WO2024017124A1 - 设备认证、凭证、标识分配方法、中继设备和网络侧设备 - Google Patents
设备认证、凭证、标识分配方法、中继设备和网络侧设备 Download PDFInfo
- Publication number
- WO2024017124A1 WO2024017124A1 PCT/CN2023/107125 CN2023107125W WO2024017124A1 WO 2024017124 A1 WO2024017124 A1 WO 2024017124A1 CN 2023107125 W CN2023107125 W CN 2023107125W WO 2024017124 A1 WO2024017124 A1 WO 2024017124A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- ncr
- network
- access
- core network
- network device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
Definitions
- This application belongs to the field of communication technology, and specifically relates to a device authentication, voucher, identification distribution method, relay device and network side device.
- the fifth generation mobile communication technology (5G) network plans to introduce a new relay node - Network Controlled Repeater (NC R) to realize network nodes (such as base stations) and The purpose of radio frequency signal forwarding between terminals.
- NCR Network Controlled Repeater
- NCR Network Controlled Repeater
- Embodiments of this application provide a device authentication, voucher, identification distribution method, relay device and network side device to solve the problem that related technologies cannot guarantee that the NCR of the access network is legal and reliable.
- a device authentication method includes: a network side device receiving a network access request of a relay device NCR, where the network access request carries identification information of the NCR; the network side device based on the The identification information authenticates the NCR to obtain an authentication result, where the authentication result is used to determine whether the NCR is allowed to access the network.
- a credential distribution method includes: a first core network device determines an authentication result for NCR; when the authentication result is authentication passed, the first core network device provides the authentication result to the NCR.
- the NCR allocates network access credentials, where the network access credentials are used for the NCR access network.
- an identifier allocation method includes: the second core network device receives the first core network An NCR network access request sent by the device, wherein the network access request is sent when the first core network device determines that the identification information of the network access request does not contain the first identity identifier of the NCR; the third The second core network device verifies whether the NCR is legal based on the identification information, and allocates a first identity to the NCR if the NCR is legal.
- a device authentication method includes: the relay device NCR sends a network access request to the network side device, wherein the network access request carries the identification information of the NCR, and the network access request is used for Request the network side device to authenticate the NCR based on the identification information, and if the NCR authentication is successful, send a network access credential to the NCR; the NCR receives the network access credential sent by the network side device , and access the network based on the network access credentials.
- an equipment authentication device which device includes: a first request receiving module, configured to receive a network access request from a relay device NCR, where the network access request carries identification information of the NCR; an authentication module, Used to authenticate the NCR based on the identification information and obtain an authentication result, where the authentication result is used to determine whether the NCR is allowed to access the network.
- a credential distribution device which device includes: an authentication result determination module for the first core network device to determine the authentication result for NCR; and a credential distribution module for when the authentication result is authentication passed.
- the first core network device allocates a network access credential to the NCR, where the network access credential is used for the NCR to access the network.
- an identity distribution device in a seventh aspect, includes: a second request receiving module, configured to receive an NCR network access request sent by a first core network device, wherein the network access request is the first core network device. Sent when the device determines that the identification information of the network access request does not contain the first identity of the NCR; the identity allocation module is used to verify whether the NCR is legal based on the identification information, and when the NCR is legal In this case, the NCR is assigned a first identity.
- a device authentication device which device includes: a sending module, configured to send a network access request to a network side device, wherein the network access request carries the identification information of the NCR, and the network access request uses Requesting the network side device to authenticate the NCR based on the identification information, and if the NCR authentication is successful, sending network access credentials to the NCR; a receiving module, configured to receive the message sent by the network side device network access credentials, and access the network based on the network access credentials.
- a communication system in a ninth aspect, includes a relay device NCR and a network side device; the NCR is used to send a network access request to the network side device and receive a network access credential sent by the network side device. and access the network based on the network access credentials, wherein the network access request carries the identification information of the NCR, and the network access request is used to request the network side device to authenticate the NCR based on the identification information, And when the NCR authentication is successful, network access credentials are sent to the NCR; the network side device is used to receive the network access request of the relay device NCR, authenticate the NCR based on the identification information, and obtain the authentication As a result, the authentication result is used to determine whether the NCR is allowed to access the network.
- a network side device in a tenth aspect, includes a processor and a memory.
- the memory Store programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in any one of the first aspect, the second aspect, and the third aspect are implemented.
- a relay device including a processor and a memory.
- the memory stores programs or instructions that can be run on the processor.
- the program or instructions are executed by the processor, the following is implemented: The steps of the method described in the fourth aspect.
- a network side device including a processor and a communication interface, wherein the communication interface is used to receive a network access request from a relay device NCR, and the network access request carries identification information of the NCR , the processor is configured to authenticate the NCR based on the identification information and obtain an authentication result, where the authentication result is used to determine whether the NCR is allowed to access the network.
- a communication system including: a relay device NCR and a network side device.
- the NCR can be used to perform the steps of the device authentication method described in the fourth aspect.
- the network side device can be used to perform The steps of the method described in any one of the first aspect, the second aspect and the third aspect.
- a readable storage medium is provided. Programs or instructions are stored on the readable storage medium. When the programs or instructions are executed by a processor, the implementation of the first aspect, the second aspect, the third aspect and The steps of the method described in any one of the fourth aspects.
- a chip in a fifteenth aspect, includes a processor and a communication interface.
- the communication interface is coupled to the processor.
- the processor is used to run programs or instructions to implement the first aspect and the second aspect. The method described in any one of the third aspect, the third aspect and the fourth aspect.
- a computer program/program product is provided, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the first aspect, the The steps of the method described in any one of the second aspect, the third aspect and the fourth aspect.
- the network side device when the NCR initiates a network access request, the network side device authenticates the NCR based on the identification information of the NCR carried in the network access request, and determines whether to allow the NCR to access the network based on the authentication result. Therefore, It can ensure that the NCR accessing the network is legal and reliable.
- Figure 1 is a block diagram of a wireless communication system provided by an embodiment of the present application.
- Figure 2 is a block diagram of a wireless communication system provided by another embodiment of the present application.
- Figure 3 is a schematic interaction flow diagram of a device authentication method provided by an embodiment of the present application.
- Figure 4 is a schematic diagram 1 of an interaction flow of a device authentication method provided by an embodiment of the present application.
- Figure 5 is a schematic diagram 2 of an interaction flow of a device authentication method provided by an embodiment of the present application.
- Figure 6 is a schematic diagram 3 of the interaction flow of a device authentication method provided by an embodiment of the present application.
- Figure 7 is a schematic flowchart of a device authentication method provided by an embodiment of the present application.
- Figure 8 is a schematic flowchart of a voucher distribution method provided by an embodiment of the present application.
- Figure 9 is a schematic flowchart of an identifier allocation method provided by an embodiment of the present application.
- Figure 10 is a schematic flowchart of a device authentication method provided by an embodiment of the present application.
- Figure 11 is a schematic structural diagram of an equipment authentication device provided by an embodiment of the present application.
- Figure 12 is a schematic structural diagram of a voucher distribution device provided by an embodiment of the present application.
- Figure 13 is a schematic structural diagram of an identification distribution device provided by an embodiment of the present application.
- Figure 14 is a schematic structural diagram of an equipment authentication device provided by an embodiment of the present application.
- Figure 15 is a schematic structural diagram of a communication device of the present application.
- Figure 16 is a schematic diagram of the hardware structure of the network side device according to the embodiment of the present application.
- first, second, etc. in the description and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and that "first" and “second” are distinguished objects It is usually one type, and the number of objects is not limited.
- the first object can be one or multiple.
- “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the related objects are in an "or” relationship.
- LTE Long Term Evolution
- LTE-Advanced, LTE-A Long Term Evolution
- LTE-A Long Term Evolution
- CDMA Code Division Multiple Access
- TDMA Time Division Multiple Access
- FDMA Frequency Division Multiple Access
- OFDMA Orthogonal Frequency Division Multiple Access
- SC-FDMA Single-carrier Frequency Division Multiple Access
- NR New Radio
- FIG. 1 shows a block diagram of a wireless communication system to which embodiments of the present application are applicable.
- the wireless communication system includes a terminal 11 and a network side device 12.
- the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a palmtop computer, a netbook, or a super mobile personal computer.
- Tablet Personal Computer Tablet Personal Computer
- laptop computer laptop computer
- PDA Personal Digital Assistant
- PDA Personal Digital Assistant
- wearable devices include: smart watches, smart bracelets, smart headphones , smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc.
- the network side device 12 may include an access network device or a core network device, where the access network device 12 may also be called a radio access network device, a radio access network (Radio Access Network, RAN), a radio access network function or Wireless access network unit.
- the access network device 12 may include a base station, a WLAN access point or a WiFi node, etc.
- the base station may be called a Node B, an evolved Node B (evolved Node B, eNB), an access point, or a Base Transceiver Station (Base Transceiver Station).
- BTS Basic Service Set
- ESS Extended Service Set
- TRP Transmitting Receiving Point
- the base station is not limited to specific technical terms. It should be noted that in the embodiment of this application, only the base station in the NR system is taken as an example. This introduction does not limit the specific type of base station.
- Core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entities (Mobility Management Entity, MME), access mobility management functions (Access and Mobility Management Function, AMF), session management functions (Session Management Function, SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Services Discovery function (Edge Application Server Discovery Function, EASDF), unified data management (Unified Data Management, UDM), unified data warehousing (Unified Data Repository, UDR), home subscriber server (Home Subscriber Server, HSS), centralized network configuration ( Centralized network configuration, CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (Local NEF, or L-NEF), Binding Support Function (Binding Support Function, BSF), application function (Application Function, AF), etc.
- MME mobility management entities
- AMF Access and Mobility Management Function
- SMF Session Management Function
- NCR Network Controlled Repeater
- NCR is also called a smart repeater or signal amplifier. NCR is used to expand the coverage of the cell, including receiving and amplifying the downlink signal from the upstream base station, so that the signal strength reaching the terminal equipment (User Equipment, UE) is increased, and amplifying the uplink signal from the UE, so that the signal strength from the UE to the upstream base station is increased. The strength of the uplink signal increases.
- UE User Equipment
- NCR can receive control from the upstream base station, that is, the base station can control the transmission parameters of NCR, such as NCR switches and transmit beams, etc., to improve the working efficiency of NCR and reduce interference.
- Figure 2 shows the structural block diagram of a communication system containing NCR.
- the communication system includes three network nodes: base station (gNB) 21, NCR 22 and UE 23.
- the NCR includes a terminal module (mobile termination, MT) and a relay module (repeater unit, RU). ), of course it does not rule out that NCR 22 contains a module in MT and RU.
- the MT in the NCR 22 can establish a connection with the upstream base station 21, and the base station 21 exchanges control signaling with the NCR 22 through the MT.
- the base station 21 can indicate the sending/receiving related parameters of the MT/RU of the NCR through the MT.
- NCR 22 forwards the signal sent by the base station 21 to the UE 23.
- the forwarding process includes receiving the signal from the base station 21, amplifying the signal and sending it to the UE 23; in the uplink In the link, NCR 22 forwards the signal sent by UE 23 to base station 21.
- the forwarding process includes receiving the signal from UE 23, amplifying the signal and sending it to base station 21.
- NCR forwards signals
- its receiving antenna provides receiving gain
- its transmitting antenna provides transmitting gain
- its power amplifier provides forwarding signal amplification gain.
- the embodiment of this application proposes a device authentication method.
- the device authentication scheme provided by this application, when an NCR initiates a network access request, the network side device will authenticate the legitimacy of the NCR. If If the authentication is successful (authentication passed), the NCR is allowed to access the network, otherwise the NCR's network access request is rejected, thereby ensuring that the NCR accessing the network is legal and reliable, and preventing illegal NCR from accessing the network, ensuring network security.
- one embodiment of the present application provides a device authentication method, which may include:
- Step 301 NCR 10 sends a network access request to the network side device 20.
- the network access request carries the identification information of NCR 10.
- the identification information of the NCR 10 may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier is different from the first identity identifier, and the first identity identifier may be Including SIM card number, network access permission, etc.
- the identification information of the NCR 10 may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- NCR 10 can initiate a network access request through its own terminal function module (MT).
- MT terminal function module
- Step 302 The network side device 20 authenticates the NCR 10 based on the identification information.
- the network side device 20 authenticates the legality of the NCR 10 based on the identification information. If the authentication is successful (the authentication passes), the NCR 10 is considered to be a legitimate node; if the authentication fails (the authentication does not pass), the NCR 10 is considered to be a legitimate node. NCR 10 is not a legal node, or in other words, NCR 10 is an illegal node.
- the network side device 20 can authenticate the legitimacy of the NCR 10 based on the identification information that uniquely identifies the NCR; in the identification of the NCR 10 If the information includes identification information that can uniquely identify the NCR and NCR indication information, the network side device 20 can first confirm whether the NCR 10 is an NCR node based on the NCR indication information. In the case of confirming that the NCR 10 is an NCR node , and then authenticate the legality of the NCR 10 based on the identification information that uniquely identifies the NCR. It is not difficult to understand that the latter authentication method is more effective.
- Step 303 When the NCR 10 authentication is successful, the network side device 20 sends the network access certificate to the NCR 10.
- Step 304 NCR 10 accesses the network based on the network access credentials.
- Step 305 When the NCR 10 authentication fails, the network side device 20 rejects the network access request of the NCR 10.
- the network side device 20 will authenticate the legitimacy of the NCR 10. If the authentication is successful (authentication passed), the NCR will be allowed. 10 to access the network, otherwise the NCR 10 network access request will be rejected, thereby ensuring that the NCR nodes accessing the network are legal and reliable, and avoiding illegal NCR access to the network, ensuring network security.
- the network side device 20 may include an access network device 201, an NCR authentication node 202 and a first core network device 203.
- This method Can include:
- Step 401 NCR 10 sends a network access request to the access network device 20.
- the network access request carries the identification information of NCR 10.
- the access network device 20 may be a radio access network (Radio Access Network, RAN) device, such as a base station, specifically a gNG.
- RAN Radio Access Network
- Step 402 The access network device 20 forwards the network access request to the NCR authentication node 202.
- the NCR authentication node 202 can be a network node introduced by the operator to specialize in NCR authentication, which is a logical node similar to the AMF; or the NCR authentication node 202 can be an existing network node introduced by the operator with the NCR authentication function.
- the NCR certification node 202 may be, but is not limited to, one of the following nodes:
- the NCR authentication node 202 when the NCR authentication node 202 is a node in the core network, the NCR authentication node 202 can be, but is not limited to, one of the following nodes in the core network:
- Session Management Function SMF
- AMF Access and Mobility Management Function
- Step 403 The NCR authentication node 202 authenticates the NCR 10 based on the identification information of the NCR 10.
- the identification information of the NCR 10 may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier is different from the first identity identifier, and the first identity identifier may be Including SIM card number, network access permission, etc.
- the identification information of the NCR 10 may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- the identification information of the NCR 10 includes the first identity identifier, that is, the identification information that can uniquely identify the NCR 10 is the first identity identifier. Further, the NCR authentication node 202 can authenticate the legitimacy of the NCR 10 based on the first identity identifier.
- the specific authentication method is similar to the following Embodiment 2. The specific authentication process can be obtained with reference to the following Embodiment 2, which will not be described again here.
- Step 404 The NCR authentication node 202 sends the authentication result to the first core network device 203.
- Step 405 When the authentication result is successful, the first core network device 203 allocates network access credentials to the NCR 10 and feeds back the network access credentials to the access network device 201.
- the first core network device 203 refers to the core network device capable of allocating network access credentials for NCR.
- the network access credential is a Temporary Mobile Station Identity (TMSI)
- TMSI Temporary Mobile Station Identity
- the first core network device can be an AMF.
- AMF Access Management Function
- the NCR authentication node 202 is an AMF in the core network
- the first core network device 203 is also an AMF in the core network
- the NCR authentication node 202 and the first core network device 203 are the same network side device.
- Step 406 The access network device 201 sends the network access certificate to the NCR 10.
- the first core network device 203 can also directly feed back the network access credentials to the NCR 10, so that the NCR 10 can access the network based on the network access credentials.
- Step 407 NCR 10 accesses the network based on the network access credentials.
- NCR 10 After NCR 10 receives the 5G-TMSI, it can use the assigned 5G-TMSI to complete the access network process.
- NCR can only access the network if it holds network access credentials, it can be guaranteed that the NCR accessing the network is legal and reliable.
- the device authentication method provided by the embodiment shown in Figure 4 may also include:
- Step 408 When the authentication result is authentication failure, the first core network device 203 feeds back the authentication result to the access network device 201.
- Step 409 The access network device 201 rejects the network access request based on the authentication result.
- the first core network device 203 can also directly feed back the result of the authentication failure to the NCR 10 to reject the network access request of the NCR 10; or, the NCR authentication node 202 can also directly feed back the result of the authentication failure to the NCR 10 to reject the NCR 10 network access request.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the network side device 20 may include an access network device 201, a first core network device 203, and a second core network device 204.
