WO2022089583A1 - 一种认证信息获取方法、装置、相关设备和存储介质 - Google Patents

一种认证信息获取方法、装置、相关设备和存储介质 Download PDF

Info

Publication number
WO2022089583A1
WO2022089583A1 PCT/CN2021/127435 CN2021127435W WO2022089583A1 WO 2022089583 A1 WO2022089583 A1 WO 2022089583A1 CN 2021127435 W CN2021127435 W CN 2021127435W WO 2022089583 A1 WO2022089583 A1 WO 2022089583A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
network device
request message
user equipment
authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2021/127435
Other languages
English (en)
French (fr)
Inventor
黄晓婷
王珂
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, Research Institute of China Mobile Communication Co Ltd filed Critical China Mobile Communications Group Co Ltd
Publication of WO2022089583A1 publication Critical patent/WO2022089583A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0807Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/141Setup of application sessions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present application relates to the field of wireless communication technologies, and in particular, to a method, apparatus, related equipment and storage medium for obtaining authentication information.
  • Non-Public Network is a network that can provide services for specific users.
  • NPN Non-Public Network
  • the terminal can obtain the certificate in the following two ways: one is to write the certificate into the chip or user card of the terminal when the terminal leaves the factory; the other is to input the certificate password by the user through the interactive interface.
  • the first method above cannot guarantee security, and it is easy to leak credentials during the production process. In addition, it lacks flexibility. The credentials cannot be modified, updated, and replaced after the terminal appears.
  • the second method above is not applicable to terminals without an interactive interface, and cannot perform interactive input operations.
  • Embodiments of the present application provide a method, apparatus, related device, and storage medium for obtaining authentication information.
  • an embodiment of the present application provides a method for obtaining authentication information, the method comprising:
  • the network device receives a first request message from the user equipment, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • the network device obtains a first key corresponding to the key identifier from the core network device, and sends a first response message corresponding to the first request message to the user equipment, where the first response message is used to indicate The user equipment generates the first key accordingly;
  • the network device establishes a channel with the user equipment based on the first key, and sends authentication information for performing secondary authentication or slice authentication on a non-public network to the user equipment through the channel.
  • the network device obtains the first key corresponding to the key identifier from the core network device, including:
  • the network device receives a second response message corresponding to the second request message sent by the core network device; the second response message includes the first key corresponding to the key identifier.
  • the non-public network is a non-public network integrated with a public network (PNI-NPN).
  • PNI-NPN public network
  • an embodiment of the present application further provides a method for obtaining authentication information, the method comprising:
  • the user equipment sends a first request message to the network device, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • the user equipment generates the first key according to the pre-obtained second key, establishes a channel with the network device based on the first key, and receives the authentication information sent by the network device through the channel.
  • the authentication information is used for secondary authentication or slice authentication of non-public networks.
  • the method before the user equipment sends the first request message to the network device, the method further includes: after the user equipment completes initial network authentication, obtaining the second key and the the key ID.
  • the method further includes: performing, by the user equipment, secondary authentication or slice authentication of a non-public network based on the authentication information.
  • the non-public network is a non-public network integrated with a public network (PNI-NPN).
  • PNI-NPN public network
  • an embodiment of the present application further provides a method for obtaining authentication information, the method comprising:
  • the core network device receives the second request message sent by the network device, where the second request message includes a key identifier, and the key identifier is the key identifier carried in the first request message sent by the user equipment to the network device ; the first request message is used by the user equipment to request access to the network device;
  • the core network device generates a first key according to the second key corresponding to the key identifier, and sends a second response message to the network device, where the second response message includes the first key.
  • an embodiment of the present application further provides an authentication information acquisition device, the device includes: a first receiving unit, a first obtaining unit, a first channel establishing unit, and a first sending unit; wherein,
  • the first receiving unit is configured to receive a first request message from the user equipment, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • the first obtaining unit is configured to obtain a first key corresponding to the key identifier from a core network device, and send a first response message corresponding to the first request message to the user equipment.
  • the response message is used to instruct the user equipment to generate the first key accordingly;
  • the first channel establishing unit configured to establish a channel with the user equipment based on the first key
  • the first sending unit is configured to send, to the user equipment through the channel, authentication information for performing secondary authentication or slice authentication on a non-public network.
  • the first obtaining unit is configured to send a second request message for requesting the first key to the core network device through the first sending unit, so The second request message includes the key identifier; the second response message corresponding to the second request message sent by the core network device is received by the first receiving unit; the second response message includes the The key identifies the corresponding first key.
  • the non-public network is a non-public network integrated with a public network (PNI-NPN).
  • PNI-NPN public network
  • an embodiment of the present application further provides a device for obtaining authentication information, the device includes: a second sending unit, a second receiving unit, a generating unit, and a second channel establishing unit; wherein,
  • the second sending unit is configured to send a first request message to a network device, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • the second receiving unit is configured to receive a first response message corresponding to the first request message sent by the network device, where the first response message is used to instruct the user equipment to generate a first key accordingly;
  • the generating unit configured to generate the first key according to the second key obtained in advance
  • the second channel establishment unit configured to establish a channel with the network device based on the first key
  • the second receiving unit is further configured to receive authentication information sent by the network device through the channel, where the authentication information is used to perform secondary authentication or slice authentication on a non-public network.
  • the apparatus further includes a second obtaining unit, configured to obtain the second key and the key identifier after completing initial network authentication.
  • the apparatus further includes an authentication unit configured to perform secondary authentication or slice authentication of a non-public network based on the authentication information.
  • the non-public network is a non-public network integrated with a public network (PNI-NPN).
  • PNI-NPN public network
  • an embodiment of the present application further provides a device for obtaining authentication information, the device includes: a third receiving unit and a third sending unit; wherein,
  • the third receiving unit is configured to receive a second request message sent by the network device, where the second request message includes a key identifier, and the key identifier is the first request message sent by the user equipment to the network device The key identifier carried in; the first request message is used by the user equipment to request access to the network device;
  • the third sending unit is configured to generate a first key according to the second key corresponding to the key identifier, and send a second response message to the network device, where the second response message includes the first key key.
  • an embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, implements the aforementioned first aspect, second aspect or third aspect of the embodiment of the present application the steps of the method.
  • an embodiment of the present application further provides a communication device, including a memory, a processor, and a computer program stored in the memory and running on the processor, and the processor implements the implementation of the present application when the processor executes the program Examples are the steps of the method described in the first aspect, the second aspect or the third aspect.
  • the authentication information acquisition method, apparatus, related device, and storage medium include: a network device receives a first request message from a user equipment, where the first request message is used to request access to the network device; the first request message includes a key identifier; the network device obtains a first key corresponding to the key identifier from a core network device, and sends the first request message corresponding to the key identifier to the user equipment
  • the first response message is used to instruct the user equipment to generate the first key accordingly;
  • the network device establishes a channel with the user equipment based on the first key, and uses the The channel sends authentication information for performing secondary authentication or slice authentication on a non-public network to the user equipment.
  • the first key used to establish the channel is obtained through information exchange between the network device and the core network device, and the user equipment is instructed to generate the first key.
  • a channel is established based on the first key, so as to ensure the issuance of authentication information, without presetting authentication information in the terminal, ensuring the security of authentication information and improving the flexibility of issuing authentication information; and there is no need to manually pass through the interactive interface.
  • Enter authentication information suitable for various types of terminals.
  • FIG. 1 is a schematic diagram of a system architecture to which a method for obtaining authentication information according to an embodiment of the present application is applied;
  • FIG. 2 is a schematic flowchart 1 of a method for obtaining authentication information according to an embodiment of the present application
  • FIG. 3 is a second schematic flowchart of a method for obtaining authentication information according to an embodiment of the present application
  • FIG. 4 is a third schematic flowchart of a method for obtaining authentication information according to an embodiment of the application.
  • FIG. 5 is a schematic diagram of an interaction flow of a method for obtaining authentication information according to an embodiment of the present application
  • FIG. 6 is a schematic diagram 1 of the composition structure of the authentication information acquisition apparatus according to the embodiment of the application.
  • FIG. 7 is a second schematic diagram of the composition and structure of an authentication information acquisition apparatus according to an embodiment of the present application.
  • FIG. 8 is a schematic diagram 3 of the composition structure of the authentication information obtaining apparatus according to the embodiment of the application.
  • FIG. 9 is a schematic diagram of a hardware structure of a communication device according to an embodiment of the present application.
  • FIG. 1 is a schematic diagram of a system architecture of an application of an authentication information acquisition method according to an embodiment of the present application; as shown in FIG. 1 , the system may include: user equipment (UE, User Equipment), access network equipment, and core network equipment;
  • the network equipment is represented by a radio access network (RAN, Radio Access Network) or an access network (AN, Access Network) in the figure, and the access network equipment is represented by (R)AN in the figure.
  • RAN Radio Access Network
  • AN Access Network
