WO2023143418A1 - Device authentication method and apparatus, and terminal and network function - Google Patents

Device authentication method and apparatus, and terminal and network function Download PDF

Info

Publication number
WO2023143418A1
WO2023143418A1 PCT/CN2023/073279 CN2023073279W WO2023143418A1 WO 2023143418 A1 WO2023143418 A1 WO 2023143418A1 CN 2023073279 W CN2023073279 W CN 2023073279W WO 2023143418 A1 WO2023143418 A1 WO 2023143418A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
authentication
related information
network function
information
Prior art date
Application number
PCT/CN2023/073279
Other languages
French (fr)
Chinese (zh)
Inventor
谢振华
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2023143418A1 publication Critical patent/WO2023143418A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present application belongs to the technical field of communication, and in particular relates to a device authentication method, device, terminal and network function.
  • the network side cannot know the status of the devices behind the gateway.
  • the personal IoT gateway can be a gateway in a smart home scenario, or a gateway in a wearable device scenario.
  • the 5G network may need to identify the device and authenticate it.
  • the 5G network cannot authenticate them.
  • NAS Non-Access Stratum
  • Embodiments of the present application provide a device authentication method, device, terminal, and network function, which can solve the problem of how to authenticate a device that does not support the NAS protocol process.
  • a device authentication method including:
  • the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal;
  • the first terminal receives the second authentication related information sent by the second terminal, and sends the second authentication related information to the network side.
  • a device authentication method including:
  • the first network function receives the indication information sent by the second network function, and the indication information includes At least one of the following: relevant information of the first terminal, relevant information of the second terminal, an indication of stopping authentication, and an indication of authentication;
  • the first network function performs or stops performing a first operation according to the instruction information, and the first operation includes:
  • the first network function receives second authentication-related information sent by the first terminal, where the second authentication-related information is received by the first terminal from the second terminal;
  • the first network function sends the second authentication-related information to a third network function.
  • a device authentication method including:
  • the second network function sends instruction information to the first network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction;
  • the indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
  • a device authentication method including:
  • the third network function executes an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process with the third network function through the first terminal.
  • a device authentication method including:
  • the second terminal completes the authentication process with the first terminal
  • the second terminal After receiving the first authentication-related information from the first terminal, the second terminal sends to the first terminal second authentication-related information carrying a first identifier, wherein the first identifier is used to communicate with the network side to perform Authentication process.
  • a device authentication device including:
  • the first transceiver module is configured to receive the first authentication related information sent by the network side, and send the first authentication related information to the second terminal;
  • the second transceiver module is configured to receive the second authentication-related information sent by the second terminal, and send the second authentication-related information to the network side.
  • a device authentication device including:
  • the third transceiver module is configured to receive the instruction information sent by the second network function, the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ;
  • the fourth transceiver module is configured to perform or stop performing a first operation according to the indication information, and the first operation includes:
  • a device authentication device including:
  • the fifth transceiver module is configured to send instruction information to the first network function, where the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction;
  • the indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
  • a device authentication device including:
  • the first processing module is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
  • a device authentication device including:
  • the second processing module is used to complete the authentication process with the first terminal
  • the sixth transceiver module is configured to receive the first authentication-related information from the first terminal, and send the second authentication-related information carrying the first identification to the first terminal, wherein the first identification is used to communicate with the network side Execute the authentication process.
  • a terminal in an eleventh aspect, includes a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, the following is implemented: The steps of the method described in the first aspect or the fifth aspect.
  • a terminal including a processor and a communication interface, wherein the communication interface is used to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second
  • the terminal receiving the second authentication-related information sent by the second terminal, and sending the second authentication-related information to the network side.
  • the processor is configured to complete the authentication process with the first terminal;
  • the communication interface is configured to send a message carrying the first identifier to the first terminal after receiving the first authentication-related information from the first terminal.
  • the second authentication-related information wherein the first identifier is used to perform an authentication process with the network side.
  • a network function in a thirteenth aspect, includes a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the program or instructions are executed by the processor. The steps of the method described in the second aspect, the third aspect or the fourth aspect are implemented.
  • a network function including a processor and a communication interface, wherein the communication interface is used to receive indication information sent by a second network function, and the indication information includes at least one of the following: first Related information of the terminal, related information of the second terminal, stop authentication instruction, authentication instruction; perform or stop performing the first operation according to the instruction information, the first operation includes: sending the first authentication related information to the first terminal information, the first authentication-related information is used by the first terminal to send to the second terminal; the second authentication-related information sent by the first terminal is received, and the second authentication-related information is sent from the first terminal to the second terminal; Received by the second terminal; sending the second authentication-related information to a third network function;
  • the communication interface is used to send instruction information to the first network function
  • the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ;
  • the indication information is used for the execution or stop of the first network function to send first authentication related information to the first terminal, and the first authentication related information is used for the first terminal to send to the second terminal;
  • the processor is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
  • a fifteenth aspect provides a device authentication system, including: a terminal and a network side, the terminal includes a first terminal and a second terminal, and the network side includes a first network function, a second network function, and a third A network function, the terminal can be used to perform the device authentication described in the first aspect or the fifth aspect
  • the steps of the device authentication method described in the second aspect, the third aspect or the fourth aspect can be executed by the network side.
  • a readable storage medium where programs or instructions are stored on the readable storage medium, and when the programs or instructions are executed by a processor, the first aspect, the second aspect, the third aspect, and The steps of the method described in the fourth aspect or the fifth aspect.
  • a chip in a seventeenth aspect, includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the first aspect and the second Aspect, the step of the method described in the third aspect, the fourth aspect or the fifth aspect.
  • a computer program/program product is provided, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the first aspect, the first The steps of the method described in the second aspect, the third aspect, the fourth aspect or the fifth aspect.
  • the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the first authentication-related information sent by the second terminal.
  • Two authentication-related information and send the second authentication-related information to the network side, so that the second terminal (such as a non-3GPP terminal, that is, does not support the NAS protocol process) is realized through the first terminal (such as a personal Internet of Things gateway) device) for authentication.
  • FIG. 1 shows a structural diagram of a communication system applicable to an embodiment of the present application
  • FIG. 2 shows one of the schematic flow diagrams of the device authentication method in the embodiment of the present application
  • FIG. 3 shows the second schematic flow diagram of the device authentication method in the embodiment of the present application
  • FIG. 4 shows the third schematic flow diagram of the device authentication method in the embodiment of the present application
  • FIG. 5 shows the fourth schematic flow diagram of the device authentication method according to the embodiment of the present application.
  • FIG. 6 shows the fifth schematic flow diagram of the device authentication method according to the embodiment of the present application.
  • FIG. 7 shows one of the module schematic diagrams of the device authentication device according to the embodiment of the present application.
  • FIG. 8 shows the second schematic diagram of the modules of the device authentication device according to the embodiment of the present application.
  • FIG. 9 shows a structural block diagram of a communication device according to an embodiment of the present application.
  • FIG. 10 shows a structural block diagram of a terminal in an embodiment of the present application.
  • Fig. 11 shows the third schematic diagram of the modules of the device authentication device according to the embodiment of the present application.
  • FIG. 12 shows the fourth schematic diagram of the modules of the device authentication device according to the embodiment of the present application.
  • Fig. 13 shows the fifth schematic diagram of the modules of the device authentication device according to the embodiment of the present application.
  • Fig. 14 represents one of the structural block diagrams of the network function of the embodiment of the present application.
  • FIG. 15 shows the second structural block diagram of the network function of the embodiment of the present application.
  • first, second and the like in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific sequence or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances such that the embodiments of the application are capable of operation in sequences other than those illustrated or described herein and that "first" and “second” distinguish objects. It is usually one category, and the number of objects is not limited. For example, there may be one or more first objects.
  • “and/or” in the description and claims means at least one of the connected objects, and the character “/” generally means that the related objects are an "or” relationship.
  • LTE Long Term Evolution
  • LTE-Advanced LTE-Advanced
  • LTE-A Long Term Evolution-Advanced
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency Division Multiple Access
  • system and “network” in the embodiments of the present application are often used interchangeably, and the described technology can be used for the above-mentioned system and radio technology, and can also be used for other systems and radio technologies.
  • the following description describes the New Radio (New Radio, NR) system for illustrative purposes, and uses NR terminology in most of the following descriptions, but these techniques can also be applied to applications other than NR system applications, such as the 6th generation (6th generation Generation, 6G) communication system.
  • 6G 6th generation Generation
  • the network side may also be referred to as a network side device.
  • Fig. 1 shows a block diagram of a wireless communication system to which the embodiment of the present application is applicable.
  • the wireless communication system includes a terminal 11 and a network side device 12 .
  • the terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a palmtop computer, a netbook, a super mobile personal computer (ultra-mobile personal computer, UMPC), mobile Internet device (Mobile Internet Device, MID), augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) equipment, robot, wearable device (Wearable Device) , Vehicle User Equipment (VUE), Pedestrian User Equipment (PUE), smart home (home equipment with wireless communication functions, such as refrigerators, TVs, washing machines or furniture, etc.), game consoles, personal computers (personal computer, PC), teller machine or self-service machine and other terminal side devices, wearable devices include: smart watches, smart bracelet
  • the network side device 12 may include an access network device or a core network device, where the access network device 12 may also be called a radio access network device, a radio access network (Radio Access Network, RAN), a radio access network function, or Wireless access network unit.
  • RAN Radio Access Network
  • RAN Radio Access Network
  • Wireless access network unit Wireless access network unit
  • the access network device 12 may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point or a WiFi node, etc., and the base station may be called a node B, an evolved node B (eNB), an access point, or a base transceiver station (Base Transceiver Station, BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (Extended Service Set, ESS), Home Node B, Home Evolved Node B, sending and receiving point (Transmitting Receiving Point, TRP) or some other appropriate term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms.
  • a base station may be called a node B, an evolved node B (eNB), an access point, or a base transceiver station (Base Transceiver Station, BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (Extended Service Set, ESS), Home
  • the core network equipment may include but not limited to at least one of the following: core network node, core network function, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), Policy Control Function (Policy Control Function, PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF) , Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (Centralized network configuration, CNC), network storage function ( Network Repository Function, NRF), Network Exposure Function (NEF), Local NEF (Local NEF, or L-NEF), Binding Support Function (Binding Support Function, BSF), Application Function (Application Function, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane
  • PIN Personal IoT Network
  • PIN is a group consisting of at least one PIN element (PIN Element, PINE), wherein at least one PIN element is a terminal (User Equipment, UE). PIN elements communicate with each other. Two PIN elements can communicate through a direct connection between them, or indirectly through a communication network.
  • PIN Element PINE
  • UE User Equipment
  • a PIN element can be a 3rd Generation Partnership Project (3rd Generation Partnership Project, 3GPP) device (such as UE) or a non-3GPP device.
  • 3GPP devices refer to devices that do not use credentials defined by 3GPP, devices that do not support NAS protocols defined by 3GPP, or devices that do not support 3GPP access technologies, such as third-generation mobile communication technology (3th-Generation, 3G)/fourth-generation mobile Communication technology (4th-Generation, 4G)/5G air interface technology, but only supports non-3GPP access technologies (such as WiFi, fixed network, Bluetooth and other access technologies).
  • PIN Element With Gateway Capability PEGC
  • the PIN elements in the PIN can communicate with each other directly or through PEGC.
  • the PIN element in the PIN can communicate with other devices or application servers outside the PIN through the PEGC.
  • PEGC devices can be different types of devices. For example, PEGC can be a gateway in a smart home scenario, or a mobile phone as a gateway for wearable devices in a wearable device scenario.
  • the embodiment of this application provides a device authentication method, including:
  • Step 201 The first terminal receives the first authentication related information sent by the network side, and sends the first authentication related information to the second terminal.
  • the above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the above-mentioned first terminal may also be a home gateway.
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
  • the aforementioned network side may also be described as a first network function, or a device capable of realizing the first network function, and the first network function may specifically be an access and mobility management function (Access and Mobility Management Function, AMF) or session management Function (Session Management Function, SMF).
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • the first authentication-related information is sent by the AMF or the SMF
  • the second authentication-related information is sent by the second terminal and arrives at the AMF or the SMF.
  • Step 202 The first terminal receives the second authentication related information sent by the second terminal, and sends the second authentication related information to the network side.
  • the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the second authentication-related information sent by the second terminal.
  • Authentication-related information, and sending the second authentication-related information to the network side so that the second terminal (such as a non-3GPP terminal, that is, that does not support the NAS protocol process) is implemented through the first terminal (such as a personal Internet of Things gateway) device) for the purpose of authentication.
  • the first terminal before receiving the first authentication-related information sent by the network side, the first terminal further performs at least one of the following:
  • the first terminal configures a first IP address for the second terminal.
  • the first authentication-related information is not protected.
  • the method of the embodiment of the present application further includes:
  • the first terminal When the first terminal receives the first authentication-related information sent by the network side, the first terminal stops initiating or stopping the authentication process between the first terminal and the second terminal.
  • the first terminal when the first terminal receives the first authentication-related information sent by the network side, if the first terminal is performing an authentication process between the first terminal and the second terminal , then the current authentication process may be continued, and after the current authentication process is completed, the execution of the authentication process between the first terminal and the second terminal may be stopped or initiated.
  • the first terminal after the first terminal sends the second authentication-related information to the network side, it further includes:
  • the first terminal sends a second Internet Protocol (Internet Protocol, IP) address to the second terminal, or the first terminal no longer executes the operation of configuring the IP address for the second terminal.
  • IP Internet Protocol
  • the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
  • the second IP address may be the same as the first IP address.
  • the first authentication-related information or the second authentication-related information is information using an extensible authentication protocol (Extensible Authentication Protocol, EAP protocol).
  • EAP protocol Extensible Authentication Protocol
  • the above-mentioned first authentication-related information may specifically be an Extensible Identity Authentication Protocol Request-Identity EAP-req/Identity message
  • the above-mentioned second authentication-related information may specifically be an EAP-res/Identity message.
  • the first authentication-related information received by the first terminal and sent by the network side is carried by a first non-access stratum NAS message, and the first terminal sends the network
  • the second authentication-related information sent by the side is carried by a second non-access stratum NAS message;
  • the first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
  • the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol (Internet Key Exchange, IKE) Transmission
  • the second authentication-related information sent by the second terminal received by the first terminal is transmitted through a direct transmission link layer protocol or a network key exchange protocol IKE.
  • IKE Internet Key Exchange
  • the first authentication-related information received by the first terminal is carried in the NAS message
  • the second authentication-related information received by the first terminal and the first authentication-related information sent to the second terminal are carried in the direct transmission link layer
  • the protocol the protocol layer under the outermost IP protocol stack of the data message, such as the local area network (Local Area Network, LAN) network layer 2 protocol, Bluetooth connection layer 2 protocol, PC5 protocol).
  • the first NAS message carries related information of the second terminal.
  • the relevant information of the second terminal includes at least one of the following:
  • Control plane identification information for example, the identification assigned by the network side to the second terminal or the identification assigned by the first terminal to the second terminal, or the identification configured by the second terminal;
  • the user plane identification information includes at least one of the following:
  • IP address where the IP address may be specifically assigned by the network side or assigned by the first terminal
  • MAC Media Access Control
  • Direct connection information between the first terminal and the second terminal optionally, the direct connection information includes a direct connection identifier between the first terminal and the second terminal, such as information identifying a connection under the MAC layer , Connection ID (Link ID), Transaction ID (Transaction ID), etc.
  • the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
  • the network key exchange protocol IKE here, the layer 2 authentication can be completed first, and then the layer 3 authentication carried by the IKE protocol can be completed.
  • the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the second authentication-related information sent by the second terminal.
  • Authentication-related information, and sending the second authentication-related information to the network side so that the second terminal (such as a non-3GPP terminal, that is, that does not support the NAS protocol process) is implemented through the first terminal (such as a personal Internet of Things gateway) device) for the purpose of authentication.
  • the embodiment of the present application also provides a device authentication method, including:
  • Step 301 The first network function receives the instruction information sent by the second network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction .
  • the foregoing first network function may also be described as a first network element, and the first network function may specifically be an Access and Mobility Management Function (Access and Mobility Management Function, AMF) or a Session Management Function (Session Management Function, SMF).
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • the above-mentioned second network function may also be described as a second network element, for example, the second network function is a Network Exposure Function (Network Exposure Function, NEF) or an Application Function (Application Function, AF).
  • NEF Network Exposure Function
  • AF Application Function
  • the above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the above-mentioned first terminal may also be a home gateway.
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
  • the first network function determines the identification information of the first terminal according to at least one of the related information of the first terminal and the related information of the second terminal.
  • Step 302 The first network function performs or stops performing the first operation according to the indication information.
  • the first network function stops performing the first operation, or if the instruction information includes an authentication instruction, then the first network function executes the first operation.
  • the first operation includes:
  • the first network function receives the second authentication-related information sent by the first terminal, and the first The second authentication-related information is received by the first terminal from the second terminal.
  • the first network function sends the second authentication-related information to a third network function.
  • the third network function here can be specifically unified data management entity (Unified Data Management, UDM), authentication service function (Authentication Server Function, AUSF) or verification, authorization and accounting (Authentication, Authorization, Accounting, AAA) equipment .
  • UDM Unified Data Management
  • AUSF Authentication Server Function
  • AAA Authorization, Accounting
  • the first network function receives the indication information sent by the second network function, so that the first network function can send the first authentication-related information to the first terminal according to the indication information, and the first The authentication-related information is used by the first terminal to send to the second terminal, and the first network function receives the second authentication-related information sent by the first terminal, and the second authentication-related information is sent by the first terminal from The second terminal receives, and the first network function sends the second authentication-related information to the third network function, so that the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process) ) for the purpose of authentication.
  • the second terminal such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process
  • the first network function when the first network function performs the first operation, the first network function further performs at least one of the following:
  • the method in this embodiment of the present application when the first network function performs the first operation, further includes:
  • the first network function forwards subsequent authentication-related information between the second terminal and the third network function, and the subsequent authentication-related information is used to perform a communication between the second terminal and the third network function certification.
  • the relevant information of the second terminal includes at least one of the following:
  • the user plane identification information includes at least one of the following:
  • the first authentication related information sent by the first network function to the first terminal is carried by a first NAS message
  • the second authentication sent by the first terminal received by the first network function Related information is carried by the second NAS message.
  • the first NAS message carries related information of the second terminal.
  • the first authentication-related information or the second authentication-related information is EAP protocol information.
  • the first authentication-related information is used to request an identifier of the first terminal.
  • the first network function receives the instruction information sent by the second network function, and the first network function executes or stops performing the first operation according to the instruction information, for example, sends the first authentication to the first terminal Related information, the first authentication related information is used by the first terminal to send to the second terminal, the first network function receives the second authentication related information sent by the first terminal, the second authentication The relevant information is received by the first terminal from the second terminal, and the first network function sends the second authentication related information to the third network function, thereby realizing the authentication of the second terminal (such as a non-3GPP terminal, that is, Devices that do not support the NAS protocol process) for the purpose of authentication.
  • the second terminal such as a non-3GPP terminal, that is, Devices that do not support the NAS protocol process
  • the embodiment of the present application also provides a device authentication method, including:
  • Step 401 The second network function sends instruction information to the first network function, and the instruction information includes at least one of the following items: related information of the first terminal, related information of the second terminal, an instruction to stop authentication, and an instruction to authenticate;
  • the indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
  • the indication information includes an indication of stopping authentication
  • the indication information is used for the first network function to stop executing and send the first authentication-related information to the first terminal.
  • the indication information includes stopping authentication at least, Then the indication information is used for the first network function to send the first authentication related information to the first terminal.
  • the second network function sends indication information to the first network function, so that the first network function
  • the identification information of the first terminal can be determined according to the indication information, so as to send the first authentication related information to the first terminal, and make the first terminal send the first authentication related information to the second terminal.
  • the above-mentioned second network function is a network exposure function (Network Exposure Function, NEF) or an application function (Application Function, AF).
  • NEF Network Exposure Function
  • AF Application Function
  • the above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the above-mentioned first terminal may also be a home gateway.
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
  • the second network function sends indication information to the first network function, so that the first network function determines the identification information of the first terminal according to the indication information, thereby sends the first authentication-related information to the first terminal, and
  • the first terminal is made to send the first authentication-related information to the second terminal, so as to accomplish the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the second authentication-related information is EAP information.
  • the second network function sends indication information to the first network function, so that the first network function determines the identification information of the first terminal according to the indication information, thereby sends the first authentication-related information to the first terminal, and
  • the first terminal is made to send the first authentication-related information to the second terminal, so as to accomplish the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the embodiment of the present application also provides a device authentication method, including:
  • Step 501 The third network function executes an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process with the third network function through the first terminal.
  • the above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the above-mentioned first terminal may also be a home gateway.
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
  • the third network function here can be specifically unified data management entity (Unified Data Management, UDM), authentication service function (Authentication Server Function, AUSF) or verification, authorization and accounting (Authentication, Authorization, Accounting, AAA) equipment .
  • UDM Unified Data Management
  • AUSF Authentication Server Function
  • AAA Authorization, Accounting
  • the third network function executes the authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the third network function performs at least one of the following during the authentication process or after the authentication process succeeds:
  • the third network function before performing the authentication process, further includes:
  • the third network function receives second authentication-related information sent by the first network function, the second authentication-related information is received by the first network function from the first terminal, and the first terminal receives from the second terminal Received.
  • the second terminal sends the second authentication-related information to the first terminal, and after the first terminal receives the second authentication-related information sent by the second terminal, The second authentication-related information is sent to the first network function, and the first network function sends the second authentication-related information to the third network function.
  • the third network function performs an authentication process between the second terminal and the third network function, including:
  • the third network function selects or uses the EAP protocol to perform the authentication based on at least one of the following: Certification process:
  • the information of the first network function, such as the third network function is based on information from the SMF instead of the AMF;
  • the second authentication-related information for example, the second authentication-related information is sent using the EAP protocol.
  • the method of the embodiment of the present application further includes:
