WO2024017181A1 - 设备授权方法、装置及网络侧设备 - Google Patents

设备授权方法、装置及网络侧设备 Download PDF

Info

Publication number
WO2024017181A1
WO2024017181A1 PCT/CN2023/107674 CN2023107674W WO2024017181A1 WO 2024017181 A1 WO2024017181 A1 WO 2024017181A1 CN 2023107674 W CN2023107674 W CN 2023107674W WO 2024017181 A1 WO2024017181 A1 WO 2024017181A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
matching
authentication
network function
following
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2023/107674
Other languages
English (en)
French (fr)
Inventor
谢振华
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Vivo Mobile Communication Co Ltd
Original Assignee
Vivo Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vivo Mobile Communication Co Ltd filed Critical Vivo Mobile Communication Co Ltd
Publication of WO2024017181A1 publication Critical patent/WO2024017181A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • This application belongs to the field of mobile communication technology, and specifically relates to a device authorization method, device and network side equipment.
  • the access device When the access device is connected to the mobile network through the gateway device, because the access device does not support Non Access Stratum (NAS) signaling, the authentication of the access device is not accurate enough and cannot prevent other devices from impersonating. The access device obtains some communication permissions of the access device, causing security risks.
  • NAS Non Access Stratum
  • Embodiments of the present application provide a device authorization method, device, and network-side equipment, which can solve the problem of inaccurate authentication of access devices.
  • a device authorization method applied to the first device, and the method includes:
  • the first device receives first information from the first network function
  • the first device initiates a first authentication process between the second network function and the second device in response to the first information, and the first authentication process includes authentication of the second device by the second network function. .
  • a device authorization device including:
  • a transceiver module configured to receive the first information from the first network function
  • An authentication module configured to initiate a first authentication process between a second network function and a second device in response to the first information, where the first authentication process includes authentication of the second device by the second network function.
  • a device authorization method applied to the first device, and the method includes:
  • the first device receives first information from the first network function, the first information including first matching information;
  • the first device receives second information from a second network function, the second information is obtained based on a first authentication process for the second device, and the second information includes second matching information;
  • the first device performs at least one of the following:
  • the third information is used to indicate at least one of the following:
  • a device authorization device including:
  • a transceiver module configured to receive first information from the first network function, where the first information includes first matching information
  • the transceiver module is also configured to receive second information from the second network function, the second information is obtained based on the first authentication process of the second device, and the second information includes second matching information;
  • An authentication module that performs at least one of the following:
  • the third information is used to indicate at least one of the following:
  • a device authorization method applied to the first network function, and the method includes:
  • the first network function sends first information to the first device, where the first information is used to indicate at least one of the following:
  • the second information is sent by the second network function based on the first authentication process of the second device, and the third information is used to indicate at least one of the following:
  • a device authorization device including:
  • the acquisition module is used to obtain the first information
  • a transmission module configured to send the first information to the first device, where the first information is used to indicate at least one of the following:
  • the second information is sent by the second network function based on the first authentication process of the second device, and the third information is used to indicate at least one of the following:
  • a device authorization method is provided, applied to the second network function, and the method includes:
  • the second network function performs the first authentication process with the second device
  • the second network function sends second information to the first device according to the first authentication process
  • the second information includes at least one of the following:
  • Second matching information the second matching information is used to match the first matching information sent by the first device.
  • a device authorization device including:
  • An execution module configured to execute the first authentication process with the second device
  • a sending module configured to send second information to the first device according to the first authentication process
  • the second information includes at least one of the following:
  • Second matching information the second matching information is used to match the first matching information sent by the first device.
  • a network side device in a ninth aspect, includes a processor and a memory.
  • the memory stores programs or instructions that can be run on the processor.
  • the program or instructions are executed by the processor.
  • a device authorization system including: a first device, a first network function and a second network function.
  • the first device can be used to perform the device authorization method as described in the first aspect or the third aspect.
  • the first network function may be used to perform the steps of the device authorization method as described in the fifth aspect, and the second network function may be used to perform the steps of the device authorization method as described in the seventh aspect.
  • a readable storage medium is provided.
  • Programs or instructions are stored on the readable storage medium.
  • the steps of the method described in the first aspect are implemented, or the steps of the method are implemented.
  • a chip in a twelfth aspect, includes a processor and a communication interface.
  • the communication interface is coupled to the processor.
  • the processor is used to run programs or instructions to implement the method described in the first aspect. Method, or implement the method as described in the third aspect, or implement the method as described in the fifth aspect, or implement the steps of the method as described in the seventh aspect.