- the method can include:
- Step 501 NCR 10 sends a network access request to the access network device 20.
- the network access request carries the identification information of NCR 10.
- the access network device 20 may be a radio access network (Radio Access Network, RAN) device, such as a base station (gNG).
- RAN Radio Access Network
- gNG base station
- Step 502 The access network device 20 forwards the network access request to the first core network device 203.
- Step 503 The first core network device 203 authenticates the NCR 10 based on the identification information.
- the first core network device 203 may first determine whether the identification information contains the first identity of the NCR 10, and if so, authenticate the NCR 10 based on the first identity, and feed back the authentication result to Access network equipment.
- authenticating the NCR 10 based on the first identity identifier it can be determined whether the NCR 10 is legal based on the correspondence between the pre-stored NCR identifier and the first identity identifier (white list).
- the first identity identifier may be a SIM card number, or other identifiers that can uniquely identify the NCR identity.
- the first core network device 203 refers to a core network device with a first identity recognition capability, such as an AMF.
- Step 504 If the identification information does not include the first identity of the NCR 10 and the NCR 10 authentication fails, the first core network device 203 forwards the network access request to the second core network device 204.
- Step 505 The second core network device 204 verifies whether the NCR 10 is legal based on the identification information, and assigns a first identity to the NCR 10 if the NCR is legal.
- the identification information includes the second identity of the NCR 10
- the second core network device 204 can verify whether the NCR 10 is legal based on the second identity.
- the second identity mark of NCR 10 includes the factory mark of NCR 10.
- Step 506 The second core network device 204 feeds back the first identity assigned to the NCR 10 to the first core network device 203.
- the second core network device 204 refers to a core network device with the first identity configuration capability.
- the second core network device may be a logical node and operation management in the core network (core network, CN).
- core network CN
- OAM Operation Administration and Maintenance
- CN can include many logical nodes.
- Step 507 The first core network device 203 forwards the first identity assigned to the NCR 10 to the access network device 201.
- Step 508 The access network device 201 sends the first identity assigned to the NCR 10 to the NCR 10, so that the NCR 10 is carried in the next network access request, so as to facilitate the authentication of the legitimacy of the NCR 10.
- one embodiment of the present application provides a device authentication method, which may also include:
- Step 509 When the authentication result is successful, the first core network device 203 gives 10 points to NCR. Allocate network access credentials, and feed back the network access credentials to the access network device 201.
- Step 510 The access network device 201 sends the network access voucher to the NCR 10.
- the first core network device 203 can also directly feed back the network access credentials to the NCR 10, so that the NCR 10 can access the network based on the network access credentials.
- NCR can only access the network if it holds network access credentials, it can be guaranteed that the NCR accessing the network is legal and reliable.
- Step 511 NCR 10 accesses the network based on the network access credentials.
- the first core network device 203 can also directly feed back the authentication failure result to the NCR 10 to reject the network access request of the NCR 10.
- the embodiment shown in Figure 5 provides a device authentication method, which may also include: if the second core network device 204 fails to authenticate the NCR 10, the second core network device 204 can pass the authentication failure result via The first core network device 203 sends it to the access network device 201, and the access network device 201 rejects the network access request of the NCR 10 accordingly.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the network side device 20 may include an access network device 201 and a first core network device 203.
- the method may include:
- Step 601 NCR 10 sends a network access request to the access network device 20.
- the network access request carries the identification information of NCR 10.
- the access network device 20 may be a radio access network (Radio Access Network, RAN) device, such as a base station (gNG).
- RAN Radio Access Network
- gNG base station
- Step 602 The access network device 20 authenticates the NCR 10 based on the identification information.
- the identification information of the NCR 10 carried in the network access request may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier and the first identity identifier
- the first identity identifier may include a SIM card number, network access permission, etc.
- the identification information of the NCR 10 may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- Step 603 When the NCR 10 authentication is successful, the access network device forwards the network access request to the first core network device 203.
- Step 604 The first core network device 203 allocates network access credentials to the NCR 10 based on the network access request, and feeds back the network access credentials to the access network device 201.
- Step 605 The access network device 201 sends the network access certificate to the NCR 10.
- Step 606 NCR 10 accesses the network based on the network access credentials.
- NCR can only access the network if it holds network access credentials, it can be guaranteed that the NCR accessing the network is legal and reliable.
- Step 607 When the NCR 10 authentication fails, the access network device 201 rejects the network access request.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the above describes a device authentication method provided by the embodiment of the present application through the interaction between the NCR 10 and the network side device 20.
- the following describes a device provided by the embodiment of the present application from a single side (network side device or relay device). Authentication method is explained. It should be noted that the device authentication method provided by the embodiment of the present application described from one side below corresponds to the device authentication method provided by the embodiment of the present application described in an interactive manner above, so the relevant points can be Cross-reference.
- one embodiment of the present application provides a device authentication method, including:
- Step 701 The network side device receives a network access request from the relay device NCR, where the network access request carries the identification information of the NCR.
- Step 702 The network side device authenticates the NCR based on the identification information and obtains an authentication result, where the authentication result is used to determine whether the NCR is allowed to access the network.
- the NCR when the authentication result is authentication successful, the NCR is allowed to access the network; when the authentication result is authentication failure, the NCR is not allowed to access the network and the network access can be refused. ask.
- a device authentication method is proposed in the embodiment shown in Figure 7.
- the network side device authenticates the NCR based on the identification information of the NCR carried in the network access request, and determines whether to allow it based on the authentication result.
- the NCR is connected to the network, so it can be ensured that the NCR accessing the network is legal and reliable.
- a device authentication method shown in FIG. 7 will be described in detail below through three specific embodiments. These three embodiments correspond to the above three embodiments.
- step 701 may include: the NCR authentication node receives a network access request from the relay device NCR, and the network access request carries the identification information of the NCR;
- step 702 may include: NCR The authentication node authenticates the NCR based on the identification information and obtains an authentication result.
- the NCR authentication node may receive the network access request of the NCR forwarded by the access network device corresponding to the NCR, that is, the network access request is initiated by the NCR to the access network device, and then by The access network device forwards it to the NCR authentication node.
- the access network equipment may be a radio access network (Radio Access Network, RAN) equipment, such as a base station (gNG).
- RAN Radio Access Network
- gNG base station
- the NCR certification node may be one of the following nodes:
- the NCR authentication node is a node in the core network, and the NCR authentication node can be one of the following nodes in the core network:
- Session Management Function SMF
- AMF Access and Mobility Management Function
- the identification information of the NCR carried in the network access request may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier and the first identity The identifiers are different, and the first identity identifier may include a SIM card number, network access permission, etc.
- the identification information of the NCR may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- the identification information of the NCR includes a first identity identifier.
- the NCR authentication node can authenticate the legality of the NCR based on the first identity identifier (such as SIM card number).
- the specific authentication method is similar to the following Embodiment 2. You can refer to the following Embodiment 2 to obtain specific authentication. The process will not be described again here.
- the method shown in Figure 7 may also include: the NCR authentication node forwarding the authentication result to the first core network device, so that the first core network device allocates network access credentials to the NCR, wherein , the network access credential is allocated by the first core network device when the authentication result is successful authentication, and the network access credential is used for the NCR access network.
- the first core network device may send the network access credential assigned to the NCR to the access network device corresponding to the NCR, and then the access network device forwards the network access credential to the NCR. .
- the first core network device may directly send the network access credential assigned to the NCR to the NCR.
- the first core network equipment refers to the core network equipment capable of allocating network access credentials to NCR.
- the network access credential is a Temporary Mobile Station Identity (TMSI)
- TMSI Temporary Mobile Station Identity
- the first core network device can be an AMF.
- AMF Access Management Function
- the first core network device may feed back the authentication result to the access network device, so that the access network device can perform authentication based on the authentication result. Reject the network access request.
- the NCR authentication node when the NCR authentication node is an AMF, the NCR authentication node can directly allocate network access credentials to the NCR when the authentication result is successful, wherein the network access credentials are used for all Describe the NCR access network.
- the NCR authentication node may feed back the authentication result to the access network device, so that the access network device rejects the network access based on the authentication result. ask.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the network side device is the first core network device.
- step 701 may include: the first core network device is receiving Following the network access request of the device NCR, the network access request carries the identification information of the NCR;
- step 702 may include: the first core network device authenticates the NCR based on the identification information, and obtains an authentication result.
- the first core network device may receive the network access request of the NCR forwarded by the access network device corresponding to the NCR, that is, the network access request is initiated by the NCR to the access network device.
- the access network device then forwards it to the first core network device.
- the access network equipment may be a radio access network (Radio Access Network, RAN) equipment, such as a base station (gNG).
- RAN Radio Access Network
- gNG base station
- the first core network device may determine whether the identification information contains the first identity of the NCR, and if so, authenticate the NCR based on the first identity. .
- the method shown in Figure 7 may also include: when the authentication result is successful, the first core network device allocates a network access credential to the NCR and sends it to the NCR, wherein the The network access credentials are used to access the NCR network.
- the first core network device may send the network access credential assigned to the NCR to the access network device corresponding to the NCR, and then the access network device The network device forwards the network access credential to the NCR, or the first core network device may directly send the network access credential assigned to the NCR to the NCR when the authentication result is successful.
- Corresponding access network equipment thereby allowing the NCR to access the network based on the network access credentials.
- NCR can only access the network if it holds network access credentials, it can be guaranteed that the NCR accessing the network is legal and reliable.
- the first core network device refers to the core network device with the first identity identification capability, for example, AMF.
- the method shown in Figure 7 may also include:
- the first core network device may also forward the network access request to the second core network device, where the identification information is used to The second core network device verifies whether the NCR is legal, and allocates a first identity to the NCR if the NCR is legal;
- the first core network device receives the first identity assigned to the NCR by the second core network device, and sends the first identity assigned to the NCR to the NCR, wherein the first The identity identifier is used to carry the NCR in the next network access request.
- the identification information includes a second identity of the NCR, wherein the second core network device can verify whether the NCR is legal based on the second identity.
- the second core network device refers to the core network device with the first identity configuration capability.
- the second core network device may be one of the following devices:
- Mobility Management Entity MME Mobility Management Entity MME
- the first core network device is an access mobility management function AMF, and the method further includes:
- the first core network device verifies whether the NCR is legal based on the second identification information in the identification information, and checks if the NCR is legal. In this case, assign a first identity identifier to the NCR;
- the first core network device sends the first identity identifier assigned to the NCR to the NCR, where the first identity identifier is used by the NCR to carry in the next network access request.
- the second identity of the NCR includes the factory identification of the NCR.
- the first identity identifier includes a SIM card number.
- the method shown in Figure 7 may also include: when the authentication result is authentication failure, the first core network device may feed back the information to the access network device corresponding to the NCR. The authentication result, so that the access network device rejects the network access request based on the authentication result; or, in the case where the second core network device fails to verify the NCR, the second core network device The result of the authentication failure may be sent to the access network device via the first core network device, and the access network device rejects the NCR's network access request accordingly.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the network side device is an access network device.
- the access network device 20 may be a radio access network (Radio Access Network, RAN) device, such as a base station (gNG).
- RAN Radio Access Network
- step 701 may include: the access network device receiving the network access request sent by the NCR;
- step 702 may include: the access network device authenticating the NCR based on the identification information.
- the identification information of the NCR carried in the network access request may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier and the first identity The identifiers are different, and the first identity identifier may include a SIM card number, network access permission, etc.
- the identification information of the NCR may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- the method shown in Figure 7 may also include:
- the access network device sends the network access request to the first core network device, where the identification information is used by the first core network device to send the NCR Assign network access credentials;
- the access network device receives the network access credential sent by the first core network device and sends the network access credential to the NCR, where the network access credential is used for the NCR access network.
- NCR can only access the network if it holds network access credentials, it can be guaranteed that the NCR accessing the network is legal and reliable.
- the first core network device is the access mobility management function AMF in the core network.
- the method shown in Figure 7 may also include:
- the access network device rejects the network access request.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- a certificate distribution method applied to the first core network device will be described below.
- an embodiment of the present application provides a method for allocating credentials, which may include:
- Step 801 The first core network device determines the authentication result for NCR.
- Step 802 When the authentication result is authentication passed, the first core network device allocates a network access credential to the NCR, where the network access credential is used for the NCR to access the network.
- the NCR authentication node After NCR initiates a network access request, the NCR authentication node authenticates NCR.
- the above-mentioned step 801 may include: the first core network device receives an authentication result for the NCR sent by an NCR authentication node, wherein the authentication result is included in the network access request of the NCR authentication node based on the NCR.
- the carried identification information of the NCR is obtained by authenticating the NCR.
- the above step 802 may include: the first core network device allocates a network access credential to the NCR, and sends the network access credential to the NCR.
- the first core network device may directly send the network access credential to the NCR, or may first send the network access credential to the access network device corresponding to the NCR, and then the access network The device sends the network access credentials to the NCR.
- the method shown in Figure 8 may also include: when the authentication result is authentication failure, the first core network device feeds back the authentication result to the access network device corresponding to the NCR, so as to The access network device is caused to reject the network access request based on the authentication result.
- the first core network device After the NCR initiates a network access request, the first core network device itself authenticates the NCR.
- the above-mentioned step 801 may include: the first core network device receives a network access request of the NCR, wherein the network access request carries the identification information of the NCR; the first core network device determines that the identification letter Whether the first identity identifier of the NCR is included in the information, and if it is included, the NCR is authenticated based on the first identity identifier, and the authentication result of the NCR is obtained.
- the method shown in Figure 8 may also include: if the identification information does not include the first identity of the NCR, the first core network device forwards the network access request to the second Core network equipment, wherein the identification information is used by the second core network equipment to verify whether the NCR is legal, and if the NCR is legal, allocate a first identity to the NCR;
- the first core network device receives the first identity assigned to the NCR by the second core network device, and sends the first identity assigned to the NCR to the NCR, wherein the first The identity identifier is used to carry the NCR in the next network access request.
- the first core network device is an access mobility management function AMF, and the method further includes:
- the first core network device verifies whether the NCR is legal based on the identification information, and if the NCR is legal, the first core network device Assign a first identity;
- the first core network device sends the first identity identifier assigned to the NCR to the NCR, where the first identity identifier is used by the NCR to carry in the next network access request.
- the identification information includes the second identity of the NCR.
- the second identity of the NCR includes the factory identification of the NCR.
- the second core network device includes one of the following:
- Mobility Management Entity MME Mobility Management Entity MME
- the first identity identifier includes a SIM card number.
- the access network device corresponding to the NCR authenticates the NCR.
- the above-mentioned step 801 may include: the first core network device receiving the authentication result of the NCR sent by the access network device corresponding to the NCR, wherein the authentication result is the authentication result of the access network device based on the The identification information of the NCR carried in the network access request of the NCR is obtained by authenticating the NCR.
- the method shown in Figure 8 may also include: when the authentication result is authentication failure, the first core network device feeds back the authentication result to the access network device corresponding to the NCR, wherein , the authentication result is used by the access network device to reject the network access request.
- the first core network device may be an AMF
- the access network device may be a wireless access network device
- the network access credential may be TMSI
- the embodiment of the present application also proposes an identifier allocation method, which will be described below.
- an identity allocation method provided by one embodiment of the present application may include:
- Step 901 The second core network device receives an NCR network access request sent by the first core network device, where the network access request is when the first core network device determines that the identification information of the network access request does not contain the NCR. Sent without first identification.
- Step 902 The second core network device verifies whether the NCR is legal based on the identification information, and allocates a first identity to the NCR if the NCR is legal.
- the identification information includes the second identity of the NCR
- step 902 may specifically include: the second core network device verifying whether the NCR is legal based on the second identity.
- the second identity of the NCR includes the factory identification of the NCR.
- step 902 may specifically include: when the NCR is legal, the second core network device allocates a first identity to the NCR and sends it to the NCR, so that the NCR is carried when the NCR enters the network next time. Requesting.
- the first core network device may be an AMF
- the access network device may be a wireless access network device
- the network access credential may be TMSI
- the second core network equipment may include one of the following:
- Mobility Management Entity MME Mobility Management Entity MME
- the first identity identifier includes a SIM card number.
- NCR can carry its own first identity in subsequent network access requests to authenticate its own legitimacy.
- the following describes a device authentication method applied to the relay device side.
- one embodiment of the present application provides a device authentication method, including:
- Step 1001 The relay device NCR sends a network access request to the network side device, where the network access request carries the identification information of the NCR, and the network access request is used to request the network side device to perform a network access request based on the identification information.
- the NCR performs authentication, and if the NCR authentication is successful, network access credentials are sent to the NCR.
- Step 1002 The NCR receives the network access voucher sent by the network side device, and accesses the network based on the network access voucher.
- the NCR when the NCR initiates a network access request, it will send a network access request to the network side device, so that the network side device can authenticate the NCR based on the identification information of the NCR carried in the network access request.
- the NCR performs authentication, and if the NCR authentication is successful, network access credentials are sent to the NCR, so that the NCR can access the network based on the network access credentials instead of randomly accessing the network, thus ensuring access to the network.