  • the third network function receives an instruction from the first network function, and the third network function performs at least one of the following during the authentication process or after the authentication process is successful according to the instruction:
  • the instructions include at least one of the following:
  • Information about the first network function an instruction related to stopping key derivation or sending key information, and the second authentication-related information.
  • the second authentication-related information is information of the EAP protocol.
  • the selecting or using the EAP protocol to perform the authentication process includes:
  • the EAP protocol is selected to execute the authentication process.
  • the third network function executes the authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the embodiment of the present application also provides a device authentication method, including:
  • Step 601 the second terminal completes the authentication process with the first terminal.
  • Step 602 After receiving the first authentication-related information from the first terminal, the second terminal sends to the first terminal second authentication-related information carrying a first identifier, wherein the first identifier is used to communicate with the first terminal.
  • the network side executes the authentication process.
  • the above-mentioned first terminal is a terminal capable of gateway in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the above-mentioned first terminal may also be a home gateway.
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
  • the second terminal after the second terminal completes the authentication process with the first terminal, it receives the first authentication-related information from the first terminal, and sends the second authentication-related information carrying the first identifier to the first terminal.
  • Information so that the subsequent network side can perform the authentication process on the second terminal based on the first identifier, so as to achieve the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the method of the embodiment of the present application further includes:
  • the second terminal stops key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
  • the method of the embodiment of the present application further includes:
  • the second terminal completes the authentication process with the first terminal by using the second identifier.
  • the second identifier may be the same as or different from the first identifier.
  • the method of the embodiment of the present application further includes:
  • the second terminal uses the first identifier based on the security protection of the first authentication-related information.
  • the second terminal using the first identifier based on the security protection of the first authentication-related information includes:
  • the second terminal uses the first identifier.
  • the first authentication-related information is used to request an identifier of the first terminal.
  • the second terminal after the second terminal completes the authentication process with the first terminal, it receives the first authentication-related information from the first terminal, and sends the second authentication-related information carrying the first identifier to the first terminal.
  • Information so that the subsequent network side can perform the authentication process on the second terminal based on the first identifier, so as to achieve the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the device authentication method provided in the embodiment of the present application may be executed by a device authentication device.
  • the embodiment of the present application provides a device authentication apparatus 700, which is applied to the first terminal, including:
  • the first transceiver module 701 is configured to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second terminal;
  • the second transceiving module 702 is configured to receive the second authentication related information sent by the second terminal, and send the second authentication related information to the network side.
  • the device of the embodiment of the present application further includes:
  • the third processing module is configured to perform at least one of the following before the first transceiver module receives the first authentication-related information sent by the network side:
  • the first terminal configures a first IP address for the second terminal.
  • the first authentication-related information is not protected.
  • the device of the embodiment of the present application further includes:
  • the fourth processing module is configured to, when the first terminal receives the first authentication-related information sent by the network side, stop the first terminal from initiating or stop executing the communication between the first terminal and the second Authentication process between endpoints.
  • the device of the embodiment of the present application further includes:
  • the fifth processing module is configured to send the second IP address from the first terminal to the second terminal after the second transceiver module sends the second authentication-related information to the network side, or the first terminal sends the second IP address to the second terminal, or the first The terminal no longer performs the operation of configuring the IP address for the second terminal.
  • the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
  • the first authentication-related information or the second authentication-related information is information using an Extensible Authentication Protocol (EAP) protocol.
  • EAP Extensible Authentication Protocol
  • the first authentication-related information sent by the network side received by the first terminal is carried in a first non-access stratum NAS message, and the first authentication-related information sent by the first terminal to the network side 2.
  • Authentication-related information is carried by a second non-access stratum NAS message;
  • the first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
  • the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol IKE, and the first terminal receives the The second authentication-related information sent by the second terminal is transmitted through the direct link layer protocol or the network key exchange protocol IKE.
  • the first NAS message carries related information of the second terminal.
  • the relevant information of the second terminal includes at least one of the following:
  • the user plane identification information includes at least one of the following:
  • the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following item:
  • the first terminal is a terminal capable of gateway in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the first terminal receives the first authentication-related information sent by the network side, and sends The first authentication-related information is sent to the second terminal, the first terminal receives the second authentication-related information sent by the second terminal, and sends the second authentication-related information to the network side, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process) through the first terminal (such as a personal Internet of Things gateway).
  • a non-3GPP terminal that is, a device that does not support the NAS protocol process
  • the embodiment of the present application also provides a device authentication device 800, which is applied to the second terminal, and the device includes:
  • the second processing module 801 is used for the second terminal to complete the authentication process with the first terminal;
  • the sixth transceiver module 802 is configured to send the second authentication-related information carrying the first identifier to the first terminal after the second terminal receives the first authentication-related information from the first terminal, wherein the first An identity is used to perform an authentication process with the network side.
  • the device of the embodiment of the present application further includes:
  • the sixth processing module is used for the second terminal to stop key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
  • the device of the embodiment of the present application further includes:
  • a seventh processing module configured to use the second identifier to complete the authentication process with the first terminal.
  • the device of the embodiment of the present application further includes:
  • An eighth processing module configured to use the first identifier based on the security protection status of the first authentication-related information.
  • the eighth processing module is configured to use the first identifier by the second terminal when the first authentication-related information is for security protection.
  • the first authentication-related information is used to request an identifier of the first terminal.
  • the second terminal after the second terminal completes the authentication process with the first terminal, it receives the first authentication-related information from the first terminal, and sends the second authentication-related information carrying the first identifier to the first terminal.
  • Information so that the subsequent network side can perform the authentication process on the second terminal based on the first identifier, so as to achieve the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the device authentication apparatus in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device may be a terminal, or other devices other than the terminal.
  • the terminal can include but It is not limited to the type of the terminal 11 listed above, and other devices may be a server, a network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in this embodiment of the present application.
  • the device authentication device provided in the embodiment of the present application can realize each process realized by the method embodiment in FIG. 2 or FIG. 6 , and achieve the same technical effect. To avoid repetition, details are not repeated here.
  • this embodiment of the present application also provides a communication device 900, including a processor 901 and a memory 902, and the memory 902 stores programs or instructions that can run on the processor 901, such as
  • the communication device 900 is the first terminal, when the program or instruction is executed by the processor 901, each step of the above embodiment of the device authentication method applied to the first terminal can be implemented, and the same technical effect can be achieved.
  • the communication device 900 is the second terminal, when the program or instruction is executed by the processor 901, each step of the above embodiment of the device authentication method applied to the second terminal can be implemented, and the same technical effect can be achieved.
  • the communication device 900 is a network function (such as a first network function, a second network function, or a third network function), when the program or instruction is executed by the processor 901, the above embodiment of the device authentication method applied to the network function is implemented.
  • a network function such as a first network function, a second network function, or a third network function
  • the program or instruction is executed by the processor 901
  • the above embodiment of the device authentication method applied to the network function is implemented.
  • Each step can achieve the same technical effect, so in order to avoid repetition, it will not be repeated here.
  • the embodiment of the present application also provides a terminal, including a processor and a communication interface, the communication interface is used to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second terminal; receive the The second terminal sends the second authentication-related information, and sends the second authentication-related information to the network side.
  • the embodiment of the present application also provides a terminal, including a processor and a communication interface, the processor is used to complete the authentication process with the first terminal; the communication interface is used to receive the first authentication-related information from the first terminal, Sending the second authentication-related information carrying the first identifier to the first terminal, where the first identifier is used to perform an authentication process with the network side.
  • FIG. 10 is a schematic diagram of a hardware structure of a terminal implementing an embodiment of the present application.
  • the terminal 1000 includes, but is not limited to: a radio frequency unit 1001, a network module 1002, an audio output unit 1003, an input unit 1004, a sensor 1005, a display unit 1006, a user input unit 1007, an interface unit 1008, a memory 1009, and a processor 1010. At least some parts.
  • the terminal 1000 may also include a power supply for supplying power to each component (such as a battery), the power supply can be logically connected to the processor 1010 through the power management system, so that functions such as management of charging, discharging, and power consumption management can be realized through the power management system.
  • the terminal structure shown in FIG. 10 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange different components, which will not be repeated here.
  • the input unit 1004 may include a graphics processing unit (Graphics Processing Unit, GPU) 10041 and a microphone 10042, and the graphics processor 10041 can be used by the image capture device (such as the image data of the still picture or video obtained by the camera) for processing.
  • the display unit 1006 may include a display panel 10061, and the display panel 10061 may be configured in the form of a liquid crystal display, an organic light emitting diode, or the like.
  • the user input unit 1007 includes at least one of a touch panel 10071 and other input devices 10072 .
  • the touch panel 10071 is also called a touch screen.
  • the touch panel 10071 may include two parts, a touch detection device and a touch controller.
  • Other input devices 10072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, switch buttons, etc.), trackballs, mice, and joysticks, which will not be repeated here.
  • the radio frequency unit 1001 may transmit it to the processor 1010 for processing; in addition, the radio frequency unit 1001 may send the uplink data to the network side device.
  • the radio frequency unit 1001 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, and the like.
  • the memory 1009 can be used to store software programs or instructions as well as various data.
  • the memory 1009 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instructions required by at least one function (such as a sound playing function, image playback function, etc.), etc.
  • memory 1009 may include volatile memory or nonvolatile memory, or, memory 1009 may include both volatile and nonvolatile memory.
  • the non-volatile memory may be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM, PROM), an erasable programmable read-only memory (Erasable PROM, EPROM), an electronically programmable Erase Programmable Read-Only Memory (Electrically EPROM, EEPROM) or Flash.
  • ROM Read-Only Memory
  • PROM programmable read-only memory
  • Erasable PROM Erasable PROM
  • EPROM electronically programmable Erase Programmable Read-Only Memory
  • Flash Flash
  • Volatile memory can be random access memory (Random Access Memory, RAM), static random access memory (Static RAM, SRAM), dynamic random access memory (Dynamic RAM, DRAM), synchronous dynamic random access memory (Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDRSDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchronous connection dynamic random access memory (Synch link DRAM , SLDRAM) and Direct Memory Bus Random Access Memory (Direct Rambus RAM, DRRAM).
  • RAM Random Access Memory
  • SRAM static random access memory
  • DRAM dynamic random access memory
  • DRAM synchronous dynamic random access memory
  • SDRAM double data rate synchronous dynamic random access memory
  • Double Data Rate SDRAM Double Data Rate SDRAM
  • DDRSDRAM double data rate synchronous dynamic random access memory
  • Enhanced SDRAM, ESDRAM enhanced synchronous dynamic random access memory
  • Synch link DRAM , SLDRAM
  • Direct Memory Bus Random Access Memory Direct Rambus
  • the processor 1010 may include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., Modem processors mainly process wireless communication signals, such as baseband processors. It can be understood that the foregoing modem processor may not be integrated into the processor 1010 .
  • the radio frequency unit 1001 is configured to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second terminal; receive the first authentication-related information sent by the second terminal; 2. Authentication related information, and sending the second authentication related information to the network side.
  • the processor 1010 is configured to perform at least one of the following:
  • the first terminal configures a first IP address for the second terminal.
  • the first authentication-related information is not protected.
  • the processor 1010 is configured to, when the first terminal receives the first authentication-related information sent by the network side, stop initiating or stopping execution of the communication between the first terminal and the second terminal. authentication process.
  • the processor 1010 is configured to send the second IP address to the second terminal through the radio frequency unit, or the operation of configuring the IP address for the second terminal is no longer performed.
  • the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
  • the first authentication-related information or the second authentication-related information is information using an Extensible Authentication Protocol (EAP) protocol.
  • EAP Extensible Authentication Protocol
  • the first authentication-related information sent by the network side received by the first terminal is carried in a first non-access stratum NAS message, and the first authentication-related information sent by the first terminal to the network side 2.
  • Authentication-related information is carried by a second non-access stratum NAS message;
  • the first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
  • the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol IKE, and the first terminal receives the The second authentication-related information sent by the second terminal is transmitted through the direct link layer protocol or the network key exchange protocol IKE.
  • the first NAS message carries related information of the second terminal.
  • the relevant information of the second terminal includes at least one of the following:
  • the user plane identification information includes at least one of the following:
  • the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
  • a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following item:
  • the first terminal is a terminal capable of gateway in the Personal Internet of Things
  • the second terminal is a non-3GPP device or a Personal Internet of Things device.
  • the processor 1010 is configured to complete authentication with the first terminal Process; the radio frequency unit 1001 is configured to send the second authentication-related information carrying the first identification to the first terminal after receiving the first authentication-related information from the first terminal, wherein the first identification is used to communicate with the network The authentication process is performed on the side.
  • the processor 1010 is configured to stop the key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
  • the processor 1010 is configured to use the second identifier to complete an authentication process with the first terminal.
  • the processor 1010 is configured to use the first identifier based on a security protection situation of the first authentication-related information.
  • the processor 1010 is configured to, when the first authentication-related information is for security protection, use the first identifier by the second terminal.
  • the first authentication-related information is used to request an identifier of the first terminal.
  • the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the second authentication-related information sent by the second terminal.
  • Authentication-related information, and sending the second authentication-related information to the network side so that the second terminal (such as a non-3GPP terminal, that is, that does not support the NAS protocol process) is implemented through the first terminal (such as a personal Internet of Things gateway) device) for the purpose of authentication.
  • the embodiment of the present application also provides a device authentication device 1100, which is applied to the first network function, and the device includes:
  • the third transceiver module 1101 is configured to receive the indication information sent by the second network function, the indication information includes at least one of the following: related information of the first terminal, related information of the second terminal, indication of stopping authentication, authentication instruct;
  • the fourth transceiver module 1102 is configured to perform or stop performing a first operation according to the indication information, the first operation includes:
  • the device of the embodiment of the present application further includes:
  • the ninth processing module is configured to perform at least one of the following when the fourth transceiver module performs the first operation:
  • the device of the embodiment of the present application further includes:
  • a first forwarding module configured to forward subsequent authentication-related information between the second terminal and the third network function when the fourth transceiver module performs the first operation, the subsequent authentication-related information is used for performing authentication between the second terminal and the third network function.
  • the relevant information of the second terminal includes at least one of the following:
  • the user plane identification information includes at least one of the following:
  • the first authentication related information sent by the first network function to the first terminal is carried by a first NAS message
  • the second authentication sent by the first terminal received by the first network function Related information is carried by the second NAS message.
  • the first NAS message carries related information of the second terminal.
  • the first authentication-related information or the second authentication-related information is EAP protocol information.
  • the first authentication-related information is used to request an identifier of the first terminal.
  • the first network function receives the indication information sent by the second network function, so that the first network function can send the first authentication-related information to the first terminal according to the indication information, and the first The authentication-related information is used by the first terminal to send to the second terminal, and the first network function receives the second authentication-related information sent by the first terminal, and the second authentication-related information is sent by the first terminal from received by the second terminal, the first network function sends the second authentication
  • the certificate-related information is sent to the third network function, thereby achieving the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the embodiment of the present application also provides a device authentication device 1200, which is applied to the second network function, and the device includes:
  • the fifth transceiver module 1201 is configured to send instruction information to the first network function, where the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction ;
  • the indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
  • the device in this embodiment of the present application further includes: a first determining module, configured to determine the indication information.
  • the first authentication-related information is EAP information.
  • the second network function sends indication information to the first network function, so that the first network function determines the identification information of the first terminal according to the indication information, thereby sends the first authentication-related information to the first terminal, and
  • the first terminal is made to send the first authentication-related information to the second terminal, so as to accomplish the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the embodiment of the present application also provides a device authentication apparatus 1300, which is applied to the third network function, including:
  • the first processing module 1301 is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
  • the third network function performs at least one of the following during the authentication process or after the authentication process succeeds:
  • the device of the embodiment of the present application further includes:
  • a seventh transceiver module configured to receive second authentication-related information sent by the first network function, the second authentication-related information is received by the first network function from the first terminal, and the first terminal terminal received from the second terminal.
  • the first processing module is configured to select or use the EAP protocol to perform the authentication process based on at least one of the following:
  • the second authentication-related information The second authentication-related information.
  • the second authentication-related information is information of the EAP protocol.
  • the method of the embodiment of the present application further includes:
  • An eighth transceiver module configured to receive an instruction from the first network function
  • a tenth processing module configured to perform at least one of the following during the authentication process or after the authentication process succeeds according to the instruction:
  • the instructions include at least one of the following:
  • Information about the first network function an instruction related to stopping key derivation or sending key information, and the second authentication-related information.
  • the first processing module is configured to select an EAP protocol to execute the authentication process when the second authentication-related information is information of an EAP protocol.
  • the third network function executes the authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
  • the embodiment of the present application also provides a network function (which can also be described as a network side device), including a processor and a communication interface, the communication interface is used to receive instruction information sent by the second network function, and the instruction information includes at least one of the following Items: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction; perform or stop performing the first operation according to the instruction information, and the first operation includes: sending to the first terminal First authentication-related information, the first authentication-related information is used by the first terminal to send to the second terminal; receiving second authentication-related information sent by the first terminal, the second authentication-related information is Received by the first terminal from the second terminal; sending the second authentication-related information to a third network function.
  • a network function which can also be described as a network side device
  • the communication interface is used to receive instruction information sent by the second network function
  • the instruction information includes at least one of the following Items: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction; perform or stop performing the first operation
  • the communication interface is used to send instruction information to the first network function
  • the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ;
  • the indication information is used for the execution or stop of the first network function to send first authentication related information to the first terminal, and the first authentication related information is used for the first terminal to send to the second terminal.
  • the processor is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
  • This network function embodiment corresponds to the above network function method embodiment, and each implementation process and implementation mode of the above method embodiment can be applied to this network function embodiment, and can achieve the same technical effect.
  • the embodiment of the present application also provides a network function (that is, the above-mentioned first network function, second network function or third network function), as shown in FIG. 14 , the network function 1400 includes: an antenna 141, a radio frequency device 142 , baseband device 143 , processor 144 and memory 145 .
  • the antenna 141 is connected to the radio frequency device 142 .
  • the radio frequency device 142 receives information through the antenna 141, and sends the received information to the baseband device 143 for processing.
  • the baseband device 143 processes the information to be sent and sends it to the radio frequency device 142
  • the radio frequency device 142 processes the received information and sends it out through the antenna 141 .
  • the method for executing the network function in the above embodiments may be implemented in the baseband device 143, where the baseband device 143 includes a baseband processor.
  • the baseband device 143 can include at least one baseband board, for example, a plurality of chips are arranged on the baseband board, as shown in FIG.
  • the program executes the network device operations shown in the above method embodiments.
  • the network function may also include a network interface 146, such as a common public radio interface (CPRI).
  • a network interface 146 such as a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network function 1400 in this embodiment of the present invention also includes: instructions or programs stored in the memory 145 and operable on the processor 144, and the processor 144 calls the instructions or programs in the memory 145 to execute FIG. 11 , 12 or 13
  • the methods executed by each module shown in the figure achieve the same technical effect, so in order to avoid repetition, they are not repeated here.
  • the embodiment of the present application further provides a network function (the above-mentioned first network function, second network function, or third network function).
  • the network function 1500 includes: a processor 1501 , a network interface 1502 and a memory 1503 .
  • the network interface 1502 is, for example, a common public radio interface (common public radio interface, CPRI).
  • the network function 1500 in this embodiment of the present invention also includes: instructions or programs stored in the memory 1503 and operable on the processor 1501, and the processor 1501 invokes the instructions or programs in the memory 1503 to execute FIG. 11 , 12 or 13
  • the methods executed by each module shown in the figure achieve the same technical effect, so in order to avoid repetition, they are not repeated here.
  • the embodiment of the present application also provides a readable storage medium, the readable storage medium stores a program or an instruction, and when the program or instruction is executed by a processor, each process of the above embodiment of the device authentication method is implemented, and can achieve The same technical effects are not repeated here to avoid repetition.
  • the processor is the processor in the terminal described in the foregoing embodiments.
  • the readable storage medium includes a computer-readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk, and the like.
  • the embodiment of the present application further provides a chip, the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the above embodiment of the device authentication method Each process, and can achieve the same technical effect, in order to avoid repetition, will not repeat them here.
  • the chip mentioned in the embodiment of the present application may also be called a system-on-chip, a system-on-chip, a system-on-a-chip, or a system-on-a-chip.
  • the embodiment of the present application further provides a computer program/program product, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the above device authentication method
  • the embodiment of the present application also provides a device authentication system, including: a terminal and a network side, the terminal includes a first terminal and a second terminal, and the network side includes a first network function, a second network function, and a third A network function, the terminal can be used to perform the above-mentioned steps of the device authentication method applied to the first terminal or the second terminal, and each network function in the network side can be used to perform the above-mentioned steps applied to the first terminal Device authentication method for network function, second network function or third network function A step of.
  • the term “comprising”, “comprising” or any other variation thereof is intended to cover a non-exclusive inclusion such that a process, method, article or apparatus comprising a set of elements includes not only those elements, It also includes other elements not expressly listed, or elements inherent in the process, method, article, or device. Without further limitations, an element defined by the phrase “comprising a " does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising that element.
  • the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved. Functions are performed, for example, the described methods may be performed in an order different from that described, and various steps may also be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
  • the methods of the above embodiments can be implemented by means of software plus a necessary general-purpose hardware platform, and of course also by hardware, but in many cases the former is better implementation.
  • the technical solution of the present application can be embodied in the form of computer software products, which are stored in a storage medium (such as ROM/RAM, magnetic disk, etc.) , CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) execute the methods described in the various embodiments of the present application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The present application belongs to the technical field of communications. Disclosed are a device authentication method and apparatus, and a terminal and a network function. The device authentication method in the embodiments of the present application comprises: a first terminal receiving first authentication-related information, which is sent by a network side, and sending the first authentication-related information to a second terminal; and the first terminal receiving second authentication-related information, which is sent by the second terminal, and sending the second authentication-related information to the network side.