  • the core network equipment is represented by the 5G core network (5GC) in the figure, and may include at least one of the following equipment: User Plane Function (UPF, User Plane Function), Access and Mobility Management Function (AMF, Access and Mobility Management Function) , Session Management Function (SMF, Session Management Function), Policy Control Function (PCF, Policy Control Function), Unified Data Management Function (UDM, Unified Data Management), Authentication Service Function (AUSF, Authentication Server Function), Network Open Function (NEF, Network Exposure Function), application-oriented authentication or key management (AKMA, Authentication and Key Management for Applications) anchor network elements (AAnF, AKMA Anchor Function) and network slice specific authentication and authorization functions (NSSAAF, Network Slice-Specific Authentication and Authorization Function).
  • UPF User Plane Function
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • PCF Policy Control Function
  • UDM Unified Data Management Function
  • AUSF Authentication Server Function
  • NEF Network Exposure Function
  • AKMA Authentic
  • the system also includes a PNI-NPN provisioning server (PNI-NPN provisioning server) for storing and delivering authentication information (such as credentials) used for secondary authentication and/or slice authentication of non-public networks.
  • PNI-NPN provisioning server PNI-NPN provisioning server
  • the PNI-NPN configuration server is connected to the AAnF through the NEF in the 5G core network to obtain a key derived based on the operator's credentials, which is used to establish the PNI-NPN configuration server.
  • a secure channel between the NPN configuration server and the UE the secure channel can be used by the PNI-NPN configuration server to send the authentication information (such as credentials) required for the secondary authentication and/or slice authentication of the non-public network to the UE.
  • the system may also include a Network Slice-Specific Authentication and Authorization (NSSAA, Network Slice-Specific Authentication and Authorization)-AAA server and a Data Network-Authentication Authorization Account (DN-AAA, Data Network-Authentication Authorization Accounting) server; wherein, NSSAA-AAA
  • NSSAA Network Slice-Specific Authentication and Authorization
  • DN-AAA Data Network-Authentication Authorization Accounting
  • the PNI-NPN configuration server can be co-located with the NSSAA-AAA server or the DN-AAA server.
  • FIG. 2 is a schematic flowchart 1 of a method for obtaining authentication information according to an embodiment of the present application; as shown in FIG. 2 , the method includes:
  • Step 101 The network device receives a first request message from the user equipment, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • Step 102 The network device obtains a first key corresponding to the key identifier from the core network device, and sends a first response message corresponding to the first request message to the user equipment, the first response message for instructing the user equipment to generate the first key accordingly;
  • Step 103 The network device establishes a channel with the user equipment based on the first key, and sends authentication information for performing secondary authentication or slice authentication on a non-public network to the user equipment through the channel.
  • the non-public network described in this embodiment is PNI-NPN.
  • the authentication information in this embodiment may also be referred to as a credential or the like, that is, information used for secondary authentication or slice authentication of a non-public network may be referred to as authentication information.
  • the network device may be the aforementioned PNI-NPN provisioning server (PNI-NPN provisioning server) shown in FIG. 1 ; the core network device may specifically be the aforementioned AKMA anchor network shown in FIG. 1 .
  • Element (AAnF) the network device in this embodiment is not limited to a PNI-NPN configuration server, but may also be other authentication information used for storing and issuing secondary authentication and/or slice authentication of non-public networks
  • the server or network element and the core network device are not limited to AAnF, and may also be other core network devices, which are not limited in this embodiment.
  • the obtaining, by the network device, the first key corresponding to the key identifier from the core network device includes: the network device sending a request to the core network device for the a second request message for the first key, where the second request message includes the key identifier; the network device receives a second response message corresponding to the second request message sent by the core network device; The second response message includes the first key corresponding to the key identifier.
  • FIG. 3 is a second schematic flowchart of a method for obtaining authentication information according to an embodiment of the application; as shown in FIG. 3 , the method includes:
  • Step 201 The user equipment sends a first request message to a network device, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • Step 202 the user equipment receives a first response message corresponding to the first request message sent by the network device, where the first response message is used to instruct the user equipment to generate a first key accordingly;
  • Step 203 The user equipment generates the first key according to the second key obtained in advance, establishes a channel with the network device based on the first key, and receives the authentication sent by the network device through the channel information, where the authentication information is used to perform secondary authentication or slice authentication on a non-public network.
  • the non-public network described in this embodiment is PNI-NPN.
  • the network device may be the aforementioned PNI-NPN provisioning server (PNI-NPN provisioning server) shown in FIG. 1 ; the core network device may specifically be the aforementioned AKMA anchor network shown in FIG. 1 .
  • Element (AAnF) the network device in this embodiment is not limited to a PNI-NPN configuration server, but may also be other authentication information used for storing and issuing secondary authentication and/or slice authentication of non-public networks
  • the server or network element and the core network device are not limited to AAnF, and may also be other core network devices, which are not limited in this embodiment.
  • the method before the user equipment sends the first request message to the network device, the method further includes: after the user equipment completes initial network authentication, obtaining the second key and the the key identifier.
  • the user equipment may generate the above-mentioned second key and the corresponding key identifier according to the subscription.
  • the second key may be an AKMA intermediate key K AKMA
  • the key identifier may be an AKMA key identifier (A-KID, AKMA Key Identifier).
  • the second key is generated from a root key used to access the operator's network.
  • an intermediate key may be generated based on the root key, and then a second key may be generated based on the intermediate key; wherein, the number of intermediate keys may be at least one.
  • the method further includes: performing, by the user equipment, secondary authentication or slice authentication of a non-public network based on the authentication information.
  • the user equipment performs secondary authentication or slice authentication on a non-public network with the NSSAA AAA server/DN-AAA server based on the authentication information.
  • FIG. 4 is a third schematic flowchart of a method for obtaining authentication information according to an embodiment of the application; as shown in FIG. 4 , the method includes:
  • Step 301 The core network device receives a second request message sent by the network device, the second request message includes a key identifier, and the key identifier is in the first request message sent by the user equipment to the network device. the key identifier carried; the first request message is used by the user equipment to request access to the network device;
  • Step 302 The core network device generates a first key according to the second key corresponding to the key identifier, and sends a second response message to the network device, where the second response message includes the first key. key.
  • the first key used to establish the channel is obtained through information exchange between the network device and the core network device, and the user equipment is instructed to generate the first key.
  • a channel is established based on the first key, so as to ensure the issuance of authentication information, without presetting authentication information in the terminal, ensuring the security of authentication information and improving the flexibility of issuing authentication information; and there is no need to manually pass through the interactive interface.
  • Enter authentication information suitable for various types of terminals.
  • the core network device generates the first key based on the second key, and the second key is a key managed by the operator, and does not need to exchange credentials with a third-party network device.
  • FIG. 5 is a schematic diagram of an interaction flow of a method for obtaining authentication information according to an embodiment of the present application; as shown in FIG. 5 , the method includes:
  • Step 400 The UE completes the initial authentication of the 5G network, and generates the key K AKMA and the corresponding A-KID.
  • K AKMA is equivalent to the second key in the foregoing embodiment
  • A-KID is equivalent to the key identifier in the foregoing embodiment.
  • the K AKMA and the corresponding A-KID are generated after the UE completes the initial authentication of the 5G network, and are stored in the UE and AAnF. Wherein, K AKMA can be generated according to the root key used by the UE to access the operator's network.
  • Step 401 The UE needs to perform secondary authentication or slice authentication, and first initiates an access request (Access Request) to the PNI-NPN configuration server, where the access request carries the A-KID.
  • the access request is equivalent to the first request message in the foregoing embodiment.
  • Step 402 After receiving the access request from the UE, the PNI-NPN configuration server sends a key request (Key request) to the AAnF, where the key request carries the A-KID and the PNI-NPN configuration server ID.
  • Key request a key request
  • the key request is equivalent to the second request message in the foregoing embodiment.
  • the key request reaches the AAnF via the NEF, in other words, the information exchange between the AAnF and the PNI-NPN configuration server needs to be forwarded by the NEF.
  • Step 403 AAnF receives the key request sent by the PNI-NPN configuration server, and generates the key K PNINPN according to the relevant parameters.
  • the K PNINPN is equivalent to the first key in the foregoing embodiment.
  • the AAnF generates K PNINPN according to the stored K AKMA corresponding to the A-KID.
  • Step 404 AAnF sends a key response (Key Response) to the PNI-NPN configuration server, where the key response includes K PNINPN and its key period.
  • the key response is equivalent to the second response message in the foregoing embodiment.
  • the key period can be used to indicate the lifetime or valid duration of K PNINPN .
  • Step 405 After receiving the key response, the PNI-NPN configuration server returns an access response (Access Response) to the UE, where the access response is used to instruct the UE to generate K PNINPN .
  • Access Response an access response
  • the access response is equivalent to the first response message in the foregoing embodiment.
  • Step 406 The UE may generate K PNINPN based on the K AKMA corresponding to the A-KID.
  • Step 407 A secure channel is established between the UE and the PNI-NPN configuration server according to K PNINPN , the secure channel is also the "channel" in the foregoing embodiment, and the PNI-NPN configuration server sends the UE based on the secure channel for
  • the authentication information of the secondary authentication or slice authentication of the non-public network the authentication information may also be referred to as a credential.
  • Step 408 The UE uses the received authentication information to perform secondary authentication or slice authentication of the non-public network, and access the corresponding slice or DN.
  • FIG. 6 is a schematic diagram 1 of the composition and structure of an authentication information acquisition apparatus according to an embodiment of the application; as shown in FIG. 6 , the apparatus includes: a first receiving unit 11 , a first acquiring unit 12 , a first channel establishing unit 13 and a first sending unit 14; wherein,
  • the first receiving unit 11 is configured to receive a first request message from the user equipment, where the first request message is used to request access to the network device; the first request message includes a key identifier;
  • the first obtaining unit 12 is configured to obtain a first key corresponding to the key identifier from a core network device, and send a first response message corresponding to the first request message to the user equipment, and the first key is sent to the user equipment.
  • a response message is used to instruct the user equipment to generate the first key accordingly;
  • the first channel establishing unit 13 configured to establish a channel with the user equipment based on the first key
