设备侧分开实施时,也解决了分别在网络侧、用户设备侧所存在的问题,只是二者结合使用时,会获得更好的技术效果。
如图2所示,本发明实施例接入控制的系统包括:用户设备10、本地服务中心20、至少一个接入节点30。
用户设备10、用于在需要接入网络时,与本地服务中心进行网络层双向鉴权;在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
本地服务中心20、用于在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的 接入节点组;通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
接入节点30、用于接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
本发明实施例用户设备在需要接入网络时,首先与本地服务中心进行网络层双向鉴权;在网络层双向鉴权通过后,用户设备与对应的接入节点组中的目标节点进行接入层双向鉴权;由于本发明实施例采用双层双向鉴权,并在双层双向鉴权通过后,该用户设备能够接入对应的接入节点组。从而使用户设备安全地接入对应的接入节点组。
其中,用户设备需要接入网络的时机可以是用户设备开机启动。
用户设备在需要接入网络时,用户设备通过接入节点向本地服务中心发送接入请求消息;
以用户设备开机启动后需要接入网络为例,确定转发接入请求消息的接入节点的方式包括下列中的部分或全部:
用户设备通过距离最近的接入节点发送接入请求消息;
用户设备通过信号强度最强的接入节点发送接入请求消息;
用户设备通过指定的发送接入请求消息。
本地服务中心在接收到用户设备发送的接入请求消息之后,所述本地服务中心根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数。
具体的,本地服务中心向网络服务中心发送请求鉴权参数消息,并且该请求鉴权参数消息中的包括用户设备的标识信息。
网络服务中心接收到本地服务中心发送的请求鉴权参数消息,根据请求鉴权参数消息中的包括用户设备的标识信息,生成该用户设备对应的网络层鉴权参数。
网络层鉴权参数包括:RAND(随机数)、XRES(期望响应参数)、AUTN(鉴权标记)、KLSC(临时密钥);
其中,KLSC是根据网络服务中心存储的该用户设备对应的根密钥k,以及网络层鉴权参数中的RAND确定的;并且,KLSC的作用是使本地服务中心根据该KLSC推演UE与网络进行通信时的通信密钥。
网络服务中心将生成该用户设备对应的网络层鉴权参数发送给本地服务中心,本地服务中心在本地保存接收到的用户设备对应的网络层鉴权参数。
本发明实施例在用户设备需要接入网络时,为了保证用户设备安全的接入网络,需要用户设备与网络进行双重双向鉴权。即共包括两次鉴权,分别为:用户设备与本地服务中心的网络层双向鉴权、用户设备与接入节点组的接入层双向鉴权。在上述两次鉴权分别通过后,用户设备接入对应的接入节点组。
下面对网络层双向鉴权和接入层双向鉴权分别进行说明。
一、用户设备与本地服务中心的网络层双向鉴权。
可选的,所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
所述本地服务中心向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络侧进行鉴权;若所述本地服务中心接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
需要说明的是,本地服务中心向所述用户设备发送的包含网络层鉴权参数的网络层鉴权请求消息,是通过转发接入请求消息的接入节点转发的;并且,用户设备返回的网络层鉴权请求响应消息,也是通过该接入节点转发的。
具体的,如图3所示的用户设备与本地服务中心的网络层双向鉴权的流程图。
步骤301、本地服务中心向用户设备发送包含网络层鉴权参数的网络层鉴权请求消息。
步骤302、用户设备接收并保存网络层鉴权请求消息中的网络层鉴权参数。
步骤303、用户设备根据网络层鉴权参数中的RAND确定AUTN;
步骤304、若确定的AUTN与网络层鉴权参数中的AUTN相同,用户设备确定对网络的网络层鉴权通过。
步骤305、用户设备根据网络层鉴权参数中的RAND确定RES(鉴权响应参数);
步骤306、用户设备向本地服务中心返回包含RES的网络层鉴权请求响应消息;
步骤307、若网络层鉴权请求响应消息中的RES与网络层鉴权参数中的XRES相同,则本地服务中心确定对用户设备的网络层鉴权通过。
需要说明的是,若用户设备对网络的网络层鉴权不通过,或本地服务中心对用户设备的网络层鉴权不通过,则用户设备不能接入网络。
本发明实施例的本地服务中心在确定与用户设备的网络层双向鉴权通过后,本地服务中心向网络服务中心申请,请求网络服务中心为该用户设备分配节点组标识。
本发明实施例可以采用下列方式确定用户设备对应的节点组标识:
本地服务中心向网络服务中心申请,请求网络服务中心为用户设备对应的接入节点组分配节点组标识;
具体的,网络服务中心在为用户设备对应的接入节点组分配节点组标识时,可以只将 为该接入节点组分配的节点组标识发送给本地服务中心;
或者,网络服务中心预先发送给本地服务中心一组节点组标识,在本地服务中心确定与用户设备的网络层双向鉴权通过后,从该组节点组标识中选择一个没有分配出去的节点组标识分配给用户设备。
在确定用户设备对应的节点组标识后,本地服务中心将为该用户设备分配的节点组标识通知给该用户设备。
本地服务中心在确定用户设备对应的节点组标识后,生成为用户设备提供通信服务的接入节点组。
具体的,在确定为用户设备提供通信服务的接入节点组时,可以根据下列方式中的部分或全部:
1、根据用户设备接收的各接入节点的参考信号强度,将参考信号强度最强的N个接入节点组成用户设备对应的接入节点组;
2、根据各接入节点针对用户设备产生的通信协作增益,将通信协作增益最大的N个接入节点组成用户设备对应的接入节点组;
3、根据各接入节点向本地服务中心请求加入用户设备对应的接入节点组的请求时间,将最先请求的N个接入节点组成用户设备对应的接入节点组;
4、将指定的N个接入节点组成用户设备对应的接入节点组。
需要说明的是,上述确定为用户设备提供通信服务的接入节点组的方式只是对本发明实施例的举例说明,本发明实施例想要保护的确定用户设备对应的接入节点组的方式并不限于上述举例,任何能够确定为用户设备提供通信服务的接入节点组的方式均适用于本发明。
二、用户设备与接入节点组的接入层双向鉴权。
本发明实施例中用户设备与接入节点组的接入层双向鉴权,在具体实施时,是将用户设备与接入节点组中的目标节点进行接入层双向鉴权。
可选的,所述本地服务中心确定所述接入节点组中的目标节点;所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权。
本地服务中心确定接入节点组中的目标节点的方式包括下列中的部分或全部:
方式1、将用户设备接收的接入节点组中参考信号强度最强的接入节点作为目标节点;
方式2、将接入节点组中的各接入节点针对用户设备产生的通信协作增益最大的接入节点作为目标节点;
方式3、将接入节点组中的最先请求加入该接入节点组的接入节点作为目标节点;
方式4、在接入节点组中任意指定一个接入节点作为目标节点。
需要说明的是,上述确定目标节点的方式只是对本发明实施例的举例说明,本发明实 施例想要保护的确定目标节点的方式并不限于上述举例,任何能够确定目标节点的方式均适用于本发明。
在从接入节点组中确定出目标节点之后,所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权。
可选的,所述本地服务中心将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
方式1、所述本地服务中心从网络服务中心获取所述用户设备对应的接入层鉴权参数。
具体的,本地服务中心向网络服务中心发送请求接入层鉴权参数消息,请求接入层鉴权参数消息中包含节点组标识;
网络服务中心接收到本地服务中心发送的请求接入层鉴权参数消息,根据请求接入层鉴权参数消息中包含的节点组标识,生成该用户设备对应的接入层鉴权参数。
接入层鉴权参数包括:RAND(随机数)、XRES(期望响应参数)、AUTN(鉴权标记)、KAPG(中间密钥);