- the NCR is legal and reliable, or in other words, illegal NCR can be prevented from accessing the network, thereby ensuring network security.
- a device authentication method shown in Figure 10 is also described in detail below through three specific embodiments. These three embodiments correspond to the three embodiments shown in Figures 4, 5 and 6 above. .
- the network side equipment includes access network equipment, NCR authentication node and first core network equipment.
- Step 1001 may specifically include: the NCR sending a network access request to the access network device, so that the access network device forwards the network access request to the NCR authentication node, where the network access request is Requesting the NCR authentication node to authenticate the NCR based on the identification information, and sending the NCR authentication result to the first core network device, so that the first core network device performs the authentication If the authentication result is successful, network access credentials are assigned to the NCR, and the network access credentials are fed back to the access network device.
- step 1002 may specifically include: the NCR receiving the network access voucher sent by the access network device.
- the network side device includes an access network device and an NCR authentication node, and the NCR authentication node is an AMF.
- Step 1001 may specifically include: the NCR sending a network access request to the access network device, so that the access network device forwards the network access request to the NCR authentication node, where the network access request is Requesting the NCR authentication node to authenticate the NCR based on the identification information, and if the authentication result is successful, allocate network access credentials to the NCR, and feed back the network access credentials to the NCR Access network equipment;
- Step 1002 may specifically include: the NCR receiving the network access voucher sent by the access network device.
- the NCR certification node may be one of the following nodes:
- the NCR authentication node is a node in the core network, and the NCR authentication node can be one of the following nodes in the core network:
- Session Management Function SMF
- AMF Access and Mobility Management Function
- the identification information of the NCR carried in the network access request may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier and the first identity The identifiers are different, and the first identity identifier may include a SIM card number, network access permission, etc.
- the identification information of the NCR may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- the identification information of the NCR includes a first identity identifier.
- the NCR authentication node can authenticate the legality of the NCR based on the first identity identifier.
- the specific authentication method is similar to the following Embodiment 2. The specific authentication process can be obtained with reference to the following Embodiment 2, which will not be discussed here. Repeat.
- the first core network equipment refers to the core network equipment capable of allocating network access credentials to NCR.
- the network access credential is a Temporary Mobile Station Identity (TMSI)
- TMSI Temporary Mobile Station Identity
- the first core network device can be an AMF.
- AMF Access Management Function
- the NCR authentication node is an AMF in the core network
- the first core network device is also an AMF in the core network
- the NCR authentication node and the first core network device are on the same network side. equipment.
- the network side equipment includes access network equipment and first core network equipment.
- step 1001 may specifically include: the NCR sending a network access request to the access network device, so that the access network device forwards the network access request to the first core network device, wherein, The network access request is used to request the first core network device to authenticate the NCR based on the identification information, and in the authentication result If the authentication is successful, network access credentials are assigned to the NCR, and the network access credentials are fed back to the access network device.
- step 1002 may specifically include: the NCR receiving the network access voucher sent by the access network device.
- the first core network device refers to the core network device with the first identity identification capability, for example, AMF.
- the network side device also includes a second core network device.
- the method shown in Figure 10 may also include: the NCR receiving a first identity sent by the access network device, wherein the first The identity identifier is assigned to the NCR by the second core network device when the first core network determines that the identification information does not contain the first identity identifier, and the first identity identifier is The second core network device is assigned by verifying that the NCR is legal based on the identification information.
- the identification information includes a second identity of the NCR, wherein the second core network device can verify whether the NCR is legal based on the second identity.
- the second core network device refers to the core network device with the first identity configuration capability.
- the second core network device can be one of the following devices:
- Mobility Management Entity MME Mobility Management Entity MME
- the first core network device accesses the mobility management function AMF, and the method further includes:
- the NCR receives the first identity identifier sent by the access network device, wherein the first identity identifier is allocated when the first core network determines that the identification information does not contain the first identity identifier. to the NCR, and the first identity identifier is assigned by the first core network device when the first core network device verifies that the NCR is legitimate based on the second identification information in the identification information.
- the network side equipment includes access network equipment and first core network equipment.
- Step 1001 may specifically include: the NCR sending a network access request to the access network device, where the network access request is used to request the access network device to authenticate the NCR based on the identification information, and Send the authentication result of the NCR to the first core network device, so that when the authentication result is successful, the first core network device allocates a network access credential to the NCR and sends the The network access credentials are fed back to the access network device.
- step 1002 may specifically include: the NCR receiving the network access voucher sent by the access network device.
- the first core network device is the access mobility management function AMF in the core network; the access network device may be a wireless access network device; the identification information also includes NCR indication information, and the NCR indication information It is used to indicate that the NCR is an NCR node; the network access certificate is a temporary mobile station identifier TMSI.
- the execution subject may be a device authentication device.
- the device authentication device executing the device authentication method is used as an example to illustrate the device authentication device provided by the embodiment of this application.
- a certificate distribution device provided by an embodiment of the present application corresponds to a device authentication method provided by an embodiment of the present application
- a certificate distribution device provided by an embodiment of the present application corresponds to a certificate distribution method provided by an embodiment of the present application.
- an identification distribution device provided by the embodiment of the present application corresponds to an identification distribution method provided by the embodiment of the present application. Therefore, the description of the device provided by the embodiment of the present application is relatively brief. For details, please refer to the above method embodiment. Part of the introduction.
- the device 1100 may include: a first request receiving module 1101 and an authentication module 1102.
- the first request receiving module 1101 is configured to receive a network access request from the relay device NCR, where the network access request carries the identification information of the NCR.
- the authentication module 1102 is configured to authenticate the NCR based on the identification information and obtain an authentication result, where the authentication result is used to determine whether the NCR is allowed to access the network.
- the NCR when the authentication result is authentication successful, the NCR is allowed to access the network; when the authentication result is authentication failure, the NCR is not allowed to access the network and the network access can be refused. ask.
- the device authentication device 1100 proposed in the embodiment shown in Figure 11 can be applied to network side equipment.
- the network side equipment will authenticate the NCR based on the identification information of the NCR carried in the network access request. Authentication is performed, and based on the authentication result, it is determined whether to allow the NCR to access the network, so it can be ensured that the NCR accessing the network is legal and reliable.
- the device authentication device 1100 shown in FIG. 11 will be described in detail below through three specific embodiments.
- the network side device is an NCR authentication node.
- the first request receiving module 1101 may be configured to: receive the network access request of the NCR forwarded by the access network device corresponding to the NCR.
- the access network device may be a Radio Access Network (RAN) Equipment such as base stations (gNG).
- RAN Radio Access Network
- gNG base stations
- the device shown in Figure 11 may also include: a result forwarding module, configured for the NCR authentication node to send the authentication result to the first core network device, so that the first core network device is the NCR allocates network access credentials, wherein the network access credentials are allocated by the first core network device when the authentication result is successful authentication, and the network access credentials are used for the NCR access network.
- a result forwarding module configured for the NCR authentication node to send the authentication result to the first core network device, so that the first core network device is the NCR allocates network access credentials, wherein the network access credentials are allocated by the first core network device when the authentication result is successful authentication, and the network access credentials are used for the NCR access network.
- the NCR authentication node when the NCR authentication node is an AMF, the NCR authentication node can directly allocate network access credentials to the NCR when the authentication result is successful, wherein the network access credentials are used for all Describe the NCR access network.
- the NCR authentication node may feed back the authentication result to the access network device, so that the access network device rejects the network access based on the authentication result. ask.
- the network side device is the first core network device.
- the first request receiving module 1101 may be configured to: receive the network access request of the NCR forwarded by the access network device corresponding to the NCR.
- the authentication module 1102 may be configured to determine whether the identification information contains the first identity of the NCR, and if so, authenticate the NCR based on the first identity.
- the device 1100 shown in Figure 11 may also include: a credential allocation module, configured to allocate a network access credential to the NCR when the authentication result is successful, wherein the network access credential is used for the NCR access network.
- a credential allocation module configured to allocate a network access credential to the NCR when the authentication result is successful, wherein the network access credential is used for the NCR access network.
- NCR can only access the network if it holds network access credentials, it can be guaranteed that the NCR accessing the network is legal and reliable.
- the first core network device refers to the core network device with the first identity identification capability, for example, AMF.
- the device 1100 shown in Figure 11 may also include: a request forwarding module and an identification receiving module.
- a request forwarding module configured to forward the network access request to the second core network device, wherein the identification information is used by the second core network device to verify whether the NCR is legal, and when the NCR is legal In this case, the NCR is assigned a first identity.
- An identity receiving module configured to receive the first identity assigned to the NCR by the second core network device, and send the first identity assigned to the NCR to the NCR, where the first identity
- the identifier is used for the NCR to be carried in the next network access request.
- the identification information includes a second identity of the NCR, wherein the second core network device may be used to verify whether the NCR is legal based on the second identity.
- the second identity of the NCR includes the factory identification of the NCR.
- the second core network equipment includes one of the following:
- Mobility Management Entity MME Mobility Management Entity MME
- the first identity identifier includes a SIM card number.
- the first core network device is an access mobility management function AMF.
- the device 1100 shown in Figure 11 may also include: an identity allocation module and an identity sending module.
- An identification allocation module configured to verify whether the NCR is legal based on the second identification information in the identification information if the identification information does not contain the first identity identification of the NCR, and if the NCR is legal, Next, assign a first identity to the NCR.
- An identity sending module configured to send the first identity assigned to the NCR to the NCR, where the first identity is used for the NCR to carry in the next network access request.
- the apparatus 1100 shown in Figure 11 may also include: a failure result feedback module, configured to, when the authentication result is an authentication failure, the first core network device report to the access network corresponding to the NCR The device feeds back the authentication result, where the authentication result is used by the access network device to reject the network access request.
- a failure result feedback module configured to, when the authentication result is an authentication failure, the first core network device report to the access network corresponding to the NCR The device feeds back the authentication result, where the authentication result is used by the access network device to reject the network access request.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the network side device is an access network device.
- the access network device 20 may be a radio access network (Radio Access Network, RAN) device, such as a base station (gNG).
- RAN Radio Access Network
- gNG base station
- the device 1100 shown in Figure 11 may also include: a request forwarding module and a voucher receiving module.
- Request forwarding module configured to send the network access request to the first core network device by the access network device when the authentication result is successful, wherein the identification information is used for the third core network device.
- a core network device allocates network access credentials to the NCR.
- a credential receiving module configured for the access network device to receive the network access credential sent by the first core network device, and send the network access credential to the NCR, where the network access credential is used for the NCR Access the network.
- the first core network device may be an AMF; the identification information may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node; the interface
- the network access device is a wireless access network device; the network access certificate may be a temporary mobile station identifier TMSI.
- the device 1100 shown in Figure 11 may also include: an access denial module, configured to deny the network access request when the authentication result is authentication failure.
- an access denial module configured to deny the network access request when the authentication result is authentication failure.
- the access network device will refuse the NCR to access the network, thereby preventing illegal NCR from accessing the network and ensuring network security.
- the device authentication device provided in Figure 11 can implement the device authentication method shown in Figure 7 and can achieve the same technical effect. Therefore, the description of the device authentication device provided in Figure 11 is relatively simple here.
- the device 1200 may include: an authentication result determination module 1201 and a voucher distribution module 1202.
- the authentication result determination module 1201 is used to determine the authentication result for NCR.
- the credential allocation module 1202 is configured to, when the authentication result is authentication passed, the first core network device allocate a network access credential to the NCR, where the network access credential is used for the NCR access network.
- the NCR authentication node After NCR initiates a network access request, the NCR authentication node authenticates NCR.
- the above-mentioned authentication result determination module 1201 may be configured to: receive the authentication result for the NCR sent by the NCR authentication node, wherein the authentication result is based on the NCR authentication node carried in the network access request of the NCR.
- the identification information of the NCR is obtained by authenticating the NCR.
- the above-mentioned voucher allocation module 1202 may be used to allocate network access vouchers to the NCR and send the network access vouchers to the NCR.
- the apparatus shown in Figure 12 may also include: a result feedback module, configured to feed back the authentication result to the access network device corresponding to the NCR when the authentication result is an authentication failure, so that The access network device rejects the network access request based on the authentication result.
- a result feedback module configured to feed back the authentication result to the access network device corresponding to the NCR when the authentication result is an authentication failure, so that The access network device rejects the network access request based on the authentication result.
- the first core network device After the NCR initiates a network access request, the first core network device itself authenticates the NCR.
- the above-mentioned authentication result determination module 1201 may be configured to: receive a network access request of the NCR, wherein the network access request carries the identification information of the NCR; determine whether the identification information contains the first NCR If the identity identifier is included, the NCR is authenticated based on the first identity identifier, and the authentication result of the NCR is obtained.
- the device 1200 may also include: a request forwarding module and an identification receiving module.
- a request forwarding module configured to forward the network access request to the second core network device if the identification information does not include the first identity of the NCR, wherein the identification information is used for the third core network device.
- the second core network device verifies whether the NCR is legal, and allocates a first identity to the NCR if the NCR is legal.
- An identity receiving module configured to receive the first identity assigned to the NCR by the second core network device, and send the first identity assigned to the NCR to the NCR, where the first identity
- the identifier is used for the NCR to be carried in the next network access request.
- the first core network device is an access mobility management function AMF
- the apparatus 1200 may also include: an identity allocation module and an identity sending module.
- An identification allocation module configured to verify whether the NCR is legal based on the identification information if the identification information does not include the first identity identification of the NCR, and allocate the NCR to the NCR if the NCR is legal.
- the first identity mark configured to verify whether the NCR is legal based on the identification information if the identification information does not include the first identity identification of the NCR, and allocate the NCR to the NCR if the NCR is legal. The first identity mark.
- An identity sending module configured to send the first identity assigned to the NCR to the NCR, where the first identity is used for the NCR to carry in the next network access request.
- the identification information includes the second identity of the NCR.
- the second identity of the NCR includes the factory identification of the NCR.
- the second core network device includes one of the following:
- Mobility Management Entity MME Mobility Management Entity MME
- the first identity identifier includes a SIM card number.
- the access network device corresponding to the NCR authenticates the NCR.
- the above-mentioned authentication result determination module 1201 may be configured to: the first core network device receives the authentication result of the NCR sent by the access network device corresponding to the NCR, wherein the authentication result is the The device authenticates the NCR based on the identification information of the NCR carried in the NCR's network access request.
- the apparatus 1200 may also include: a result feedback module, configured to feed back the authentication result to the access network device corresponding to the NCR by the first core network device when the authentication result is authentication failure. , wherein the authentication result is used by the access network device to reject the network access request.
- a result feedback module configured to feed back the authentication result to the access network device corresponding to the NCR by the first core network device when the authentication result is authentication failure. , wherein the authentication result is used by the access network device to reject the network access request.
- the first core network device may be an AMF
- the access network device may be a wireless access network device
- the network access credential may be TMSI
- the voucher distribution device provided in Figure 12 can implement the voucher distribution method shown in Figure 8 and can achieve the same technical effect. Therefore, the description of the voucher distribution device provided in Figure 12 is relatively simple here.
- the device 1300 may include: a second request receiving module 1301 and an identity distribution module 1302.
- the second request receiving module 1301 is configured to receive an NCR network access request sent by the first core network device, where the network access request is when the first core network device determines that the identification information of the network access request does not contain the NCR. Sent without the first identification.
- the identity allocation module 1302 is configured to verify whether the NCR is legal based on the identification information, and allocate a first identity to the NCR if the NCR is legal.
- the identification information includes the second identity of the NCR
- the identity allocation module 1302 may be configured to verify whether the NCR is legal based on the second identity.
- the identity allocation module 1302 can be specifically configured to: when the NCR is legal, the second core network device allocates a first identity to the NCR and sends it to the NCR, so that the NCR is carried in the next A network access request is in progress.
- the first core network device may be an AMF
- the access network device may be a wireless access network device
- the network access credential may be TMSI
- the second core network equipment may include one of the following:
- Mobility Management Entity MME Mobility Management Entity MME
- the first identity identifier may be a SIM card number.
- NCR can carry its own first identity in subsequent network access requests to authenticate its own legitimacy.
- the identification distribution device provided in Figure 13 can implement the identification distribution method shown in Figure 9 and can achieve the same technical effect. Therefore, the description of the identification distribution device provided in Figure 13 here is relatively simple.
- the device 1400 may include a sending module 1401 and a receiving module 1402.
- the sending module 1401 is configured to send a network access request to a network side device, where the network access request carries the identification information of the NCR, and the network access request is used to request the network side device to perform a request to the network side device based on the identification information.
- the NCR performs authentication, and if the NCR authentication is successful, sends the network access credentials to the NCR.
- the receiving module 1402 is configured to receive the network access voucher sent by the network side device, and access the network based on the network access voucher.
- the device authentication device proposed in the embodiment of this application will send a network access request to the network side device when the NCR initiates a network access request, so that the network side device authenticates the NCR based on the identification information carried in the network access request.