  • the first sending unit 14 is configured to send, to the user equipment through the channel, authentication information for performing secondary authentication or slice authentication on a non-public network.
  • the first obtaining unit 12 is configured to send a second request message for requesting the first key to the core network device through the first sending unit 14 , the second request message includes the key identifier; the second response message corresponding to the second request message sent by the core network device is received by the first receiving unit 11; the second response message includes the first key corresponding to the key identifier.
  • the non-public network is a non-public network integrated with a public network (PNI-NPN).
  • PNI-NPN public network
  • the apparatus is applied to a network device.
  • the first channel establishment unit 13 in the device can be used in practical applications by a central processing unit (CPU, Central Processing Unit), a digital signal processor (DSP, Digital Signal Processor), a microcontroller unit (MCU, Microcontroller Unit) or A programmable gate array (FPGA, Field-Programmable Gate Array) is realized; the first receiving unit 11, the first acquiring unit 12 and the first transmitting unit 14 in the device can be implemented through a communication module (including: Basic communication suites, operating systems, communication modules, standardized interfaces and protocols, etc.) and transceiver antenna implementation.
  • a communication module including: Basic communication suites, operating systems, communication modules, standardized interfaces and protocols, etc.
  • FIG. 7 is a second schematic diagram of the composition and structure of an authentication information acquisition apparatus according to an embodiment of the application; as shown in FIG. 7 , the apparatus includes: a second sending unit 21 , a second receiving unit 22 , a generating unit 23 and a second channel establishing unit 24; of which,
  • the second sending unit 21 is configured to send a first request message to a network device, where the first request message is used to request access to the network device; the request message includes a key identifier;
  • the second receiving unit 22 is configured to receive a first response message corresponding to the first request message sent by the network device, where the first response message is used to instruct the user equipment to generate a first key accordingly;
  • the generating unit 23 is configured to generate the first key according to the second key obtained in advance;
  • the second channel establishing unit 24 configured to establish a channel with the network device based on the first key
  • the second receiving unit 22 is further configured to receive authentication information sent by the network device through the channel, where the authentication information is used for secondary authentication or slice authentication of a non-public network.
  • the apparatus further includes a second obtaining unit, configured to obtain the second key and the key identifier after completing initial network authentication.
  • the apparatus further includes an authentication unit configured to perform secondary authentication or slice authentication of a non-public network based on the authentication information.
  • the non-public network is PNI-NPN.
  • the apparatus is applied in user equipment.
  • the generating unit 23, the second channel establishing unit 24, the second obtaining unit and the authentication unit in the device can be realized by CPU, DSP, MCU or FPGA in practical application; the second receiving unit 22 and the first receiving unit in the device are
  • the second sending unit 21 can be implemented by a communication module (including: a basic communication suite, an operating system, a communication module, standardized interfaces and protocols, etc.) and a transceiver antenna in practical applications.
  • FIG. 8 is a third schematic diagram of the composition and structure of an authentication information acquisition apparatus according to an embodiment of the application; as shown in FIG. 8 , the apparatus includes: a third receiving unit 31 and a third sending unit 32; wherein,
  • the third receiving unit 31 is configured to receive a second request message sent by a network device, where the second request message includes a key identifier, and the key identifier is a first request sent by the user equipment to the network device The key identifier carried in the message; the first request message is used by the user equipment to request access to the network device;
  • the third sending unit 32 is configured to generate a first key according to the second key corresponding to the key identifier, and send a second response message to the network device, where the second response message includes the first key. a key.
  • the apparatus is applied to core network equipment.
  • the third receiving unit 31 and the third sending unit 32 in the device can be implemented by a communication module (including: basic communication suite, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in practical applications.
  • the authentication information acquisition device provided by the above embodiment performs the acquisition of authentication information
  • only the division of the above program modules is used as an example for illustration.
  • the above processing may be allocated to different program modules as required
  • Completion means dividing the internal structure of the device into different program modules to complete all or part of the processing described above.
  • the apparatus for obtaining authentication information provided in the above embodiments and the embodiments of the method for obtaining authentication information belong to the same concept, and the specific implementation process thereof is detailed in the method embodiments, which will not be repeated here.
  • FIG. 9 is a schematic diagram of the hardware structure of a communication device according to an embodiment of the application. As shown in FIG.
  • the communication device includes a memory 42, a processor 41, and a computer program stored in the memory 42 and running on the processor 41,
  • the processor 41 executes the program, it implements the steps of the method for obtaining authentication information in the network device according to the embodiment of the present application; The steps of the method for acquiring authentication information in the device; or, when the processor 41 executes the program, the steps of the foregoing method for acquiring authentication information applied to the core network device in the embodiments of the present application are implemented.
  • a network interface 43 may also be included in the communication device.
  • the various components in the communication device are coupled together by a bus system 44 .
  • the bus system 44 is used to implement the connection communication between these components.
  • the bus system 44 also includes a power bus, a control bus and a status signal bus.
  • the various buses are labeled as bus system 44 in FIG. 9 .
  • the memory 42 may be either volatile memory or non-volatile memory, and may include both volatile and non-volatile memory.
  • the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-only memory) Only Memory), Electrically Erasable Programmable Read-Only Memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), Magnetic Random Access Memory (FRAM, ferromagnetic random access memory), Flash Memory (Flash Memory), Magnetic Surface Memory , CD-ROM, or CD-ROM (Compact Disc Read-Only Memory); magnetic surface memory can be disk memory or tape memory.
  • RAM Random Access Memory
  • SRAM Static Random Access Memory
  • SSRAM Synchronous Static Random Access Memory
  • DRAM Dynamic Random Access Memory
  • SDRAM Synchronous Dynamic Random Access Memory
  • DDRSDRAM Double Data Rate Synchronous Dynamic Random Access Memory
  • ESDRAM Enhanced Type Synchronous Dynamic Random Access Memory
  • SLDRAM Synchronous Link Dynamic Random Access Memory
  • DRRAM Direct Rambus Random Access Memory
  • the memory 42 described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
  • the methods disclosed in the above embodiments of the present application may be applied to the processor 41 or implemented by the processor 41 .
  • the processor 41 may be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above-mentioned method can be completed by a hardware integrated logic circuit in the processor 41 or an instruction in the form of software.
  • the above-mentioned processor 41 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and the like.
  • the processor 41 may implement or execute the methods, steps, and logical block diagrams disclosed in the embodiments of this application.
  • a general purpose processor may be a microprocessor or any conventional processor or the like.
  • the steps of the methods disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor.
  • the software module may be located in a storage medium, and the storage medium is located in the memory 42, and the processor 41 reads the information in the memory 42, and completes the steps of the foregoing method in combination with its hardware.
  • the communication device may be implemented by one or more Application Specific Integrated Circuit (ASIC, Application Specific Integrated Circuit), DSP, Programmable Logic Device (PLD, Programmable Logic Device), Complex Programmable Logic Device (CPLD, Complex Programmable Logic Device), FPGA, general-purpose processor, controller, MCU, Microprocessor (Microprocessor), or other electronic components implemented for performing the aforementioned method.
  • ASIC Application Specific Integrated Circuit
  • DSP Digital Signal processor
  • PLD Programmable Logic Device
  • CPLD Complex Programmable Logic Device
  • FPGA general-purpose processor
  • controller MCU
  • Microprocessor Microprocessor
  • the embodiment of the present application further provides a computer-readable storage medium, such as a memory 42 including a computer program, and the computer program can be executed by the processor 41 of the communication device to complete the steps of the foregoing method.
  • the computer-readable storage medium can be memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM; it can also be various devices including one or any combination of the above memories.
  • the computer-readable storage medium provided by the embodiment of the present application stores a computer program thereon.
  • the steps of the foregoing method for obtaining authentication information applied to a network device in the embodiment of the present application are implemented, or the program is executed by the processor.
  • the steps of the aforementioned method for obtaining authentication information applied to the user equipment in the embodiment of the present application are implemented, or, when the program is executed by the processor, the steps of the aforementioned method for obtaining authentication information applied to the core network device in the embodiment of the present application are implemented. step.
  • the disclosed apparatus and method may be implemented in other manners.
  • the device embodiments described above are only illustrative.
  • the division of the units is only a logical function division. In actual implementation, there may be other division methods.
  • multiple units or components may be combined, or Can be integrated into another system, or some features can be ignored, or not implemented.
  • the coupling, or direct coupling, or communication connection between the components shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or units may be electrical, mechanical or other forms. of.
  • the unit described above as a separate component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units; Some or all of the units may be selected according to actual needs to achieve the purpose of the solution in this embodiment.
  • each functional unit in each embodiment of the present application may all be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above integration
  • the unit can be implemented either in the form of hardware or in the form of hardware plus software functional units.
  • the aforementioned program may be stored in a computer-readable storage medium, and when the program is executed, execute It includes the steps of the above method embodiments; and the aforementioned storage medium includes: a removable storage device, a ROM, a RAM, a magnetic disk or an optical disk and other media that can store program codes.
  • the above-mentioned integrated units of the present application are implemented in the form of software function modules and sold or used as independent products, they may also be stored in a computer-readable storage medium.
  • the computer software products are stored in a storage medium and include several instructions for A computer device (which may be a personal computer, a server, or a network device, etc.) is caused to execute all or part of the methods described in the various embodiments of the present application.
  • the aforementioned storage medium includes: a removable storage device, a ROM, a RAM, a magnetic disk or an optical disk and other mediums that can store program codes.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例公开了一种认证信息获取方法、装置、相关设备和存储介质。所述方法包括:网络设备接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;所述网络设备基于所述第一密钥与所述用户设备建立通道,通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。