其中,KAPG是根据网络服务中心存储的该用户设备对应的根密钥k,接入层鉴权参数消息中包含节点组标识APG_ID,以及网络层鉴权参数中的RAND确定的;并且,KAPG的作用是使本地服务中心根据该KAPG推演UE与网络进行通信时的通信密钥。
方式2、所述本地服务中心根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
本地服务中心根据从网络服务中心获取的网络层鉴权参数中的RAND、XRES、AUTN、KLSC,以及节点组标识APG_ID,确定所述用户设备对应的接入层鉴权参数。
具体的,根据KLSC和APG_ID,确定KAPG,将RAND、XRES、AUTN、KAPG作为接入层鉴权参数。
需要说明的是,由于本发明实施例中每个接入节点可以同时归属于不同的接入节点组,即一个接入节点可以同时为多个用户设备提供通信服务。因此,在接入节点组中的目标节点与用户设备进行接入层双向鉴权时,目标节点与用户设备之间鉴权过程中发送的消息中需要包含节点组标识,以使目标节点与用户设备进行安全且准确地鉴权。
本发明实施例的本地服务中心在将确定的接入层鉴权参数发送给目标节点时,还需要将该接入层鉴权参数对应的用户设备的标识信息发送给目标节点,以使目标节点确定需要进行接入层鉴权的用户设备。
下面具体说明用户设备与目标节点进行接入层双向鉴权的过程。
如图4所示,本发明实施例进行接入层双向鉴权的系统包括:用户设备20、目标节点40。
目标节点40、用于向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;若接收到所述用户设备返回的包含节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
用户设备10、用于根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
其中,目标节点向所述用户设备发送的接入层鉴权请求消息中包含的节点组标识APG_ID,以及接入层鉴权参数包括RAND、AUTN。
节点组标识APG_ID可以作为一个单独的参数添加在接入层鉴权请求消息中;或者,将节点组标识APG_ID与接入层鉴权参数中某个参数进行异或隐藏添加在接入层鉴权请求消息中,例如将APG_ID与AUTN进行异或隐藏。
相应地,若采用将节点组标识APG_ID与接入层鉴权参数中某个参数进行异或隐藏添加在接入层鉴权请求消息中进行传递的方式,用户设备在接收到接入层鉴权请求消息后,会从接入层鉴权参数中将节点组标识APG_ID解析出来。
用户设备与目标节点的接入层双向鉴权包括:用户设备对目标节点进行网络鉴权、目标节点对用户设备进行鉴权。
1、用户设备对目标节点进行网络鉴权。
所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;
具体的,用户设备根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则所述用户设备确定对网络鉴权通过。
即,用户设备根据接入层鉴权请求消息中的RAND确定AUTN,若用户设备确定的AUTN与接入层鉴权请求消息中的AUTN相同,则接入节点确定对网络鉴权通过。
用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
具体的,用户设备在鉴权通过后,根据所述随机数确定鉴权响应参数;所述用户设备向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消 息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
即,用户设备在对网络鉴权通过后,根据接入层鉴权参数中的RAND,确定RES(鉴权响应参数),向所述本地服务中心返回包含APG_ID和RES的接入层鉴权响应消息。
节点组标识APG_ID可以作为一个单独的参数添加在接入层鉴权响应消息中;或者,将节点组标识APG_ID与鉴权响应参数进行异或隐藏添加在接入层鉴权响应消息中,例如将APG_ID与RES进行异或隐藏。
相应地,若采用将节点组标识APG_ID与鉴权响应参数进行异或隐藏添加在接入层鉴权响应消息中进行传递的方式,本地服务中心在接收到接入层鉴权响应消息后,会从鉴权响应参数中将节点组标识APG_ID解析出来。
2、目标节点对用户设备进行鉴权。
目标节点接收到所述用户设备返回的包含所述节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,所述目标节点确定对所述用户设备鉴权通过。
具体的,目标节点判断接入层鉴权响应消息中的RES,与接入层鉴权参数中的XRES是否相同,若相同,则确定对用户设备鉴权通过。
如图5所示的用户设备与目标节点的接入层双向鉴权的流程图。
步骤501、目标节点向用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息。
步骤502、用户设备接收并保存接入层鉴权请求消息中的接入层鉴权参数。
步骤503、用户设备根据接入层鉴权请求消息中的RAND确定AUTN。
步骤504、若确定的AUTN与接入层鉴权参数中的AUTN相同,用户设备确定对网络鉴权通过。
步骤505、用户设备根据接入层鉴权参数中的RAND确定RES。
步骤506、用户设备用户设备向目标节点返回包含节点组标识和所述RES的接入层鉴权请求响应消息。
步骤507、目标节点在确定接入层鉴权请求响应消息中包含的鉴权响应参数与所述接入层鉴权参数中的期望响应参数相同后,确定对所述用户设备鉴权通过。
其中,本发明实施例的接入节点可以是基站(比如宏基站、家庭基站等),还可以是其它节点。
如图6所示,本发明实施例一种用户设备包括:
第一网络鉴权模块601,用于在需要接入网络时,与本地服务中心进行网络层双向鉴 权;
第一接入鉴权模块602,用于在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
可选的,所述第一接入鉴权模块602,具体用于:
根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述第一接入鉴权模块602,具体用于:
根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则确定对网络鉴权通过。
可选的,所述第一接入鉴权模块602,具体用于:
在鉴权通过后,根据所述随机数确定鉴权响应参数;向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
如图7所示、本发明实施例一种本地服务中心包括:
第二网络鉴权模块701,用于在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
通知模块702,用于在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
第二接入鉴权模块703,用于通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
可选的,所述第二网络鉴权模块701,还用于:
在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前,根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
所述第二网络鉴权模块701,具体用于:
根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
可选的,所述第二网络鉴权模块701,具体用于:
向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述第二网络鉴权模块701,具体用于:
若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,确定对所述用户设备鉴权通过。
可选的,所述第二接入鉴权模块703,具体用于:
确定所述接入节点组中的目标节点;通知所述目标节点与所述用户设备进行接入层双向鉴权。