Description

设备鉴权方法、装置、终端及网络功能Device authentication method, device, terminal and network function
相关申请的交叉引用Cross References to Related Applications
本申请主张在2022年1月27日在中国提交的中国专利申请No.202210101704.2的优先权,其全部内容通过引用包含于此。This application claims priority to Chinese Patent Application No. 202210101704.2 filed in China on January 27, 2022, the entire contents of which are hereby incorporated by reference.
技术领域technical field
本申请属于通信技术领域,具体涉及一种设备鉴权方法、装置、终端及网络功能。The present application belongs to the technical field of communication, and in particular relates to a device authentication method, device, terminal and network function.
背景技术Background technique
相关技术中,网络侧无法获知网关后的设备的情况,在特定的一些场景,例如个人物联网场景下,个人物联网网关可以是智能家居场景中的网关,也可以是可穿戴设备场景中的手机等,在网关后的通信设备通过网关接入第五代移动通信技术(5th-Generation,5G)网络时,5G网络可能需要识别该设备,并对其鉴权。然而,由于网关后的通信设备类型多种多样,在通信设备不支持非接入层(Non-Access Stratum,NAS)协议过程时,5G网络无法对其进行鉴权。In related technologies, the network side cannot know the status of the devices behind the gateway. In some specific scenarios, such as the personal Internet of Things scenario, the personal IoT gateway can be a gateway in a smart home scenario, or a gateway in a wearable device scenario. When the communication device behind the gateway accesses the fifth-generation mobile communication technology (5th-Generation, 5G) network through the gateway, the 5G network may need to identify the device and authenticate it. However, due to the various types of communication devices behind the gateway, when the communication devices do not support the Non-Access Stratum (NAS) protocol process, the 5G network cannot authenticate them.
发明内容Contents of the invention
本申请实施例提供一种设备鉴权方法、装置、终端及网络功能,能够解决如何对不支持NAS协议过程的设备进行鉴权的问题。Embodiments of the present application provide a device authentication method, device, terminal, and network function, which can solve the problem of how to authenticate a device that does not support the NAS protocol process.
第一方面,提供了一种设备鉴权方法,包括:In the first aspect, a device authentication method is provided, including:
第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;The first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal;
所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。The first terminal receives the second authentication related information sent by the second terminal, and sends the second authentication related information to the network side.
第二方面,提供了一种设备鉴权方法,包括:In the second aspect, a device authentication method is provided, including:
第一网络功能接收第二网络功能发送的指示信息,所述指示信息中包含 以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The first network function receives the indication information sent by the second network function, and the indication information includes At least one of the following: relevant information of the first terminal, relevant information of the second terminal, an indication of stopping authentication, and an indication of authentication;
所述第一网络功能根据所述指示信息执行或停止执行第一操作,所述第一操作包含:The first network function performs or stops performing a first operation according to the instruction information, and the first operation includes:
向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;Sending first authentication-related information to the first terminal, where the first authentication-related information is used by the first terminal to send to the second terminal;
所述第一网络功能接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的;The first network function receives second authentication-related information sent by the first terminal, where the second authentication-related information is received by the first terminal from the second terminal;
所述第一网络功能将所述第二认证相关信息发送给第三网络功能。The first network function sends the second authentication-related information to a third network function.
第三方面,提供了一种设备鉴权方法,包括:In a third aspect, a device authentication method is provided, including:
第二网络功能向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The second network function sends instruction information to the first network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction;
所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。The indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
第四方面,提供了一种设备鉴权方法,包括:In a fourth aspect, a device authentication method is provided, including:
第三网络功能执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。The third network function executes an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process with the third network function through the first terminal.
第五方面,提供了一种设备鉴权方法,包括:In the fifth aspect, a device authentication method is provided, including:
第二终端完成与第一终端之间的认证过程;The second terminal completes the authentication process with the first terminal;
所述第二终端接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。After receiving the first authentication-related information from the first terminal, the second terminal sends to the first terminal second authentication-related information carrying a first identifier, wherein the first identifier is used to communicate with the network side to perform Authentication process.
第六方面,提供了一种设备鉴权装置,包括:In a sixth aspect, a device authentication device is provided, including:
第一收发模块,用于接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;The first transceiver module is configured to receive the first authentication related information sent by the network side, and send the first authentication related information to the second terminal;
第二收发模块,用于接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。 The second transceiver module is configured to receive the second authentication-related information sent by the second terminal, and send the second authentication-related information to the network side.
第七方面,提供了一种设备鉴权装置,包括:In the seventh aspect, a device authentication device is provided, including:
第三收发模块,用于接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The third transceiver module is configured to receive the instruction information sent by the second network function, the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ;
第四收发模块,用于根据所述指示信息执行或停止执行第一操作,所述第一操作包含:The fourth transceiver module is configured to perform or stop performing a first operation according to the indication information, and the first operation includes:
向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;Sending first authentication-related information to the first terminal, where the first authentication-related information is used by the first terminal to send to the second terminal;
接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的;receiving second authentication-related information sent by the first terminal, where the second authentication-related information is received by the first terminal from the second terminal;
将所述第二认证相关信息发送给第三网络功能。Send the second authentication-related information to a third network function.
第八方面,提供了一种设备鉴权装置,包括:In an eighth aspect, a device authentication device is provided, including:
第五收发模块,用于向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The fifth transceiver module is configured to send instruction information to the first network function, where the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction;
所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。The indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
第九方面,提供了一种设备鉴权装置,包括:In the ninth aspect, a device authentication device is provided, including:
第一处理模块,用于执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。The first processing module is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
第十方面,提供了一种设备鉴权装置,包括:In a tenth aspect, a device authentication device is provided, including:
第二处理模块,用于完成与第一终端之间的认证过程;The second processing module is used to complete the authentication process with the first terminal;
第六收发模块,用于接收到来自第一终端的第一认证相关信息,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。The sixth transceiver module is configured to receive the first authentication-related information from the first terminal, and send the second authentication-related information carrying the first identification to the first terminal, wherein the first identification is used to communicate with the network side Execute the authentication process.
第十一方面,提供了一种终端,该终端包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面或第五方面所述的方法的步骤。 In an eleventh aspect, a terminal is provided, the terminal includes a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, the following is implemented: The steps of the method described in the first aspect or the fifth aspect.
第十二方面,提供了一种终端,包括处理器及通信接口,其中,所述通信接口用于接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。In a twelfth aspect, a terminal is provided, including a processor and a communication interface, wherein the communication interface is used to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second The terminal: receiving the second authentication-related information sent by the second terminal, and sending the second authentication-related information to the network side.
或者,所述处理器用于完成与第一终端之间的认证过程;所述通信接口用于接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。Alternatively, the processor is configured to complete the authentication process with the first terminal; the communication interface is configured to send a message carrying the first identifier to the first terminal after receiving the first authentication-related information from the first terminal. The second authentication-related information, wherein the first identifier is used to perform an authentication process with the network side.
第十三方面,提供了一种网络功能,该网络功能包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第二方面、第三方面或第四方面所述的方法的步骤。In a thirteenth aspect, a network function is provided, the network function includes a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the program or instructions are executed by the processor The steps of the method described in the second aspect, the third aspect or the fourth aspect are implemented.
第十四方面,提供了一种网络功能,包括处理器及通信接口,其中,所述通信接口用于接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;根据所述指示信息执行或停止执行第一操作,所述第一操作包含:向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的;将所述第二认证相关信息发送给第三网络功能;In a fourteenth aspect, a network function is provided, including a processor and a communication interface, wherein the communication interface is used to receive indication information sent by a second network function, and the indication information includes at least one of the following: first Related information of the terminal, related information of the second terminal, stop authentication instruction, authentication instruction; perform or stop performing the first operation according to the instruction information, the first operation includes: sending the first authentication related information to the first terminal information, the first authentication-related information is used by the first terminal to send to the second terminal; the second authentication-related information sent by the first terminal is received, and the second authentication-related information is sent from the first terminal to the second terminal; Received by the second terminal; sending the second authentication-related information to a third network function;
或者,所述通信接口用于向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;Alternatively, the communication interface is used to send instruction information to the first network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ; The indication information is used for the execution or stop of the first network function to send first authentication related information to the first terminal, and the first authentication related information is used for the first terminal to send to the second terminal;
或者,所述处理器用于执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。Alternatively, the processor is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
第十五方面,提供了一种设备鉴权系统,包括:终端及网络侧,所述终端包括第一终端和第二终端,所述网络侧包括第一网络功能、第二网络功能和第三网络功能,所述终端可用于执行如第一方面或第五方面所述的设备鉴 权方法的步骤,所述网络侧可用于执行如第二方面、第三方面或第四方面所述的设备鉴权方法的步骤。A fifteenth aspect provides a device authentication system, including: a terminal and a network side, the terminal includes a first terminal and a second terminal, and the network side includes a first network function, a second network function, and a third A network function, the terminal can be used to perform the device authentication described in the first aspect or the fifth aspect The steps of the device authentication method described in the second aspect, the third aspect or the fourth aspect can be executed by the network side.
第十六方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法的步骤。In a sixteenth aspect, a readable storage medium is provided, where programs or instructions are stored on the readable storage medium, and when the programs or instructions are executed by a processor, the first aspect, the second aspect, the third aspect, and The steps of the method described in the fourth aspect or the fifth aspect.
第十七方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法的步骤。In a seventeenth aspect, a chip is provided, the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the first aspect and the second Aspect, the step of the method described in the third aspect, the fourth aspect or the fifth aspect.
第十八方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现如第一方面、第二方面、第三方面、第四方面或第五方面所述的方法的步骤。In an eighteenth aspect, a computer program/program product is provided, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the first aspect, the first The steps of the method described in the second aspect, the third aspect, the fourth aspect or the fifth aspect.
在本申请实施例中,第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端,所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧,从而实现通过第一终端(如个人物联网网关)对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权。In this embodiment of the present application, the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the first authentication-related information sent by the second terminal. Two authentication-related information, and send the second authentication-related information to the network side, so that the second terminal (such as a non-3GPP terminal, that is, does not support the NAS protocol process) is realized through the first terminal (such as a personal Internet of Things gateway) device) for authentication.
附图说明Description of drawings
图1表示本申请实施例可应用的一种通信系统的结构图;FIG. 1 shows a structural diagram of a communication system applicable to an embodiment of the present application;
图2表示本申请实施例的设备鉴权方法的流程示意图之一;FIG. 2 shows one of the schematic flow diagrams of the device authentication method in the embodiment of the present application;
图3表示本申请实施例的设备鉴权方法的流程示意图之二;FIG. 3 shows the second schematic flow diagram of the device authentication method in the embodiment of the present application;
图4表示本申请实施例的设备鉴权方法的流程示意图之三;FIG. 4 shows the third schematic flow diagram of the device authentication method in the embodiment of the present application;
图5表示本申请实施例的设备鉴权方法的流程示意图之四;FIG. 5 shows the fourth schematic flow diagram of the device authentication method according to the embodiment of the present application;
图6表示本申请实施例的设备鉴权方法的流程示意图之五;FIG. 6 shows the fifth schematic flow diagram of the device authentication method according to the embodiment of the present application;
图7表示本申请实施例的设备鉴权装置的模块示意图之一;FIG. 7 shows one of the module schematic diagrams of the device authentication device according to the embodiment of the present application;
图8表示本申请实施例的设备鉴权装置的模块示意图之二;FIG. 8 shows the second schematic diagram of the modules of the device authentication device according to the embodiment of the present application;
图9表示本申请实施例的通信设备的结构框图;FIG. 9 shows a structural block diagram of a communication device according to an embodiment of the present application;
图10表示本申请实施例的终端的结构框图; FIG. 10 shows a structural block diagram of a terminal in an embodiment of the present application;
图11表示本申请实施例的设备鉴权装置的模块示意图之三;Fig. 11 shows the third schematic diagram of the modules of the device authentication device according to the embodiment of the present application;
图12表示本申请实施例的设备鉴权装置的模块示意图之四;FIG. 12 shows the fourth schematic diagram of the modules of the device authentication device according to the embodiment of the present application;
图13表示本申请实施例的设备鉴权装置的模块示意图之五;Fig. 13 shows the fifth schematic diagram of the modules of the device authentication device according to the embodiment of the present application;
图14表示本申请实施例的网络功能的结构框图之一;Fig. 14 represents one of the structural block diagrams of the network function of the embodiment of the present application;
图15表示本申请实施例的网络功能的结构框图之二。FIG. 15 shows the second structural block diagram of the network function of the embodiment of the present application.
具体实施方式Detailed ways
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。The technical solutions in the embodiments of the present application will be clearly described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, but not all of them. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in this application belong to the protection scope of this application.
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。The terms "first", "second" and the like in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific sequence or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances such that the embodiments of the application are capable of operation in sequences other than those illustrated or described herein and that "first" and "second" distinguish objects. It is usually one category, and the number of objects is not limited. For example, there may be one or more first objects. In addition, "and/or" in the description and claims means at least one of the connected objects, and the character "/" generally means that the related objects are an "or" relationship.
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统应用以外的应用,如第6代(6th  Generation,6G)通信系统。It is worth pointing out that the technology described in the embodiment of this application is not limited to the Long Term Evolution (Long Term Evolution, LTE)/LTE-Advanced (LTE-Advanced, LTE-A) system, and can also be used in other wireless communication systems, such as code Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access, OFDMA), Single-carrier Frequency Division Multiple Access (Single-carrier Frequency Division Multiple Access, SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used for the above-mentioned system and radio technology, and can also be used for other systems and radio technologies. The following description describes the New Radio (New Radio, NR) system for illustrative purposes, and uses NR terminology in most of the following descriptions, but these techniques can also be applied to applications other than NR system applications, such as the 6th generation (6th generation Generation, 6G) communication system.
需要说明的是,本申请中,网络侧也可以称为网络侧设备。It should be noted that in this application, the network side may also be referred to as a network side device.
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(augmented reality,AR)/虚拟现实(virtual reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(personal computer,PC)、柜员机或者自助机等终端侧设备,可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以包括接入网设备或核心网设备,其中,接入网设备12也可以称为无线接入网设备、无线接入网(Radio Access Network,RAN)、无线接入网功能或无线接入网单元。接入网设备12可以包括基站、无线局域网(Wireless Local Area Network,WLAN)接入点或WiFi节点等,基站可被称为节点B、演进节点B(eNB)、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点、家用演进型B节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能 (User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM),统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF),网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。Fig. 1 shows a block diagram of a wireless communication system to which the embodiment of the present application is applicable. The wireless communication system includes a terminal 11 and a network side device 12 . Wherein, the terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a palmtop computer, a netbook, a super mobile personal computer (ultra-mobile personal computer, UMPC), mobile Internet device (Mobile Internet Device, MID), augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) equipment, robot, wearable device (Wearable Device) , Vehicle User Equipment (VUE), Pedestrian User Equipment (PUE), smart home (home equipment with wireless communication functions, such as refrigerators, TVs, washing machines or furniture, etc.), game consoles, personal computers (personal computer, PC), teller machine or self-service machine and other terminal side devices, wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart feet bracelets, smart anklets, etc.), smart wristbands, smart clothing, etc. It should be noted that, the embodiment of the present application does not limit the specific type of the terminal 11 . The network side device 12 may include an access network device or a core network device, where the access network device 12 may also be called a radio access network device, a radio access network (Radio Access Network, RAN), a radio access network function, or Wireless access network unit. The access network device 12 may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point or a WiFi node, etc., and the base station may be called a node B, an evolved node B (eNB), an access point, or a base transceiver station (Base Transceiver Station, BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (Extended Service Set, ESS), Home Node B, Home Evolved Node B, sending and receiving point (Transmitting Receiving Point, TRP) or some other appropriate term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiment of this application, only the NR system The base station in the example is introduced as an example, and the specific type of the base station is not limited. The core network equipment may include but not limited to at least one of the following: core network node, core network function, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), Policy Control Function (Policy Control Function, PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF) , Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (Centralized network configuration, CNC), network storage function ( Network Repository Function, NRF), Network Exposure Function (NEF), Local NEF (Local NEF, or L-NEF), Binding Support Function (Binding Support Function, BSF), Application Function (Application Function, AF) wait. It should be noted that, in the embodiment of the present application, only the core network equipment in the NR system is used as an example for introduction, and the specific type of the core network equipment is not limited.
为使本领域技术人员能够更好地理解本申请实施例,先进行如下说明。In order to enable those skilled in the art to better understand the embodiments of the present application, the following descriptions are given first.
个人物联网(Personal IoT Network,PIN):Personal IoT Network (PIN):
PIN是一个由至少一个PIN元素(PIN Element,PINE)构成的组,其中至少一个PIN元素为一个终端(User Equipment,UE)。PIN元素之间彼此通信。两个PIN元素可以通过它们之间的直接连接进行通信,也可以通过通信网络进行间接通信。PIN is a group consisting of at least one PIN element (PIN Element, PINE), wherein at least one PIN element is a terminal (User Equipment, UE). PIN elements communicate with each other. Two PIN elements can communicate through a direct connection between them, or indirectly through a communication network.
一个PIN元素可以为一个第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)设备(例如UE)或一个非3GPP设备。非3GPP设备指未使用3GPP定义的凭证的设备,不支持3GPP定义的NAS协议的设备,或者不支持3GPP接入技术,如第三代移动通信技术(3th-Generation,3G)/第四代移动通信技术(4th-Generation,4G)/5G空口技术,而只支持非3GPP接入技术(如WiFi,固网,蓝牙等接入技术)的设备。A PIN element can be a 3rd Generation Partnership Project (3rd Generation Partnership Project, 3GPP) device (such as UE) or a non-3GPP device. Non-3GPP devices refer to devices that do not use credentials defined by 3GPP, devices that do not support NAS protocols defined by 3GPP, or devices that do not support 3GPP access technologies, such as third-generation mobile communication technology (3th-Generation, 3G)/fourth-generation mobile Communication technology (4th-Generation, 4G)/5G air interface technology, but only supports non-3GPP access technologies (such as WiFi, fixed network, Bluetooth and other access technologies).
一个PIN中可以有一个或多个具有网关能力的PIN元素(PIN Element With Gateway Capability,PEGC)。该PIN中的PIN元素互相之间可以直接交互通信或者通过PEGC进行通信。该PIN中的PIN元素和该PIN外的其他设备或应用服务器可以通过PEGC进行通信。PEGC的设备可以是不同类型的设备,例如,PEGC可以是智能家居场景中的网关,也可以是可穿戴设备场景中,作为可穿戴设备的网关的手机。 One or more PIN elements with gateway capability (PIN Element With Gateway Capability, PEGC) can be included in one PIN. The PIN elements in the PIN can communicate with each other directly or through PEGC. The PIN element in the PIN can communicate with other devices or application servers outside the PIN through the PEGC. PEGC devices can be different types of devices. For example, PEGC can be a gateway in a smart home scenario, or a mobile phone as a gateway for wearable devices in a wearable device scenario.
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的设备鉴权方法进行详细地说明。The device authentication method provided by the embodiment of the present application will be described in detail below through some embodiments and application scenarios with reference to the accompanying drawings.