Description

一种认证信息获取方法、装置、相关设备和存储介质
相关申请的交叉引用
本申请基于申请号为202011197396.5、申请日为2020年10月30日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此以引入方式并入本申请。
技术领域
本申请涉及无线通信技术领域,具体涉及一种认证信息获取方法、装置、相关设备和存储介质。
背景技术
非公共网络(NPN,Non-Public Network),区别于公共网络,是可以为特定用户提供服务的网络。非公共网络有两种类型:一是独立组网的NPN,即网络不依赖于公共陆地移动网(PLMN,Public Land Mobile Network);二是与公共网络集成的NPN(PNI-NPN,Public Network Integrated-NPN),网络依赖于PLMN,由传统运营商运营。
在PNI-NPN中,终端在通过初始认证接入PLMN之后,如果要进行二次认证或切片认证,前提是终端需要具备二次认证或切片认证的凭证。而终端可通过以下两种方式获得凭证:一是在终端出厂时将凭证写入终端的芯片或用户卡中;二是由用户通过交互界面输入凭证口令。而上述第一种方式无法保证安全性,容易在生产过程中导致凭证泄露,另外也缺乏灵活性,终端出场后凭证无法修改、更新和替换。上述第二种方式不适用于不具有交互界面的终端,无法进行交互输入操作。
发明内容
本申请实施例提供一种认证信息获取方法、装置、相关设备和存储介质。
本申请实施例的技术方案是这样实现的:
第一方面,本申请实施例提供了一种认证信息获取方法,所述方法包括:
网络设备接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;
所述网络设备基于所述第一密钥与所述用户设备建立通道,通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。
在本申请的一些可选实施例中,所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,包括:
所述网络设备向所述核心网设备发送用于请求所述第一密钥的第二请求消息,所述第二请求消息中包括所述密钥标识;
所述网络设备接收所述核心网设备发送的所述第二请求消息对应的第二响应消息;所述第二响应消息中包括所述密钥标识对应的第一密钥。
在本申请的一些可选实施例中,所述非公共网络为与公共网络集成的非公共网络(PNI-NPN)。
第二方面,本申请实施例还提供了一种认证信息获取方法,所述方法包括:
用户设备向网络设备发送第一请求消息,所述第一请求消息用于请求 接入所述网络设备;所述第一请求消息中包括密钥标识;
所述用户设备接收所述网络设备发送的所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成第一密钥;
所述用户设备根据预先获得的第二密钥生成所述第一密钥,基于所述第一密钥与所述网络设备建立通道,通过所述通道接收所述网络设备发送的认证信息,所述认证信息用于进行非公共网络的二次认证或切片认证。
在本申请的一些可选实施例中,所述用户设备向网络设备发送第一请求消息之前,所述方法还包括:所述用户设备完成网络初始认证后,获得所述第二密钥和所述密钥标识。
在本申请的一些可选实施例中,所述方法还包括:所述用户设备基于所述认证信息进行非公共网络的二次认证或切片认证。
在本申请的一些可选实施例中,所述非公共网络为与公共网络集成的非公共网络(PNI-NPN)。
第三方面,本申请实施例还提供了一种认证信息获取方法,所述方法包括:
核心网设备接收网络设备发送的第二请求消息,所述第二请求消息中包括密钥标识,所述密钥标识为用户设备向所述网络设备发送的第一请求消息中携带的密钥标识;所述第一请求消息用于所述用户设备请求接入所述网络设备;
所述核心网设备根据所述密钥标识对应的第二密钥生成第一密钥,向所述网络设备发送第二响应消息,所述第二响应消息中包括所述第一密钥。
第四方面,本申请实施例还提供了一种认证信息获取装置,所述装置包括:第一接收单元、第一获取单元、第一通道建立单元和第一发送单元;其中,
所述第一接收单元,配置为接收到来自用户设备的第一请求消息,所 述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
所述第一获取单元,配置为从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;
所述第一通道建立单元,配置为基于所述第一密钥与所述用户设备建立通道;
所述第一发送单元,配置为通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。
在本申请的一些可选实施例中,所述第一获取单元,配置为通过所述第一发送单元向所述核心网设备发送用于请求所述第一密钥的第二请求消息,所述第二请求消息中包括所述密钥标识;通过所述第一接收单元接收所述核心网设备发送的所述第二请求消息对应的第二响应消息;所述第二响应消息中包括所述密钥标识对应的第一密钥。
在本申请的一些可选实施例中,所述非公共网络为与公共网络集成的非公共网络(PNI-NPN)。
第五方面,本申请实施例还提供了一种认证信息获取装置,所述装置包括:第二发送单元、第二接收单元、生成单元和第二通道建立单元;其中,
所述第二发送单元,配置为向网络设备发送第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
所述第二接收单元,配置为接收所述网络设备发送的所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成第一密钥;
所述生成单元,配置为根据预先获得的第二密钥生成所述第一密钥;
所述第二通道建立单元,配置为基于所述第一密钥与所述网络设备建立通道;
所述第二接收单元,还配置为通过所述通道接收所述网络设备发送的认证信息,所述认证信息用于进行非公共网络的二次认证或切片认证。
在本申请的一些可选实施例中,所述装置还包括第二获取单元,配置为完成网络初始认证后,获得所述第二密钥和所述密钥标识。
在本申请的一些可选实施例中,所述装置还包括认证单元,配置为基于所述认证信息进行非公共网络的二次认证或切片认证。
在本申请的一些可选实施例中,所述非公共网络为与公共网络集成的非公共网络(PNI-NPN)。
第六方面,本申请实施例还提供了一种认证信息获取装置,所述装置包括:第三接收单元和第三发送单元;其中,
所述第三接收单元,配置为接收网络设备发送的第二请求消息,所述第二请求消息中包括密钥标识,所述密钥标识为用户设备向所述网络设备发送的第一请求消息中携带的密钥标识;所述第一请求消息用于所述用户设备请求接入所述网络设备;
所述第三发送单元,配置为根据所述密钥标识对应的第二密钥生成第一密钥,向所述网络设备发送第二响应消息,所述第二响应消息中包括所述第一密钥。
第七方面,本申请实施例还提供了一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现本申请实施例前述第一方面、第二方面或第三方面所述方法的步骤。
第八方面,本申请实施例还提供了一种通信设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现本申请实施例前述第一方面、第二方面或第三方面所述方 法的步骤。
本申请实施例提供的认证信息获取方法、装置、相关设备和存储介质,所述方法包括:网络设备接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;所述网络设备基于所述第一密钥与所述用户设备建立通道,通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。采用本申请实施例的方案,通过网络设备与核心网设备之间进行信息交互,获得用于建立通道的第一密钥,并指示用户设备生成该第一密钥,网络设备与用户设备之间基于该第一密钥建立通道,从而保证认证信息的下发,无需在终端内预置认证信息,保证了认证信息的安全性以及提升了认证信息下发的灵活性;也无需通过交互界面手动输入认证信息,适合各种类型的终端。
附图说明
图1为本申请实施例的认证信息获取方法应用的系统架构示意图;
图2为本申请实施例的认证信息获取方法的流程示意图一;
图3为本申请实施例的认证信息获取方法的流程示意图二;
图4为本申请实施例的认证信息获取方法的流程示意图三;
图5为本申请实施例的认证信息获取方法的交互流程示意图;
图6为本申请实施例的认证信息获取装置的组成结构示意图一;
图7为本申请实施例的认证信息获取装置的组成结构示意图二;
图8为本申请实施例的认证信息获取装置的组成结构示意图三;
图9为本申请实施例的通信设备的硬件结构示意图。
具体实施方式
图1为本申请实施例的认证信息获取方法应用的系统架构示意图;如图1所示,系统可包括:用户设备(UE,User Equipment)、接入网设备和核心网设备;其中,接入网设备在图中以无线接入网(RAN,Radio Access Network)或接入网(AN,Access Network)表示,图中以(R)AN表示接入网设备。
核心网设备在图中以5G核心网(5GC)表示,可包括以下设备的至少之一:用户面功能(UPF,User Plane Function)、接入和移动管理功能(AMF,Access and Mobility Management Function)、会话管理功能(SMF,Session Management Function)、策略控制功能(PCF,Policy Control function)、统一数据管理功能(UDM,Unified Data Management)、鉴权服务功能(AUSF,Authentication Server Function)、网络开放功能(NEF,Network Exposure Function)、面向应用的认证或密钥管理(AKMA,Authentication and Key Management for Applications)锚点网元(AAnF,AKMA Anchor Function)和网络切片特定身份验证和授权功能(NSSAAF,Network Slice-Specific Authentication and Authorization Function)。
其中,系统还包括PNI-NPN配置服务器(PNI-NPN provisioning server),用于存储和下发非公共网络的二次认证和/或切片认证所用的认证信息(如凭证)。当PNI-NPN配置服务器位于运营商外部时,PNI-NPN配置服务器通过5G核心网中的NEF与AAnF相连接,用于获取基于运营商凭证推导出的密钥,该密钥用于建立PNI-NPN配置服务器与UE之间的安全通道,安全通道可用于PNI-NPN配置服务器向UE发送非公共网络的二次认证和/或切片认证所需的认证信息(如凭证)。