可选的,所述第二接入鉴权模块703,具体用于:
将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
可选的,所述第二接入鉴权模块703,具体用于:
所述本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
如图8所示,本发明实施例一种接入节点包括:
接收模块801,用于接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
第三接入鉴权模块802,用于与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
可选的,所述第三接入鉴权模块802,具体用于:
向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;若接收到所述用户设备返回的包含所述节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
可选的,所述第三接入鉴权模块802,具体用于:
若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,则确定对所述用户设备鉴权通过。
如图9所示,本发明实施例第二种用户设备包括:
处理器901,用于读取存储器904中的程序,执行下列过程:
在需要接入网络时,与本地服务中心进行网络层双向鉴权;在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备 接入到对应的接入节点组中。
收发机902,用于在处理器901的控制下接收和发送数据。
可选的,所述处理器901,具体用于:
根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;在鉴权通过后通过收发机902向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述处理器901,具体用于:
根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则确定对网络鉴权通过。
可选的,所述处理器901,具体用于:
在鉴权通过后,根据所述随机数确定鉴权响应参数;通过收发机902向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
在实施中,处理器901和本地服务中心、接入节点之间的交互都是通过收发机902实现的,在此不再分别进行描述。
在图9中,总线架构(用总线900来代表),总线900可以包括任意数量的互联的总线和桥,总线900将包括由通用处理器901代表的一个或多个处理器和存储器904代表的存储器的各种电路链接在一起。总线900还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口903在总线900和收发机902之间提供接口。收发机902可以是一个元件,也可以是多个元件,比如多个接收器和发送器,提供用于在传输介质上与各种其他装置通信的单元。例如:收发机902从其他设备接收外部数据。收发机902用于将处理器901处理后的数据发送给其他设备。取决于计算系统的性质,还可以提供用户接口905,例如小键盘、显示器、扬声器、麦克风、操纵杆。
处理器901负责管理总线900和通常的处理,如前述所述运行通用操作系统。而存储器904可以被用于存储处理器901在执行操作时所使用的数据。
可选的,处理器901可以是CPU(中央处埋器)、ASIC(Application Specific Integrated Circuit,专用集成电路)、FPGA(Field-Programmable Gate Array,现场可编程门阵列)或CPLD(Complex Programmable Logic Device,复杂可编程逻辑器件)。
如图10所示,本发明实施例第二种本地服务中心包括:
处理器1001,用于读取存储器1004中的程序,执行下列过程:
接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;在确定与 所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;通过收发机1002通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
收发机1002,用于在处理器1001的控制下接收和发送数据。
可选的,所述处理器1001,还用于:
在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前,根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
所述处理器1001,具体用于:
根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
可选的,所述处理器1001,具体用于:
向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述处理器1001,具体用于:
若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,确定对所述用户设备鉴权通过。
可选的,所述处理器1001,具体用于:
确定所述接入节点组中的目标节点;通知所述目标节点与所述用户设备进行接入层双向鉴权。
可选的,所述处理器1001,具体用于:
将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
可选的,所述处理器1001,具体用于:
所述本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
在实施中,处理器1001和用户设备之间的交互是通过收发机1002和接入节点实现的,即处理器1001通过收发机1002将需要发送给用户设备的信息发送给接入节点,由接入节点发送给用户设备;接入节点在收到来自用户设备的需要发送给本地服务中心的信息后,将该信息发送给本地服务中心,处理器1001通过收发机1002接收该信息。
其中,本地服务中心和接入节点之间可以通过有线、无线等方式连接。
在图10中,总线架构(用总线1000来代表),总线1000可以包括任意数量的互联的总线和桥,总线1000将包括由处理器1001代表的一个或多个处理器和存储器1004代表的存储器的各种电路链接在一起。总线1000还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口1003在总线1000和收发机1002之间提供接口。收发机1002可以是一个元件,也可以是多个元件,比如多个接收器和发送器,提供用于在传输介质上与各种其他装置通信的单元。经处理器1001处理的数据通过天线1005在无线介质上进行传输,进一步,天线1005还接收数据并将数据传送给处理器1001。
处理器1001负责管理总线1000和通常的处理,还可以提供各种功能,包括定时,外围接口,电压调节、电源管理以及其他控制功能。而存储器1004可以被用于存储处理器1001在执行操作时所使用的数据。
可选的,处理器1001可以是CPU、ASIC、FPGA或CPLD。
如图11所示,本发明实施例第二种接入节点包括:
处理器1101,用于读取存储器1104中的程序,执行下列过程:
通过收发机1102接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
收发机1102,用于在处理器1101的控制下接收和发送数据。
可选的,所述处理器1101,具体用于:
通过收发机1102向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;若通过收发机1102接收到所述用户设备返回的包含所述节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
可选的,所述第三接入鉴权模块802,具体用于:
若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,则确定对所述用户设备鉴权通过。