  • a computer program/program product is provided, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement as described in the first aspect
  • the device authorization method or implements the device authorization method as described in the third aspect, or implements the device authorization method as described in the fifth aspect, or implements the steps of the device authorization method as described in the seventh aspect.
  • the first authentication process includes The second network function authenticates the second device by triggering the first authentication process by the first device responding to the first information, thereby realizing authorization of the second device when accessing the mobile network.
  • Figure 1 is a schematic structural diagram of a wireless communication system applicable to the embodiment of the present application.
  • Figure 2 is a schematic structural diagram of a device authorization system provided by an embodiment of the present application.
  • Figure 3 is a schematic flowchart of a device authorization method provided by an embodiment of the present application.
  • Figure 4 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
  • Figure 5 is a schematic diagram of the signaling flow of a device authorization method provided by an embodiment of the present application.
  • Figure 6 is a schematic structural diagram of a device authorization device provided by an embodiment of the present application.
  • Figure 7 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
  • Figure 8 is a schematic structural diagram of another device authorization device provided by an embodiment of the present application.
  • Figure 9 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
  • Figure 10 is a schematic structural diagram of another device authorization device provided by an embodiment of the present application.
  • Figure 11 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
  • Figure 12 is a schematic structural diagram of another device authorization device provided by an embodiment of the present application.
  • Figure 13 is a schematic structural diagram of a communication device provided by an embodiment of the present application.
  • Figure 14 is a schematic structural diagram of a network side device that implements an embodiment of the present application.
  • first, second, etc. in the description and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and that "first" and “second” are distinguished objects It is usually one type, and the number of objects is not limited.
  • the first object can be one or multiple.
  • “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the related objects are in an "or” relationship.
  • LTE Long Term Evolution
  • LTE-Advanced, LTE-A Long Term Evolution
  • LTE-A Long Term Evolution
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency Division Multiple Access
  • NR New Radio
  • FIG. 1 shows a block diagram of a wireless communication system to which embodiments of the present application are applicable.
  • the wireless communication system includes a terminal (also called User Equipment (UE)) 11 and a network side device 12 .
  • the terminal 11 may be Mobile phone, tablet computer (Tablet Personal Computer), laptop computer (Laptop Computer) or notebook computer, personal digital assistant (Personal Digital Assistant, PDA), handheld computer, netbook, ultra-mobile personal computer , UMPC), Mobile Internet Device (MID), augmented reality (AR)/virtual reality (VR) equipment, robots, wearable devices (Wearable Device), vehicle user equipment (Vehicle User) Equipment (VUE), Pedestrian User Equipment (PUE), smart home (home equipment with wireless communication functions, such as refrigerators, TVs, washing machines or furniture, etc.), game consoles, personal computers (PC), teller machines Or terminal-side devices such as self-service machines.
  • UE User Equipment
  • the network side device 12 may include an access network device or a core network device, where the access network device 12 may also be called a radio access network device, a radio access network (Radio Access Network, RAN), a radio access network function or Wireless access network unit.
  • the access network device 12 may include a base station, a Wireless Local Area Network (WLAN) access point or a WiFi node, etc.
  • WLAN Wireless Local Area Network
  • the base station may be called a Node B, an evolved Node B (eNB), an access point, Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home B-node, home evolved B-node , Transmitting Receiving Point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiment of the present application This introduction only takes the base station in the NR system as an example, and does not limit the specific type of base station.
  • eNB evolved Node B
  • BTS Base Transceiver Station
  • BSS Basic Service Set
  • ESS Extended Service Set
  • TRP Transmitting Receiving Point
  • Core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entities (Mobility Management Entity, MME), access mobility management functions (Access and Mobility Management Function, AMF), session management functions (Session Management Function, SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Service Discovery function (Edge Application Server Discovery Function, EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), centralized network configuration ( Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (Local NEF, or L-NEF), Binding Support Function (Binding Support Function, BSF), application function (Application Function, AF), etc.
  • MME mobility management entities
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • UPF User Plane Function
  • PCF Policy Control Function
  • the embodiment of the present application provides a device authorization method, and the execution subject of the method is the first A device, in other words, the method may be executed by software or hardware installed on the first device.
  • the method also includes the following steps.
  • the first device receives the first information from the first network function.
  • the embodiment of this application realizes the authentication of the personal Internet of Things device (PIN Element, PINE) 201 in the Personal Internet of Things (Personal IoT Networks, PIN) through the mobile network.
  • PIN personal Internet of Things device
  • the PIN also includes a personal IoT device with management functions.