系统还可包括网络切片特定身份验证和授权(NSSAA,Network Slice-Specific Authentication and Authorization)-AAA服务器和数据网络认 证授权服务器(DN-AAA,Data Network-Authentication Authorization Accounting)服务器;其中,NSSAA-AAA服务器与NSSAAF相连接,用于执行切片认证,DN-AAA服务器与UPF相连接,用于执行二次认证。
可选地,PNI-NPN配置服务器可与NSSAA-AAA服务器或DN-AAA服务器合设。
基于以上系统架构,提出以下各实施例。
本申请实施例提供了一种认证信息获取方法,应用于网络设备中。图2为本申请实施例的认证信息获取方法的流程示意图一;如图2所示,所述方法包括:
步骤101:网络设备接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
步骤102:所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;
步骤103:所述网络设备基于所述第一密钥与所述用户设备建立通道,通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。
本实施例所述的非公共网络为PNI-NPN。本实施例中的认证信息,也可称为凭证(credential)等,即用于进行非公共网络的二次认证或切片认证的信息均可称为认证信息。
本实施例中,所述网络设备可以是前述图1中所示的PNI-NPN配置服务器(PNI-NPN provisioning server);所述核心网设备具体可以是前述图1中所示的AKMA锚点网元(AAnF);当然,本实施例中的网络设备不限于是PNI-NPN配置服务器,也可以是用于存储和下发非公共网络的二次认证和/或切片认证所用的认证信息的其他服务器或网元,核心网设备也不限于 是AAnF,也可以是其他核心网设备,本实施例中对此不做限定。
在本申请的一些可选实施例中,所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,包括:所述网络设备向所述核心网设备发送用于请求所述第一密钥的第二请求消息,所述第二请求消息中包括所述密钥标识;所述网络设备接收所述核心网设备发送的所述第二请求消息对应的第二响应消息;所述第二响应消息中包括所述密钥标识对应的第一密钥。
基于前述实施例,本申请实施例还提供了一种认证信息获取方法,应用于用户设备中。图3为本申请实施例的认证信息获取方法的流程示意图二;如图3所示,所述方法包括:
步骤201:用户设备向网络设备发送第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
步骤202:所述用户设备接收所述网络设备发送的所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成第一密钥;
步骤203:所述用户设备根据预先获得的第二密钥生成所述第一密钥,基于所述第一密钥与所述网络设备建立通道,通过所述通道接收所述网络设备发送的认证信息,所述认证信息用于进行非公共网络的二次认证或切片认证。
本实施例所述的非公共网络为PNI-NPN。
本实施例中,所述网络设备可以是前述图1中所示的PNI-NPN配置服务器(PNI-NPN provisioning server);所述核心网设备具体可以是前述图1中所示的AKMA锚点网元(AAnF);当然,本实施例中的网络设备不限于是PNI-NPN配置服务器,也可以是用于存储和下发非公共网络的二次认证和/或切片认证所用的认证信息的其他服务器或网元,核心网设备也不限于是AAnF,也可以是其他核心网设备,本实施例中对此不做限定。
在本申请的一些可选实施例中,所述用户设备向网络设备发送第一请求消息之前,所述方法还包括:所述用户设备完成网络初始认证后,获得所述第二密钥和所述密钥标识。
本实施例中,用户设备完成5G网络的初始认证后,可根据订阅(subscription)生成上述第二密钥以及对应的密钥标识。示例性的,所述第二密钥可以是AKMA中间密钥K AKMA,所述密钥标识可以是AKMA密钥标识(A-KID,AKMA Key Identifier)。
在一些示例中,所述第二密钥根据用于接入运营商网络的根密钥生成。可选地,可基于根密钥生成中间密钥,再基于中间密钥生成第二密钥;其中,中间密钥的数量可以是至少一个。
在本申请的一些可选实施例中,所述方法还包括:所述用户设备基于所述认证信息进行非公共网络的二次认证或切片认证。
示例性的,参照图1所示,用户设备科基于所述认证信息与NSSAA AAA服务器/DN-AAA服务器进行非公共网络的二次认证或切片认证。
基于上述实施例,本申请实施例还提供了一种认证信息获取方法,应用于核心网设备中。图4为本申请实施例的认证信息获取方法的流程示意图三;如图4所示,所述方法包括:
步骤301:核心网设备接收网络设备发送的第二请求消息,所述第二请求消息中包括密钥标识,所述密钥标识为所述用户设备向所述网络设备发送的第一请求消息中携带的密钥标识;所述第一请求消息用于所述用户设备请求接入所述网络设备;
步骤302:所述核心网设备根据所述密钥标识对应的第二密钥生成第一密钥,向所述网络设备发送第二响应消息,所述第二响应消息中包括所述第一密钥。
采用本申请实施例的方案,通过网络设备与核心网设备之间进行信息 交互,获得用于建立通道的第一密钥,并指示用户设备生成该第一密钥,网络设备与用户设备之间基于该第一密钥建立通道,从而保证认证信息的下发,无需在终端内预置认证信息,保证了认证信息的安全性以及提升了认证信息下发的灵活性;也无需通过交互界面手动输入认证信息,适合各种类型的终端。另外,本申请实施例中,核心网设备是基于第二密钥生成第一密钥的,而第二密钥是运营商管理的密钥,无需与第三方的网络设备互通凭证。
下面结合一个具体的示例对本申请实施例的认证信息获取方法进行说明。在本示例中,以网络设备为PNI-NPN配置服务器、以核心网设备为AAnF为例进行说明。图5为本申请实施例的认证信息获取方法的交互流程示意图;如图5所示,所述方法包括:
步骤400:UE完成5G网络初始认证,并生成密钥K AKMA及对应的A-KID。
本步骤是执行后续步骤的前提条件。其中,密钥K AKMA相当于前述实施例中的第二密钥;A-KID相当于前述实施例中的密钥标识。K AKMA及对应的A-KID在UE完成5G网络初始认证后生成,并存储在UE和AAnF中。其中,K AKMA可根据用于UE接入运营商网络的根密钥生成。
步骤401:UE需要进行二次认证或切片认证,首先向PNI-NPN配置服务器发起接入请求(Access Request),所述接入请求中携带A-KID。
其中,所述接入请求相当于前述实施例中的第一请求消息。
步骤402:PNI-NPN配置服务器接收到来自UE的接入请求后,向AAnF发送密钥请求(Key request),所述密钥请求中携带A-KID和PNI-NPN配置服务器ID。
其中,所述密钥请求相当于前述实施例中的第二请求消息。所述密钥请求经NEF到达AAnF,换句话说,AAnF与PNI-NPN配置服务器之间的 信息交互需要经过NEF的转发。
步骤403:AAnF接收到PNI-NPN配置服务器发来的密钥请求,根据相关参数生成密钥K PNINPN
其中,所述K PNINPN相当于前述实施例中的第一密钥。示例性的,AAnF根据存储的A-KID对应的K AKMA生成K PNINPN
步骤404:AAnF向PNI-NPN配置服务器发送密钥响应(Key Response),所述密钥响应中包括K PNINPN及其密钥周期。
其中,所述密钥响应相当于前述实施例中的第二响应消息。所述密钥周期可用于指示K PNINPN的生存时间或有效时长。
步骤405:PNI-NPN配置服务器收到密钥响应后,向UE返回接入响应(Access Response),所述接入响应用于指示UE生成K PNINPN
其中,所述接入响应相当于前述实施例中的第一响应消息。
步骤406:UE可基于A-KID对应的K AKMA生成K PNINPN
步骤407:UE与PNI-NPN配置服务器之间根据K PNINPN建立安全通道,该安全通道也即前述实施例中的“通道”,PNI-NPN配置服务器基于所述安全通道向UE下发用于进行非公共网络的二次认证或切片认证的认证信息,该认证信息也可称为凭证(credential)。
步骤408:UE使用接收到的认证信息进行非公共网络的二次认证或切片认证,接入对应的切片或DN。
本申请实施例还提供了一种认证信息获取装置。图6为本申请实施例的认证信息获取装置的组成结构示意图一;如图6所示,所述装置包括:第一接收单元11、第一获取单元12、第一通道建立单元13和第一发送单元14;其中,
所述第一接收单元11,配置为接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括 密钥标识;
所述第一获取单元12,配置为从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;
所述第一通道建立单元13,配置为基于所述第一密钥与所述用户设备建立通道;
所述第一发送单元14,配置为通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。
在本申请的一些可选实施例中,所述第一获取单元12,配置为通过所述第一发送单元14向所述核心网设备发送用于请求所述第一密钥的第二请求消息,所述第二请求消息中包括所述密钥标识;通过所述第一接收单元11接收所述核心网设备发送的所述第二请求消息对应的第二响应消息;所述第二响应消息中包括所述密钥标识对应的第一密钥。
在本申请的一些可选实施例中,所述非公共网络为与公共网络集成的非公共网络(PNI-NPN)。
本申请实施例中,所述装置应用于网络设备中。所述装置中的第一通道建立单元13,在实际应用中可由中央处理器(CPU,Central Processing Unit)、数字信号处理器(DSP,Digital Signal Processor)、微控制单元(MCU,Microcontroller Unit)或可编程门阵列(FPGA,Field-Programmable Gate Array)实现;所述装置中的第一接收单元11、第一获取单元12和第一发送单元14,在实际应用中可通过通信模组(包含:基础通信套件、操作系统、通信模块、标准化接口和协议等)及收发天线实现。
本申请实施例还提供了一种认证信息获取装置。图7为本申请实施例的认证信息获取装置的组成结构示意图二;如图7所示,所述装置包括:第二发送单元21、第二接收单元22、生成单元23和第二通道建立单元24; 其中,