如图2所示,本申请实施例提供了一种设备鉴权方法,包括:As shown in Figure 2, the embodiment of this application provides a device authentication method, including:
步骤201:第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端。Step 201: The first terminal receives the first authentication related information sent by the network side, and sends the first authentication related information to the second terminal.
上述第一终端为个人物联网中具有网关能力的终端,第二终端为非3GPP设备或者为个人物联网设备。可选地,上述第一终端也可以为家庭网关。The above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device. Optionally, the above-mentioned first terminal may also be a home gateway.
上述第一终端和第二终端之间建立有直连连接,所述直连连接包括以下一项:A direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
非3GPP连接;Non-3GPP connection;
旁链路PC5/Sidelink连接;Sidelink PC5/Sidelink connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
上述网络侧也可描述为第一网络功能,或者,能实现第一网络功能的设备,该第一网络功能可具体为接入和移动性管理功能(Access and Mobility Management Function,AMF)或会话管理功能(Session Management Function,SMF)。例如,上述第一认证相关信息由AMF或SMF发出,上述第二认证相关信息从第二终端发出后到达AMF或SMF。The aforementioned network side may also be described as a first network function, or a device capable of realizing the first network function, and the first network function may specifically be an access and mobility management function (Access and Mobility Management Function, AMF) or session management Function (Session Management Function, SMF). For example, the first authentication-related information is sent by the AMF or the SMF, and the second authentication-related information is sent by the second terminal and arrives at the AMF or the SMF.
步骤202:所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。Step 202: The first terminal receives the second authentication related information sent by the second terminal, and sends the second authentication related information to the network side.
本申请实施例中,第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端,所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧,从而实现通过第一终端(如个人物联网网关)对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the second authentication-related information sent by the second terminal. Authentication-related information, and sending the second authentication-related information to the network side, so that the second terminal (such as a non-3GPP terminal, that is, that does not support the NAS protocol process) is implemented through the first terminal (such as a personal Internet of Things gateway) device) for the purpose of authentication.
可选地,所述第一终端接收网络侧发送的第一认证相关信息之前,还执行以下至少一项:Optionally, before receiving the first authentication-related information sent by the network side, the first terminal further performs at least one of the following:
所述第一终端与所述第二终端之间的认证过程;an authentication process between the first terminal and the second terminal;
所述第一终端为所述第二终端配置第一IP地址。 The first terminal configures a first IP address for the second terminal.
可选地,所述第一认证相关信息未做安全保护。Optionally, the first authentication-related information is not protected.
可选地,本申请实施例的方法,还包括:Optionally, the method of the embodiment of the present application further includes:
在所述第一终端接收到所述网络侧发送的所述第一认证相关信息时,所述第一终端停止发起或停止执行所述第一终端与所述第二终端之间的认证过程。When the first terminal receives the first authentication-related information sent by the network side, the first terminal stops initiating or stopping the authentication process between the first terminal and the second terminal.
具体的,在所述第一终端接收到所述网络侧发送的所述第一认证相关信息时,如果所述第一终端正在执行所述第一终端与所述第二终端之间的认证过程,则可继续执行本次认证过程,并在执行完本次认证过程后,停止执行或发起所述第一终端与所述第二终端之间的认证过程。Specifically, when the first terminal receives the first authentication-related information sent by the network side, if the first terminal is performing an authentication process between the first terminal and the second terminal , then the current authentication process may be continued, and after the current authentication process is completed, the execution of the authentication process between the first terminal and the second terminal may be stopped or initiated.
可选地,所述第一终端将所述第二认证相关信息发送给所述网络侧之后,还包括:Optionally, after the first terminal sends the second authentication-related information to the network side, it further includes:
所述第一终端向所述第二终端发送第二网际协议(Internet Protocol,IP)地址,或者,所述第一终端不再执行为所述第二终端配置IP地址的操作。The first terminal sends a second Internet Protocol (Internet Protocol, IP) address to the second terminal, or the first terminal no longer executes the operation of configuring the IP address for the second terminal.
可选地,所述第二IP地址为所述网络侧指示的,或者,所述第二IP地址为所述第二终端选择的。Optionally, the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
这里,第二IP地址可以与第一IP地址相同。Here, the second IP address may be the same as the first IP address.
可选地,所述第一认证相关信息或所述第二认证相关信息为使用可扩展的身份验证协议(Extensible Authentication Protocol,EAP协议)的信息。Optionally, the first authentication-related information or the second authentication-related information is information using an extensible authentication protocol (Extensible Authentication Protocol, EAP protocol).
例如,上述第一认证相关信息可以具体为使用可扩展的身份验证协议请求-身份EAP-req/Identity消息,上述第二认证相关信息可以具体为EAP-res/Identity消息。For example, the above-mentioned first authentication-related information may specifically be an Extensible Identity Authentication Protocol Request-Identity EAP-req/Identity message, and the above-mentioned second authentication-related information may specifically be an EAP-res/Identity message.
可选地,本申请实施例中,所述第一终端接收的所述网络侧发送的所述第一认证相关信息通过第一非接入层NAS消息承载,所述第一终端向所述网络侧发送的所述第二认证相关信息通过第二非接入层NAS消息承载;Optionally, in this embodiment of the present application, the first authentication-related information received by the first terminal and sent by the network side is carried by a first non-access stratum NAS message, and the first terminal sends the network The second authentication-related information sent by the side is carried by a second non-access stratum NAS message;
所述第一终端向所述第二终端发送的所述第一认证相关信息不通过非接入层NAS消息承载,所述第一终端接收的所述第二终端发送的所述第二认证相关信息不通过非接入层NAS消息承载。The first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
可选地,所述第一终端向所述第二终端发送的所述第一认证相关信息通过直连传输链路层协议或网络密钥交换协议(Internet Key Exchange,IKE) 传输,所述第一终端接收的所述第二终端发送的所述第二认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输。Optionally, the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol (Internet Key Exchange, IKE) Transmission, the second authentication-related information sent by the second terminal received by the first terminal is transmitted through a direct transmission link layer protocol or a network key exchange protocol IKE.
例如,第一终端接收到的第一认证相关信息承载在NAS消息上,第一终端接收到的第二认证相关信息和向第二终端发送的第一认证相关信息承载在直连传输链路层协议上(数据报文的最外层IP协议栈之下的协议层,比如局域网(Local Area Network,LAN)网络二层协议,蓝牙连接二层协议,PC5协议)。For example, the first authentication-related information received by the first terminal is carried in the NAS message, and the second authentication-related information received by the first terminal and the first authentication-related information sent to the second terminal are carried in the direct transmission link layer On the protocol (the protocol layer under the outermost IP protocol stack of the data message, such as the local area network (Local Area Network, LAN) network layer 2 protocol, Bluetooth connection layer 2 protocol, PC5 protocol).
可选地,所述第一NAS消息中携带有所述第二终端的相关信息。Optionally, the first NAS message carries related information of the second terminal.
可选地,所述第二终端的相关信息包括以下至少一项:Optionally, the relevant information of the second terminal includes at least one of the following:
控制面标识信息,例如,网络侧为第二终端分配的标识或第一终端为第二终端分配的标识,或第二终端配置的标识;Control plane identification information, for example, the identification assigned by the network side to the second terminal or the identification assigned by the first terminal to the second terminal, or the identification configured by the second terminal;
用户面标识信息。User plane identification information.
所述用户面标识信息包括以下至少一项:The user plane identification information includes at least one of the following:
IP地址,该IP地址可具体为网络侧分配的或者为第一终端分配的;An IP address, where the IP address may be specifically assigned by the network side or assigned by the first terminal;
IP地址和端口号;IP address and port number;
媒体接入控制(Media Access Control,MAC)地址;Media Access Control (MAC) address;
所述第一终端与所述第二终端的直连连接信息,可选地,该直连连接信息包括第一终端与第二终端的直连连接标识,比如MAC层之下的标识连接的信息,连接标识(Link ID),事务标识(Transaction ID)等。Direct connection information between the first terminal and the second terminal, optionally, the direct connection information includes a direct connection identifier between the first terminal and the second terminal, such as information identifying a connection under the MAC layer , Connection ID (Link ID), Transaction ID (Transaction ID), etc.
可选地,所述第一终端与所述第二终端之间的认证过程通过以下至少一项协议消息承载:Optionally, the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
直连传输链路层协议(层2协议);Directly connected transmission link layer protocol (layer 2 protocol);
网络密钥交换协议IKE,这里,可以先完成层2的认证再完成层3的通过IKE协议承载的认证。The network key exchange protocol IKE, here, the layer 2 authentication can be completed first, and then the layer 3 authentication carried by the IKE protocol can be completed.
本申请实施例中,第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端,所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧,从而实现通过第一终端(如个人物联网网关)对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。 In this embodiment of the present application, the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the second authentication-related information sent by the second terminal. Authentication-related information, and sending the second authentication-related information to the network side, so that the second terminal (such as a non-3GPP terminal, that is, that does not support the NAS protocol process) is implemented through the first terminal (such as a personal Internet of Things gateway) device) for the purpose of authentication.
如图3所示,本申请实施例还提供了一种设备鉴权方法,包括:As shown in Figure 3, the embodiment of the present application also provides a device authentication method, including:
步骤301:第一网络功能接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示。Step 301: The first network function receives the instruction information sent by the second network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction .
上述第一网络功能也可描述为第一网元,该第一网络功能可具体为接入和移动性管理功能(Access and Mobility Management Function,AMF)或会话管理功能(Session Management Function,SMF)。The foregoing first network function may also be described as a first network element, and the first network function may specifically be an Access and Mobility Management Function (Access and Mobility Management Function, AMF) or a Session Management Function (Session Management Function, SMF).
上述第二网络功能也可描述为第二网元,比如,该第二网络功能为网络开放功能(Network Exposure Function,NEF)或应用功能(Application Function,AF)。The above-mentioned second network function may also be described as a second network element, for example, the second network function is a Network Exposure Function (Network Exposure Function, NEF) or an Application Function (Application Function, AF).
上述第一终端为个人物联网中具有网关能力的终端,第二终端为非3GPP设备或者为个人物联网设备。可选地,上述第一终端也可以为家庭网关。The above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device. Optionally, the above-mentioned first terminal may also be a home gateway.
上述第一终端和第二终端之间建立有直连连接,所述直连连接包括以下一项:A direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
非3GPP连接;Non-3GPP connection;
旁链路PC5/Sidelink连接;Sidelink PC5/Sidelink connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
这里,第一网络功能根据该第一终端的相关信息和第二终端的相关信息中的至少一项,确定第一终端的标识信息。Here, the first network function determines the identification information of the first terminal according to at least one of the related information of the first terminal and the related information of the second terminal.
步骤302:所述第一网络功能根据所述指示信息执行或停止执行第一操作。Step 302: The first network function performs or stops performing the first operation according to the indication information.
例如,所述指示信息包含停止鉴权指示,则第一网络功能停止执行第一操作,或者,所述指示信息包含鉴权指示,则第一网络功能执行所述第一操作。For example, if the instruction information includes an authentication stop instruction, then the first network function stops performing the first operation, or if the instruction information includes an authentication instruction, then the first network function executes the first operation.
其中,所述第一操作包含:Wherein, the first operation includes:
向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。Sending first authentication-related information to the first terminal, where the first authentication-related information is used by the first terminal to send to the second terminal.
所述第一网络功能接收所述第一终端发送的第二认证相关信息,所述第 二认证相关信息为第一终端从所述第二终端接收的。The first network function receives the second authentication-related information sent by the first terminal, and the first The second authentication-related information is received by the first terminal from the second terminal.
所述第一网络功能将所述第二认证相关信息发送给第三网络功能。The first network function sends the second authentication-related information to a third network function.
这里的第三网络功能可具体为统一数据管理实体(Unified Data Management,UDM)、鉴权服务功能(Authentication Server Function,AUSF)或为验证、授权和记账(Authentication、Authorization、Accounting,AAA)设备。The third network function here can be specifically unified data management entity (Unified Data Management, UDM), authentication service function (Authentication Server Function, AUSF) or verification, authorization and accounting (Authentication, Authorization, Accounting, AAA) equipment .
本申请实施例中,第一网络功能接收第二网络功能发送的指示信息,以使所述第一网络功能能够根据所述指示信息,向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端,所述第一网络功能接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的,所述第一网络功能将所述第二认证相关信息发送给第三网络功能,从而实现了对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the first network function receives the indication information sent by the second network function, so that the first network function can send the first authentication-related information to the first terminal according to the indication information, and the first The authentication-related information is used by the first terminal to send to the second terminal, and the first network function receives the second authentication-related information sent by the first terminal, and the second authentication-related information is sent by the first terminal from The second terminal receives, and the first network function sends the second authentication-related information to the third network function, so that the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process) ) for the purpose of authentication.
可选地,在所述第一网络功能执行所述第一操作的情况下,所述第一网络功能还执行以下至少一项:Optionally, when the first network function performs the first operation, the first network function further performs at least one of the following:
指示所述第三网络功能停止密钥派生或停止发送密钥信息;instructing said third network function to stop key derivation or to stop sending key information;
停止发送密钥信息给所述第一终端。Stop sending key information to the first terminal.
可选地,本申请实施例的方法,在所述第一网络功能执行所述第一操作的情况下,还包括:Optionally, the method in this embodiment of the present application, when the first network function performs the first operation, further includes:
所述第一网络功能转发所述第二终端和所述第三网络功能之间的后续认证相关信息,所述后续认证相关信息用于执行所述第二终端和所述第三网络功能之间的认证。The first network function forwards subsequent authentication-related information between the second terminal and the third network function, and the subsequent authentication-related information is used to perform a communication between the second terminal and the third network function certification.
可选地,所述第二终端的相关信息包括以下至少一项:Optionally, the relevant information of the second terminal includes at least one of the following:
控制面标识信息;Control plane identification information;
用户面标识信息。User plane identification information.
可选地,所述用户面标识信息包括以下至少一项:Optionally, the user plane identification information includes at least one of the following:
IP地址;IP address;
IP地址和端口号;IP address and port number;
MAC地址; MAC address;
所述第一终端与所述第二终端的直连连接信息。Direct connection information between the first terminal and the second terminal.
需要说明的是,该第二终端的相关信息已在上述第一终端侧的方法实施例中进行详细说明,此处不再赘述。It should be noted that the relevant information of the second terminal has been described in detail in the above-mentioned embodiment of the method at the side of the first terminal, and will not be repeated here.
可选地,所述第一网络功能向所述第一终端发送的所述第一认证相关信息通过第一NAS消息承载,所述第一网络功能接收的所述第一终端发送的第二认证相关信息通过第二NAS消息承载。Optionally, the first authentication related information sent by the first network function to the first terminal is carried by a first NAS message, and the second authentication sent by the first terminal received by the first network function Related information is carried by the second NAS message.
可选地,所述第一NAS消息中携带有所述第二终端的相关信息。Optionally, the first NAS message carries related information of the second terminal.
可选地,所述第一认证相关信息或所述第二认证相关信息为EAP协议的信息。Optionally, the first authentication-related information or the second authentication-related information is EAP protocol information.
可选地,所述第一认证相关信息用于请求第一终端的标识。Optionally, the first authentication-related information is used to request an identifier of the first terminal.
本申请实施例中,第一网络功能接收第二网络功能发送的指示信息,所述第一网络功能根据所述指示信息,执行或停止执行第一操作,例如,向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端,所述第一网络功能接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的,所述第一网络功能将所述第二认证相关信息发送给第三网络功能,从而实现了对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the first network function receives the instruction information sent by the second network function, and the first network function executes or stops performing the first operation according to the instruction information, for example, sends the first authentication to the first terminal Related information, the first authentication related information is used by the first terminal to send to the second terminal, the first network function receives the second authentication related information sent by the first terminal, the second authentication The relevant information is received by the first terminal from the second terminal, and the first network function sends the second authentication related information to the third network function, thereby realizing the authentication of the second terminal (such as a non-3GPP terminal, that is, Devices that do not support the NAS protocol process) for the purpose of authentication.
如图4所示,本申请实施例还提供了一种设备鉴权方法,包括:As shown in Figure 4, the embodiment of the present application also provides a device authentication method, including:
步骤401:第二网络功能向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;Step 401: The second network function sends instruction information to the first network function, and the instruction information includes at least one of the following items: related information of the first terminal, related information of the second terminal, an instruction to stop authentication, and an instruction to authenticate;
所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。The indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
例如,所述指示信息中包含停止鉴权指示,则该指示信息用于第一网络功能停止执行向第一终端发送第一认证相关信息,又例如,所述指示信息中包含停止鉴权至少,则该指示信息用于第一网络功能执行向第一终端发送第一认证相关信息。For example, if the indication information includes an indication of stopping authentication, the indication information is used for the first network function to stop executing and send the first authentication-related information to the first terminal. For another example, the indication information includes stopping authentication at least, Then the indication information is used for the first network function to send the first authentication related information to the first terminal.
这里,第二网络功能向第一网络功能发送指示信息,以便于第一网络功 能根据该指示信息确定第一终端的标识信息,从而向第一终端发送第一认证相关信息,并使得第一终端将该第一认证相关信息发送给第二终端。Here, the second network function sends indication information to the first network function, so that the first network function The identification information of the first terminal can be determined according to the indication information, so as to send the first authentication related information to the first terminal, and make the first terminal send the first authentication related information to the second terminal.
本申请实施例中,上述第二网络功能为网络开放功能(Network Exposure Function,NEF)或应用功能(Application Function,AF)。In the embodiment of the present application, the above-mentioned second network function is a network exposure function (Network Exposure Function, NEF) or an application function (Application Function, AF).
上述第一终端为个人物联网中具有网关能力的终端,第二终端为非3GPP设备或者为个人物联网设备。可选地,上述第一终端也可以为家庭网关。The above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device. Optionally, the above-mentioned first terminal may also be a home gateway.
上述第一终端和第二终端之间建立有直连连接,所述直连连接包括以下一项:A direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
非3GPP连接;Non-3GPP connection;
旁链路PC5/Sidelink连接;Sidelink PC5/Sidelink connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
本申请实施例中,第二网络功能向第一网络功能发送指示信息,以便于第一网络功能根据该指示信息确定第一终端的标识信息,从而向第一终端发送第一认证相关信息,并使得第一终端将该第一认证相关信息发送给第二终端,以便于完成对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the second network function sends indication information to the first network function, so that the first network function determines the identification information of the first terminal according to the indication information, thereby sends the first authentication-related information to the first terminal, and The first terminal is made to send the first authentication-related information to the second terminal, so as to accomplish the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
可选地,所述第二认证相关信息为EAP的信息。Optionally, the second authentication-related information is EAP information.
该第二认证相关信息已在上述实施例中进行详细描述,此处不再赘述。The second authentication-related information has been described in detail in the foregoing embodiments, and will not be repeated here.
本申请实施例中,第二网络功能向第一网络功能发送指示信息,以便于第一网络功能根据该指示信息确定第一终端的标识信息,从而向第一终端发送第一认证相关信息,并使得第一终端将该第一认证相关信息发送给第二终端,以便于完成对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the second network function sends indication information to the first network function, so that the first network function determines the identification information of the first terminal according to the indication information, thereby sends the first authentication-related information to the first terminal, and The first terminal is made to send the first authentication-related information to the second terminal, so as to accomplish the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
如图5所示,本申请实施例还提供了一种设备鉴权方法,包括:As shown in Figure 5, the embodiment of the present application also provides a device authentication method, including:
步骤501:第三网络功能执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。Step 501: The third network function executes an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process with the third network function through the first terminal.
上述第一终端为个人物联网中具有网关能力的终端,第二终端为非3GPP设备或者为个人物联网设备。可选地,上述第一终端也可以为家庭网关。 The above-mentioned first terminal is a terminal with gateway capability in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device. Optionally, the above-mentioned first terminal may also be a home gateway.
上述第一终端和第二终端之间建立有直连连接,所述直连连接包括以下一项:A direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
非3GPP连接;Non-3GPP connection;
旁链路PC5/Sidelink连接;Sidelink PC5/Sidelink connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
这里的第三网络功能可具体为统一数据管理实体(Unified Data Management,UDM)、鉴权服务功能(Authentication Server Function,AUSF)或为验证、授权和记账(Authentication、Authorization、Accounting,AAA)设备。The third network function here can be specifically unified data management entity (Unified Data Management, UDM), authentication service function (Authentication Server Function, AUSF) or verification, authorization and accounting (Authentication, Authorization, Accounting, AAA) equipment .
本申请实施例中,第三网络功能执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程,从而实现对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the third network function executes the authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
可选地,所述第三网络功能在所述认证过程中或在所述认证过程成功后执行以下至少一项:Optionally, the third network function performs at least one of the following during the authentication process or after the authentication process succeeds:
停止密钥派生;stop key derivation;
停止发送密钥信息给所述第一网络功能。Stop sending key information to the first network function.
可选地,所述第三网络功能在执行所述认证过程之前,还包括:Optionally, before performing the authentication process, the third network function further includes:
所述第三网络功能接收第一网络功能发送的第二认证相关信息,所述第二认证相关信息为所述第一网络功能从第一终端接收的,以及所述第一终端从第二终端接收的。The third network function receives second authentication-related information sent by the first network function, the second authentication-related information is received by the first network function from the first terminal, and the first terminal receives from the second terminal Received.
具体的,第一终端将第一认证相关信息发送给第二终端后,第二终端向第一终端发送第二认证相关信息,第一终端接收到第二终端发送的第二认证相关信息后,将该第二认证相关信息发送给第一网络功能,第一网络功能将该第二认证相关信息发送给第三网络功能。Specifically, after the first terminal sends the first authentication-related information to the second terminal, the second terminal sends the second authentication-related information to the first terminal, and after the first terminal receives the second authentication-related information sent by the second terminal, The second authentication-related information is sent to the first network function, and the first network function sends the second authentication-related information to the third network function.