在实施中,处理器1101和用户设备之间的交互是通过收发机1102实现的,处理器1101和本地服务中心之间的交互也可以通过收发机1102实现。收发机1102有至少两套传输方式,其中一套是与用户设备进行交互使用的方式,比如可以是无线方式;另一套是与本地服务中心进行交互使用的方式,比如无线方式、有线方式等。
其中,本地服务中心和接入节点之间可以通过有线、无线等方式连接。接入节点和用 户设备之间通过无线方式连接。
在图11中,总线架构(用总线1100来代表),总线1100可以包括任意数量的互联的总线和桥,总线1100将包括由处理器1101代表的一个或多个处理器和存储器1104代表的存储器的各种电路链接在一起。总线1100还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口1103在总线1100和收发机1102之间提供接口。收发机1102可以是一个元件,也可以是多个元件,比如多个接收器和发送器,提供用于在传输介质上与各种其他装置通信的单元。经处理器1101处理的数据通过天线1105在无线介质上进行传输,进一步,天线1105还接收数据并将数据传送给处理器1101。
处理器1101负责管理总线1100和通常的处理,还可以提供各种功能,包括定时,外围接口,电压调节、电源管理以及其他控制功能。而存储器1104可以被用于存储处理器1101在执行操作时所使用的数据。
可选的,处理器1101可以是CPU、ASIC、FPGA或CPLD。
基于同一发明构思,本发明实施例中还提供了一种接入控制的方法,由于该方法对应的设备是本发明实施例接入控制的系统中的用户设备,并且该方法解决问题的原理与该设备相似,因此该方法的实施可以参见设备的实施,重复之处不再赘述。
如图12所示,本发明实施例一种接入控制的方法包括:
步骤1201、用户设备在需要接入网络时,所述用户设备与本地服务中心进行网络层双向鉴权;步骤1202、在网络层双向鉴权通过后,所述用户设备与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
可选的,所述用户设备与对应的接入节点组进行接入层双向鉴权,包括:
所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;
所述用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权,包括:
所述用户设备根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;
若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则所述用户设备确定对网络鉴权通过。
可选的,所述用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入 层鉴权请求响应消息,包括:
所述用户设备在鉴权通过后,根据所述随机数确定鉴权响应参数;
所述用户设备向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
基于同一发明构思,本发明实施例中还提供了一种接入控制的方法,由于该方法对应的设备是本发明实施例接入控制的系统中的本地服务中心,并且该方法解决问题的原理与该设备相似,因此该方法的实施可以参见设备的实施,重复之处不再赘述。
如图13所示,本发明实施例提供的一种接入控制的方法包括:
步骤1301、本地服务中心在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
步骤1302、所述本地服务中心在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
步骤1303、所述本地服务中心通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
可选的,所述本地服务中心在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前,还包括:
所述本地服务中心根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
所述本地服务中心与所述用户设备进行网络层双向鉴权,包括:
所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
可选的,所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权,包括:
所述本地服务中心向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;
若所述本地服务中心接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
可选的,所述本地服务中心根据所述用户设备返回的网络层鉴权请求响应消息,对所述用户设备进行鉴权,包括:
若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,所述本地服务中心确定对所述用户设备鉴权通过。
可选的,所述本地服务中心通知所述接入节点组与所述用户设备进行接入层双向鉴权,包括:
所述本地服务中心确定所述接入节点组中的目标节点;
所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权。
可选的,所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权,包括:
所述本地服务中心将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
可选的,所述本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
所述本地服务中心从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
所述本地服务中心根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
基于同一发明构思,本发明实施例中还提供了一种接入控制的方法,由于该方法对应的设备是本发明实施例接入控制的系统中的接入节点,并且该方法解决问题的原理与该设备相似,因此该方法的实施可以参见设备的实施,重复之处不再赘述。
如图14所示,本发明实施例提供的一种接入控制的方法包括:
步骤1401、接入节点接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
步骤1402、所述接入节点与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
可选的,所述接入节点与所述接入层鉴权参数对应的用户设备进行接入层双向鉴权,包括:
所述接入节点向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;
若所述接入节点接收到所述用户设备返回的包含节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
可选的,所述接入节点根据所述用户设备返回的包含节点组标识的接入层鉴权请求响应消息,对所述用户设备进行鉴权,包括:
若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,所述接入节点确定对所述用户设备鉴权通过。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实 施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本发明的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本发明范围的所有变更和修改。
显然,本领域的技术人员可以对本发明实施例进行各种改动和变型而不脱离本发明实施例的精神和范围。这样,倘若本发明实施例的这些修改和变型属于本发明权利要求及其等同技术的范围之内,则本发明也意图包含这些改动和变型在内。