所述第二发送单元21,配置为向网络设备发送第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述请求消息中包括密钥标识;
所述第二接收单元22,配置为接收所述网络设备发送的所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成第一密钥;
所述生成单元23,配置为根据预先获得的第二密钥生成所述第一密钥;
所述第二通道建立单元24,配置为基于所述第一密钥与所述网络设备建立通道;
所述第二接收单元22,还配置为通过所述通道接收所述网络设备发送的认证信息,所述认证信息用于进行非公共网络的二次认证或切片认证。
在本申请的一些可选实施例中,所述装置还包括第二获取单元,配置为完成网络初始认证后,获得所述第二密钥和所述密钥标识。
在本申请的一些可选实施例中,所述装置还包括认证单元,配置为基于所述认证信息进行非公共网络的二次认证或切片认证。
在本申请的一些可选实施例中,所述非公共网络为PNI-NPN。
本申请实施例中,所述装置应用于用户设备中。所述装置中的生成单元23、第二通道建立单元24、第二获取单元和认证单元,在实际应用中可由CPU、DSP、MCU或FPGA实现;所述装置中的第二接收单元22和第二发送单元21,在实际应用中可通过通信模组(包含:基础通信套件、操作系统、通信模块、标准化接口和协议等)及收发天线实现。
本申请实施例还提供了一种认证信息获取装置。图8为本申请实施例的认证信息获取装置的组成结构示意图三;如图8所示,所述装置包括:第三接收单元31和第三发送单元32;其中,
所述第三接收单元31,配置为接收网络设备发送的第二请求消息,所 述第二请求消息中包括密钥标识,所述密钥标识为用户设备向所述网络设备发送的第一请求消息中携带的密钥标识;所述第一请求消息用于所述用户设备请求接入所述网络设备;
所述第三发送单元32,配置为根据所述密钥标识对应的第二密钥生成第一密钥,向所述网络设备发送第二响应消息,所述第二响应消息中包括所述第一密钥。
本申请实施例中,所述装置应用于核心网设备中。所述装置中的第三接收单元31和第三发送单元32,在实际应用中可通过通信模组(包含:基础通信套件、操作系统、通信模块、标准化接口和协议等)及收发天线实现。
需要说明的是:上述实施例提供的认证信息获取装置在进行认证信息获取时,仅以上述各程序模块的划分进行举例说明,实际应用中,可以根据需要而将上述处理分配由不同的程序模块完成,即将装置的内部结构划分成不同的程序模块,以完成以上描述的全部或者部分处理。另外,上述实施例提供的认证信息获取装置与认证信息获取方法实施例属于同一构思,其具体实现过程详见方法实施例,这里不再赘述。
本申请实施例还提供了一种通信设备,所述通信设备具体可以是前述实施例中所述的网络设备、用户设备或核心网设备。图9为本申请实施例的通信设备的硬件结构示意图,如图9所示,所述通信设备包括存储器42、处理器41及存储在存储器42上并可在处理器41上运行的计算机程序,所述处理器41执行所述程序时实现本申请实施例前述应用于网络设备中的认证信息获取方法的步骤;或者,所述处理器41执行所述程序时实现本申请实施例前述应用于用户设备中的认证信息获取方法的步骤;或者,所述处理器41执行所述程序时实现本申请实施例前述应用于核心网设备中的认证信息获取方法的步骤。
可选地,通信设备中还可包括网络接口43。通信设备中的各个组件通过总线系统44耦合在一起。可理解,总线系统44用于实现这些组件之间的连接通信。总线系统44除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图9中将各种总线都标为总线系统44。
可以理解,存储器42可以是易失性存储器或非易失性存储器,也可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(ROM,Read Only Memory)、可编程只读存储器(PROM,Programmable Read-Only Memory)、可擦除可编程只读存储器(EPROM,Erasable Programmable Read-Only Memory)、电可擦除可编程只读存储器(EEPROM,Electrically Erasable Programmable Read-Only Memory)、磁性随机存取存储器(FRAM,ferromagnetic random access memory)、快闪存储器(Flash Memory)、磁表面存储器、光盘、或只读光盘(CD-ROM,Compact Disc Read-Only Memory);磁表面存储器可以是磁盘存储器或磁带存储器。易失性存储器可以是随机存取存储器(RAM,Random Access Memory),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(SRAM,Static Random Access Memory)、同步静态随机存取存储器(SSRAM,Synchronous Static Random Access Memory)、动态随机存取存储器(DRAM,Dynamic Random Access Memory)、同步动态随机存取存储器(SDRAM,Synchronous Dynamic Random Access Memory)、双倍数据速率同步动态随机存取存储器(DDRSDRAM,Double Data Rate Synchronous Dynamic Random Access Memory)、增强型同步动态随机存取存储器(ESDRAM,Enhanced Synchronous Dynamic Random Access Memory)、同步连接动态随机存取存储器(SLDRAM,SyncLink Dynamic Random Access Memory)、直接内存总线随机存取存储器(DRRAM,Direct  Rambus Random Access Memory)。本申请实施例描述的存储器42旨在包括但不限于这些和任意其它适合类型的存储器。
上述本申请实施例揭示的方法可以应用于处理器41中,或者由处理器41实现。处理器41可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器41中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器41可以是通用处理器、DSP,或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。处理器41可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本申请实施例所公开的方法的步骤,可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于存储介质中,该存储介质位于存储器42,处理器41读取存储器42中的信息,结合其硬件完成前述方法的步骤。
在示例性实施例中,通信设备可以被一个或多个应用专用集成电路(ASIC,Application Specific Integrated Circuit)、DSP、可编程逻辑器件(PLD,Programmable Logic Device)、复杂可编程逻辑器件(CPLD,Complex Programmable Logic Device)、FPGA、通用处理器、控制器、MCU、微处理器(Microprocessor)、或其他电子元件实现,用于执行前述方法。
在示例性实施例中,本申请实施例还提供了一种计算机可读存储介质,例如包括计算机程序的存储器42,上述计算机程序可由通信设备的处理器41执行,以完成前述方法所述步骤。计算机可读存储介质可以是FRAM、ROM、PROM、EPROM、EEPROM、Flash Memory、磁表面存储器、光盘、或CD-ROM等存储器;也可以是包括上述存储器之一或任意组合的各种设备。
本申请实施例提供的计算机可读存储介质,其上存储有计算机程序, 该程序被处理器执行时实现本申请实施例前述应用于网络设备中的认证信息获取方法的步骤,或者,该程序被处理器执行时实现本申请实施例前述应用于用户设备中的认证信息获取方法的步骤,或者,该程序被处理器执行时实现本申请实施例前述应用于核心网设备中的认证信息获取方法的步骤。
本申请所提供的几个方法实施例中所揭露的方法,在不冲突的情况下可以任意组合,得到新的方法实施例。
本申请所提供的几个产品实施例中所揭露的特征,在不冲突的情况下可以任意组合,得到新的产品实施例。
本申请所提供的几个方法或设备实施例中所揭露的特征,在不冲突的情况下可以任意组合,得到新的方法实施例或设备实施例。
在本申请所提供的几个实施例中,应该理解到,所揭露的设备和方法,可以通过其它的方式实现。以上所描述的设备实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,如:多个单元或组件可以结合,或可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的各组成部分相互之间的耦合、或直接耦合、或通信连接可以是通过一些接口,设备或单元的间接耦合或通信连接,可以是电性的、机械的或其它形式的。
上述作为分离部件说明的单元可以是、或也可以不是物理上分开的,作为单元显示的部件可以是、或也可以不是物理单元,即可以位于一个地方,也可以分布到多个网络单元上;可以根据实际的需要选择其中的部分或全部单元来实现本实施例方案的目的。
另外,在本申请各实施例中的各功能单元可以全部集成在一个处理单元中,也可以是各单元分别单独作为一个单元,也可以两个或两个以上单元集成在一个单元中;上述集成的单元既可以采用硬件的形式实现,也可 以采用硬件加软件功能单元的形式实现。
本领域普通技术人员可以理解:实现上述方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成,前述的程序可以存储于一计算机可读取存储介质中,该程序在执行时,执行包括上述方法实施例的步骤;而前述的存储介质包括:移动存储设备、ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。
或者,本申请上述集成的单元如果以软件功能模块的形式实现并作为独立的产品销售或使用时,也可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请实施例的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机、服务器、或者网络设备等)执行本申请各个实施例所述方法的全部或部分。而前述的存储介质包括:移动存储设备、ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。