  • IoT devices PIN Elements with Management Capability, PEMC
  • PIN devices with gateway capabilities PIN Elements with Gateway Capability, PEGC
  • the mobile network may include: a personal IoT management function (PIN Management Function, PINMF) 211 connected to the network where the access device is located, a session management function (Session Management Function, SMF) 212 in the mobile network, and a network opening function (Network Exposure Function (NEF), Policy Control Function (PCF), and Unified Data Management Function (Unified Data Management, UDM) 213 or third-party authentication functions, such as Authentication Authorization and Accounting (AAA).
  • PIN Management Function PIN Management Function
  • SMF Session Management Function
  • NEF Network Exposure Function
  • PCF Policy Control Function
  • UDM Unified Data Management Function
  • the first device may be a terminal, a network device or a network function.
  • the first device may be a PEMC or an SMF.
  • the first device is an SMF as an example.
  • the second device may be PINE
  • the third device may be PMEC
  • the fourth device may be PEGC.
  • the first network function may be PINMF, NEF or PCF.
  • the second network function may be UDM or AAA, etc.
  • the first network function After receiving a data forwarding or authentication request message from the second device from the third device and/or the fourth device, the first network function will send the first information to the first device.
  • the first information may include authentication instruction information, used to instruct a first authentication process between the second network function and the second device.
  • the first device In response to the first information, the first device initiates a first authentication process between the second network function and the second device.
  • the first authentication process includes the second network function authenticating the second device to the second network function. certification.
  • the first authentication process may be one-way or two-way.
  • the one-way authentication is the authentication of the second network function to the second device
  • the two-way authentication also includes the authentication of the second network function by the second device.
  • the authentication of the second device by the second network function is used as an example for illustration.
  • the method further includes:
  • the first device receives second information from the second network function, where the second information is obtained based on the first authentication process of the second device.
  • the second network function may send second information to the first device after completing the first authentication process on the second device.
  • the second information may include the authentication result of the first authentication process. Specifically, it may include: authentication successful. indication or authentication failure indication.
  • the second network function may also send the second information including the authentication success indication to the first device when the authentication result of the first authentication process is authentication success, but does not send the second information when the authentication result is authentication failure.
  • the first device may determine that the authentication of the second device has failed.
  • the first device performs at least one of the following:
  • the third information is used to indicate at least one of the following:
  • the authentication result information for the second device may, for example, include an authentication success indication or an authentication failure indication, etc.
  • the first device may perform matching of the first information and the second information according to the matching result information. If the matching result information is that the first information and the second information match, That is, corresponding to the same device, the third information including the matching success indication or the authentication success indication is sent to the first network function.
  • the first network function can determine whether the second device is suitable for the second device according to the received third information. Authorization is successful, and a response message indicating successful authentication or successful access is sent to the second device through the third device and/or the fourth device; if the matching result information is that the first information and the second information do not match , that is, corresponding to different devices, the third information is not sent to the first network function.
  • the first network function may also determine whether the third information is received within the preset time period. Second device authorization failed.
  • the first device may match the first information and the second information in various ways.
  • the first information includes first matching information
  • the second information includes second matching information.
  • the matching of the first information and the second information includes:
  • the first matching information and the second matching information can be set according to actual needs.
  • the first matching information and the second matching information include at least one of the following information:
  • Identification information such as device identification PINE ID or UE ID
  • IP Internet Protocol
  • the first network function determines whether to authorize the second device based on the received third information, and sends the authorization result to the third device and the fourth device through the feedback information, and then the third device and the fourth device send the authorization result to the second device.
  • the device authorization method mainly includes the following steps.
  • A1.PINE sends a relay request (PINE Relay Request) message to PINEMF through PEGC and PEMC.
  • the relay request message may include PINE's personal IoT identification (PIN ID) on the network, the personal IoT device of the second device Identification (PINE ID), data filtering rules (Packet filters), data network related identification (Data Network specific Identifier, DN-specific ID), etc.
  • the first information sends the first information to the SMF through NEF and PCF.
  • the first information can be activated by the relay.
  • the first information may include first matching information and authentication indication information, where the first matching information may be represented as authentication assistance information (Authentication Assistance Info),
  • the first information may also include: an optional User Permanent Identifier (Subscription Permanent Identifier, SUPI) or a Generic Public Subscription Identifier (GPSI), a terminal address (UE address), an optional data network Name (Data Network Name, DNN) or slice related information (such as Single Network Slice Selection Assistance Information (S-NSSAI), Network Slicing Identifier (NSI)), PIN ID, PINE ID , routing information between devices (Device to Device Routing Information, D2D Routing Info), routing information between devices and networks (Device to Network Routing Information, D2N Routing Info), routing information between networks (Network to Network Routing Information, N2N Routing Info) , downlink data process rules (Downlink Packet Filters, DL Pack
  • A4.SMF initiates the first authentication process between UDM and PINE or between AAA and PINE.