Claims (31)

  1. 一种接入控制的方法,其特征在于,该方法包括:
    用户设备在需要接入网络时,所述用户设备与本地服务中心进行网络层双向鉴权;
    在网络层双向鉴权通过后,所述用户设备与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
  2. 如权利要求1所述的方法,其特征在于,所述用户设备与对应的接入节点组进行接入层双向鉴权,包括:
    所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;
    所述用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
  3. 如权利要求2所述的方法,其特征在于,所述用户设备根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权,包括:
    所述用户设备根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;
    若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则所述用户设备确定对网络鉴权通过。
  4. 如权利要求3所述的方法,其特征在于,所述用户设备在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,包括:
    所述用户设备在鉴权通过后,根据所述随机数确定鉴权响应参数;
    所述用户设备向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
  5. 一种接入控制的方法,其特征在于,该方法包括:
    本地服务中心在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
    所述本地服务中心在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
    所述本地服务中心通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
  6. 如权利要求5所述的方法,其特征在于,所述本地服务中心在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前,还包括:
    所述本地服务中心根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
    所述本地服务中心与所述用户设备进行网络层双向鉴权,包括:
    所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
  7. 如权利要求6所述的方法,其特征在于,所述本地服务中心根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权,包括:
    所述本地服务中心向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;
    若所述本地服务中心接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
  8. 如权利要求7所述的方法,其特征在于,所述本地服务中心根据所述用户设备返回的网络层鉴权请求响应消息,对所述用户设备进行鉴权,包括:
    若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,所述本地服务中心确定对所述用户设备鉴权通过。
  9. 如权利要求5所述的方法,其特征在于,所述本地服务中心通知所述接入节点组与所述用户设备进行接入层双向鉴权,包括:
    所述本地服务中心确定所述接入节点组中的目标节点;
    所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权。
  10. 如权利要求9所述的方法,其特征在于,所述本地服务中心通知所述目标节点与所述用户设备进行接入层双向鉴权,包括:
    所述本地服务中心将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
  11. 如权利要求10所述的方法,其特征在于,所述本地服务中心根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
    所述本地服务中心从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
    所述本地服务中心根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备对应的接入层鉴权参数。
  12. 一种接入控制的方法,其特征在于,该方法包括:
    接入节点接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
    所述接入节点与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
  13. 如权利要求12所述的方法,其特征在于,所述接入节点与所述接入层鉴权参数对应的用户设备进行接入层双向鉴权,包括:
    所述接入节点向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;
    若所述接入节点接收到所述用户设备返回的包含所述节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
  14. 如权利要求13所述的方法,其特征在于,所述接入节点根据所述用户设备返回的包含节点组标识的接入层鉴权请求响应消息,对所述用户设备进行鉴权,包括:
    若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,所述接入节点确定对所述用户设备鉴权通过。
  15. 一种用户设备,其特征在于,包括:
    第一网络鉴权模块,用于在需要接入网络时,与本地服务中心进行网络层双向鉴权;
    第一接入鉴权模块,用于在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
  16. 如权利要求15所述的用户设备,其特征在于,所述第一接入鉴权模块,具体用于:
    根据所述接入节点组中的目标节点发送的包含节点组标识的接入层鉴权请求消息,对网络进行鉴权;在鉴权通过后向所述目标节点返回包含所述节点组标识的接入层鉴权请求响应消息,以使所述目标节点根据所述接入层鉴权请求响应消息对所述用户设备进行鉴权。