Claims (18)

  1. 一种认证信息获取方法,所述方法包括:
    网络设备接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
    所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;
    所述网络设备基于所述第一密钥与所述用户设备建立通道,通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。
  2. 根据权利要求1所述的方法,其中,所述网络设备从核心网设备获得与所述密钥标识对应的第一密钥,包括:
    所述网络设备向所述核心网设备发送用于请求所述第一密钥的第二请求消息,所述第二请求消息中包括所述密钥标识;
    所述网络设备接收所述核心网设备发送的所述第二请求消息对应的第二响应消息;所述第二响应消息中包括所述密钥标识对应的第一密钥。
  3. 根据权利要求1所述的方法,其中,所述非公共网络为与公共网络集成的非公共网络PNI-NPN。
  4. 一种认证信息获取方法,所述方法包括:
    用户设备向网络设备发送第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
    所述用户设备接收所述网络设备发送的所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成第一密钥;
    所述用户设备根据预先获得的第二密钥生成所述第一密钥,基于所述第一密钥与所述网络设备建立通道,通过所述通道接收所述网络设备发送 的认证信息,所述认证信息用于进行非公共网络的二次认证或切片认证。
  5. 根据权利要求4所述的方法,其中,所述用户设备向网络设备发送第一请求消息之前,所述方法还包括:
    所述用户设备完成网络初始认证后,获得所述第二密钥和所述密钥标识。
  6. 根据权利要求4所述的方法,其中,所述方法还包括:
    所述用户设备基于所述认证信息进行非公共网络的二次认证或切片认证。
  7. 根据权利要求4所述的方法,其中,所述非公共网络为与公共网络集成的非公共网络PNI-NPN。
  8. 一种认证信息获取方法,所述方法包括:
    核心网设备接收网络设备发送的第二请求消息,所述第二请求消息中包括密钥标识,所述密钥标识为用户设备向所述网络设备发送的第一请求消息中携带的密钥标识;所述第一请求消息用于所述用户设备请求接入所述网络设备;
    所述核心网设备根据所述密钥标识对应的第二密钥生成第一密钥,向所述网络设备发送第二响应消息,所述第二响应消息中包括所述第一密钥。
  9. 一种认证信息获取装置,所述装置包括:第一接收单元、第一获取单元、第一通道建立单元和第一发送单元;其中,
    所述第一接收单元,配置为接收到来自用户设备的第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
    所述第一获取单元,配置为从核心网设备获得与所述密钥标识对应的第一密钥,向所述用户设备发送所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成所述第一密钥;
    所述第一通道建立单元,配置为基于所述第一密钥与所述用户设备建立通道;
    所述第一发送单元,配置为通过所述通道向所述用户设备发送用于进行非公共网络的二次认证或切片认证的认证信息。
  10. 根据权利要求9所述的装置,其中,所述第一获取单元,配置为通过所述第一发送单元向所述核心网设备发送用于请求所述第一密钥的第二请求消息,所述第二请求消息中包括所述密钥标识;通过所述第一接收单元接收所述核心网设备发送的所述第二请求消息对应的第二响应消息;所述第二响应消息中包括所述密钥标识对应的第一密钥。
  11. 根据权利要求9所述的装置,其中,所述非公共网络为与公共网络集成的非公共网络PNI-NPN。
  12. 一种认证信息获取装置,所述装置包括:第二发送单元、第二接收单元、生成单元和第二通道建立单元;其中,
    所述第二发送单元,配置为向网络设备发送第一请求消息,所述第一请求消息用于请求接入所述网络设备;所述第一请求消息中包括密钥标识;
    所述第二接收单元,配置为接收所述网络设备发送的所述第一请求消息对应的第一响应消息,所述第一响应消息用于指示所述用户设备相应生成第一密钥;
    所述生成单元,配置为根据预先获得的第二密钥生成所述第一密钥;
    所述第二通道建立单元,配置为基于所述第一密钥与所述网络设备建立通道;
    所述第二接收单元,还配置为通过所述通道接收所述网络设备发送的认证信息,所述认证信息用于进行非公共网络的二次认证或切片认证。
  13. 根据权利要求12所述的装置,其中,所述装置还包括第二获取单元,配置为完成网络初始认证后,获得所述第二密钥和所述密钥标识。
  14. 根据权利要求12所述的装置,其中,所述装置还包括认证单元,配置为基于所述认证信息进行非公共网络的二次认证或切片认证。
  15. 根据权利要求12所述的装置,其中,所述非公共网络为与公共网络集成的非公共网络PNI-NPN。
  16. 一种认证信息获取装置,所述装置包括:第三接收单元和第三发送单元;其中,
    所述第三接收单元,配置为接收网络设备发送的第二请求消息,所述第二请求消息中包括密钥标识,所述密钥标识为用户设备向所述网络设备发送的第一请求消息中携带的密钥标识;所述第一请求消息用于所述用户设备请求接入所述网络设备;
    所述第三发送单元,配置为根据所述密钥标识对应的第二密钥生成第一密钥,向所述网络设备发送第二响应消息,所述第二响应消息中包括所述第一密钥。
  17. 一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现权利要求1至3任一项所述方法的步骤;或者,该程序被处理器执行时实现权利要求4至7任一项所述方法的步骤;或者,该程序被处理器执行时实现权利要求8所述方法的步骤。
  18. 一种通信设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现权利要求1至3任一项所述方法的步骤;或者,所述处理器执行所述程序时实现权利要求4至7任一项所述方法的步骤;或者,所述处理器执行所述程序时实现权利要求8所述方法的步骤。
PCT/CN2021/127435 2020-10-30 2021-10-29 一种认证信息获取方法、装置、相关设备和存储介质 Ceased WO2022089583A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202011197396.5 2020-10-30
CN202011197396.5A CN114531254B (zh) 2020-10-30 2020-10-30 一种认证信息获取方法、装置、相关设备和存储介质