- the NCR performs authentication and, if the NCR authentication is successful, sends a network access credential to the NCR, so that the NCR can access the network based on the network access credential instead of randomly accessing the network. Therefore, access to the network can be guaranteed.
- NCR is legal and reliable, or in other words, it can prevent illegal NCR from accessing the network, thereby ensuring network security.
- the device authentication device shown in Figure 14 will be described in detail below through three specific embodiments.
- the network side equipment includes access network equipment, NCR authentication node and first core network equipment.
- the sending module 1401 may be specifically configured to: send a network access request to the access network device, so that the access network device forwards the network access request to the NCR authentication node, where the network access request is used to request
- the NCR authentication node authenticates the NCR based on the identification information, and sends the NCR authentication result to the first core network device, so that the first core network device performs the authentication when the authentication result is If the authentication is successful, network access credentials are assigned to the NCR, and the network access credentials are fed back to the access network device.
- the receiving module 1402 may be specifically configured to: receive the network access voucher sent by the access network device.
- the network side device includes an access network device and an NCR authentication node, and the NCR authentication node is an AMF.
- the sending module 1401 can be specifically configured to: the NCR sends a network access request to the access network device, so that The access network device forwards the network access request to the NCR authentication node, where the network access request is used to request the NCR authentication node to authenticate the NCR based on the identification information, and in the authentication If the authentication result is successful, allocate network access credentials to the NCR, and feed back the network access credentials to the access network device;
- the receiving module 1402 may be specifically configured to: the NCR receive the network access voucher sent by the access network device.
- the NCR certification node may be one of the following nodes:
- the NCR authentication node is a node in the core network, and the NCR authentication node can be one of the following nodes in the core network:
- Session Management Function SMF
- AMF Access and Mobility Management Function
- the identification information of the NCR carried in the network access request may include at least one of a first identity identifier and a second identity identifier that can uniquely identify the NCR, wherein the second identity identifier and the first identity The identifiers are different, and the first identity identifier may include a SIM card number, network access permission, etc.
- the identification information of the NCR may also include NCR indication information, and the NCR indication information is used to indicate that the NCR is an NCR node.
- the identification information of the NCR includes a first identity identifier, that is, the identification information that can uniquely identify the NCR is the first identity identifier. Further, the NCR authentication node can authenticate the legality of the NCR based on the first identity identifier.
- the specific authentication method is similar to the following Embodiment 2. The specific authentication process can be obtained with reference to the following Embodiment 2, which will not be discussed here. Repeat.
- the first core network equipment refers to the core network equipment capable of allocating network access credentials to NCR.
- the network access credential is a Temporary Mobile Station Identity (TMSI)
- TMSI Temporary Mobile Station Identity
- the first core network device can be an AMF.
- AMF Access Management Function
- the NCR authentication node is an AMF in the core network
- the first core network device is also an AMF in the core network
- the NCR authentication node and the first core network device are on the same network side. equipment.
- the network side equipment includes access network equipment and first core network equipment.
- the sending module 1401 may be configured to: send a network access request to the access network device, so that the access network device forwards the network access request to the first core network device, where the network access request is Requesting the first core network device to authenticate the NCR based on the identification information, and if the authentication result is successful, allocate network access credentials to the NCR, and feed back the network access credentials to The access network equipment.
- the receiving module 1402 may be specifically configured to: receive the network access voucher sent by the access network device.
- the first core network device 203 refers to a core network device with the first identity recognition capability, such as an AMF.
- the network side device also includes a second core network device
- the apparatus 1400 may also include: an identity receiving module, configured to receive a first identity identity sent by the access network device, wherein the first identity The identifier is assigned to the NCR by the second core network device when the first core network determines that the identification information does not contain the first identity identifier, and the first identity identifier is the The second core network device is allocated after verifying that the NCR is legal based on the identification information.
- the identification information includes a second identity of the NCR, wherein the second core network device is specifically configured to verify whether the NCR is legal based on the second identity.
- the second core network device 204 refers to the core network device with the first identity configuration capability
- the second core network device can be one of the following devices:
- Mobility Management Entity MME Mobility Management Entity MME
- the network side equipment includes access network equipment and first core network equipment.
- the sending module 1401 may be specifically configured to: send a network access request to the access network device, where the network access request is used to request the access network device to authenticate the NCR based on the identification information, and authenticate the NCR.
- the authentication result of the NCR is sent to the first core network device, so that the first core network device allocates a network access credential to the NCR and sends the network access credential when the authentication result is successful. Feedback to the access network equipment.
- the receiving module 1402 may be specifically configured to: receive the network access voucher sent by the access network device.
- the first core network device is the access mobility management function AMF in the core network.
- the access network equipment For wireless access network equipment.
- the device authentication device 1400 in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
- the electronic device may be a terminal or other devices other than the terminal.
- terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
- NAS Network Attached Storage
- the device authentication device 1400 provided by the embodiment of this application can implement each process implemented by the method embodiment in Figure 10 and achieve the same technical effect. To avoid duplication, the details will not be described here.
- this embodiment of the present application also provides a communication device 1500, which includes a processor 1501 and a memory 1502.
- the memory 1502 stores programs or instructions that can be run on the processor 1501, such as , when the communication device 1500 is a relay device, when the program or instruction is executed by the processor 1501, each step of the device authentication method embodiment shown in FIG. 10 is implemented, and the same technical effect can be achieved.
- the communication device 1500 is a network-side device, when the program or instruction is executed by the processor 1501, the device authentication method shown in Figure 7, the voucher distribution method shown in Figure 8 or the identity distribution method shown in Figure 9 are implemented. Each step can achieve the same technical effect. To avoid repetition, we will not repeat them here.
- Embodiments of the present application also provide a network-side device, including a processor and a communication interface.
- the communication interface is used to receive a network access request from a relay device NCR.
- the network access request carries the identification information of the NCR.
- the processor uses The NCR is authenticated based on the identification information to obtain an authentication result, where the authentication result is used to determine whether the NCR is allowed to access the network.
- This network-side device embodiment corresponds to the above-mentioned network-side device method embodiment.
- Each implementation process and implementation manner of the above-mentioned method embodiment can be applied to this network-side device embodiment, and can achieve the same technical effect.
- the embodiment of the present application also provides a network side device.
- the network side device 1600 includes: an antenna 161 , a radio frequency device 162 , a baseband device 163 , a processor 164 and a memory 165 .
- the antenna 161 is connected to the radio frequency device 162 .
- the radio frequency device 162 receives information through the antenna 161 and sends the received information to the baseband device 163 for processing.
- the baseband device 163 processes the information to be sent and sends it to the radio frequency device 162.
- the radio frequency device 162 processes the received information and then sends it out through the antenna 161.
- the method performed by the network side device in the above embodiment can be implemented in the baseband device 163, which includes a baseband processor.
- the baseband device 163 may include, for example, at least one baseband board on which multiple chips are disposed, as shown in FIG. Program to perform the network device operations shown in the above method embodiments.
- the network side device may also include a network interface 166, which is, for example, a common public radio interface (CPRI).
- a network interface 166 which is, for example, a common public radio interface (CPRI).
- CPRI common public radio interface
- the network side device 1600 in this embodiment of the present invention also includes: instructions or programs stored in the memory 165 and executable on the processor 164.
- the processor 164 calls the instructions or programs in the memory 165 to execute Figures 7 and 8
- the method shown in any of the figures in Figure 9 can achieve the same technical effect. To avoid repetition, it will not be described again here.