  17. 如权利要求16所述的用户设备,其特征在于,所述第一接入鉴权模块,具体用于:
    根据所述接入层鉴权请求消息中的随机数确定第二鉴权标记;若所述第二鉴权标记与所述接入层鉴权请求消息中的第一鉴权标记相同,则确定对网络鉴权通过。
  18. 如权利要求17所述的用户设备,其特征在于,所述第一接入鉴权模块,具体用于:
    在鉴权通过后,根据所述随机数确定鉴权响应参数;向所述目标节点返回包含所述节点组标识和所述鉴权响应参数的接入层鉴权请求响应消息,以使所述目标节点根据所述节点组标识和所述鉴权响应参数对所述用户设备进行鉴权。
  19. 一种本地服务中心,其特征在于,包括:
    第二网络鉴权模块,用于在接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
    通知模块,用于在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对 应的接入节点组;
    第二接入鉴权模块,用于通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
  20. 如权利要求19所述的本地服务中心,其特征在于,所述第二网络鉴权模块,还用于:
    在接收到用户设备的接入请求消息之后,与所述用户设备进行网络层双向鉴权之前,根据所述接入请求消息中的用户设备的上下文信息,向网络服务中心请求所述用户设备对应的网络层鉴权参数;
    所述第二网络鉴权模块,具体用于:
    根据所述网络层鉴权参数,与所述用户设备进行网络层双向鉴权。
  21. 如权利要求20所述的本地服务中心,其特征在于,所述第二网络鉴权模块,具体用于:
    向所述用户设备发送包含网络层鉴权参数的网络层鉴权请求消息,以使所述用户设备根据所述网络层鉴权请求消息对网络进行鉴权;接收到所述用户设备返回的网络层鉴权请求响应消息,则根据所述网络层鉴权请求响应消息对所述用户设备进行鉴权。
  22. 如权利要求21所述的本地服务中心,其特征在于,所述第二网络鉴权模块,具体用于:
    若所述网络层鉴权请求响应消息中包含的鉴权响应参数与所述网络层鉴权参数中的期望响应参数相同,确定对所述用户设备鉴权通过。
  23. 如权利要求19所述的本地服务中心,其特征在于,所述第二接入鉴权模块,具体用于:
    确定所述接入节点组中的目标节点;通知所述目标节点与所述用户设备进行接入层双向鉴权。
  24. 如权利要求23所述的本地服务中心,其特征在于,所述第二接入鉴权模块,具体用于:
    将所述接入节点组对应的节点组标识和所述用户设备对应的接入层鉴权参数发送给所述目标节点,以使所述目标节点根据所述节点组标识和所述接入层鉴权参数,与所述用户设备进行接入层双向鉴权。
  25. 如权利要求24所述的本地服务中心,其特征在于,所述第二接入鉴权模块,具体用于:
    根据下列方式确定所述用户设备对应的对应的接入层鉴权参数:
    从网络服务中心获取所述用户设备对应的接入层鉴权参数;或
    根据所述用户设备对应的网络层鉴权参数,以及所述节点组标识,确定所述用户设备 对应的接入层鉴权参数。
  26. 一种接入节点,其特征在于,包括:
    接收模块,用于接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
    第三接入鉴权模块,用于与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通过后,允许所述用户设备接入。
  27. 如权利要求26所述的接入节点,其特征在于,所述第三接入鉴权模块,具体用于:
    向所述用户设备发送包含节点组标识和接入层鉴权参数的接入层鉴权请求消息,以使所述用户设备根据所述接入层鉴权请求消息对网络进行鉴权;若接收到所述用户设备返回的包含所述节点组标识的接入层鉴权请求响应消息,则根据所述接入层鉴权请求响应消息,对所述用户设备进行鉴权。
  28. 如权利要求27所述的接入节点,其特征在于,所述第三接入鉴权模块,具体用于:
    若所述接入层鉴权请求响应消息中包含的鉴权响应参数,与所述接入层鉴权参数中的期望响应参数相同,则确定对所述用户设备鉴权通过。
  29. 一种用户设备,其特征在于,包括存储器和处理器,其中,
    处理器,用于读取存储器中的程序,执行下列过程:
    在需要接入网络时,与本地服务中心进行网络层双向鉴权;
    在网络层双向鉴权通过后,与对应的接入节点组进行接入层双向鉴权,以便在接入层双向鉴权通过后使所述用户设备接入到对应的接入节点组中。
  30. 一种本地服务中心,其特征在于,包括存储器和处理器,其中,
    处理器,用于读取存储器中的程序,执行下列过程:
    接收到用户设备的接入请求消息后,与所述用户设备进行网络层双向鉴权;
    在确定与所述用户设备网络层双向鉴权通过后,确定所述用户设备对应的接入节点组;
    通知所述接入节点组与所述用户设备进行接入层双向鉴权,以使所述接入节点组在接入层双向鉴权通过后允许所述用户设备接入。
  31. 一种接入节点,其特征在于,包括存储器和处理器,其中,
    处理器,用于读取存储器中的程序,执行下列过程:
    接收本地服务中心发送的用户设备对应的接入层鉴权参数,其中所述接入层鉴权参数是所述本地服务中心在确定与用户设备的网络双向鉴权通过后发送的;
    与所述用户设备进行接入层双向鉴权,并在确定与所述用户设备的接入层双向鉴权通 过后,允许所述用户设备接入。
PCT/CN2017/099523 2016-12-21 2017-08-29 一种接入控制的方法及设备 WO2018113338A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP17885077.2A EP3562186A4 (en) 2016-12-21 2017-08-29 ACCESS CONTROL METHOD AND DEVICE
US16/472,728 US11405783B2 (en) 2016-12-21 2017-08-29 Access control method and device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201611193853.7A CN108235317B (zh) 2016-12-21 2016-12-21 一种接入控制的方法及设备
CN201611193853.7 2016-12-21