Publications (1)

Publication Number Publication Date
WO2022089583A1 true WO2022089583A1 (zh) 2022-05-05

Family

ID=81383571

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/127435 Ceased WO2022089583A1 (zh) 2020-10-30 2021-10-29 一种认证信息获取方法、装置、相关设备和存储介质

Country Status (2)

Country Link
CN (1) CN114531254B (zh)
WO (1) WO2022089583A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023125642A1 (zh) * 2021-12-31 2023-07-06 中国移动通信有限公司研究院 认证和/或密钥管理方法、第一设备、终端及通信设备
WO2024098194A1 (en) * 2022-11-07 2024-05-16 Apple Inc. Mec-service subscription synchronisation in roaming architecture

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115243254B (zh) * 2022-08-03 2023-03-21 广州爱浦路网络技术有限公司 一种网络信息的获取方法及系统
CN116095681B (zh) * 2023-04-11 2023-07-11 北京首信科技股份有限公司 一种网络融合认证的方法和设备
WO2025236135A1 (zh) * 2024-05-11 2025-11-20 北京小米移动软件有限公司 用户认证方法、通信设备及存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108702626A (zh) * 2016-03-09 2018-10-23 高通股份有限公司 无线广域网(wwan)无线局域网(wlan)聚合保全
CN110830991A (zh) * 2018-08-10 2020-02-21 华为技术有限公司 安全会话方法和装置
WO2020212643A1 (en) * 2019-04-17 2020-10-22 Nokia Technologies Oy Cryptographic key generation for mobile communications device

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101990201B (zh) * 2009-07-31 2013-09-04 中国移动通信集团公司 生成gba密钥的方法及其系统和设备
CN108243416B (zh) * 2016-12-27 2020-11-03 中国移动通信集团公司 用户设备鉴权方法、移动管理实体及用户设备
FR3068854A1 (fr) * 2017-08-11 2019-01-11 Orange Gestion de communication entre un terminal et un serveur reseau
CN110167081B (zh) * 2018-02-13 2022-07-26 中兴通讯股份有限公司 认证方法及装置、消息处理方法及装置、存储介质
CN111447675B (zh) * 2019-01-17 2021-11-09 华为技术有限公司 通信方法和相关产品
CN111818516B (zh) * 2019-04-12 2022-10-18 华为技术有限公司 认证方法、装置及设备
WO2020218843A1 (en) * 2019-04-25 2020-10-29 Samsung Electronics Co., Ltd. Method and system for providing non-access stratum (nas) message protection
CN110708337B (zh) * 2019-10-30 2022-06-28 浪潮软件科技有限公司 一种基于身份认证的大数据安全框架系统
CN111586007B (zh) * 2020-04-29 2022-09-09 国家电网公司华中分部 一种数据传输的安全认证系统和方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108702626A (zh) * 2016-03-09 2018-10-23 高通股份有限公司 无线广域网(wwan)无线局域网(wlan)聚合保全
CN110830991A (zh) * 2018-08-10 2020-02-21 华为技术有限公司 安全会话方法和装置
WO2020212643A1 (en) * 2019-04-17 2020-10-22 Nokia Technologies Oy Cryptographic key generation for mobile communications device

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
INTERDIGITAL INC: "Solution for supporting Non-standalone NPN", 3GPP DRAFT; S2-1811027, 19 October 2018 (2018-10-19), pages 1 - 4, XP051539917 *
VIVO: "Solution for accessing to Non Public Network services via PLMN", 3GPP DRAFT; S2-1810200, vol. SA WG2, 9 October 2018 (2018-10-09), Dongguan, P. R. China, pages 1 - 6, XP051539193 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023125642A1 (zh) * 2021-12-31 2023-07-06 中国移动通信有限公司研究院 认证和/或密钥管理方法、第一设备、终端及通信设备
WO2024098194A1 (en) * 2022-11-07 2024-05-16 Apple Inc. Mec-service subscription synchronisation in roaming architecture

Also Published As

Publication number Publication date
CN114531254A (zh) 2022-05-24
CN114531254B (zh) 2023-03-31

Similar Documents

Publication Publication Date Title
CN114531254B (zh) 一种认证信息获取方法、装置、相关设备和存储介质
CN113541925B (zh) 通信系统、方法及装置
US10349267B1 (en) Systems and methods for transferring SIM profiles between eUICC devices
WO2024149148A1 (zh) 一种通信方法、通信装置和通信系统
RU2734693C1 (ru) Усовершенствованная процедура регистрации в системе мобильной связи, поддерживающей сетевое сегментирование
US9319413B2 (en) Method for establishing resource access authorization in M2M communication
US9319412B2 (en) Method for establishing resource access authorization in M2M communication
WO2020221219A1 (zh) 通信方法和通信设备
CN110798833A (zh) 一种鉴权过程中验证用户设备标识的方法及装置
US20160261581A1 (en) User authentication
JP7681725B2 (ja) Nswoサービスの認証のための方法、デバイス、および記憶媒体
US20100238988A1 (en) System and method for controlling wireless network access information in using removable external modem
CN105025005A (zh) 提供网络证书
CN103493541A (zh) 切换运营商网络的方法及终端
WO2018233726A1 (zh) 网络切片的认证方法及相应装置、系统和介质
WO2018045983A1 (zh) 信息处理方法、装置以及网络系统
JP2023527193A (ja) サービス取得方法、装置、通信機器及び可読記憶媒体
CN114285736A (zh) Supi号段配置系统、方法、装置、网络设备和介质
CN117295068A (zh) 一种通信方法、装置、通信设备和计算机存储介质
CN110268730A (zh) 用于管理向运营商的订阅的技术
CN116471590A (zh) 终端接入方法、装置及鉴权服务功能网元
CN117412288A (zh) 通信方法、装置、相关设备及存储介质
CN119325090A (zh) 一种家庭基站位置验证方法、装置、节点和存储介质
JP7338070B2 (ja) 情報処理方法及び関連するネットワーク機器
WO2020215272A1 (zh) 通信方法、通信装置和通信系统

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 16.08.2023).

122 Ep: pct application non-entry in european phase

Ref document number: 21885309

Country of ref document: EP

Kind code of ref document: A1