- Embodiments of the present application also provide a readable storage medium, in which a program or instructions are stored on the readable storage medium.
- a program or instructions are stored on the readable storage medium.
- the above-mentioned device authentication method, voucher distribution method or identification distribution method embodiments are implemented.
- Each process can achieve the same technical effect. To avoid repetition, we will not go into details here.
- the processor is the processor in the terminal described in the above embodiment.
- the readable storage medium includes computer readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disk or optical disk, etc.
- An embodiment of the present application further provides a chip.
- the chip includes a processor and a communication interface.
- the communication interface is coupled to the processor.
- the processor is used to run programs or instructions to implement the above device authentication method and voucher distribution.
- Each process of the method or identification allocation method embodiment can achieve the same technical effect. To avoid duplication, it will not be described again here.
- chips mentioned in the embodiments of this application may also be called system-on-chip, system-on-a-chip, system-on-chip or system-on-chip, etc.
- Embodiments of the present application further provide a computer program/program product.
- the computer program/program product is stored in a non-volatile storage medium.
- the computer program/program product is executed by at least one processor to implement the above device.
- Each process of the authentication method, credential distribution method or identity distribution method embodiment can achieve the same technical effect. To avoid duplication, it will not be described again here.
- Embodiments of the present application also provide a communication system, including: a relay device and a network side device.
- the relay device can be used to perform the steps of the device authentication method shown in Figure 10 above.
- the network side device can be used to perform The steps of the device authentication method are shown in Figure 7 above.
- the methods of the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is better. implementation.
- the technical solution of the present application can be embodied in the form of a computer software product that is essentially or contributes to the existing technology.
- the computer software product is stored in a storage medium (such as ROM/RAM, disk , CD), including several instructions to cause a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of this application.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Power Engineering (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请公开了一种设备认证、凭证、标识分配方法、中继设备和网络侧设备,属于通信技术领域,本申请实施例的设备认证方法包括:网络侧设备接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;所述网络侧设备基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
Description
交叉引用
本申请要求在2022年07月19日提交中国专利局、申请号为202210849257.9、名称为“设备认证、凭证、标识分配方法、中继设备和网络侧设备”的中国专利申请的优先权,该申请的全部内容通过引用结合在本申请中。
本申请属于通信技术领域,具体涉及一种设备认证、凭证、标识分配方法、中继设备和网络侧设备。
第五代移动通信技术(5th Generation Mobile Communication Technology,简称5G)网络计划引入新的中继节点——网络控制中继器(Network Controlled Repeater,简称NC R),以实现网络节点(如基站)和终端之间的射频信号转发的目的。使用NCR进行射频信号转发之前,需要确保NCR是一个可靠合法的节点。但是,目前没有有效的NCR认证方法保证接入网络的NCR是合法可靠的。
发明内容
本申请实施例提供一种设备认证、凭证、标识分配方法、中继设备和网络侧设备,以解决相关技术无法保证接入网络的NCR合法可靠的问题。
第一方面,提供了一种设备认证方法,该方法包括:网络侧设备接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;所述网络侧设备基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
第二方面,提供了一种凭证分配方法,该方法包括:第一核心网设备确定针对NCR的认证结果;在所述认证结果为认证通过的情况下,所述第一核心网设备给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
第三方面,提供了一种标识分配方法,该方法包括:第二核心网设备接收第一核心网
设备发送的NCR的入网请求,其中,所述入网请求是所述第一核心网设备确定所述入网请求的识别信息中不包含所述NCR的第一身份标识的情况下发送的;所述第二核心网设备基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
第四方面,提供了一种设备认证方法,该方法包括:中继设备NCR向网络侧设备发送入网请求,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证;所述NCR接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络。
第五方面,提供了一种设备认证装置,该装置包括:第一请求接收模块,用于接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;认证模块,用于基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
第六方面,提供了一种凭证分配装置,该装置包括:认证结果确定模块,用于第一核心网设备确定针对NCR的认证结果;凭证分配模块,用于在所述认证结果为认证通过的情况下,所述第一核心网设备给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
第七方面,提供了一种标识分配装置,该装置包括:第二请求接收模块,用于接收第一核心网设备发送的NCR的入网请求,其中,所述入网请求是所述第一核心网设备确定所述入网请求的识别信息中不包含所述NCR的第一身份标识的情况下发送的;标识分配模块,用于基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
第八方面,提供了一种设备认证装置,该装置包括:发送模块,用于向网络侧设备发送入网请求,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证;接收模块,用于接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络。
第九方面,提供了一种通信系统,所述通信系统包括中继设备NCR和网络侧设备;所述NCR,用于向网络侧设备发送入网请求,接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证;所述网络侧设备,用于接收中继设备NCR的入网请求,基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
第十方面,提供了一种网络侧设备,该网络侧设备包括处理器和存储器,所述存储器
存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面、第二方面和第三方面任一方面所述的方法的步骤。
第十一方面,提供了一种中继设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第四方面所述的方法的步骤。
第十二方面,提供了一种网络侧设备,包括处理器及通信接口,其中,所述通信接口用于接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息,所述处理器用于基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
第十三方面,提供了一种通信系统,包括:中继设备NCR及网络侧设备,所述NCR可用于执行如第四方面所述的设备认证方法的步骤,所述网络侧设备可用于执行如第一方面、第二方面和第三方面任一方面所述的方法的步骤。
第十四方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面、第二方面、第三方面和第四方面中任一方面所述的方法的步骤。
第十五方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面、第二方面、第三方面和第四方面中任一方面所述的方法。
第十六方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现如第一方面、第二方面、第三方面和第四方面中任一方面所述的方法的步骤。
在本申请实施例中,由于NCR发起入网请求时,网络侧设备会基于入网请求中携带的所述NCR的识别信息对所述NCR进行认证,并基于认证结果确定是否允许所述NCR入网,所以可以保证接入网络的NCR合法可靠。
图1是本申请一个实施例提供的一种无线通信系统的框图。
图2是本申请另一实施例提供的一种无线通信系统的框图。
图3是本申请一实施例提供的一种设备认证方法的交互流程示意图。
图4是本申请一实施例提供的一种设备认证方法的交互流程示意图一。
图5是本申请一实施例提供的一种设备认证方法的交互流程示意图二。
图6是本申请一实施例提供的一种设备认证方法的交互流程示意图三。
图7是本申请一实施例提供的一种设备认证方法的流程示意图。
图8是本申请一实施例提供的一种凭证分配方法的流程示意图。
图9是本申请一实施例提供的一种标识分配方法的流程示意图。
图10是本申请一实施例提供的一种设备认证方法的流程示意图。
图11是本申请一实施例提供的一种设备认证装置的结构示意图。
图12是本申请一实施例提供的一种凭证分配装置的结构示意图。
图13是本申请一实施例提供的一种标识分配装置的结构示意图。
图14是本申请一实施例提供的一种设备认证装置的结构示意图。
图15是本申请一种通信设备的结构示意图。
图16本申请实施例的网络侧设备的硬件结构示意图。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统应用以外的应用,如第6代(6th Generation,6G)通信系统。
图1示出了本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(augmented reality,AR)/虚拟
现实(virtual reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(Vehicle-mounted User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(personal computer,PC)、柜员机或者自助机等终端侧设备,可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以包括接入网设备或核心网设备,其中,接入网设备12也可以称为无线接入网设备、无线接入网(Radio Access Network,RAN)、无线接入网功能或无线接入网单元。接入网设备12可以包括基站、WLAN接入点或WiFi节点等,基站可被称为节点B、演进节点B(evolved Node B,eNB)、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点、家用演进型B节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。
核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM),统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF),网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。
为了便于理解,下面先对中继设备——基站控制放大器(Network Controlled Repeater,NCR)进行简要的介绍。
NCR又被称为智能放大器(smart repeater)或信号放大器。NCR用于扩展小区的覆盖范围,包括接收和放大来自上游基站的下行信号,使得到达终端设备(User Equipment,UE)的信号强度增加,以及放大来自UE的上行信号,使得自UE到上游基站的上行信号的强度增加。
NCR可以接收来自上游基站的控制,即基站可以控制NCR的发送参数,例如NCR
的开关和发送波束等,以提高NCR的工作效率,降低干扰。图2示出了含有NCR的通信系统结构框图。如图2所示,该通信系统包括3个网络节点:基站(gNB)21、NCR 22和UE 23,其中,NCR包括一个终端模块(mobile termination,MT)和一个中继模块(repeater unit,RU),当然也不排除NCR 22包含MT和RU中一个模块的情况。NCR 22中的MT可以与上游基站21建立连接,基站21通过MT与NCR 22交互控制信令,如基站21可通过MT指示NCR的MT/RU的发送/接收相关参数。
参考图2,NCR的工作原理是:在下行链路中,NCR 22转发基站21发送给UE 23的信号,转发过程包括接收来自基站21的信号、对信号进行放大并发送给UE 23;在上行链路中,NCR 22转发UE 23发送给基站21的信号,转发过程包括接收来自UE 23的信号、对信号进行放大并发送给基站21。
NCR在转发信号时,其接收天线提供接收增益、其发送天线提供发送增益、其功放提供转发信号放大增益。使用NCR对上行信号进行转发,可以使得基站接收到的来自UE的信号增强,从而可以更好地对抗干扰。
NCR进行上行信号或下行信号的转发时,需要确保NCR是个合法可靠的节点。但是,目前没有有效的NCR认证方法,以确保NCR的合法性。为了解决该问题,本申请实施例提出了一种设备认证方法,在本申请提供的设备认证方案中,当一个NCR发起入网请求时,会由网络侧设备对该NCR的合法性进行认证,如果认证成功(认证通过),则允许该NCR入网,否则拒绝该NCR的入网请求,从而可以保证接入网络的NCR是合法可靠的,并避免不合法的NCR接入网络,保证了网络的安全,下面详细介绍。
首先对本申请实施例提供的一种设备认证方法进行介绍。
如图3所示,本申请的一个实施例提供一种设备认证方法,可以包括:
步骤301、NCR 10向网络侧设备20发送入网请求。
其中,所述入网请求中携带有NCR 10的识别信息。
NCR 10的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,NCR 10的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
可选的,NCR 10可以通过自身包含的终端功能模块(MT)发起入网请求。
步骤302、网络侧设备20基于所述识别信息对NCR 10进行认证。
具体而言,网络侧设备20基于所述识别信息对NCR 10的合法性进行认证,如果认证成功(认证通过),则认为NCR 10是一个合法节点;如果认证失败(认证不通过),则认为NCR 10不是合法节点,或者说,NCR 10是一个不合法节点。
在NCR 10的识别信息包括能够唯一识别该NCR的标识信息的情况下,网络侧设备20可基于唯一识别该NCR的标识信息对NCR 10的合法性进行认证;在NCR 10的识别
信息包括能够唯一识别该NCR的标识信息以及NCR指示信息的情况下,网络侧设备20可先基于所述NCR指示信息确认NCR 10是否是一个NCR节点,在确认NCR 10是一个NCR节点的情况下,再基于唯一识别该NCR的标识信息对NCR 10的合法性进行认证。不难理解,后一认证方式更有效。
步骤303、网络侧设备20在NCR 10认证成功的情况下,向NCR 10发送入网凭证。
步骤304、NCR 10基于所述入网凭证接入网络。
步骤305、网络侧设备20在NCR 10认证失败的情况下,拒绝NCR 10的入网请求。
图3所示实施例提出的一种设备认证方法,当NCR 10发起入网请求时,会由网络侧设备20对该NCR 10的合法性进行认证,如果认证成功(认证通过),则允许该NCR 10入网,否则拒绝NCR 10的入网请求,从而可以保证接入网络的NCR节点是合法可靠的,并避免不合法的NCR接入网络,保证了网络的安全。
下面通过三个具体的实施例对本申请提供的一种设备认证方法进行说明。
需要说明的是,下述三个实施例仅仅是本申请提供的一种设备认证方法的三种可能的实施方式,并不排除还有其他实施方式也可以实现本申请提供的一种设备认证方法。
实施例一
如图4所示,本申请的一个实施例提供一种设备认证方法,在该方法中,网络侧设备20可包括接入网设备201、NCR认证节点202和第一核心网设备203,该方法可以包括:
步骤401、NCR 10向接入网设备20发送入网请求。
其中,所述入网请求中携带有NCR 10的识别信息。
其中,接入网设备20可以为无线接入网(Radio Access Network,RAN)设备,例如基站,具体如gNG。
步骤402、接入网设备20向NCR认证节点202转发所述入网请求。
其中,NCR认证节点202可以是运营商引入专做NCR认证的网络节点,是一种类似于AMF的逻辑节点;或者,NCR认证节点202可以是运营商引入NCR认证功能的现有网络节点。例如,NCR认证节点202可以是但不限于下述节点中的一种:
(1)接入网中的一个独立节点;
(2)核心网中的一个节点;
(3)接入网网关的预设位置。
可选的,当NCR认证节点202为核心网中的一个节点时,NCR认证节点202具体可以为但不限于核心网的如下节点之一:
(1)会话管理功能(Session Management Function,SMF);
(2)应用功能(Application Function,AF);
(3)统一数据管理(Unified Data Management,UDM);
(4)接入移动管理功能(Access and Mobility Management Function,AMF)。
步骤403、NCR认证节点202基于NCR 10的识别信息对NCR 10进行认证。
NCR 10的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,NCR 10的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
可选的,当NCR认证节点202具体为核心网中的AMF时,NCR 10的识别信息包括第一身份标识,也即能够唯一识别NCR 10的标识信息为第一身份标识。进一步的,NCR认证节点202可以基于第一身份标识对NCR 10的合法性进行认证,具体认证方式与下面的实施例二类似,可参照下面的实施例二获得具体认证过程,这里不再赘述。
步骤404、NCR认证节点202向第一核心网设备203发送认证结果。
步骤405、第一核心网设备203在所述认证结果为认证成功的情况下,给NCR 10分配入网凭证,并将所述入网凭证反馈给接入网设备201。
其中,第一核心网设备203是指具备为NCR分配入网凭证能力的核心网设备。例如,当入网凭证为临时移动台标识符(Temperate Mobile Station Identity,TMSI),第一核心网设备可以为AMF,当然其他类型的入网凭证也可由AMF分配,只要AMF具备能够分配该入网凭证的能力即可。
可以理解,当NCR认证节点202为核心网中的AMF,且第一核心网设备203也为核心网中的AMF时,NCR认证节点202与第一核心网设备203为同一网络侧设备。
步骤406、接入网设备201向NCR 10发送所述入网凭证。
当然,第一核心网设备203也可直接向NCR 10反馈入网凭证,以使NCR 10基于该入网凭证接入网络。
步骤407、NCR 10基于所述入网凭证接入网络。
以入网凭证为5G-TMSI为例,NCR 10收到5G-TMSI后,即可用分配的5G-TMSI完成接入网流程。
可以理解,由于NCR在持有入网凭证的情况下才能接入网络,因此可以保证接入网络的NCR是合法可靠的。
可选的,图4所示实施例提供的一种设备认证方法,还可以包括:
步骤408、第一核心网设备203在所述认证结果为认证失败的情况下,向接入网设备201反馈所述认证结果。
步骤409、接入网设备201基于所述认证结果拒绝所述入网请求。
当然,第一核心网设备203也可直接向NCR 10反馈认证失败的结果,以拒绝NCR 10的入网请求;或者,NCR认证节点202也可直接向NCR 10反馈认证失败的结果,以拒绝NCR 10的入网请求。
可以理解,在NCR认证失败的情况下,接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
实施例二
如图5所示,本申请的一个实施例提供一种设备认证方法,在该方法中,网络侧设备20可包括接入网设备201、第一核心网设备203和第二核心网设备204,该方法可以包括:
步骤501、NCR 10向接入网设备20发送入网请求。
其中,所述入网请求中携带有NCR 10的识别信息。
其中,接入网设备20可以为无线接入网(Radio Access Network,RAN)设备,例如基站(gNG)。
步骤502、接入网设备20将所述入网请求转发给第一核心网设备203。
步骤503、第一核心网设备203基于所述识别信息对NCR 10进行认证。
具体的,第一核心网设备203可先确定所述识别信息中是否包含NCR 10的第一身份标识,若包含,则基于所述第一身份标识对NCR 10进行认证,并将认证结果反馈给接入网设备。在基于第一身份标识对NCR 10进行认证时,可基于预存的NCR标识与第一身份标识的对应关系(白名单)来判断NCR 10是否合法。其中,所述第一身份标识可以是SIM卡号,也可以是其他能够唯一标识NCR身份的标识。
在本实施例中,第一核心网设备203是指具备第一身份标识识别能力的核心网设备,例如,AMF。