Publications (1)

Publication Number Publication Date
WO2018113338A1 true WO2018113338A1 (zh) 2018-06-28

Family

ID=62624644

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/099523 WO2018113338A1 (zh) 2016-12-21 2017-08-29 一种接入控制的方法及设备

Country Status (5)

Country Link
US (1) US11405783B2 (zh)
EP (1) EP3562186A4 (zh)
CN (1) CN108235317B (zh)
TW (1) TWI685267B (zh)
WO (1) WO2018113338A1 (zh)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101951027B1 (ko) * 2018-01-04 2019-02-22 엔쓰리엔 주식회사 무선 액세스 포인트에서의 라이선스 인증 방법, 라이선스 인증을 수행하는 무선 액세스 포인트 장치, 클라이언트 장치의 라이선스 활성화 방법, 및 무선 액세스 포인트와 연동하는 클라이언트 장치
CN111294846B (zh) * 2018-12-07 2022-04-12 华为技术有限公司 一种接入网设备通信功能测试方法、装置及系统
CN116156500A (zh) * 2021-11-23 2023-05-23 大唐移动通信设备有限公司 设备鉴权方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102625307A (zh) * 2011-01-31 2012-08-01 电信科学技术研究院 一种无线网络接入系统
KR20140111513A (ko) * 2013-03-11 2014-09-19 삼성전자주식회사 무선 통신 방법 및 장치
CN104852896A (zh) * 2015-02-03 2015-08-19 四川通信科研规划设计有限责任公司 一种Wi-Fi无线节点入网方法及系统
CN105245338A (zh) * 2014-05-26 2016-01-13 中兴通讯股份有限公司 一种认证方法及装置系统