  • SMF performs authentication based on the EAP framework by sending an Extensible Authentication Protocol request message (Extensible Authentication Protocol, EAP Identity Request) to PINE. and authorization.
  • EAP Identity Request Extensible Authentication Protocol
  • AAA or UDM will send second information to the SMF.
  • the second information may include an authentication success indication and second matching information.
  • the second matching information may include: MAC address, number information, identification At least one of information, IP address and other matching information.
  • the SMF matches the first matching information and the second matching information.
  • A5-A6 SMF sends third information to PINMF through PCF and NEF, where the third information includes matching result information of the first matching information and the second matching information to indicate whether the matching is successful.
  • the third information may also include relay assistance information (Relay Assistance Info), specifically including PINE-related information, such as PINE's converted IPv6 address, converted IPv4 address and PI port range.
  • A7-A8.PINEMF sends feedback information to PEMC, PEGC, and PINE to indicate the request result.
  • the embodiments of the present application receive the first information from the first network function and initiate the first authentication process between the second network function and the second device in response to the first information.
  • the first authentication process includes authentication of the second device by the second network function, thereby realizing authorization of the second device when accessing the mobile network.
  • the execution subject may be a device authorization device.
  • the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
  • the device authorization device includes: a transceiver module 601 and an authentication module 602.
  • the transceiver module 601 is configured to receive first information from the first network function; the authentication module 602 is configured to initiate a first authentication process between the second network function and the second device in response to the first information.
  • the first authentication process includes authentication of the second device by the second network function.
  • the transceiver module 601 is also configured to receive second information from the second network function, where the second information is obtained based on the first authentication process of the second device;
  • the authentication module 602 is also used to perform at least one of the following:
  • the third information is used to indicate at least one of the following:
  • the first information includes first matching information
  • the second information includes second matching information
  • the authentication module 602 is used to match the first matching information and the second matching information.
  • the first information includes at least one of the following:
  • Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
  • the second information includes at least one of the following:
  • the first matching information and the second matching information include at least one of the following information:
  • the second network function is one of the following:
  • the embodiments of the present application receive the first information from the first network function and initiate the first authentication process between the second network function and the second device in response to the first information.
  • the first authentication process includes authentication of the second device by the second network function, thereby realizing authorization of the second device when accessing the mobile network.
  • the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be a terminal or other devices other than the terminal.
  • terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
  • NAS Network Attached Storage
  • the device authorization device provided by the embodiment of the present application can implement various processes implemented by the method embodiments of Figures 3 to 5, And achieve the same technical effect, to avoid repetition, they will not be described again here.
  • an embodiment of the present application provides a device authorization method.
  • the execution subject of the method is the first device.
  • the method can be executed by software or hardware installed on the first device.
  • the method also includes the following steps.
  • the first device receives first information from the first network function, where the first information includes first matching information;
  • the first device receives second information from the second network function, the second information is obtained based on the first authentication process of the second device, and the second information includes second matching information;
  • the first device performs at least one of the following:
  • the third information is used to indicate at least one of the following:
  • the first information also includes
  • Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
  • the second information also includes:
  • the first matching information and the second matching information include at least one of the following information:
  • the second network function is one of the following:
  • Steps S710-730 can implement the method embodiment of steps S330-340 as shown in Figure 4, and obtain the same technical effect, and the repeated parts will not be repeated here.
  • the embodiments of the present application receive first information from the first network function, where the first information includes first matching information; receive second information from the second network function, and the second information including second matching information; and matching the first matching information and the second matching information; sending third information to the first network function, thereby realizing the second matching when the second device accesses the mobile network.
  • Device authentication and authorization
  • the execution subject may be a device authorization device.
  • the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
  • the device authorization device includes: a transceiver module 801 and an authentication module 802.
  • the transceiver module 801 is configured to receive first information from a first network function, where the first information includes a first matching information. information; the transceiver module 801 is also configured to receive second information from the second network function, the second information is obtained based on the first authentication process of the second device, and the second information includes second matching information;
  • the authentication module 802 is used to perform at least one of the following:
  • the third information is used to indicate at least one of the following:
  • the first information also includes
  • Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
  • the second information also includes:
  • the first matching information and the second matching information include at least one of the following information:
  • the second network function is one of the following:
  • the embodiments of the present application receive first information from the first network function, where the first information includes first matching information; receive second information from the second network function, and the second information including second matching information; and matching the first matching information and the second matching information; sending third information to the first network function, thereby realizing the second matching when the second device accesses the mobile network.