可选地,所述第三网络功能执行所述第二终端与所述第三网络功能间的认证过程,包括:Optionally, the third network function performs an authentication process between the second terminal and the third network function, including:
所述第三网络功能基于以下至少一项,选择或使用EAP协议执行所述认 证过程:The third network function selects or uses the EAP protocol to perform the authentication based on at least one of the following: Certification process:
第一网络功能的信息,如第三网络功能基于来自SMF而非AMF的信息;the information of the first network function, such as the third network function is based on information from the SMF instead of the AMF;
所述第二认证相关信息,如该第二认证相关信息使用EAP协议发送。The second authentication-related information, for example, the second authentication-related information is sent using the EAP protocol.
可选地,本申请实施例的方法,还包括:Optionally, the method of the embodiment of the present application further includes:
所述第三网络功能接收来自第一网络功能的指示,所述第三网络功能根据所述指示在所述认证过程中或在所述认证过程成功后执行以下至少一项:The third network function receives an instruction from the first network function, and the third network function performs at least one of the following during the authentication process or after the authentication process is successful according to the instruction:
停止密钥派生;stop key derivation;
停止发送密钥信息给所述第一网络功能;stop sending key information to said first network function;
所述指示包括以下至少一项:The instructions include at least one of the following:
第一网络功能的信息,与停止密钥派生或发送密钥信息相关的指示,所述第二认证相关信息。Information about the first network function, an instruction related to stopping key derivation or sending key information, and the second authentication-related information.
可选地,所述第二认证相关信息为EAP协议的信息。Optionally, the second authentication-related information is information of the EAP protocol.
可选地,所述选择或使用EAP协议执行所述认证过程,包括:Optionally, the selecting or using the EAP protocol to perform the authentication process includes:
在所述第二认证相关信息为EAP协议的信息时,选择EAP协议执行所述认证过程。When the second authentication-related information is information of the EAP protocol, the EAP protocol is selected to execute the authentication process.
本申请实施例中,第三网络功能执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程,从而实现对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the third network function executes the authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
如图6所示,本申请实施例还提供了一种设备鉴权方法,包括:As shown in Figure 6, the embodiment of the present application also provides a device authentication method, including:
步骤601:第二终端完成与第一终端之间的认证过程。Step 601: the second terminal completes the authentication process with the first terminal.
步骤602:所述第二终端接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。Step 602: After receiving the first authentication-related information from the first terminal, the second terminal sends to the first terminal second authentication-related information carrying a first identifier, wherein the first identifier is used to communicate with the first terminal. The network side executes the authentication process.
本申请实施例中,上述第一终端为个人物联网中具有网关能力的终端,第二终端为非3GPP设备或者为个人物联网设备。可选地,上述第一终端也可以为家庭网关。In the embodiment of the present application, the above-mentioned first terminal is a terminal capable of gateway in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device. Optionally, the above-mentioned first terminal may also be a home gateway.
上述第一终端和第二终端之间建立有直连连接,所述直连连接包括以下一项: A direct connection is established between the first terminal and the second terminal, and the direct connection includes the following items:
非3GPP连接;Non-3GPP connection;
旁链路PC5/Sidelink连接;Sidelink PC5/Sidelink connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
本申请实施例中,第二终端完成与第一终端之间的认证过程后,接收到来自第一终端的第一认证相关信息,向所述第一终端发送携带第一标识的第二认证相关信息,以便于后续网络侧基于该第一标识执行对第二终端的认证过程,从而实现对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the application, after the second terminal completes the authentication process with the first terminal, it receives the first authentication-related information from the first terminal, and sends the second authentication-related information carrying the first identifier to the first terminal. Information, so that the subsequent network side can perform the authentication process on the second terminal based on the first identifier, so as to achieve the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
可选地,本申请实施例的方法,还包括:Optionally, the method of the embodiment of the present application further includes:
所述第二终端在与网络侧执行认证的过程中或成功完成与网络侧的认证过程后停止密钥派生。The second terminal stops key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
可选地,本申请实施例的方法,还包括:Optionally, the method of the embodiment of the present application further includes:
所述第二终端使用第二标识完成与所述第一终端之间的认证过程。The second terminal completes the authentication process with the first terminal by using the second identifier.
该第二标识可以与第一标识相同,也可以不同。The second identifier may be the same as or different from the first identifier.
可选地,本申请实施例的方法,还包括:Optionally, the method of the embodiment of the present application further includes:
所述第二终端基于所述第一认证相关信息的安全保护情况,使用所述第一标识。The second terminal uses the first identifier based on the security protection of the first authentication-related information.
可选地,所述第二终端基于所述第一认证相关信息的安全保护情况,使用所述第一标识,包括:Optionally, the second terminal using the first identifier based on the security protection of the first authentication-related information includes:
在所述第一认证相关信息为做安全保护时,所述第二终端使用所述第一标识。When the first authentication-related information is for security protection, the second terminal uses the first identifier.
可选地,所述第一认证相关信息用于请求第一终端的标识。Optionally, the first authentication-related information is used to request an identifier of the first terminal.
本申请实施例中,第二终端完成与第一终端之间的认证过程后,接收到来自第一终端的第一认证相关信息,向所述第一终端发送携带第一标识的第二认证相关信息,以便于后续网络侧基于该第一标识执行对第二终端的认证过程,从而实现对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the application, after the second terminal completes the authentication process with the first terminal, it receives the first authentication-related information from the first terminal, and sends the second authentication-related information carrying the first identifier to the first terminal. Information, so that the subsequent network side can perform the authentication process on the second terminal based on the first identifier, so as to achieve the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
本申请实施例提供的设备鉴权方法,执行主体可以为设备鉴权装置。本 申请实施例中以设备鉴权装置执行设备鉴权方法为例,说明本申请实施例提供的设备鉴权装置。The device authentication method provided in the embodiment of the present application may be executed by a device authentication device. Book In the embodiment of the application, the device authentication method performed by the device authentication device is taken as an example to illustrate the device authentication device provided in the embodiment of the present application.
如图7所示,本申请实施例提供了一种设备鉴权装置700,应用于第一终端,包括:As shown in Figure 7, the embodiment of the present application provides a device authentication apparatus 700, which is applied to the first terminal, including:
第一收发模块701,用于接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;The first transceiver module 701 is configured to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second terminal;
第二收发模块702,用于接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。The second transceiving module 702 is configured to receive the second authentication related information sent by the second terminal, and send the second authentication related information to the network side.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第三处理模块,用于在第一收发模块接收网络侧发送的第一认证相关信息之前,还执行以下至少一项:The third processing module is configured to perform at least one of the following before the first transceiver module receives the first authentication-related information sent by the network side:
所述第一终端与所述第二终端之间的认证过程;an authentication process between the first terminal and the second terminal;
所述第一终端为所述第二终端配置第一IP地址。The first terminal configures a first IP address for the second terminal.
可选地,所述第一认证相关信息未做安全保护。Optionally, the first authentication-related information is not protected.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第四处理模块,用于在所述第一终端接收到所述网络侧发送的所述第一认证相关信息时,所述第一终端停止发起或停止执行所述第一终端与所述第二终端之间的认证过程。The fourth processing module is configured to, when the first terminal receives the first authentication-related information sent by the network side, stop the first terminal from initiating or stop executing the communication between the first terminal and the second Authentication process between endpoints.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第五处理模块,用于第二收发模块将所述第二认证相关信息发送给所述网络侧之后,所述第一终端向所述第二终端发送第二IP地址,或者,所述第一终端不再执行为所述第二终端配置IP地址的操作。The fifth processing module is configured to send the second IP address from the first terminal to the second terminal after the second transceiver module sends the second authentication-related information to the network side, or the first terminal sends the second IP address to the second terminal, or the first The terminal no longer performs the operation of configuring the IP address for the second terminal.
可选地,所述第二IP地址为所述网络侧指示的,或者,所述第二IP地址为所述第二终端选择的。Optionally, the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
可选地,所述第一认证相关信息或所述第二认证相关信息为使用可扩展的身份验证协议EAP协议的信息。Optionally, the first authentication-related information or the second authentication-related information is information using an Extensible Authentication Protocol (EAP) protocol.
可选地,所述第一终端接收的所述网络侧发送的所述第一认证相关信息通过第一非接入层NAS消息承载,所述第一终端向所述网络侧发送的所述第二认证相关信息通过第二非接入层NAS消息承载; Optionally, the first authentication-related information sent by the network side received by the first terminal is carried in a first non-access stratum NAS message, and the first authentication-related information sent by the first terminal to the network side 2. Authentication-related information is carried by a second non-access stratum NAS message;
所述第一终端向所述第二终端发送的所述第一认证相关信息不通过非接入层NAS消息承载,所述第一终端接收的所述第二终端发送的所述第二认证相关信息不通过非接入层NAS消息承载。The first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
可选地,所述第一终端向所述第二终端发送的所述第一认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输,所述第一终端接收的所述第二终端发送的所述第二认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输。Optionally, the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol IKE, and the first terminal receives the The second authentication-related information sent by the second terminal is transmitted through the direct link layer protocol or the network key exchange protocol IKE.
可选地,所述第一NAS消息中携带有所述第二终端的相关信息。Optionally, the first NAS message carries related information of the second terminal.
可选地,所述第二终端的相关信息包括以下至少一项:Optionally, the relevant information of the second terminal includes at least one of the following:
控制面标识信息;Control plane identification information;
用户面标识信息。User plane identification information.
可选地,所述用户面标识信息包括以下至少一项:Optionally, the user plane identification information includes at least one of the following:
IP地址;IP address;
IP地址和端口号;IP address and port number;
MAC地址;MAC address;
所述第一终端与所述第二终端的直连连接信息。Direct connection information between the first terminal and the second terminal.
可选地,所述第一终端与所述第二终端之间的认证过程通过以下至少一项协议消息承载:Optionally, the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
直连传输链路层协议;Directly connected to the transport link layer protocol;
网络密钥交换协议IKE。Network key exchange protocol IKE.
可选地,所述第一终端和所述第二终端之间建立有直连连接,所述直连连接包括以下一项:Optionally, a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following item:
非3GPP连接;Non-3GPP connection;
旁链路PC5连接;Sidelink PC5 connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
可选地,所述第一终端为个人物联网中具有网关能力的终端,所述第二终端为非3GPP设备或者为个人物联网设备。Optionally, the first terminal is a terminal capable of gateway in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device.
本申请实施例中,第一终端接收网络侧发送的第一认证相关信息,并将 所述第一认证相关信息发送给第二终端,所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧,从而实现通过第一终端(如个人物联网网关)对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the application, the first terminal receives the first authentication-related information sent by the network side, and sends The first authentication-related information is sent to the second terminal, the first terminal receives the second authentication-related information sent by the second terminal, and sends the second authentication-related information to the network side, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process) through the first terminal (such as a personal Internet of Things gateway).
如图8所示,本申请实施例还提供了一种设备鉴权装置800,应用于第二终端,该装置包括:As shown in Figure 8, the embodiment of the present application also provides a device authentication device 800, which is applied to the second terminal, and the device includes:
第二处理模块801,用于第二终端完成与第一终端之间的认证过程;The second processing module 801 is used for the second terminal to complete the authentication process with the first terminal;
第六收发模块802,用于所述第二终端接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。The sixth transceiver module 802 is configured to send the second authentication-related information carrying the first identifier to the first terminal after the second terminal receives the first authentication-related information from the first terminal, wherein the first An identity is used to perform an authentication process with the network side.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第六处理模块,用于所述第二终端在与网络侧执行认证的过程中或成功完成与网络侧的认证过程后停止密钥派生。The sixth processing module is used for the second terminal to stop key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第七处理模块,用于使用第二标识完成与所述第一终端之间的认证过程。A seventh processing module, configured to use the second identifier to complete the authentication process with the first terminal.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第八处理模块,用于基于所述第一认证相关信息的安全保护情况,使用所述第一标识。An eighth processing module, configured to use the first identifier based on the security protection status of the first authentication-related information.
可选地,所述第八处理模块用于在所述第一认证相关信息为做安全保护时,所述第二终端使用所述第一标识。Optionally, the eighth processing module is configured to use the first identifier by the second terminal when the first authentication-related information is for security protection.
可选地,所述第一认证相关信息用于请求第一终端的标识。Optionally, the first authentication-related information is used to request an identifier of the first terminal.
本申请实施例中,第二终端完成与第一终端之间的认证过程后,接收到来自第一终端的第一认证相关信息,向所述第一终端发送携带第一标识的第二认证相关信息,以便于后续网络侧基于该第一标识执行对第二终端的认证过程,从而实现对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the application, after the second terminal completes the authentication process with the first terminal, it receives the first authentication-related information from the first terminal, and sends the second authentication-related information carrying the first identifier to the first terminal. Information, so that the subsequent network side can perform the authentication process on the second terminal based on the first identifier, so as to achieve the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
本申请实施例中的设备鉴权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但 不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。The device authentication apparatus in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal, or other devices other than the terminal. Exemplary, the terminal can include but It is not limited to the type of the terminal 11 listed above, and other devices may be a server, a network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in this embodiment of the present application.
本申请实施例提供的设备鉴权装置能够实现图2或图6的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The device authentication device provided in the embodiment of the present application can realize each process realized by the method embodiment in FIG. 2 or FIG. 6 , and achieve the same technical effect. To avoid repetition, details are not repeated here.
可选的,如图9所示,本申请实施例还提供一种通信设备900,包括处理器901和存储器902,存储器902上存储有可在所述处理器901上运行的程序或指令,例如,该通信设备900为第一终端时,该程序或指令被处理器901执行时实现上述应用于第一终端的设备鉴权方法实施例的各个步骤,且能达到相同的技术效果。该通信设备900为第二终端时,该程序或指令被处理器901执行时实现上述应用于第二终端的设备鉴权方法实施例的各个步骤,且能达到相同的技术效果。该通信设备900为网络功能(如第一网络功能、第二网络功能或第三网络功能)时,该程序或指令被处理器901执行时实现上述应用于网络功能的设备鉴权方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。Optionally, as shown in FIG. 9 , this embodiment of the present application also provides a communication device 900, including a processor 901 and a memory 902, and the memory 902 stores programs or instructions that can run on the processor 901, such as When the communication device 900 is the first terminal, when the program or instruction is executed by the processor 901, each step of the above embodiment of the device authentication method applied to the first terminal can be implemented, and the same technical effect can be achieved. When the communication device 900 is the second terminal, when the program or instruction is executed by the processor 901, each step of the above embodiment of the device authentication method applied to the second terminal can be implemented, and the same technical effect can be achieved. When the communication device 900 is a network function (such as a first network function, a second network function, or a third network function), when the program or instruction is executed by the processor 901, the above embodiment of the device authentication method applied to the network function is implemented. Each step can achieve the same technical effect, so in order to avoid repetition, it will not be repeated here.
本申请实施例还提供一种终端,包括处理器和通信接口,通信接口用于接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。The embodiment of the present application also provides a terminal, including a processor and a communication interface, the communication interface is used to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second terminal; receive the The second terminal sends the second authentication-related information, and sends the second authentication-related information to the network side.
本申请实施例还提供了一种终端,包括处理器和通信接口,处理器用于完成与第一终端之间的认证过程;通信接口用于接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。The embodiment of the present application also provides a terminal, including a processor and a communication interface, the processor is used to complete the authentication process with the first terminal; the communication interface is used to receive the first authentication-related information from the first terminal, Sending the second authentication-related information carrying the first identifier to the first terminal, where the first identifier is used to perform an authentication process with the network side.
该终端实施例与上述终端侧方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该终端实施例中,且能达到相同的技术效果。具体地,图10为实现本申请实施例的一种终端的硬件结构示意图。This terminal embodiment corresponds to the above-mentioned terminal-side method embodiment, and each implementation process and implementation mode of the above-mentioned method embodiment can be applied to this terminal embodiment, and can achieve the same technical effect. Specifically, FIG. 10 is a schematic diagram of a hardware structure of a terminal implementing an embodiment of the present application.
该终端1000包括但不限于:射频单元1001、网络模块1002、音频输出单元1003、输入单元1004、传感器1005、显示单元1006、用户输入单元1007、接口单元1008、存储器1009以及处理器1010等中的至少部分部件。The terminal 1000 includes, but is not limited to: a radio frequency unit 1001, a network module 1002, an audio output unit 1003, an input unit 1004, a sensor 1005, a display unit 1006, a user input unit 1007, an interface unit 1008, a memory 1009, and a processor 1010. At least some parts.
本领域技术人员可以理解,终端1000还可以包括给各个部件供电的电源 (比如电池),电源可以通过电源管理系统与处理器1010逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图10中示出的终端结构并不构成对终端的限定,终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。Those skilled in the art can understand that the terminal 1000 may also include a power supply for supplying power to each component (such as a battery), the power supply can be logically connected to the processor 1010 through the power management system, so that functions such as management of charging, discharging, and power consumption management can be realized through the power management system. The terminal structure shown in FIG. 10 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange different components, which will not be repeated here.
应理解的是,本申请实施例中,输入单元1004可以包括图形处理单元(Graphics Processing Unit,GPU)10041和麦克风10042,图形处理器10041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元1006可包括显示面板10061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板10061。用户输入单元1007包括触控面板10071以及其他输入设备10072中的至少一种。触控面板10071,也称为触摸屏。触控面板10071可包括触摸检测装置和触摸控制器两个部分。其他输入设备10072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。It should be understood that, in the embodiment of the present application, the input unit 1004 may include a graphics processing unit (Graphics Processing Unit, GPU) 10041 and a microphone 10042, and the graphics processor 10041 can be used by the image capture device ( Such as the image data of the still picture or video obtained by the camera) for processing. The display unit 1006 may include a display panel 10061, and the display panel 10061 may be configured in the form of a liquid crystal display, an organic light emitting diode, or the like. The user input unit 1007 includes at least one of a touch panel 10071 and other input devices 10072 . The touch panel 10071 is also called a touch screen. The touch panel 10071 may include two parts, a touch detection device and a touch controller. Other input devices 10072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, switch buttons, etc.), trackballs, mice, and joysticks, which will not be repeated here.
本申请实施例中,射频单元1001接收来自网络侧设备的下行数据后,可以传输给处理器1010进行处理;另外,射频单元1001可以向网络侧设备发送上行数据。通常,射频单元1001包括但不限于天线、放大器、收发信机、耦合器、低噪声放大器、双工器等。In the embodiment of the present application, after the radio frequency unit 1001 receives the downlink data from the network side device, it may transmit it to the processor 1010 for processing; in addition, the radio frequency unit 1001 may send the uplink data to the network side device. Generally, the radio frequency unit 1001 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, and the like.
存储器1009可用于存储软件程序或指令以及各种数据。存储器1009可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器1009可以包括易失性存储器或非易失性存储器,或者,存储器1009可以包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous  DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器1009包括但不限于这些和任意其它适合类型的存储器。The memory 1009 can be used to store software programs or instructions as well as various data. The memory 1009 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instructions required by at least one function (such as a sound playing function, image playback function, etc.), etc. Furthermore, memory 1009 may include volatile memory or nonvolatile memory, or, memory 1009 may include both volatile and nonvolatile memory. Wherein, the non-volatile memory may be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM, PROM), an erasable programmable read-only memory (Erasable PROM, EPROM), an electronically programmable Erase Programmable Read-Only Memory (Electrically EPROM, EEPROM) or Flash. Volatile memory can be random access memory (Random Access Memory, RAM), static random access memory (Static RAM, SRAM), dynamic random access memory (Dynamic RAM, DRAM), synchronous dynamic random access memory (Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDRSDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchronous connection dynamic random access memory (Synch link DRAM , SLDRAM) and Direct Memory Bus Random Access Memory (Direct Rambus RAM, DRRAM). The memory 1009 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
处理器1010可包括一个或多个处理单元;可选的,处理器1010集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器1010中。The processor 1010 may include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., Modem processors mainly process wireless communication signals, such as baseband processors. It can be understood that the foregoing modem processor may not be integrated into the processor 1010 .
在本申请的一实施例中,射频单元1001,用于接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。In an embodiment of the present application, the radio frequency unit 1001 is configured to receive the first authentication-related information sent by the network side, and send the first authentication-related information to the second terminal; receive the first authentication-related information sent by the second terminal; 2. Authentication related information, and sending the second authentication related information to the network side.
可选地,处理器1010用于执行以下至少一项:Optionally, the processor 1010 is configured to perform at least one of the following:
所述第一终端与所述第二终端之间的认证过程;an authentication process between the first terminal and the second terminal;
所述第一终端为所述第二终端配置第一IP地址。The first terminal configures a first IP address for the second terminal.
可选地,所述第一认证相关信息未做安全保护。Optionally, the first authentication-related information is not protected.
可选地,处理器1010用于在所述第一终端接收到所述网络侧发送的所述第一认证相关信息时,停止发起或停止执行所述第一终端与所述第二终端之间的认证过程。Optionally, the processor 1010 is configured to, when the first terminal receives the first authentication-related information sent by the network side, stop initiating or stopping execution of the communication between the first terminal and the second terminal. authentication process.