步骤504、若所述识别信息中不包含NCR 10的第一身份标识导致NCR 10认证失败,则第一核心网设备203将所述入网请求转发给第二核心网设备204。
步骤505、第二核心网设备204基于所述识别信息验证NCR 10是否合法,在所述NCR合法的情况下给NCR 10分配第一身份标识。
具体的,所述识别信息中包含NCR 10的第二身份标识,第二核心网设备204可以基于所述第二身份标识验证NCR 10是否合法。
进一步的,NCR 10的第二身份标识包括NCR 10的出厂标识。
步骤506、第二核心网设备204将分配给NCR 10的配第一身份标识反馈给第一核心网设备203。
在本实施例中,第二核心网设备204是指具备第一身份标识配置能力的核心网设备,例如,第二核心网设备可以是核心网(core network,CN)中的逻辑节点以及操作管理和维护(Operation Administration and Maintenance,OAM)中的一种。其中,CN可以包括许多逻辑节点。
步骤507、第一核心网设备203将分配给NCR 10的第一身份标识转发给接入网设备201。
步骤508、接入网设备201将分配给NCR 10的第一身份标识发送给NCR 10,以使NCR 10携带在下一次入网请求中,以便于进行NCR 10合法性的认证。
可选的,如图5所示,本申请的一个实施例提供一种设备认证方法,还可以包括:
步骤509、第一核心网设备203在所述认证结果为认证成功的情况下,给NCR 10分
配入网凭证,并将所述入网凭证反馈给接入网设备201。
步骤510、接入网设备201向NCR 10发送所述入网凭证。
当然,第一核心网设备203也可直接向NCR 10反馈入网凭证,以使NCR 10基于该入网凭证接入网络。
可以理解,由于NCR在持有入网凭证的情况下才能接入网络,因此可以保证接入网络的NCR是合法可靠的。
步骤511、NCR 10基于所述入网凭证接入网络。
当然,第一核心网设备203也可直接向NCR 10反馈认证失败的结果,以拒绝NCR 10的入网请求。
可选的,图5所示实施例提供一种设备认证方法,还可以包括:如果第二核心网设备204对NCR 10认证结果为失败,则第二核心网设备204可将认证失败的结果经由第一核心网设备203发送给接入网设备201,接入网设备201据此拒绝NCR 10的入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
实施例三
如图6所示,本申请的一个实施例提供一种设备认证方法,在该方法中,网络侧设备20可包括接入网设备201和第一核心网设备203,该方法可以包括:
步骤601、NCR 10向接入网设备20发送入网请求。
其中,所述入网请求中携带有NCR 10的识别信息。
其中,接入网设备20可以为无线接入网(Radio Access Network,RAN)设备,例如基站(gNG)。
步骤602、接入网设备20基于所述识别信息对NCR 10进行认证。
其中,所述入网请求中携带的NCR 10的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,NCR 10的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
步骤603、接入网设备在NCR 10认证成功的情况下,将所述入网请求转发给第一核心网设备203。
步骤604、第一核心网设备203基于所述入网请求给NCR 10分配入网凭证,并将所述入网凭证反馈给接入网设备201。
步骤605、接入网设备201向NCR 10发送所述入网凭证。
步骤606、NCR 10基于所述入网凭证接入网络。
可以理解,由于NCR在持有入网凭证的情况下才能接入网络,因此可以保证接入网络的NCR是合法可靠的。
步骤607、接入网设备201在NCR 10认证失败的情况下,拒绝所述入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
以上通过NCR 10与网络侧设备20的交互,对本申请实施例提供的一种设备认证方法进行了介绍,下面分别从单侧(网络侧设备或中继设备)对本申请实施例提供的一种设备认证方法进行说明。需要说明的是,下面从单侧描述的本申请实施例提供的一种设备认证方法与上文通过交互的方式描述的本申请实施例提供的一种设备认证方法相对应,因此相关之处可相互参考。
首先对应用于网络侧设备的一种设备认证方法进行说明。
如图7所示,本申请的一个实施例提供一种设备认证方法,包括:
步骤701、网络侧设备接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息。
步骤702、所述网络侧设备基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
一般而言,在所述认证结果为认证成功的情况下,允许所述NCR接入网络;在所述认证结果为认证失败的情况下,不允许所述NCR接入网络,可拒绝所述入网请求。
图7所示实施例提出的一种设备认证方法,NCR发起入网请求时,网络侧设备会基于入网请求中携带的所述NCR的识别信息对所述NCR进行认证,并基于认证结果确定是否允许所述NCR入网,所以可以保证接入网络的NCR合法可靠。
下面通过三个具体的实施例对图7所示的一种设备认证方法进行详细说明,这三个实施例与上文中的三个实施例相互对应。
实施例一
所述网络侧设备为NCR认证节点,此时,步骤701可包括:NCR认证节点接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;步骤702可包括:NCR认证节点基于所述识别信息对所述NCR进行认证,获得认证结果。
具体的,在步骤701中,NCR认证节点可接收NCR对应的接入网设备转发的所述NCR的入网请求,也即所述入网请求由所述NCR向所述接入网设备发起,再由所述接入网设备转发给所述NCR认证节点。其中,所述接入网设备可以为无线接入网(Radio Access Network,RAN)设备,例如基站(gNG)。
其中,所述NCR认证节点可以为下述节点中的一种:
(1)接入网中的一个独立节点;
(2)核心网中的一个节点;
(3)接入网网关的预设位置。
具体的,所述NCR认证节点为核心网中的一个节点,且所述NCR认证节点具体可以为核心网的如下节点之一:
(1)会话管理功能(Session Management Function,SMF);
(2)应用功能(Application Function,AF);
(3)统一数据管理(Unified Data Management,UDM);
(4)接入移动管理功能(Access and Mobility Management Function,AMF)。
其中,所述入网请求中携带的所述NCR的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,所述NCR的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
可选的,当所述NCR认证节点具体为核心网中的AMF时,所述NCR的识别信息包括第一身份标识。进一步的,所述NCR认证节点可以基于第一身份标识(如SIM卡号)对所述NCR的合法性进行认证,具体认证方式与下面的实施例二类似,可参照下面的实施例二获得具体认证过程,这里不再赘述。
可选的,图7所示的方法还可以包括:所述NCR认证节点将所述认证结果转发给第一核心网设备,以使所述第一核心网设备为所述NCR分配入网凭证,其中,所述入网凭证为所述第一核心网设备在所述认证结果为认证成功的情况下分配的,所述入网凭证用于所述NCR接入网络。
具体的,所述第一核心网设备可将分配给所述NCR的入网凭证发送给所述NCR对应的接入网设备,再由所述接入网设备将所述入网凭证转发给所述NCR。或者,所述第一核心网设备可直接将分配给所述NCR的入网凭证发送给所述NCR。
其中,第一核心网设备是指具备为NCR分配入网凭证能力的核心网设备。例如,当入网凭证为临时移动台标识符(Temperate Mobile Station Identity,TMSI),第一核心网设备可以为AMF,当然其他类型的入网凭证也可由AMF分配,只要AMF具备能够分配该入网凭证的能力即可。
可选的,在所述认证结果为认证失败的情况下,所述第一核心网设备可向所述接入网设备反馈所述认证结果,以使所述接入网设备基于所述认证结果拒绝所述入网请求。
可选的,在所述NCR认证节点为AMF时,所述NCR认证节点在所述认证结果为认证成功的情况下,可以直接给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
可选的,在所述NCR认证节点为AMF时,所述NCR认证节点可向所述接入网设备反馈所述认证结果,以使所述接入网设备基于所述认证结果拒绝所述入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
实施例二
所述网络侧设备为第一核心网设备,此时,步骤701可包括:第一核心网设备接收中
继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;步骤702可包括:第一核心网设备基于所述识别信息对所述NCR进行认证,获得认证结果。
具体的,在步骤701中,第一核心网设备可接收NCR对应的接入网设备转发的所述NCR的入网请求,也即所述入网请求由所述NCR向所述接入网设备发起,再由所述接入网设备转发给第一核心网设备。其中,所述接入网设备可以为无线接入网(Radio Access Network,RAN)设备,例如基站(gNG)。
具体的,在步骤702中,所述第一核心网设备可确定所述识别信息中是否包含所述NCR的第一身份标识,若包含,则基于所述第一身份标识对所述NCR进行认证。
进一步的,图7所示的方法还可以包括:在所述认证结果为认证成功的情况下,所述第一核心网设备给所述NCR分配入网凭证并发送至所述NCR,其中,所述入网凭证用于所述NCR接入网络。
具体的,所述第一核心网设备可在所述认证结果为认证成功的情况下,将分配给所述NCR的入网凭证发送给所述NCR对应的接入网设备,再由所述接入网设备将所述入网凭证转发给所述NCR,或者,所述第一核心网设备可在所述认证结果为认证成功的情况下,直接将分配给所述NCR的入网凭证发送给所述NCR对应的接入网设备,从而使得所述NCR基于所述入网凭证接入网络。
可以理解,由于NCR在持有入网凭证的情况下才能接入网络,因此可以保证接入网络的NCR是合法可靠的。
其中,第一核心网设备是指具备第一身份标识识别能力的核心网设备,例如,AMF。
可选的,图7所示的方法还可以包括:
若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备还可以将所述入网请求转发给所述第二核心网设备,其中,所述识别信息用于所述第二核心网设备验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;
所述第一核心网设备接收所述第二核心网设备分配给所述NCR的第一身份标识,并将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述识别信息中包含所述NCR的第二身份标识,其中,所述第二核心网设备可基于所述第二身份标识验证所述NCR是否合法。
其中,第二核心网设备是指具备第一身份标识配置能力的核心网设备,例如,第二核心网设备可以是下述设备中的一种:
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
可选的,所述第一核心网设备为接入移动管理功能AMF,所述方法还包括:
若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备基于所述识别信息中的第二识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;
所述第一核心网设备将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述NCR的第二身份标识包括所述NCR的出厂标识。
所述第一身份标识包括SIM卡号。
可选的,可选的,图7所示的方法还可以包括:在所述认证结果为认证失败的情况下,所述第一核心网设备可以向所述NCR对应的接入网设备反馈所述认证结果,以使所述接入网设备基于所述认证结果拒绝所述入网请求;或者,在所述第二核心网设备对所述NCR验证失败的情况下,所述第二核心网设备可将认证失败的结果经由所述第一核心网设备发送给所述接入网设备,所述接入网设备据此拒绝所述NCR的入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
实施例三
所述网络侧设备为接入网设备。该接入网设备20可以为无线接入网(Radio Access Network,RAN)设备,例如基站(gNG)。此时,步骤701可包括:接入网设备接收所述NCR发送的入网请求;步骤702可包括:所述接入网设备基于所述识别信息对所述NCR进行认证。
其中,所述入网请求中携带的所述NCR的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,所述NCR的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
进一步的,图7所示的方法还可以包括:
在所述认证结果为认证成功的情况下,所述接入网设备将所述入网请求发送给第一核心网设备,其中,所述识别信息用于所述第一核心网设备给所述NCR分配入网凭证;
所述接入网设备接收所述第一核心网设备发送的所述入网凭证,并将所述入网凭证发送至所述NCR,其中,所述入网凭证用于所述NCR接入网络。
可以理解,由于NCR在持有入网凭证的情况下才能接入网络,因此可以保证接入网络的NCR是合法可靠的。
其中,所述第一核心网设备为核心网中的接入移动管理功能AMF。
可选的,图7所示的方法还可以包括:
在所述认证结果为认证失败的情况下,所述接入网设备拒绝所述入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
下面对应用于第一核心网设备的一种凭证分配方法进行说明。
如图8所示,本申请的一个实施例提供的一种凭证分配方法,可包括:
步骤801、第一核心网设备确定针对NCR的认证结果。
步骤802、在所述认证结果为认证通过的情况下,所述第一核心网设备给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
分别对应于本申请提供的一种中继设备认证方法的三个实施例,本申请提供的一种凭证分配方法,也对应存在三种实施方式。
实施方式一
在NCR发起入网请求后,由NCR认证节点对NCR进行认证。
相应的,上述步骤801可包括:所述第一核心网设备接收NCR认证节点发送的针对所述NCR的认证结果,其中,所述认证结果由所述NCR认证节点基于所述NCR的入网请求中携带的所述NCR的识别信息对所述NCR进行认证得到。
上述步骤802可包括:所述第一核心网设备给所述NCR分配入网凭证,并将所述入网凭证发送给所述NCR。具体的,所述第一核心网设备可直接将所述入网凭证发送给所述NCR,也可以先将所述入网凭证发送给所述NCR对应的接入网设备,再由所述接入网设备将所述入网凭证发送给所述NCR。
可选的,图8所示的方法还可以包括:在所述认证结果为认证失败的情况下,所述第一核心网设备向所述NCR对应的接入网设备反馈所述认证结果,以使所述接入网设备基于所述认证结果拒绝所述入网请求。
实施方式二
在NCR发起入网请求后,由第一核心网设备本身对NCR进行认证。
相应的,上述步骤801可包括:所述第一核心网设备接收所述NCR的入网请求,其中,所述入网请求中携带有所述NCR的识别信息;所述第一核心网设备确定所述识别信
息中是否包含所述NCR的第一身份标识,若包含,则基于所述第一身份标识对所述NCR进行认证,得到所述NCR的认证结果。
第一核心网设备对NCR进行认证的过程可参考上文通过实施例二对设备认证方法的介绍,此处不再赘述。
可选的,图8所示的方法还可以包括:若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备将所述入网请求转发给所述第二核心网设备,其中,所述识别信息用于所述第二核心网设备验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;
所述第一核心网设备接收所述第二核心网设备分配给所述NCR的第一身份标识,并将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述第一核心网设备为接入移动管理功能AMF,所述方法还包括:
若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;
所述第一核心网设备将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述识别信息中包含所述NCR的第二身份标识。
可选的,所述NCR的第二身份标识包括所述NCR的出厂标识。
可选的,所述第二核心网设备包括下述一种:
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
可选的,所述第一身份标识包括SIM卡号。
实施方三
在NCR发起入网请求后,由NCR对应的接入网设备对NCR进行认证。
相应的,上述步骤801可包括:所述第一核心网设备接收所述NCR对应的接入网设备发送的所述NCR的认证结果,其中,所述认证结果是所述接入网设备基于所述NCR的入网请求中携带的所述NCR的识别信息对所述NCR进行认证得到的。
可选的,图8所示的方法还可以包括:在所述认证结果为认证失败的情况下,所述第一核心网设备向所述NCR对应的接入网设备反馈所述认证结果,其中,所述认证结果用于所述接入网设备拒绝所述入网请求。
在上述三种实施方中,第一核心网设备可以为AMF,接入网设备可以为无线接入网设备,入网凭证可以为TMSI。
对应于上文中的实施例二,本申请实施例还提出了一种标识分配方法,下面进行说明。
如图9所示,本申请的一个实施例提供的一种标识分配方法,可以包括:
步骤901、第二核心网设备接收第一核心网设备发送的NCR的入网请求,其中,所述入网请求是所述第一核心网设备确定所述入网请求的识别信息中不包含所述NCR的第一身份标识的情况下发送的。
步骤902、所述第二核心网设备基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
可选的,所述识别信息中包含所述NCR的第二身份标识,步骤902具体可包括:所述第二核心网设备基于所述第二身份标识验证所述NCR是否合法。
可选的,所述NCR的第二身份标识包括所述NCR的出厂标识。
进一步的,步骤902具体可包括:所述第二核心网设备在所述NCR合法的情况下,给所述NCR分配第一身份标识并发送给所述NCR,以使所述NCR携带在下一次入网请求中。
在该实施例中,第一核心网设备可以为AMF,接入网设备可以为无线接入网设备,入网凭证可以为TMSI。
其中,第二核心网设备可以包括下述一种:
接入移动管理功能AMF;
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
可选的,所述第一身份标识包括SIM卡号。
可以理解,给NCR分配第一身份标识以后,NCR可在以后的入网请求中携带自己的第一身份标识,以进行自身合法性的认证。
下面对应用于中继设备侧的一种设备认证方法进行说明。
如图10所示,本申请的一个实施例提供一种设备认证方法,包括:
步骤1001、中继设备NCR向网络侧设备发送入网请求,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证。
步骤1002、所述NCR接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络。
图10所示实施例提出的一种设备认证方法,NCR发起入网请求时,会向网络侧设备发送入网请求,以使网络侧设备基于所述入网请求中携带的所述NCR的标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证,从而使得该NCR可以根据该入网凭证接入网络,而不是随意接入网络,因此可保证接入网络的NCR是合法可靠的,或者说,可以避免不合法的NCR接入网络,从而保证了网络的安全。
下面也通过三个具体的实施例对图10所示的一种设备认证方法进行详细说明,这三个实施例分别与上文中图4、图5和图6所示的三个实施例相对应。
实施例一
所述网络侧设备包括接入网设备、NCR认证节点和第一核心网设备。
其中,步骤1001具体可包括:所述NCR向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述NCR认证节点,其中,所述入网请求用于请求所述NCR认证节点基于所述识别信息对所述NCR进行认证,并将所述NCR的认证结果发送给所述第一核心网设备,以使所述第一核心网设备在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备。
相应的,步骤1002具体可包括:所述NCR接收所述接入网设备发送的入网凭证。
或者,所述网络侧设备包括接入网设备和NCR认证节点,且所述NCR认证节点为AMF。
其中,步骤1001具体可包括:所述NCR向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述NCR认证节点,其中,所述入网请求用于请求所述NCR认证节点基于所述识别信息对所述NCR进行认证,并在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备;
其中,步骤1002具体可包括:所述NCR接收所述接入网设备发送的入网凭证。
其中,所述NCR认证节点可以为下述节点中的一种:
(1)接入网中的一个独立节点;
(2)核心网中的一个节点;
(3)接入网网关的预设位置。
具体的,所述NCR认证节点为核心网中的一个节点,且所述NCR认证节点具体可以为核心网的如下节点之一:
(1)会话管理功能(Session Management Function,SMF);
(2)应用功能(Application Function,AF);
(3)统一数据管理(Unified Data Management,UDM);
(4)接入移动管理功能(Access and Mobility Management Function,AMF)。
其中,所述入网请求中携带的所述NCR的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,所述NCR的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
可选的,当所述NCR认证节点具体为核心网中的AMF时,所述NCR的识别信息包括第一身份标识。进一步的,所述NCR认证节点可以基于第一身份标识对所述NCR的合法性进行认证,具体认证方式与下面的实施例二类似,可参照下面的实施例二获得具体认证过程,这里不再赘述。
其中,第一核心网设备是指具备为NCR分配入网凭证能力的核心网设备。例如,当入网凭证为临时移动台标识符(Temperate Mobile Station Identity,TMSI),第一核心网设备可以为AMF,当然其他类型的入网凭证也可由AMF分配,只要AMF具备能够分配该入网凭证的能力即可。
可以理解,当所述NCR认证节点为核心网中的AMF,且所述第一核心网设备也为核心网中的AMF时,所述NCR认证节点与所述第一核心网设备为同一网络侧设备。
实施例二
所述网络侧设备包括接入网设备和第一核心网设备。
在一个例子中,步骤1001具体可包括:所述NCR向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述第一核心网设备,其中,所述入网请求用于请求所述第一核心网设备基于所述识别信息对所述NCR进行认证,并在所述认证结果
为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备。
相应的,步骤1002具体可包括:所述NCR接收所述接入网设备发送的入网凭证。
其中,第一核心网设备是指具备第一身份标识识别能力的核心网设备,例如,AMF。
可选的,所述网络侧设备还包括第二核心网设备,图10所示的方法还可以包括:所述NCR接收所述接入网设备发送的第一身份标识,其中,所述第一身份标识是所述第一核心网确定所述识别信息中不含所述第一身份标识的情况下,由所述第二核心网设备分配给所述NCR的,且所述第一身份标识是所述第二核心网设备基于所述识别信息验证所述NCR合法的情况下分配的。
可选的,所述识别信息中包含所述NCR的第二身份标识,其中,所述第二核心网设备可基于所述第二身份标识验证所述NCR是否合法。
其中,第二核心网设备是指具备第一身份标识配置能力的核心网设备,例如,第二核心网设备可以下述设备中的一种:
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
在另一个例子中,所述第一核心网设备位接入移动管理功能AMF,所述方法还包括:
所述NCR接收所述接入网设备发送的第一身份标识,其中,所述第一身份标识是所述第一核心网确定所述识别信息中不含所述第一身份标识的情况下分配给所述NCR的,且所述第一身份标识是所述第一核心网设备基于所述识别信息中的第二识别信息验证所述NCR合法的情况下分配的。
实施例三
所述网络侧设备包括接入网设备和第一核心网设备。
其中,步骤1001具体可包括:所述NCR向所述接入网设备发送入网请求,其中,所述入网请求用于请求所述接入网设备基于所述识别信息对所述NCR进行认证,并将所述NCR的认证结果发送给所述第一核心网设备,以使所述第一核心网设备在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备。