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8260259B2 (en) * 2004-09-08 2012-09-04 Qualcomm Incorporated Mutual authentication with modified message authentication code
KR100762644B1 (ko) * 2004-12-14 2007-10-01 삼성전자주식회사 Wlan-umts 연동망 시스템과 이를 위한 인증 방법
DE202005021930U1 (de) * 2005-08-01 2011-08-08 Corning Cable Systems Llc Faseroptische Auskoppelkabel und vorverbundene Baugruppen mit Toning-Teilen
WO2007062689A1 (en) * 2005-12-01 2007-06-07 Telefonaktiebolaget Lm Ericsson (Publ) Method and apparatus for distributing keying information
CN106131081A (zh) * 2010-12-30 2016-11-16 交互数字专利控股公司 从应用服务器接入服务的方法及移动装置
WO2013165605A1 (en) * 2012-05-02 2013-11-07 Interdigital Patent Holdings, Inc. One round trip authentication using single sign-on systems
WO2015096138A1 (zh) 2013-12-27 2015-07-02 华为技术有限公司 分流方法、用户设备、基站和接入点
WO2016015749A1 (en) * 2014-07-28 2016-02-04 Telefonaktiebolaget L M Ericsson (Publ) Authentication in a wireless communications network
CN107018676B (zh) * 2015-01-09 2021-06-25 三星电子株式会社 用户设备与演进分组核心之间的相互认证
CN105451250B (zh) * 2015-09-01 2017-07-11 电信科学技术研究院 一种网络接入点动态组网方法及设备
US9883385B2 (en) * 2015-09-15 2018-01-30 Qualcomm Incorporated Apparatus and method for mobility procedure involving mobility management entity relocation
CN105516961B (zh) * 2015-12-09 2019-08-16 上海斐讯数据通信技术有限公司 基于无感知认证的控制方法和系统
EP3208222B1 (en) * 2016-02-18 2020-06-17 Otis Elevator Company Anonymous and ephemeral tokens to authenticate elevator calls

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102625307A (zh) * 2011-01-31 2012-08-01 电信科学技术研究院 一种无线网络接入系统
KR20140111513A (ko) * 2013-03-11 2014-09-19 삼성전자주식회사 무선 통신 방법 및 장치
CN105245338A (zh) * 2014-05-26 2016-01-13 中兴通讯股份有限公司 一种认证方法及装置系统
CN104852896A (zh) * 2015-02-03 2015-08-19 四川通信科研规划设计有限责任公司 一种Wi-Fi无线节点入网方法及系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3562186A4

Also Published As

Publication number Publication date
EP3562186A4 (en) 2019-12-11
CN108235317B (zh) 2019-06-21
EP3562186A1 (en) 2019-10-30
TW201824900A (zh) 2018-07-01
US20200196150A1 (en) 2020-06-18
US11405783B2 (en) 2022-08-02
TWI685267B (zh) 2020-02-11
CN108235317A (zh) 2018-06-29

Similar Documents

Publication Publication Date Title
US10904753B2 (en) Systems and methods for authentication
EP3668042B1 (en) Registration method and apparatus based on service-oriented architecture
KR102354626B1 (ko) 연결 재개 요청 방법 및 장치
JP5079853B2 (ja) 無線アクセスポイント間での安全なローミング
US20160242033A1 (en) Communication service using method and electronic device supporting the same
CN101785343B (zh) 用于快速转换资源协商的方法、系统和装置
CN110505627B (zh) 一种基于接入节点组的认证方法及装置
CN107211272A (zh) 方法、装置和系统
US20220174482A1 (en) Establishing a protocol data unit session
KR102600917B1 (ko) 고정 네트워크 가정용 게이트웨이들에 대한 인증 결정
CN111182546B (zh) 接入无线网络的方法、设备及系统
KR102119586B1 (ko) 통신 네트워크를 통해 데이터를 릴레이하는 시스템 및 방법
CN112512045A (zh) 一种通信系统、方法及装置
WO2018113338A1 (zh) 一种接入控制的方法及设备
WO2018113402A1 (zh) 一种加入接入节点组的方法及设备
WO2019122495A1 (en) Authentication for wireless communications system
CN116723507B (zh) 针对边缘网络的终端安全方法及装置
CN116528234B (zh) 一种虚拟机的安全可信验证方法及装置
WO2023072275A1 (zh) 通信方法、装置及系统
CN117641311A (zh) 通信方法和通信装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17885077

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2017885077

Country of ref document: EP

Effective date: 20190722