可选地,处理器1010用于通过射频单元向所述第二终端发送第二IP地址,或者,所述不再执行为所述第二终端配置IP地址的操作。Optionally, the processor 1010 is configured to send the second IP address to the second terminal through the radio frequency unit, or the operation of configuring the IP address for the second terminal is no longer performed.
可选地,所述第二IP地址为所述网络侧指示的,或者,所述第二IP地址为所述第二终端选择的。Optionally, the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
可选地,所述第一认证相关信息或所述第二认证相关信息为使用可扩展的身份验证协议EAP协议的信息。Optionally, the first authentication-related information or the second authentication-related information is information using an Extensible Authentication Protocol (EAP) protocol.
可选地,所述第一终端接收的所述网络侧发送的所述第一认证相关信息通过第一非接入层NAS消息承载,所述第一终端向所述网络侧发送的所述第二认证相关信息通过第二非接入层NAS消息承载; Optionally, the first authentication-related information sent by the network side received by the first terminal is carried in a first non-access stratum NAS message, and the first authentication-related information sent by the first terminal to the network side 2. Authentication-related information is carried by a second non-access stratum NAS message;
所述第一终端向所述第二终端发送的所述第一认证相关信息不通过非接入层NAS消息承载,所述第一终端接收的所述第二终端发送的所述第二认证相关信息不通过非接入层NAS消息承载。The first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
可选地,所述第一终端向所述第二终端发送的所述第一认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输,所述第一终端接收的所述第二终端发送的所述第二认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输。Optionally, the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol IKE, and the first terminal receives the The second authentication-related information sent by the second terminal is transmitted through the direct link layer protocol or the network key exchange protocol IKE.
可选地,所述第一NAS消息中携带有所述第二终端的相关信息。Optionally, the first NAS message carries related information of the second terminal.
可选地,所述第二终端的相关信息包括以下至少一项:Optionally, the relevant information of the second terminal includes at least one of the following:
控制面标识信息;Control plane identification information;
用户面标识信息。User plane identification information.
可选地,所述用户面标识信息包括以下至少一项:Optionally, the user plane identification information includes at least one of the following:
IP地址;IP address;
IP地址和端口号;IP address and port number;
MAC地址;MAC address;
所述第一终端与所述第二终端的直连连接信息。Direct connection information between the first terminal and the second terminal.
可选地,所述第一终端与所述第二终端之间的认证过程通过以下至少一项协议消息承载:Optionally, the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
直连传输链路层协议;Directly connected to the transport link layer protocol;
网络密钥交换协议IKE。Network key exchange protocol IKE.
可选地,所述第一终端和所述第二终端之间建立有直连连接,所述直连连接包括以下一项:Optionally, a direct connection is established between the first terminal and the second terminal, and the direct connection includes the following item:
非3GPP连接;Non-3GPP connection;
旁链路PC5连接;Sidelink PC5 connection;
WiFi连接;WiFi connection;
蓝牙连接。Bluetooth connection.
可选地,所述第一终端为个人物联网中具有网关能力的终端,所述第二终端为非3GPP设备或者为个人物联网设备。Optionally, the first terminal is a terminal capable of gateway in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device.
在本申请的又一实施例中,处理器1010用于完成与第一终端之间的认证 过程;射频单元1001用于接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。In yet another embodiment of the present application, the processor 1010 is configured to complete authentication with the first terminal Process; the radio frequency unit 1001 is configured to send the second authentication-related information carrying the first identification to the first terminal after receiving the first authentication-related information from the first terminal, wherein the first identification is used to communicate with the network The authentication process is performed on the side.
可选地,处理器1010用于在与网络侧执行认证的过程中或成功完成与网络侧的认证过程后停止密钥派生。Optionally, the processor 1010 is configured to stop the key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
可选地,处理器1010用于使用第二标识完成与所述第一终端之间的认证过程。Optionally, the processor 1010 is configured to use the second identifier to complete an authentication process with the first terminal.
可选地,处理器1010用于基于所述第一认证相关信息的安全保护情况,使用所述第一标识。Optionally, the processor 1010 is configured to use the first identifier based on a security protection situation of the first authentication-related information.
可选地,处理器1010用于在所述第一认证相关信息为做安全保护时,所述第二终端使用所述第一标识。Optionally, the processor 1010 is configured to, when the first authentication-related information is for security protection, use the first identifier by the second terminal.
可选地,所述第一认证相关信息用于请求第一终端的标识。Optionally, the first authentication-related information is used to request an identifier of the first terminal.
本申请实施例中,第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端,所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧,从而实现通过第一终端(如个人物联网网关)对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal, and the first terminal receives the second authentication-related information sent by the second terminal. Authentication-related information, and sending the second authentication-related information to the network side, so that the second terminal (such as a non-3GPP terminal, that is, that does not support the NAS protocol process) is implemented through the first terminal (such as a personal Internet of Things gateway) device) for the purpose of authentication.
如图11所示,本申请实施例还提供了一种设备鉴权装置1100,应用于第一网络功能,该装置包括:As shown in Figure 11, the embodiment of the present application also provides a device authentication device 1100, which is applied to the first network function, and the device includes:
第三收发模块1101,用于接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The third transceiver module 1101 is configured to receive the indication information sent by the second network function, the indication information includes at least one of the following: related information of the first terminal, related information of the second terminal, indication of stopping authentication, authentication instruct;
第四收发模块1102,用于根据所述指示信息执行或停止执行第一操作,所述第一操作包含:The fourth transceiver module 1102 is configured to perform or stop performing a first operation according to the indication information, the first operation includes:
向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;Sending first authentication-related information to the first terminal, where the first authentication-related information is used by the first terminal to send to the second terminal;
接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的;receiving second authentication-related information sent by the first terminal, where the second authentication-related information is received by the first terminal from the second terminal;
将所述第二认证相关信息发送给第三网络功能。 Send the second authentication-related information to a third network function.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第九处理模块用于在第四收发模块执行所述第一操作的情况下,执行以下至少一项:The ninth processing module is configured to perform at least one of the following when the fourth transceiver module performs the first operation:
指示所述第三网络功能停止密钥派生或停止发送密钥信息;instructing said third network function to stop key derivation or to stop sending key information;
停止发送密钥信息给所述第一终端。Stop sending key information to the first terminal.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第一转发模块,用于在第四收发模块执行所述第一操作的情况下,转发所述第二终端和所述第三网络功能之间的后续认证相关信息,所述后续认证相关信息用于执行所述第二终端和所述第三网络功能之间的认证。A first forwarding module, configured to forward subsequent authentication-related information between the second terminal and the third network function when the fourth transceiver module performs the first operation, the subsequent authentication-related information is used for performing authentication between the second terminal and the third network function.
可选地,所述第二终端的相关信息包括以下至少一项:Optionally, the relevant information of the second terminal includes at least one of the following:
控制面标识信息;Control plane identification information;
用户面标识信息。User plane identification information.
可选地,所述用户面标识信息包括以下至少一项:Optionally, the user plane identification information includes at least one of the following:
IP地址;IP address;
IP地址和端口号;IP address and port number;
MAC地址;MAC address;
所述第一终端与所述第二终端的直连连接信息。Direct connection information between the first terminal and the second terminal.
可选地,所述第一网络功能向所述第一终端发送的所述第一认证相关信息通过第一NAS消息承载,所述第一网络功能接收的所述第一终端发送的第二认证相关信息通过第二NAS消息承载。Optionally, the first authentication related information sent by the first network function to the first terminal is carried by a first NAS message, and the second authentication sent by the first terminal received by the first network function Related information is carried by the second NAS message.
可选地,所述第一NAS消息中携带有所述第二终端的相关信息。Optionally, the first NAS message carries related information of the second terminal.
可选地,所述第一认证相关信息或所述第二认证相关信息为EAP协议的信息。Optionally, the first authentication-related information or the second authentication-related information is EAP protocol information.
可选地,所述第一认证相关信息用于请求第一终端的标识。Optionally, the first authentication-related information is used to request an identifier of the first terminal.
本申请实施例中,第一网络功能接收第二网络功能发送的指示信息,以使所述第一网络功能能够根据所述指示信息,向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端,所述第一网络功能接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的,所述第一网络功能将所述第二认 证相关信息发送给第三网络功能,从而实现了对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the first network function receives the indication information sent by the second network function, so that the first network function can send the first authentication-related information to the first terminal according to the indication information, and the first The authentication-related information is used by the first terminal to send to the second terminal, and the first network function receives the second authentication-related information sent by the first terminal, and the second authentication-related information is sent by the first terminal from received by the second terminal, the first network function sends the second authentication The certificate-related information is sent to the third network function, thereby achieving the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
如图12所示,本申请实施例还提供了一种设备鉴权装置1200,应用于第二网络功能,该装置包括:As shown in Figure 12, the embodiment of the present application also provides a device authentication device 1200, which is applied to the second network function, and the device includes:
第五收发模块1201,用于向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The fifth transceiver module 1201 is configured to send instruction information to the first network function, where the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction ;
所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。The indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
可选地,本申请实施例的装置,还包括:第一确定模块,用于确定所述指示信息。Optionally, the device in this embodiment of the present application further includes: a first determining module, configured to determine the indication information.
可选地,所述第一认证相关信息为EAP的信息。Optionally, the first authentication-related information is EAP information.
本申请实施例中,第二网络功能向第一网络功能发送指示信息,以便于第一网络功能根据该指示信息确定第一终端的标识信息,从而向第一终端发送第一认证相关信息,并使得第一终端将该第一认证相关信息发送给第二终端,以便于完成对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the second network function sends indication information to the first network function, so that the first network function determines the identification information of the first terminal according to the indication information, thereby sends the first authentication-related information to the first terminal, and The first terminal is made to send the first authentication-related information to the second terminal, so as to accomplish the purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
如图13所示,本申请实施例还提供了一种设备鉴权装置1300,应用于第三网络功能,包括:As shown in Figure 13, the embodiment of the present application also provides a device authentication apparatus 1300, which is applied to the third network function, including:
第一处理模块1301,用于执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。The first processing module 1301 is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
可选地,所述第三网络功能在所述认证过程中或在所述认证过程成功后执行以下至少一项:Optionally, the third network function performs at least one of the following during the authentication process or after the authentication process succeeds:
停止密钥派生;stop key derivation;
停止发送密钥信息给所述第一网络功能。Stop sending key information to the first network function.
可选地,本申请实施例的装置,还包括:Optionally, the device of the embodiment of the present application further includes:
第七收发模块,用于接收第一网络功能发送的第二认证相关信息,所述第二认证相关信息为所述第一网络功能从第一终端接收的,以及所述第一终 端从第二终端接收的。A seventh transceiver module, configured to receive second authentication-related information sent by the first network function, the second authentication-related information is received by the first network function from the first terminal, and the first terminal terminal received from the second terminal.
可选地,所述第一处理模块用于基于以下至少一项,选择或使用EAP协议执行所述认证过程:Optionally, the first processing module is configured to select or use the EAP protocol to perform the authentication process based on at least one of the following:
第一网络功能的信息;information about the capabilities of the first network;
所述第二认证相关信息。The second authentication-related information.
可选地,所述第二认证相关信息为EAP协议的信息。Optionally, the second authentication-related information is information of the EAP protocol.
可选地,本申请实施例的方法,还包括:Optionally, the method of the embodiment of the present application further includes:
第八收发模块,用于接收来自第一网络功能的指示;An eighth transceiver module, configured to receive an instruction from the first network function;
第十处理模块,用于根据所述指示在所述认证过程中或在所述认证过程成功后执行以下至少一项:A tenth processing module, configured to perform at least one of the following during the authentication process or after the authentication process succeeds according to the instruction:
停止密钥派生;stop key derivation;
停止发送密钥信息给所述第一网络功能;stop sending key information to said first network function;
所述指示包括以下至少一项:The instructions include at least one of the following:
第一网络功能的信息,与停止密钥派生或发送密钥信息相关的指示,所述第二认证相关信息。Information about the first network function, an instruction related to stopping key derivation or sending key information, and the second authentication-related information.
可选地,所述第一处理模块用于在所述第二认证相关信息为EAP协议的信息时,选择EAP协议执行所述认证过程。Optionally, the first processing module is configured to select an EAP protocol to execute the authentication process when the second authentication-related information is information of an EAP protocol.
本申请实施例中,第三网络功能执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程,从而实现对第二终端(如非3GPP终端,即不支持NAS协议过程的设备)进行鉴权的目的。In this embodiment of the present application, the third network function executes the authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function, thereby realizing The purpose of authenticating the second terminal (such as a non-3GPP terminal, that is, a device that does not support the NAS protocol process).
本申请实施例还提供一种网络功能(也可描述为网络侧设备),包括处理器和通信接口,通信接口用于接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;根据所述指示信息执行或停止执行第一操作,所述第一操作包含:向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的;将所述第二认证相关信息发送给第三网络功能。 The embodiment of the present application also provides a network function (which can also be described as a network side device), including a processor and a communication interface, the communication interface is used to receive instruction information sent by the second network function, and the instruction information includes at least one of the following Items: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction; perform or stop performing the first operation according to the instruction information, and the first operation includes: sending to the first terminal First authentication-related information, the first authentication-related information is used by the first terminal to send to the second terminal; receiving second authentication-related information sent by the first terminal, the second authentication-related information is Received by the first terminal from the second terminal; sending the second authentication-related information to a third network function.
或者,所述通信接口用于向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。Alternatively, the communication interface is used to send instruction information to the first network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ; The indication information is used for the execution or stop of the first network function to send first authentication related information to the first terminal, and the first authentication related information is used for the first terminal to send to the second terminal.
或者,所述处理器用于执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。Alternatively, the processor is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
该网络功能实施例与上述网络功能方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该网络功能实施例中,且能达到相同的技术效果。This network function embodiment corresponds to the above network function method embodiment, and each implementation process and implementation mode of the above method embodiment can be applied to this network function embodiment, and can achieve the same technical effect.
具体地,本申请实施例还提供了一种网络功能(即上述第一网络功能、第二网络功能或第三网络功能),如图14所示,该网络功能1400包括:天线141、射频装置142、基带装置143、处理器144和存储器145。天线141与射频装置142连接。在上行方向上,射频装置142通过天线141接收信息,将接收的信息发送给基带装置143进行处理。在下行方向上,基带装置143对要发送的信息进行处理,并发送给射频装置142,射频装置142对收到的信息进行处理后经过天线141发送出去。Specifically, the embodiment of the present application also provides a network function (that is, the above-mentioned first network function, second network function or third network function), as shown in FIG. 14 , the network function 1400 includes: an antenna 141, a radio frequency device 142 , baseband device 143 , processor 144 and memory 145 . The antenna 141 is connected to the radio frequency device 142 . In the uplink direction, the radio frequency device 142 receives information through the antenna 141, and sends the received information to the baseband device 143 for processing. In the downlink direction, the baseband device 143 processes the information to be sent and sends it to the radio frequency device 142 , and the radio frequency device 142 processes the received information and sends it out through the antenna 141 .
以上实施例中网络功能执行的方法可以在基带装置143中实现,该基带装置143包括基带处理器。The method for executing the network function in the above embodiments may be implemented in the baseband device 143, where the baseband device 143 includes a baseband processor.
基带装置143例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图14所示,其中一个芯片例如为基带处理器,通过总线接口与存储器145连接,以调用存储器145中的程序,执行以上方法实施例中所示的网络设备操作。The baseband device 143 can include at least one baseband board, for example, a plurality of chips are arranged on the baseband board, as shown in FIG. The program executes the network device operations shown in the above method embodiments.
该网络功能还可以包括网络接口146,该接口例如为通用公共无线接口(common public radio interface,CPRI)。The network function may also include a network interface 146, such as a common public radio interface (CPRI).
具体地,本发明实施例的网络功能1400还包括:存储在存储器145上并可在处理器144上运行的指令或程序,处理器144调用存储器145中的指令或程序执行图11、12或13所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。 Specifically, the network function 1400 in this embodiment of the present invention also includes: instructions or programs stored in the memory 145 and operable on the processor 144, and the processor 144 calls the instructions or programs in the memory 145 to execute FIG. 11 , 12 or 13 The methods executed by each module shown in the figure achieve the same technical effect, so in order to avoid repetition, they are not repeated here.
具体地,本申请实施例还提供了一种网络功能(上述第一网络功能、第二网络功能或第三网络功能)。如图15所示,该网络功能1500包括:处理器1501、网络接口1502和存储器1503。其中,网络接口1502例如为通用公共无线接口(common public radio interface,CPRI)。Specifically, the embodiment of the present application further provides a network function (the above-mentioned first network function, second network function, or third network function). As shown in FIG. 15 , the network function 1500 includes: a processor 1501 , a network interface 1502 and a memory 1503 . Wherein, the network interface 1502 is, for example, a common public radio interface (common public radio interface, CPRI).
具体地,本发明实施例的网络功能1500还包括:存储在存储器1503上并可在处理器1501上运行的指令或程序,处理器1501调用存储器1503中的指令或程序执行图11、12或13所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。Specifically, the network function 1500 in this embodiment of the present invention also includes: instructions or programs stored in the memory 1503 and operable on the processor 1501, and the processor 1501 invokes the instructions or programs in the memory 1503 to execute FIG. 11 , 12 or 13 The methods executed by each module shown in the figure achieve the same technical effect, so in order to avoid repetition, they are not repeated here.
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述设备鉴权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。The embodiment of the present application also provides a readable storage medium, the readable storage medium stores a program or an instruction, and when the program or instruction is executed by a processor, each process of the above embodiment of the device authentication method is implemented, and can achieve The same technical effects are not repeated here to avoid repetition.
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。Wherein, the processor is the processor in the terminal described in the foregoing embodiments. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk, and the like.
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述设备鉴权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。The embodiment of the present application further provides a chip, the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the above embodiment of the device authentication method Each process, and can achieve the same technical effect, in order to avoid repetition, will not repeat them here.
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。It should be understood that the chip mentioned in the embodiment of the present application may also be called a system-on-chip, a system-on-chip, a system-on-a-chip, or a system-on-a-chip.
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述设备鉴权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。The embodiment of the present application further provides a computer program/program product, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the above device authentication method Each process of the example, and can achieve the same technical effect, in order to avoid repetition, will not repeat them here.
本申请实施例还提供了一种设备鉴权系统,包括:终端及网络侧,所述终端包括第一终端和第二终端,所述网络侧包括第一网络功能、第二网络功能和第三网络功能,所述终端可用于执行如上所述的应用于第一终端或第二终端的设备鉴权方法的步骤,所述网络侧中的各个网络功能可用于执行如上所述的应用于第一网络功能、第二网络功能或第三网络功能的设备鉴权方法 的步骤。The embodiment of the present application also provides a device authentication system, including: a terminal and a network side, the terminal includes a first terminal and a second terminal, and the network side includes a first network function, a second network function, and a third A network function, the terminal can be used to perform the above-mentioned steps of the device authentication method applied to the first terminal or the second terminal, and each network function in the network side can be used to perform the above-mentioned steps applied to the first terminal Device authentication method for network function, second network function or third network function A step of.
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。It should be noted that, in this document, the term "comprising", "comprising" or any other variation thereof is intended to cover a non-exclusive inclusion such that a process, method, article or apparatus comprising a set of elements includes not only those elements, It also includes other elements not expressly listed, or elements inherent in the process, method, article, or device. Without further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved. Functions are performed, for example, the described methods may be performed in an order different from that described, and various steps may also be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general-purpose hardware platform, and of course also by hardware, but in many cases the former is better implementation. Based on such an understanding, the technical solution of the present application can be embodied in the form of computer software products, which are stored in a storage medium (such as ROM/RAM, magnetic disk, etc.) , CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) execute the methods described in the various embodiments of the present application.
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。 The embodiments of the present application have been described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementations. The above-mentioned specific implementations are only illustrative and not restrictive. Those of ordinary skill in the art will Under the inspiration of this application, without departing from the purpose of this application and the scope of protection of the claims, many forms can also be made, all of which belong to the protection of this application.