相应的,步骤1002具体可包括:所述NCR接收所述接入网设备发送的入网凭证。
其中,所述第一核心网设备为核心网中的接入移动管理功能AMF;所述接入网设备可以为无线接入网设备;所述识别信息还包括NCR指示信息,所述NCR指示信息用于指示所述NCR为NCR节点;所述入网凭证为临时移动台标识符TMSI。
需要说明的是,图10所示实施例提供的设备认证方法,执行主体可以为设备认证装置。本申请实施例中以设备认证装置执行设备认证方法为例,说明本申请实施例提供的设备认证装置。
下面结合附图对本申请实施例提供的一种设备认证装置、凭证分配装置以及标识分配装置进行说明。由于本申请实施例提供的一种凭证分配装置与本申请实施例提供的一种设备认证方法对应,本申请实施例提供的一种凭证分配装置与本申请实施例提供的一种凭证分配方法对应,以及,本申请实施例提供的一种标识分配装置与本申请实施例提供的一种标识分配方法对应,因此对本申请实施例提供的装置描述的较为简要,详细内容可参考上文方法实施例部分的介绍。
如图11所示,本申请的一个实施例提供了一种设备认证装置1100,装置1100可包括:第一请求接收模块1101和认证模块1102。
第一请求接收模块1101,用于接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息。
认证模块1102,用于基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
一般而言,在所述认证结果为认证成功的情况下,允许所述NCR接入网络;在所述认证结果为认证失败的情况下,不允许所述NCR接入网络,可拒绝所述入网请求。
图11所示实施例提出的一种设备认证装置1100可应用网络侧设备,这样一来,NCR发起入网请求时,网络侧设备会基于入网请求中携带的所述NCR的识别信息对所述NCR进行认证,并基于认证结果确定是否允许所述NCR入网,所以可以保证接入网络的NCR合法可靠。
下面通过三个具体的实施例对图11所示的一种设备认证装置1100进行详细说明。
实施例一
所述网络侧设备为NCR认证节点。
具体的,第一请求接收模块1101可用于:接收NCR对应的接入网设备转发的所述NCR的入网请求。其中,所述接入网设备可以为无线接入网(Radio Access Network,RAN)
设备,例如基站(gNG)。
可选的,图11所示的装置还可以包括:结果转发模块,用于所述NCR认证节点将所述认证结果发送至第一核心网设备,以使所述第一核心网设备为所述NCR分配入网凭证,其中,所述入网凭证为所述第一核心网设备在所述认证结果为认证成功的情况下分配的,所述入网凭证用于所述NCR接入网络。
可选的,在所述NCR认证节点为AMF时,所述NCR认证节点在所述认证结果为认证成功的情况下,可以直接给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
可选的,在所述NCR认证节点为AMF时,所述NCR认证节点可向所述接入网设备反馈所述认证结果,以使所述接入网设备基于所述认证结果拒绝所述入网请求。
实施例二
所述网络侧设备为第一核心网设备。
具体的,第一请求接收模块1101可用于:接收NCR对应的接入网设备转发的所述NCR的入网请求。
具体的,认证模块1102可用于:确定所述识别信息中是否包含所述NCR的第一身份标识,若包含,则基于所述第一身份标识对所述NCR进行认证。
进一步的,图11所示的装置1100还可以包括:凭证分配模块,用于在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
可以理解,由于NCR在持有入网凭证的情况下才能接入网络,因此可以保证接入网络的NCR是合法可靠的。
其中,第一核心网设备是指具备第一身份标识识别能力的核心网设备,例如,AMF。
可选的,图11所示的装置1100还可以包括:请求转发模块和标识接收模块。
请求转发模块,用于将所述入网请求转发给所述第二核心网设备,其中,所述识别信息用于所述第二核心网设备验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
标识接收模块,用于接收所述第二核心网设备分配给所述NCR的第一身份标识,并将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述识别信息中包含所述NCR的第二身份标识,其中,所述第二核心网设备可用于基于所述第二身份标识验证所述NCR是否合法。
可选的,所述NCR的第二身份标识包括所述NCR的出厂标识。
所述第二核心网设备包括下述一种:
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
所述第一身份标识包括SIM卡号。
可选的,所述第一核心网设备为接入移动管理功能AMF,图11所示的装置1100还可以包括:标识分配模块和标识发送模块。
标识分配模块,用于若所述识别信息中不包含所述NCR的第一身份标识,则基于所述识别信息中的第二识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
标识发送模块,用于将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,图11所示的装置1100还可以包括:失败结果反馈模块,用于在所述认证结果为认证失败的情况下,所述第一核心网设备向所述NCR对应的接入网设备反馈所述认证结果,其中,所述认证结果用于所述接入网设备拒绝所述入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
实施例三
所述网络侧设备为接入网设备。该接入网设备20可以为无线接入网(Radio Access Network,RAN)设备,例如基站(gNG)。
进一步的,图11所示的装置1100还可以包括:请求转发模块和凭证接收模块。
请求转发模块,用于用于在所述认证结果为认证成功的情况下,所述接入网设备将所述入网请求发送给第一核心网设备,其中,所述识别信息用于所述第一核心网设备给所述NCR分配入网凭证。
凭证接收模块,用于所述接入网设备接收所述第一核心网设备发送的所述入网凭证,并将所述入网凭证发送至所述NCR,其中,所述入网凭证用于所述NCR接入网络。
可选的,在本实施例中,所述第一核心网设备可以为AMF;所述识别信息还可包括NCR指示信息,所述NCR指示信息用于指示所述NCR为NCR节点;所述接入网设备为无线接入网设备;所述入网凭证可以为临时移动台标识符TMSI。
可选的,图11所示的装置1100还可以包括:拒绝接入模块,用于在所述认证结果为认证失败的情况下,拒绝所述入网请求。
可以理解,在NCR认证失败的情况下,由于接入网设备会拒绝该NCR入网,从而可以避免不合法的NCR接入网络,保证了网络的安全。
需要说明的是,图11提供的设备认证装置能够实现图7所示的设备认证方法,并能取得相同的技术效果,因此这里对图11提供的设备认证装置描述的较为简单。
如图12所示,本申请的一个实施例提供了一种凭证分配装置1200,装置1200可包括:认证结果确定模块1201和凭证分配模块1202。
认证结果确定模块1201,用于确定针对NCR的认证结果。
凭证分配模块1202,用于在所述认证结果为认证通过的情况下,所述第一核心网设备给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
分别对应于本申请提供的一种中继设备认证方法的三个实施例,本申请提供的一种凭证分配方法,也对应存在三种实施方式。
实施方式一
在NCR发起入网请求后,由NCR认证节点对NCR进行认证。
相应的,上述认证结果确定模块1201可用于:接收NCR认证节点发送的针对所述NCR的认证结果,其中,所述认证结果由所述NCR认证节点基于所述NCR的入网请求中携带的所述NCR的识别信息对所述NCR进行认证得到。
上述凭证分配模块1202可用于:给所述NCR分配入网凭证,并将所述入网凭证发送给所述NCR。
可选的,图12所示的装置还可以包括:结果反馈模块,用于在所述认证结果为认证失败的情况下,向所述NCR对应的接入网设备反馈所述认证结果,以使所述接入网设备基于所述认证结果拒绝所述入网请求。
实施方式二
在NCR发起入网请求后,由第一核心网设备本身对NCR进行认证。
相应的,上述认证结果确定模块1201可用于:接收所述NCR的入网请求,其中,所述入网请求中携带有所述NCR的识别信息;确定所述识别信息中是否包含所述NCR的第一身份标识,若包含,则基于所述第一身份标识对所述NCR进行认证,得到所述NCR的认证结果。
第一核心网设备对NCR进行认证的过程可参考上文通过实施例二对设备认证方法的介绍,此处不再赘述。
可选的,装置1200还可以包括:请求转发模块和标识接收模块。
请求转发模块,用于若所述识别信息中不包含所述NCR的第一身份标识,则将所述入网请求转发给所述第二核心网设备,其中,所述识别信息用于所述第二核心网设备验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
标识接收模块,用于接收所述第二核心网设备分配给所述NCR的第一身份标识,并将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述第一核心网设备为接入移动管理功能AMF,装置1200还可以包括:标识分配模块和标识发送模块。
标识分配模块,用于若所述识别信息中不包含所述NCR的第一身份标识,则基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
标识发送模块,用于将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
可选的,所述识别信息中包含所述NCR的第二身份标识。
可选的,所述NCR的第二身份标识包括所述NCR的出厂标识。
可选的,所述第二核心网设备包括下述一种:
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
可选的,所述第一身份标识包括SIM卡号。
实施方三
在NCR发起入网请求后,由NCR对应的接入网设备对NCR进行认证。
相应的,上述认证结果确定模块1201可用于:所述第一核心网设备接收所述NCR对应的接入网设备发送的所述NCR的认证结果,其中,所述认证结果是所述接入网设备基于所述NCR的入网请求中携带的所述NCR的识别信息对所述NCR进行认证得到的。
可选的,装置1200还可以包括:结果反馈模块,用于在所述认证结果为认证失败的情况下,所述第一核心网设备向所述NCR对应的接入网设备反馈所述认证结果,其中,所述认证结果用于所述接入网设备拒绝所述入网请求。
在上述三种实施方中,第一核心网设备可以为AMF,接入网设备可以为无线接入网设备,入网凭证可以为TMSI。
需要说明的是,图12提供的凭证分配装置能够实现图8所示的凭证分配方法,并能取得相同的技术效果,因此这里对图12提供的凭证分配装置描述的较为简单。
如图13所示,本申请的一个实施例提供了一种标识分配装置1300,装置1300可包括:第二请求接收模块1301和标识分配模块1302。
第二请求接收模块1301,用于接收第一核心网设备发送的NCR的入网请求,其中,所述入网请求是所述第一核心网设备确定所述入网请求的识别信息中不包含所述NCR的第一身份标识的情况下发送的。
标识分配模块1302,用于基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
可选的,所述识别信息中包含所述NCR的第二身份标识,标识分配模块1302具体可用于:基于所述第二身份标识验证所述NCR是否合法。
进一步的,标识分配模块1302具体可用于:所述第二核心网设备在所述NCR合法的情况下,给所述NCR分配第一身份标识并发送给所述NCR,以使所述NCR携带在下一次入网请求中。
在该实施例中,第一核心网设备可以为AMF,接入网设备可以为无线接入网设备,入网凭证可以为TMSI。
其中,第二核心网设备可以包括下述一种:
接入移动管理功能AMF;
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
其中,第一身份标识可以为SIM卡号。
可以理解,给NCR分配第一身份标识以后,NCR可在以后的入网请求中携带自己的第一身份标识,以进行自身合法性的认证。
需要说明的是,图13提供的标识分配装置能够实现图9所示的标识分配方法,并能取得相同的技术效果,因此这里对图13提供的标识分配装置描述的较为简单。
如图14所示,本申请的一个实施例提供了一种设备认证装置1400,该装置1400可包括发送模块1401和接收模块1402。
发送模块1401,用于向网络侧设备发送入网请求,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证。
接收模块1402,用于接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络。
本申请实施例提出的一种设备认证装置,在NCR发起入网请求时,会向网络侧设备发送入网请求,以使网络侧设备基于所述入网请求中携带的所述NCR的标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证,从而使得该NCR可以根据该入网凭证接入网络,而不是随意接入网络,因此可保证接入网络的NCR是合法可靠的,或者说,可以避免不合法的NCR接入网络,从而保证了网络的安全。
下面通过三个具体的实施例对图14所示的一种设备认证装置进行详细说明。
实施例一
所述网络侧设备包括接入网设备、NCR认证节点和第一核心网设备。
其中,发送模块1401具体可用于:向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述NCR认证节点,其中,所述入网请求用于请求所述NCR认证节点基于所述识别信息对所述NCR进行认证,并将所述NCR的认证结果发送给所述第一核心网设备,以使所述第一核心网设备在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备。
相应的,接收模块1402具体可用于:接收所述接入网设备发送的入网凭证。
或者,所述网络侧设备包括接入网设备和NCR认证节点,且所述NCR认证节点为AMF。
其中,发送模块1401具体可用于:所述NCR向所述接入网设备发送入网请求,以使
所述接入网设备将所述入网请求转发给所述NCR认证节点,其中,所述入网请求用于请求所述NCR认证节点基于所述识别信息对所述NCR进行认证,并在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备;
其中,接收模块1402具体可用于:所述NCR接收所述接入网设备发送的入网凭证。
其中,所述NCR认证节点可以为下述节点中的一种:
(1)接入网中的一个独立节点;
(2)核心网中的一个节点;
(3)接入网网关的预设位置。
具体的,所述NCR认证节点为核心网中的一个节点,且所述NCR认证节点具体可以为核心网的如下节点之一:
(1)会话管理功能(Session Management Function,SMF);
(2)应用功能(Application Function,AF);
(3)统一数据管理(Unified Data Management,UDM);
(4)接入移动管理功能(Access and Mobility Management Function,AMF)。
其中,所述入网请求中携带的所述NCR的识别信息可以包括能够唯一识别该NCR的第一身份标识和第二身份标识中的至少一种,其中,所述第二身份标识与第一身份标识不同,所述第一身份标识可以包括SIM卡号、入网许可等。
可选的,所述NCR的识别信息还可以包括NCR指示信息,该NCR指示信息用于表示该NCR是一个NCR节点。
可选的,当所述NCR认证节点具体为核心网中的AMF时,所述NCR的识别信息包括第一身份标识,也即能够唯一识别所述NCR的标识信息为第一身份标识。进一步的,所述NCR认证节点可以基于第一身份标识对所述NCR的合法性进行认证,具体认证方式与下面的实施例二类似,可参照下面的实施例二获得具体认证过程,这里不再赘述。
其中,第一核心网设备是指具备为NCR分配入网凭证能力的核心网设备。例如,当入网凭证为临时移动台标识符(Temperate Mobile Station Identity,TMSI),第一核心网设备可以为AMF,当然其他类型的入网凭证也可由AMF分配,只要AMF具备能够分配该入网凭证的能力即可。
可以理解,当所述NCR认证节点为核心网中的AMF,且所述第一核心网设备也为核心网中的AMF时,所述NCR认证节点与所述第一核心网设备为同一网络侧设备。
实施例二
所述网络侧设备包括接入网设备和第一核心网设备。
其中,发送模块1401具体可用于:向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述第一核心网设备,其中,所述入网请求用于请求所述第一核心网设备基于所述识别信息对所述NCR进行认证,并在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备。
相应的,接收模块1402具体可用于:接收所述接入网设备发送的入网凭证。
其中,第一核心网设备203是指具备第一身份标识识别能力的核心网设备,例如,AMF。
可选的,所述网络侧设备还包括第二核心网设备,装置1400还可以包括:标识接收模块,用于接收所述接入网设备发送的第一身份标识,其中,所述第一身份标识是所述第一核心网确定所述识别信息中不含所述第一身份标识的情况下,由所述第二核心网设备分配给所述NCR的,且所述第一身份标识是所述第二核心网设备基于所述识别信息验证所述NCR合法的情况下分配的。
可选的,所述识别信息中包含所述NCR的第二身份标识,其中,所述第二核心网设备具体用于基于所述第二身份标识验证所述NCR是否合法。
其中,第二核心网设备204是指具备第一身份标识配置能力的核心网设备,
第二核心网设备可以下述设备中的一种:
移动管理实体MME;
会话管理功能SMF;
用户平面功能UPF;
策略控制功能PCF;
策略与计费规则功能单元PCRF;
边缘应用服务发现功能EASDF;
统一数据管理UDM;
统一数据仓储UDR;
归属用户服务器HSS;
集中式网络配置CNC;
网络存储功能NRF;
网络开放功能NEF;
本地NEF;
绑定支持功能BSF;
应用功能AF。
实施例三
所述网络侧设备包括接入网设备和第一核心网设备。
其中,发送模块1401具体可用于:向所述接入网设备发送入网请求,其中,所述入网请求用于请求所述接入网设备基于所述识别信息对所述NCR进行认证,并将所述NCR的认证结果发送给所述第一核心网设备,以使所述第一核心网设备在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备。
相应的,接收模块1402具体可用于:接收所述接入网设备发送的入网凭证。
其中,所述第一核心网设备为核心网中的接入移动管理功能AMF。所述接入网设备
为无线接入网设备。
本申请实施例中的设备认证装置1400可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的设备认证装置1400能够实现图10的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
可选的,如图15所示,本申请实施例还提供一种通信设备1500,包括处理器1501和存储器1502,存储器1502上存储有可在所述处理器1501上运行的程序或指令,例如,该通信设备1500为中继设备时,该程序或指令被处理器1501执行时实现上述图10所示的设备认证方法实施例的各个步骤,且能达到相同的技术效果。该通信设备1500为网络侧设备时,该程序或指令被处理器1501执行时实现上述图7所示的设备认证方法、图8所示的凭证分配方法或图9所示的标识分配方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种网络侧设备,包括处理器和通信接口,通信接口用于接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息,所述处理器用于基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。该网络侧设备实施例与上述网络侧设备方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该网络侧设备实施例中,且能达到相同的技术效果。
具体地,本申请实施例还提供了一种网络侧设备。如图16所示,该网络侧设备1600包括:天线161、射频装置162、基带装置163、处理器164和存储器165。天线161与射频装置162连接。在上行方向上,射频装置162通过天线161接收信息,将接收的信息发送给基带装置163进行处理。在下行方向上,基带装置163对要发送的信息进行处理,并发送给射频装置162,射频装置162对收到的信息进行处理后经过天线161发送出去。
以上实施例中网络侧设备执行的方法可以在基带装置163中实现,该基带装置163包括基带处理器。
基带装置163例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图16所示,其中一个芯片例如为基带处理器,通过总线接口与存储器165连接,以调用存储器165中的程序,执行以上方法实施例中所示的网络设备操作。
该网络侧设备还可以包括网络接口166,该接口例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本发明实施例的网络侧设备1600还包括:存储在存储器165上并可在处理器164上运行的指令或程序,处理器164调用存储器165中的指令或程序执行图7、图8
和图9中任一附图所示的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述设备认证方法、凭证分配方法或标识分配方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述设备认证方法、凭证分配方法或标识分配方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在非易失的存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述设备认证方法、凭证分配方法或标识分配方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种通信系统,包括:中继设备及网络侧设备,所述中继设备可用于执行如上图10所示的设备认证方法的步骤,所述网络侧设备可用于执行如上图7所示的设备认证方法的步骤。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。
Claims (74)
- 一种设备认证方法,所述方法包括:网络侧设备接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;所述网络侧设备基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
- 根据权利要求1所述的方法,其中,所述网络侧设备为NCR认证节点。
- 根据权利要求2所述的方法,其中,所述NCR认证节点为下述节点中的一种:接入网中的一个独立节点;核心网中的一个节点;接入网网管的预设位置。
- 根据权利要求3所述的方法,其中,所述NCR认证节点为核心网中的一个节点,且所述NCR认证节点具体为核心网的如下节点之一:会话管理功能SMF;应用功能AF;统一数据管理UDM;接入移动管理功能AMF。
- 根据权利要求4所述的方法,其中,所述NCR认证节点为所述AMF。
- 根据权利要求5所述的方法,其中,所述NCR认证节点在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
- 根据权利要求2-4任一项所述的方法,其中,所述方法还包括:所述NCR认证节点将所述认证结果发送至第一核心网设备,以使所述第一核心网设备为所述NCR分配入网凭证,其中,所述入网凭证为所述第一核心网设备在所述认证结果为认证成功的情况下分配的,所述入网凭证用于所述NCR接入网络。
- 根据权利要求1所述的方法,其中,所述网络侧设备为第一核心网设备,所述网络侧设备基于所述识别信息对所述NCR进行认证,包括:所述第一核心网设备确定所述识别信息中是否包含所述NCR的第一身份标识,若包含,则基于所述第一身份标识对所述NCR进行认证。
- 根据权利要求8所述的方法,其中,所述方法还包括:在所述认证结果为认证成功的情况下,所述第一核心网设备给所述NCR分配入网凭证并发送至所述NCR,其中,所述入网凭证用于所述NCR接入网络。
- 根据权利要求8或9所述的方法,其中,所述方法还包括:若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备将所述入网请求转发给所述第二核心网设备,其中,所述识别信息用于所述第二核心网设备验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;所述第一核心网设备接收所述第二核心网设备分配给所述NCR的第一身份标识,并将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
- 根据权利要求10所述的方法,其中,所述第二核心网设备包括下述一种:移动管理实体MME;会话管理功能SMF;用户平面功能UPF;策略控制功能PCF;策略与计费规则功能单元PCRF;边缘应用服务发现功能EASDF;统一数据管理UDM;统一数据仓储UDR;归属用户服务器HSS;集中式网络配置CNC;网络存储功能NRF;网络开放功能NEF;本地NEF;绑定支持功能BSF;应用功能AF。
- 根据权利要求8或9所述的方法,其中,所述第一核心网设备为接入移动管理功能AMF,所述方法还包括:若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;所述第一核心网设备将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
- 根据权利要求11或12所述的方法,其中,所述识别信息中包含所述NCR的第二身份标识。
- 根据权利要求10所述的方法,其中,所述NCR的第二身份标识包括所述NCR的出厂标识。
- 根据权利要求5、8-14任一项所述的方法,其中,所述第一身份标识包括SIM卡号。
- 根据权利要求10所述的方法,其中,所述方法还包括:在所述认证结果为认证失败的情况下,所述第一核心网设备向所述NCR对应的接入网设备反馈所述认证结果,其中,所述认证结果用于所述接入网设备拒绝所述入网请求。
- 根据权利要求1所述的方法,其中,所述网络侧设备为所述NCR对应的接入网设备。
- 根据权利要求17所述的方法,其中,所述方法还包括:在所述认证结果为认证成功的情况下,所述接入网设备将所述入网请求发送给第一核心网设备,其中,所述识别信息用于所述第一核心网设备给所述NCR分配入网凭证;所述接入网设备接收所述第一核心网设备发送的所述入网凭证,并将所述入网凭证发送至所述NCR,其中,所述入网凭证用于所述NCR接入网络。
- 根据权利要求17所述的方法,其中,所述方法还包括:在所述认证结果为认证失败的情况下,所述接入网设备拒绝所述入网请求。
- 根据权利要求7-11中任一项所述的方法,其中,所述第一核心网设备为核心网中的接入移动管理功能AMF。
- 根据权利要求1-20任一项所述的方法,其中,所述识别信息还包括NCR指示信息,所述NCR指示信息用于指示所述NCR为NCR节点。
- 根据权利要求16-21任一项所述的方法,其中,所述接入网设备为无线接入网设备。
- 根据权利要求6-9、18任一项所述的方法,其中,所述入网凭证为临时移动台标识符TMSI。
- 一种凭证分配方法,所述方法包括:第一核心网设备确定针对NCR的认证结果;在所述认证结果为认证通过的情况下,所述第一核心网设备给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
- 根据权利要求24所述的方法,其中,所述第一核心网设备确定针对NCR的认证结果,包括:所述第一核心网设备接收NCR认证节点发送的针对所述NCR的认证结果,其中,所述认证结果由所述NCR认证节点基于所述NCR的入网请求中携带的所述NCR的识别信息对所述NCR进行认证得到。
- 根据权利要求25所述的方法,其中,所述第一核心网设备给所述NCR分配入网凭证,包括:所述第一核心网设备给所述NCR分配入网凭证,并将所述入网凭证发送给所述NCR。
- 根据权利要求25或26所述的方法,其中,所述NCR认证节点为下述节点中的 一种:接入网中的一个独立节点;核心网中的一个节点;接入网网管的预设位置。
- 根据权利要求27所述的方法,其中,所述NCR认证节点为核心网中的一个节点,且所述NCR认证节点具体为核心网的如下节点之一:会话管理功能SMF;应用功能AF;统一数据管理UDM;接入移动管理功能AMF。
- 根据根据权利要求24所述的方法,其中,所述第一核心网设备确定针对NCR的认证结果,包括:所述第一核心网设备接收所述NCR的入网请求,其中,所述入网请求中携带有所述NCR的识别信息;所述第一核心网设备确定所述识别信息中是否包含所述NCR的第一身份标识,若包含,则基于所述第一身份标识对所述NCR进行认证,得到所述NCR的认证结果。
- 根据权利要求28所述的方法,其中,所述方法还包括:若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备将所述入网请求转发给所述第二核心网设备,其中,所述识别信息用于所述第二核心网设备验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;所述第一核心网设备接收所述第二核心网设备分配给所述NCR的第一身份标识,并将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
- 根据权利要求30所述的方法,其中,所述第二核心网设备包括下述一种:移动管理实体MME;会话管理功能SMF;用户平面功能UPF;策略控制功能PCF;策略与计费规则功能单元PCRF;边缘应用服务发现功能EASDF;统一数据管理UDM;统一数据仓储UDR;归属用户服务器HSS;集中式网络配置CNC;网络存储功能NRF;网络开放功能NEF;本地NEF;绑定支持功能BSF;应用功能AF。
- 根据权利要求28所述的方法,其中,所述第一核心网设备为接入移动管理功能AMF,所述方法还包括:若所述识别信息中不包含所述NCR的第一身份标识,则所述第一核心网设备基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识;所述第一核心网设备将分配给所述NCR的第一身份标识发送至所述NCR,其中,所述第一身份标识用于所述NCR携带在下一次入网请求中。
- 根据权利要求31或32所述的方法,其中,所述识别信息中包含所述NCR的第二身份标识。
- 根据权利要求33所述的方法,其中,所述NCR的第二身份标识包括所述NCR的出厂标识。
- 根据权利要求29、30-34任一项所述的方法,其中,所述第一身份标识包括SIM卡号。
- 根据权利要求24所述的方法,其中,所述第一核心网设备确定针对NCR的认证结果,包括:所述第一核心网设备接收所述NCR对应的接入网设备发送的所述NCR的认证结果,其中,所述认证结果是所述接入网设备基于所述NCR的入网请求中携带的所述NCR的识别信息对所述NCR进行认证得到的。
- 根据权利要求24-36任一项所述的方法,其中,所述方法还包括:在所述认证结果为认证失败的情况下,所述第一核心网设备向所述NCR对应的接入网设备反馈所述认证结果,其中,所述认证结果用于所述接入网设备拒绝所述入网请求。
- 根据权利要求24-31任一项所述的方法,其中,所述第一核心网设备为核心网中的接入移动管理功能AMF。
- 根据权利要求25-35中任一项所述的方法,其中,所述识别信息还包括NCR指示信息,所述NCR指示信息用于指示所述NCR为NCR节点。
- 根据权利要求36或37所述的方法,其中,所述接入网设备为无线接入网设备。
- 根据权利要求24-40任一项所述的方法,其中,所述入网凭证为临时移动台标识符TMSI。
- 一种标识分配方法,所述方法包括:第二核心网设备接收第一核心网设备发送的NCR的入网请求,其中,所述入网请求是所述第一核心网设备确定所述入网请求的识别信息中不包含所述NCR的第一身份标识的情况下发送的;所述第二核心网设备基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
- 根据权利要求41所述的方法,其中,所述识别信息中包含所述NCR的第二身份标识,其中,所述第二核心网设备基于所述识别信息验证所述NCR是否合法,包括:所述第二核心网设备基于所述第二身份标识验证所述NCR是否合法。
- 根据权利要求43所述的方法,其中,所述NCR的第二身份标识包括所述NCR的出厂标识。
- 根据权利要求41-44任一项所述的方法,其中,所述第二核心网设备在所述NCR合法的情况下给所述NCR分配第一身份标识,包括:所述第二核心网设备在所述NCR合法的情况下,给所述NCR分配第一身份标识并发送给所述NCR,以使所述NCR携带在下一次入网请求中。
- 根据权利要求41-45任一项所述的方法,其中,所述第一核心网设备为核心网中的接入移动管理功能AMF。
- 根据权利要求41-46任一项所述的方法,其中,所述识别信息还包括NCR指示信息,所述NCR指示信息用于指示所述NCR为NCR节点。
- 根据权利要求41-46任一项所述的方法,其中,所述第二核心网设备包括下述一种:接入移动管理功能AMF;移动管理实体MME;会话管理功能SMF;用户平面功能UPF;策略控制功能PCF;策略与计费规则功能单元PCRF;边缘应用服务发现功能EASDF;统一数据管理UDM;统一数据仓储UDR;归属用户服务器HSS;集中式网络配置CNC;网络存储功能NRF;网络开放功能NEF;本地NEF;绑定支持功能BSF;应用功能AF。
- 根据权利要求41-48任一项所述的方法,其中,所述第一身份标识包括SIM卡号。
- 一种设备认证方法,所述方法包括:中继设备NCR向网络侧设备发送入网请求,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证;所述NCR接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络。
- 根据权利要求50所述的方法,其中,所述网络侧设备包括接入网设备、NCR认证节点和第一核心网设备;其中,所述中继设备NCR向网络侧设备发送入网请求,包括:所述NCR向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述NCR认证节点,其中,所述入网请求用于请求所述NCR认证节点基于所述识别信息对所述NCR进行认证,并将所述NCR的认证结果发送给所述第一核心网设备,以使所述第一核心网设备在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备;其中,所述NCR接收所述网络侧设备发送的入网凭证,包括:所述NCR接收所述接入网设备发送的入网凭证。
- 根据权利要求51所述的方法,其中,所述NCR认证节点为下述节点中的一种:接入网中的一个独立节点;核心网中的一个节点;接入网网管的预设位置。
- 根据权利要求52所述的方法,其中,所述NCR认证节点为核心网中的一个节点,且所述NCR认证节点具体为核心网的如下节点之一:会话管理功能SMF;应用功能AF;统一数据管理UDM;接入移动管理功能AMF。
- 根据权利要求50所述的方法,其中,所述网络侧设备包括接入网设备和NCR认证节点,且所述NCR认证节点为AMF;其中,所述中继设备NCR向网络侧设备发送入网请求,包括:所述NCR向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述NCR认证节点,其中,所述入网请求用于请求所述NCR认证节点基于所述识别 信息对所述NCR进行认证,并在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备;其中,所述NCR接收所述网络侧设备发送的入网凭证,包括:所述NCR接收所述接入网设备发送的入网凭证。
- 根据权利要求54所述的方法,其中,所述识别信息包括第一身份标识。
- 根据权利要求50所述的方法,其中,所述网络侧设备包括接入网设备和第一核心网设备;其中,所述中继设备NCR向网络侧设备发送入网请求,包括:所述NCR向所述接入网设备发送入网请求,以使所述接入网设备将所述入网请求转发给所述第一核心网设备,其中,所述入网请求用于请求所述第一核心网设备基于所述识别信息对所述NCR进行认证,并在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备;其中,所述NCR接收所述网络侧设备发送的入网凭证,包括:所述NCR接收所述接入网设备发送的入网凭证。
- 根据权利要求56所述的方法,其中,所述网络侧设备还包括第二核心网设备,所述方法还包括:所述NCR接收所述接入网设备发送的第一身份标识,其中,所述第一身份标识是所述第一核心网确定所述识别信息中不含所述第一身份标识的情况下,由所述第二核心网设备分配给所述NCR的,且所述第一身份标识是所述第二核心网设备基于所述识别信息验证所述NCR合法的情况下分配的。
- 根据权利要求57所述的方法,其中,所述第二核心网设备包括下述一种:移动管理实体MME;会话管理功能SMF;用户平面功能UPF;策略控制功能PCF;策略与计费规则功能单元PCRF;边缘应用服务发现功能EASDF;统一数据管理UDM;统一数据仓储UDR;归属用户服务器HSS;集中式网络配置CNC;网络存储功能NRF;网络开放功能NEF;本地NEF;绑定支持功能BSF;应用功能AF。
- 根据权利要求56所述的方法,其中,所述第一核心网设备位接入移动管理功能AMF,所述方法还包括:所述NCR接收所述接入网设备发送的第一身份标识,其中,所述第一身份标识是所述第一核心网确定所述识别信息中不含所述第一身份标识的情况下分配给所述NCR的,且所述第一身份标识是所述第一核心网设备基于所述识别信息验证所述NCR合法的情况下分配的。
- 根据权利要求50所述的方法,其中,所述网络侧设备包括接入网设备和第一核心网设备;其中,所述中继设备NCR向网络侧设备发送入网请求,包括:所述NCR向所述接入网设备发送入网请求,其中,所述入网请求用于请求所述接入网设备基于所述识别信息对所述NCR进行认证,并将所述NCR的认证结果发送给所述第一核心网设备,以使所述第一核心网设备在所述认证结果为认证成功的情况下,给所述NCR分配入网凭证,并将所述入网凭证反馈给所述接入网设备;其中,所述NCR接收所述网络侧设备发送的入网凭证,包括:所述NCR接收所述接入网设备发送的入网凭证。
- 根据权利要求51-53、56-58中任一项所述的方法,其中,所述第一核心网设备为核心网中的接入移动管理功能AMF。
- 根据权利要求51-61任一项所述的方法,其中,所述接入网设备为无线接入网设备。
- 根据权利要求50-62任一项所述的方法,其中,所述识别信息还包括NCR指示信息,所述NCR指示信息用于指示所述NCR为NCR节点。
- 根据权利要求50-63任一项所述的方法,其中,所述入网凭证为临时移动台标识符TMSI。
- 根据权利要求55或57所述的方法,其中,所述第一身份标识包括SIM卡号。
- 一种设备认证装置,所述装置包括:第一请求接收模块,用于接收中继设备NCR的入网请求,所述入网请求中携带有所述NCR的识别信息;认证模块,用于基于所述识别信息对所述NCR进行认证,获得认证结果,其中,所述认证结果用于确定是否允许所述NCR接入网络。
- 一种凭证分配装置,所述装置包括:认证结果确定模块,用于第一核心网设备确定针对NCR的认证结果;凭证分配模块,用于在所述认证结果为认证通过的情况下,所述第一核心网设备给所述NCR分配入网凭证,其中,所述入网凭证用于所述NCR接入网络。
- 一种标识分配装置,所述装置包括:第二请求接收模块,用于接收第一核心网设备发送的NCR的入网请求,其中,所述入网请求是所述第一核心网设备确定所述入网请求的识别信息中不包含所述NCR的第一身份标识的情况下发送的;标识分配模块,用于基于所述识别信息验证所述NCR是否合法,并在所述NCR合法的情况下给所述NCR分配第一身份标识。
- 一种设备认证装置,所述装置包括:发送模块,用于向网络侧设备发送入网请求,其中,所述入网请求中携带有所述NCR的识别信息,所述入网请求用于请求所述网络侧设备基于所述标识信息对所述NCR进行认证,并在所述NCR认证成功的情况下,向所述NCR发送入网凭证;接收模块,用于接收所述网络侧设备发送的入网凭证,并基于所述入网凭证接入网络。
- 一种网络侧设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至23任一项所述的设备认证方法的步骤。
- 一种网络侧设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求24至41任一项所述的设备认证方法的步骤。
- 一种网络侧设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求42至48任一项所述的设备认证方法的步骤。
- 一种中继设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求50至65任一项所述的设备认证方法的步骤。
- 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1-23任一项所述的设备认证方法,或者实现如权利要求24至41任一项所述的凭证分配方法,或者实现如权利要求42至49任一项所述的标识分配方法,或者实现如权利要求50至65任一项所述的设备认证方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202210849257.9 | 2022-07-19 | ||
| CN202210849257.9A CN117459932A (zh) | 2022-07-19 | 2022-07-19 | 设备认证、凭证、标识分配方法、中继设备和网络侧设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024017124A1 true WO2024017124A1 (zh) | 2024-01-25 |
Family
ID=89582320
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/107125 Ceased WO2024017124A1 (zh) | 2022-07-19 | 2023-07-13 | 设备认证、凭证、标识分配方法、中继设备和网络侧设备 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117459932A (zh) |
| WO (1) | WO2024017124A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2026081211A1 (zh) * | 2024-10-18 | 2026-04-23 | Oppo广东移动通信有限公司 | 信息处理方法和设备 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20210105622A1 (en) * | 2019-08-26 | 2021-04-08 | Samsung Electronics Co., Ltd. | Method and apparatus for authentication of integrated access and backhaul (iab) node in wireless network |
| CN115136663A (zh) * | 2020-02-26 | 2022-09-30 | 中兴通讯股份有限公司 | 基于iab节点识别信息授权iab节点连接的系统和方法 |
-
2022
- 2022-07-19 CN CN202210849257.9A patent/CN117459932A/zh active Pending
-
2023
- 2023-07-13 WO PCT/CN2023/107125 patent/WO2024017124A1/zh not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20210105622A1 (en) * | 2019-08-26 | 2021-04-08 | Samsung Electronics Co., Ltd. | Method and apparatus for authentication of integrated access and backhaul (iab) node in wireless network |
| CN115136663A (zh) * | 2020-02-26 | 2022-09-30 | 中兴通讯股份有限公司 | 基于iab节点识别信息授权iab节点连接的系统和方法 |
Non-Patent Citations (2)
| Title |
|---|
| "3rd Generation Partnership Project; Technical Specification Group Radio Access network; Study on NR network-controlled repeaters; (Release 18)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 38.867, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.2.0, 16 September 2022 (2022-09-16), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, pages 1 - 18, XP052210810 * |
| FUJITSU: "Other issues on network-controlled repeaters", 3GPP DRAFT; R1-2205087, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. RAN WG1, no. e-Meeting; 20220509 - 20220520, 29 April 2022 (2022-04-29), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, XP052191746 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117459932A (zh) | 2024-01-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12452651B2 (en) | Method and device for activating 5G user | |
| KR102593822B1 (ko) | 무선 네트워크에서 서비스 거부 공격을 완화하기 위한 방법 및 시스템 | |
| US12231900B2 (en) | Communication method and apparatus | |
| US12401690B2 (en) | Mechanism for dynamic authorization | |
| US12382284B2 (en) | User equipment authentication and authorization procedure for edge data network | |
| US20250184731A1 (en) | Communication method and communication apparatus | |
| KR20210040776A (ko) | 5g 사용자 활성화 방법 및 장치 | |
| CN115843447B (zh) | 用户装备对边缘数据网络的接入的网络认证 | |
| JP7613818B2 (ja) | ネットワークノード及び通信方法 | |
| WO2024093783A1 (zh) | 操作执行方法、装置、终端及网络功能 | |
| WO2024017124A1 (zh) | 设备认证、凭证、标识分配方法、中继设备和网络侧设备 | |
| WO2022174399A1 (en) | User equipment authentication and authorization procedure for edge data network | |
| CN115412911A (zh) | 一种鉴权方法、通信装置和系统 | |
| US12323793B2 (en) | Edge enabler client identification authentication procedures | |
| CN105072666A (zh) | Wifi热点连接控制方法、服务器及wifi热点 | |
| WO2023141945A1 (en) | Authentication mechanism for access to an edge data network based on tls-psk | |
| US20260081835A1 (en) | Subscriber attribute based user plane function (upf) selection in wireless communication networks | |
| WO2024065483A1 (en) | Authentication procedures for edge computing in roaming deployment scenarios | |
| US20250106697A1 (en) | Interworking between fifth generation core (5gc) and evolved packet core (epc) in wireless communication networks | |
| EP4583493A1 (en) | Capability calling method and communication apparatus | |
| WO2025209362A1 (zh) | 通信方法、装置、设备及存储介质 | |
| KR20220138354A (ko) | 온보딩 네트워크를 통해 단말에게 자격증명을 제공하는 방법 및 장치 | |
| JP2025171504A (ja) | 認証システムおよび認証サーバ | |
| WO2025213393A1 (zh) | 用户认证方法、通信设备及存储介质 | |
| CN118945695A (zh) | 信息处理方法、信息传输方法、装置及相关设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23842189 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23842189 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23842189 Country of ref document: EP Kind code of ref document: A1 |