Claims (47)

  1. 一种设备鉴权方法,包括:A device authentication method, comprising:
    第一终端接收网络侧发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;The first terminal receives the first authentication-related information sent by the network side, and sends the first authentication-related information to the second terminal;
    所述第一终端接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述网络侧。The first terminal receives the second authentication related information sent by the second terminal, and sends the second authentication related information to the network side.
  2. 根据权利要求1所述的方法,其中,所述第一终端接收网络侧发送的第一认证相关信息之前,还执行以下至少一项:The method according to claim 1, wherein, before the first terminal receives the first authentication-related information sent by the network side, it further performs at least one of the following:
    所述第一终端与所述第二终端之间的认证过程;an authentication process between the first terminal and the second terminal;
    所述第一终端为所述第二终端配置第一IP地址。The first terminal configures a first IP address for the second terminal.
  3. 根据权利要求1所述的方法,其中,所述第一认证相关信息未做安全保护。The method according to claim 1, wherein the first authentication-related information is not protected.
  4. 根据权利要求1所述的方法,其中,还包括:The method according to claim 1, further comprising:
    在所述第一终端接收到所述网络侧发送的所述第一认证相关信息时,所述第一终端停止发起或停止执行所述第一终端与所述第二终端之间的认证过程。When the first terminal receives the first authentication-related information sent by the network side, the first terminal stops initiating or stopping the authentication process between the first terminal and the second terminal.
  5. 根据权利要求1所述的方法,其中,所述第一终端将所述第二认证相关信息发送给所述网络侧之后,还包括:The method according to claim 1, wherein after the first terminal sends the second authentication-related information to the network side, further comprising:
    所述第一终端向所述第二终端发送第二IP地址,或者,所述第一终端不再执行为所述第二终端配置IP地址的操作。The first terminal sends the second IP address to the second terminal, or the first terminal no longer performs the operation of configuring the IP address for the second terminal.
  6. 根据权利要求5所述的方法,其中,所述第二IP地址为所述网络侧指示的,或者,所述第二IP地址为所述第二终端选择的。The method according to claim 5, wherein the second IP address is indicated by the network side, or the second IP address is selected by the second terminal.
  7. 根据权利要求1所述的方法,其中,所述第一认证相关信息或所述第二认证相关信息为使用可扩展的身份验证协议EAP协议的信息。The method according to claim 1, wherein the first authentication-related information or the second authentication-related information is information using an Extensible Authentication Protocol (EAP) protocol.
  8. 根据权利要求1所述的方法,其中,The method according to claim 1, wherein,
    所述第一终端接收的所述网络侧发送的所述第一认证相关信息通过第一非接入层NAS消息承载,所述第一终端向所述网络侧发送的所述第二认证相关信息通过第二非接入层NAS消息承载; The first authentication-related information sent by the network side received by the first terminal is carried in a first non-access stratum NAS message, and the second authentication-related information sent by the first terminal to the network side carried by the second non-access stratum NAS message;
    所述第一终端向所述第二终端发送的所述第一认证相关信息不通过非接入层NAS消息承载,所述第一终端接收的所述第二终端发送的所述第二认证相关信息不通过非接入层NAS消息承载。The first authentication-related information sent by the first terminal to the second terminal is not carried in a non-access stratum NAS message, and the second authentication-related information sent by the second terminal received by the first terminal Information is not carried by non-access stratum NAS messages.
  9. 根据权利要求1所述的方法,其中,所述第一终端向所述第二终端发送的所述第一认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输,所述第一终端接收的所述第二终端发送的所述第二认证相关信息通过直连传输链路层协议或网络密钥交换协议IKE传输。The method according to claim 1, wherein the first authentication-related information sent by the first terminal to the second terminal is transmitted through a direct link layer protocol or a network key exchange protocol (IKE), and the The second authentication-related information sent by the second terminal received by the first terminal is transmitted through a direct link layer protocol or a network key exchange protocol IKE.
  10. 根据权利要求8所述的方法,其中,所述第一NAS消息中携带有所述第二终端的相关信息。The method according to claim 8, wherein the first NAS message carries related information of the second terminal.
  11. 根据权利要求10所述的方法,其中,所述第二终端的相关信息包括以下至少一项:The method according to claim 10, wherein the relevant information of the second terminal includes at least one of the following:
    控制面标识信息;Control plane identification information;
    用户面标识信息。User plane identification information.
  12. 根据权利要求11所述的方法,其中,所述用户面标识信息包括以下至少一项:The method according to claim 11, wherein the user plane identification information includes at least one of the following:
    IP地址;IP address;
    IP地址和端口号;IP address and port number;
    MAC地址;MAC address;
    所述第一终端与所述第二终端的直连连接信息。Direct connection information between the first terminal and the second terminal.
  13. 根据权利要求2所述的方法,其中,所述第一终端与所述第二终端之间的认证过程通过以下至少一项协议消息承载:The method according to claim 2, wherein the authentication process between the first terminal and the second terminal is carried by at least one of the following protocol messages:
    直连传输链路层协议;Directly connected to the transport link layer protocol;
    网络密钥交换协议IKE。Network key exchange protocol IKE.
  14. 根据权利要求1所述的方法,其中,所述第一终端和所述第二终端之间建立有直连连接,所述直连连接包括以下一项:The method according to claim 1, wherein a direct connection is established between the first terminal and the second terminal, and the direct connection includes one of the following items:
    非3GPP连接;Non-3GPP connection;
    旁链路PC5连接;Sidelink PC5 connection;
    WiFi连接;WiFi connection;
    蓝牙连接。 Bluetooth connection.
  15. 根据权利要求1所述的方法,其中,所述第一终端为个人物联网中具有网关能力的终端,所述第二终端为非3GPP设备或者为个人物联网设备。The method according to claim 1, wherein the first terminal is a terminal capable of gateway in the Personal Internet of Things, and the second terminal is a non-3GPP device or a Personal Internet of Things device.
  16. 一种设备鉴权方法,包括:A device authentication method, comprising:
    第一网络功能接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The first network function receives the indication information sent by the second network function, and the indication information includes at least one of the following: related information of the first terminal, related information of the second terminal, an indication of stopping authentication, and an indication of authentication;
    所述第一网络功能根据所述指示信息执行或停止执行第一操作,所述第一操作包含:The first network function performs or stops performing a first operation according to the instruction information, and the first operation includes:
    向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;Sending first authentication-related information to the first terminal, where the first authentication-related information is used by the first terminal to send to the second terminal;
    所述第一网络功能接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的;The first network function receives second authentication-related information sent by the first terminal, where the second authentication-related information is received by the first terminal from the second terminal;
    所述第一网络功能将所述第二认证相关信息发送给第三网络功能。The first network function sends the second authentication-related information to a third network function.
  17. 根据权利要求16所述的方法,其中,在所述第一网络功能执行所述第一操作的情况下,所述第一网络功能还执行以下至少一项:The method according to claim 16, wherein, where the first network function performs the first operation, the first network function further performs at least one of the following:
    指示所述第三网络功能停止密钥派生或停止发送密钥信息;instructing said third network function to stop key derivation or to stop sending key information;
    停止发送密钥信息给所述第一终端。Stop sending key information to the first terminal.
  18. 根据权利要求16所述的方法,其中,在所述第一网络功能执行所述第一操作的情况下,还包括:The method according to claim 16, wherein, in case the first network function performs the first operation, further comprising:
    所述第一网络功能转发所述第二终端和所述第三网络功能之间的后续认证相关信息,所述后续认证相关信息用于执行所述第二终端和所述第三网络功能之间的认证。The first network function forwards subsequent authentication-related information between the second terminal and the third network function, and the subsequent authentication-related information is used to perform a communication between the second terminal and the third network function certification.
  19. 根据权利要求16所述的方法,其中,所述第二终端的相关信息包括以下至少一项:The method according to claim 16, wherein the relevant information of the second terminal includes at least one of the following:
    控制面标识信息;Control plane identification information;
    用户面标识信息。User plane identification information.
  20. 根据权利要求19所述的方法,其中,所述用户面标识信息包括以下至少一项:The method according to claim 19, wherein the user plane identification information includes at least one of the following:
    IP地址; IP address;
    IP地址和端口号;IP address and port number;
    MAC地址;MAC address;
    所述第一终端与所述第二终端的直连连接信息。Direct connection information between the first terminal and the second terminal.
  21. 根据权利要求16所述的方法,其中,所述第一网络功能向所述第一终端发送的所述第一认证相关信息通过第一NAS消息承载,所述第一网络功能接收的所述第一终端发送的第二认证相关信息通过第二NAS消息承载。The method according to claim 16, wherein the first authentication-related information sent by the first network function to the first terminal is carried by a first NAS message, and the first authentication-related information received by the first network function The second authentication-related information sent by a terminal is carried in a second NAS message.
  22. 根据权利要求21所述的方法,其中,所述第一NAS消息中携带有所述第二终端的相关信息。The method according to claim 21, wherein the first NAS message carries related information of the second terminal.
  23. 根据权利要求16所述的方法,其中,所述第一认证相关信息或所述第二认证相关信息为EAP协议的信息。The method according to claim 16, wherein the first authentication-related information or the second authentication-related information is information of an EAP protocol.
  24. 根据权利要求16所述的方法,其中,所述第一认证相关信息用于请求第一终端的标识。The method according to claim 16, wherein the first authentication-related information is used to request an identification of the first terminal.
  25. 一种设备鉴权方法,包括:A device authentication method, comprising:
    第二网络功能向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The second network function sends instruction information to the first network function, and the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction;
    所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。The indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
  26. 根据权利要求25所述的方法,其中,所述第一认证相关信息为EAP的信息。The method according to claim 25, wherein the first authentication-related information is EAP information.
  27. 一种设备鉴权方法,包括:A device authentication method, comprising:
    第三网络功能执行第二终端与所述第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。The third network function executes an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process with the third network function through the first terminal.
  28. 根据权利要求27所述的方法,其中,所述第三网络功能在所述认证过程中或在所述认证过程成功后执行以下至少一项:The method of claim 27, wherein the third network function performs at least one of the following during or after the authentication process is successful:
    停止密钥派生;stop key derivation;
    停止发送密钥信息给第一网络功能。Stop sending key information to the first network function.
  29. 根据权利要求27所述的方法,其中,所述第三网络功能在执行所述 认证过程之前,还包括:The method of claim 27, wherein said third network function performs said Before the certification process, also include:
    所述第三网络功能接收第一网络功能发送的第二认证相关信息,所述第二认证相关信息为所述第一网络功能从第一终端接收的,以及所述第一终端从第二终端接收的。The third network function receives second authentication-related information sent by the first network function, the second authentication-related information is received by the first network function from the first terminal, and the first terminal receives from the second terminal Received.
  30. 根据权利要求29所述的方法,其中,所述第三网络功能执行所述第二终端与所述第三网络功能间的认证过程,包括:The method according to claim 29, wherein the third network function performs an authentication process between the second terminal and the third network function, comprising:
    所述第三网络功能基于以下至少一项,选择或使用EAP协议执行所述认证过程:The third network function selects or uses the EAP protocol to perform the authentication process based on at least one of the following:
    第一网络功能的信息;information about the capabilities of the first network;
    所述第二认证相关信息。The second authentication-related information.
  31. 根据权利要求27或29所述的方法,其中,还包括:The method according to claim 27 or 29, further comprising:
    所述第三网络功能接收来自第一网络功能的指示,所述第三网络功能根据所述指示在所述认证过程中或在所述认证过程成功后执行以下至少一项:The third network function receives an instruction from the first network function, and the third network function performs at least one of the following during the authentication process or after the authentication process is successful according to the instruction:
    停止密钥派生;stop key derivation;
    停止发送密钥信息给所述第一网络功能;stop sending key information to said first network function;
    所述指示包括以下至少一项:The instructions include at least one of the following:
    第一网络功能的信息,与停止密钥派生或发送密钥信息相关的指示,所述第二认证相关信息。Information about the first network function, an instruction related to stopping key derivation or sending key information, and the second authentication-related information.
  32. 根据权利要求29或31所述的方法,其中,所述第二认证相关信息为EAP协议的信息。The method according to claim 29 or 31, wherein the second authentication-related information is information of the EAP protocol.
  33. 根据权利要求30所述的方法,其中,所述选择或使用EAP协议执行所述认证过程,包括:The method according to claim 30, wherein said selecting or using the EAP protocol to perform said authentication process comprises:
    在所述第二认证相关信息为EAP协议的信息时,选择EAP协议执行所述认证过程。When the second authentication-related information is information of the EAP protocol, the EAP protocol is selected to execute the authentication process.
  34. 一种设备鉴权方法,包括:A device authentication method, comprising:
    第二终端完成与第一终端之间的认证过程;The second terminal completes the authentication process with the first terminal;
    所述第二终端接收到来自第一终端的第一认证相关信息后,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。 After receiving the first authentication-related information from the first terminal, the second terminal sends to the first terminal second authentication-related information carrying a first identifier, wherein the first identifier is used to communicate with the network side to perform Authentication process.
  35. 根据权利要求34所述的方法,其中,还包括:The method of claim 34, further comprising:
    所述第二终端在与网络侧执行认证的过程中或成功完成与网络侧的认证过程后停止密钥派生。The second terminal stops key derivation during the authentication process with the network side or after successfully completing the authentication process with the network side.
  36. 根据权利要求34所述的方法,其中,还包括:The method of claim 34, further comprising:
    所述第二终端使用第二标识完成与所述第一终端之间的认证过程。The second terminal completes the authentication process with the first terminal by using the second identifier.
  37. 根据权利要求34所述的方法,其中,还包括:The method of claim 34, further comprising:
    所述第二终端基于所述第一认证相关信息的安全保护情况,使用所述第一标识。The second terminal uses the first identifier based on the security protection of the first authentication-related information.
  38. 根据权利要求37所述的方法,其中,所述第二终端基于所述第一认证相关信息的安全保护情况,使用所述第一标识,包括:The method according to claim 37, wherein the second terminal uses the first identification based on the security protection of the first authentication-related information, comprising:
    在所述第一认证相关信息为做安全保护时,所述第二终端使用所述第一标识。When the first authentication-related information is for security protection, the second terminal uses the first identifier.
  39. 根据权利要求34所述的方法,其中,所述第一认证相关信息用于请求第一终端的标识。The method according to claim 34, wherein the first authentication related information is used to request the identification of the first terminal.
  40. 一种设备鉴权装置,包括:A device authentication device, comprising:
    第一收发模块,用于接收第一网络功能发送的第一认证相关信息,并将所述第一认证相关信息发送给第二终端;The first transceiver module is configured to receive the first authentication-related information sent by the first network function, and send the first authentication-related information to the second terminal;
    第二收发模块,用于接收所述第二终端发送的第二认证相关信息,并将所述第二认证相关信息发送给所述第一网络功能。The second transceiver module is configured to receive the second authentication-related information sent by the second terminal, and send the second authentication-related information to the first network function.
  41. 一种设备鉴权装置,包括:A device authentication device, comprising:
    第三收发模块,用于接收第二网络功能发送的指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The third transceiver module is configured to receive the instruction information sent by the second network function, the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, authentication instruction ;
    第四收发模块,用于根据所述指示信息执行或停止执行第一操作,所述第一操作包含:The fourth transceiver module is configured to perform or stop performing a first operation according to the indication information, and the first operation includes:
    向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端;Sending first authentication-related information to the first terminal, where the first authentication-related information is used by the first terminal to send to the second terminal;
    接收所述第一终端发送的第二认证相关信息,所述第二认证相关信息为第一终端从所述第二终端接收的; receiving second authentication-related information sent by the first terminal, where the second authentication-related information is received by the first terminal from the second terminal;
    将所述第二认证相关信息发送给第三网络功能。Send the second authentication-related information to a third network function.
  42. 一种设备鉴权装置,包括:A device authentication device, comprising:
    第五收发模块,用于向第一网络功能发送指示信息,所述指示信息中包含以下至少一项:第一终端的相关信息,第二终端的相关信息,停止鉴权指示,鉴权指示;The fifth transceiver module is configured to send instruction information to the first network function, where the instruction information includes at least one of the following: related information of the first terminal, related information of the second terminal, stop authentication instruction, and authentication instruction;
    所述指示信息用于所述第一网络功能执行或停止执行向第一终端发送第一认证相关信息,所述第一认证相关信息用于所述第一终端发送给所述第二终端。The indication information is used to send the first authentication-related information to the first terminal when the first network function is executed or stopped, and the first authentication-related information is used for the first terminal to send to the second terminal.
  43. 一种设备鉴权装置,包括:A device authentication device, comprising:
    第一处理模块,用于执行第二终端与第三网络功能间的认证过程,所述第二终端通过第一终端与所述第三网络功能执行所述认证过程。The first processing module is configured to execute an authentication process between the second terminal and the third network function, and the second terminal executes the authentication process through the first terminal and the third network function.
  44. 一种设备鉴权装置,包括:A device authentication device, comprising:
    第二处理模块,用于完成与第一终端之间的认证过程;The second processing module is used to complete the authentication process with the first terminal;
    第六收发模块,用于接收到来自第一终端的第一认证相关信息,向所述第一终端发送携带第一标识的第二认证相关信息,其中,所述第一标识用于与网络侧执行认证过程。The sixth transceiver module is configured to receive the first authentication-related information from the first terminal, and send the second authentication-related information carrying the first identification to the first terminal, wherein the first identification is used to communicate with the network side Execute the authentication process.
  45. 一种终端,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至15任一项所述的设备鉴权方法的步骤,或者,实现如权利要求34至39任一项所述的设备鉴权方法的步骤。A terminal, including a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, the process described in any one of claims 1 to 15 is implemented. The steps of the device authentication method described above, or the steps of the device authentication method described in any one of claims 34 to 39.
  46. 一种网络功能,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求16至24任一项所述的设备鉴权方法的步骤,或者,实现如权利要求25至26任一项所述的设备鉴权方法的步骤,或者,实现如权利要求27至33任一项所述的设备鉴权方法的步骤。A network function, including a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, any one of claims 16 to 24 is implemented The steps of the device authentication method, or, realizing the steps of the device authentication method according to any one of claims 25 to 26, or, realizing the device authentication according to any one of claims 27 to 33 method steps.
  47. 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至15任一项所述的设备鉴权方法的步骤,或者,实现如权利要求16至24任一项所述的设备鉴权方法的步骤,或者,实现如权利要求25至26任一项所述的设备鉴权方法的步骤,或者, 实现如权利要求27至33任一项所述的设备鉴权方法的步骤,或者,实现如权利要求34至39任一项所述的设备鉴权方法的步骤。 A readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the steps of the device authentication method according to any one of claims 1 to 15 are implemented, or , realizing the steps of the device authentication method according to any one of claims 16 to 24, or, realizing the steps of the device authentication method according to any one of claims 25 to 26, or, Realize the steps of the device authentication method according to any one of claims 27 to 33, or realize the steps of the device authentication method according to any one of claims 34 to 39.
PCT/CN2023/073279 2022-01-27 2023-01-20 Device authentication method and apparatus, and terminal and network function WO2023143418A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202210101704.2A CN116567625A (en) 2022-01-27 2022-01-27 Equipment authentication method, device, terminal and network function
CN202210101704.2 2022-01-27

Publications (1)

Publication Number Publication Date
WO2023143418A1 true WO2023143418A1 (en) 2023-08-03

Family

ID=87470822

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/073279 WO2023143418A1 (en) 2022-01-27 2023-01-20 Device authentication method and apparatus, and terminal and network function

Country Status (2)

Country Link
CN (1) CN116567625A (en)
WO (1) WO2023143418A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102204306A (en) * 2011-04-28 2011-09-28 华为技术有限公司 Method, device and system for machine type communication (mtc) terminal communicating with network through gateway
CN102625306A (en) * 2011-01-31 2012-08-01 电信科学技术研究院 Method, system and equipment for authentication
CN109391940A (en) * 2017-08-02 2019-02-26 华为技术有限公司 A kind of method, equipment and system accessing network
WO2020091281A1 (en) * 2018-11-02 2020-05-07 엘지전자 주식회사 Method and apparatus for performing proxy authentication for access permission by terminal in wireless communication system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102625306A (en) * 2011-01-31 2012-08-01 电信科学技术研究院 Method, system and equipment for authentication
CN102204306A (en) * 2011-04-28 2011-09-28 华为技术有限公司 Method, device and system for machine type communication (mtc) terminal communicating with network through gateway
CN109391940A (en) * 2017-08-02 2019-02-26 华为技术有限公司 A kind of method, equipment and system accessing network
WO2020091281A1 (en) * 2018-11-02 2020-05-07 엘지전자 주식회사 Method and apparatus for performing proxy authentication for access permission by terminal in wireless communication system

Also Published As

Publication number Publication date
CN116567625A (en) 2023-08-08

Similar Documents

Publication Publication Date Title
WO2023116786A1 (en) Registration method and apparatus of internet of things device, communication device, core network device, storage medium and system
WO2023071836A1 (en) Communication method and apparatus
WO2023143418A1 (en) Device authentication method and apparatus, and terminal and network function
WO2023143436A1 (en) Data forwarding method and apparatus, and terminal device and network device
WO2023143411A1 (en) Device authentication methods, apparatus and communication device
WO2024061091A1 (en) Network communication method and apparatus, and network-side device, terminal and medium
WO2024093783A1 (en) Operation execution method and apparatus, terminal and network function
WO2023143554A1 (en) Pin establishment method and device
WO2023131286A1 (en) Resource control method and apparatus, terminal, network side device, and readable storage medium
WO2023143453A1 (en) Direct-connectivity air interface configuration method, and terminal and network-side device
WO2024041469A1 (en) Paging message processing method and apparatus, communication device and readable storage medium
WO2023165480A1 (en) Data transmission method and apparatus, and terminal, device and storage medium
WO2023143450A1 (en) Method for configuring data processing rule, and terminal and network-side device
WO2023143423A1 (en) Information acquisition, storage and reporting method and device, terminal, and network function
WO2023185728A1 (en) Service processing method and apparatus, and terminal, network-side devices and readable storage medium
WO2024041470A1 (en) System information message receiving method, system information message sending method, and terminal and network-side device
WO2022257876A1 (en) Key material processing method, acquisition method, information transmission method, and device
WO2024037409A1 (en) Positioning message transmission methods, terminal and network side device
WO2023208048A1 (en) Cell handover method and apparatus, terminal, and network side device
WO2023143414A1 (en) Data transmission method and apparatus, configuration method and apparatus, and terminal and network-side device
WO2023202631A1 (en) Subscription method and apparatus, and communication device, internet of things device and network element
WO2023143412A1 (en) Ip address assignment method, device, and readable storage medium
WO2024093712A1 (en) Relay communication link processing method, relay communication link configuration method, relay terminal processing method and related device
WO2023109686A1 (en) Parameter configuration method and apparatus, and communication device, storage medium and system
WO2023179595A1 (en) Session channel establishment method and apparatus for non-3gpp device, and device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23746297

Country of ref document: EP

Kind code of ref document: A1