  • Device authentication and authorization
  • the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be a terminal or other devices other than the terminal.
  • terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
  • NAS Network Attached Storage
  • the device authorization device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 7 and achieve the same technical effect. To avoid duplication, the details will not be described here.
  • this embodiment of the present application provides a device authorization method.
  • the execution subject of the method is the first network function.
  • the method can be executed by software or hardware installed in the first network function.
  • the method also includes the following steps.
  • the first network function sends first information to the first device, where the first information is used to indicate at least one of the following:
  • the second information is sent by the second network function based on the first authentication process of the second device, and the third information is used to indicate at least one of the following:
  • the first information includes at least one of the following:
  • Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
  • the first matching information includes at least one of the following information:
  • the second network function is one of the following:
  • Step S910 can implement the method embodiments shown in Figure 3 and Figure 4 and obtain the same technical effect, and the repeated parts will not be described again here.
  • the embodiments of the present application send first information to the first device, and the first information is used to indicate at least one of the following: performing the first authentication process between the second network function and the second device. ; Match the first information and the second information; send third information to the first network function, thereby realizing authentication and authorization of the second device when the second device accesses the mobile network.
  • the execution subject may be a device authorization device.
  • the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
  • the device authorization device includes: an acquisition module 1001 and a transmission module 1002.
  • the acquisition module 1001 is used to acquire first information; the transmission module 1002 is used to send the first information to a first device, where the first information is used to indicate at least one of the following:
  • the second information is sent by the second network function based on the first authentication process of the second device,
  • the third information is used to indicate at least one of the following:
  • the first information includes at least one of the following:
  • Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
  • the first matching information includes at least one of the following information:
  • the second network function is one of the following:
  • the embodiments of the present application send first information to the first device, and the first information is used to indicate at least one of the following: performing the first authentication process between the second network function and the second device. ; Match the first information and the second information; send third information to the first network function, thereby realizing authentication and authorization of the second device when the second device accesses the mobile network.
  • the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be a terminal or other devices other than the terminal.
  • terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
  • NAS Network Attached Storage
  • the device authorization device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 9 and achieve the same technical effect. To avoid duplication, details will not be described here.
  • this embodiment of the present application provides a device authorization method.
  • the execution subject of the method is the second network function.
  • the method can be executed by software or hardware installed in the second network function.
  • the method also includes the following steps.
  • the second network function sends second information to the first device according to the first authentication process
  • the second information includes at least one of the following:
  • Second matching information the second matching information is used to match the first matching information sent by the first device.
  • the first authentication process is initiated by the first device.
  • the first matching information and the second matching information include at least one of the following information:
  • the second network function is one of the following:
  • Steps S1110-S1120 can implement the method embodiment shown in Figure 3 or Figure 4, and obtain the same technical effect, and the repeated parts will not be described again here.
  • the embodiments of the present application perform a first authentication process with the second device and send second information to the first device according to the first authentication process; wherein, the second The information includes at least one of the following: an authentication success indication or an authentication failure indication; second matching information, the second matching information is used to match the first matching information sent by the first device, so that when the second device accesses the mobile network Implement authentication and authorization of the second device.
  • the execution subject may be a device authorization device.
  • the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
  • the device authorization device includes: an execution module 1201 and a sending module 1202.
  • the execution module 1201 is used to execute a first authentication process with a second device; the sending module 1202 is used to send second information to the first device according to the first authentication process;
  • the second information includes at least one of the following:
  • Second matching information the second matching information is used to match the first matching information sent by the first device.
  • the first authentication process is initiated by the first device.
  • the first matching information and the second matching information include at least one of the following information:
  • the second network function is one of the following:
  • the embodiments of the present application perform the first authentication process with the second device. process, and sends second information to the first device according to the first authentication process; wherein the second information includes at least one of the following: an authentication success indication or an authentication failure indication; second matching information, the second matching The information is used to match the first matching information sent by the first device, thereby realizing authentication and authorization of the second device when the second device accesses the mobile network.
  • the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
  • the electronic device may be a terminal or other devices other than the terminal.
  • terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
  • NAS Network Attached Storage
  • the device authorization device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 11 and achieve the same technical effect. To avoid duplication, the details will not be described here.
  • this embodiment of the present application also provides a communication device 1300, which includes a processor 1301 and a memory 1302.
  • the memory 1302 stores programs or instructions that can be run on the processor 1301, such as , when the communication device 1300 is a terminal, when the program or instruction is executed by the processor 1301, each step of the above device authorization method embodiment is implemented, and the same technical effect can be achieved.
  • the communication device 1300 is a network-side device, when the program or instruction is executed by the processor 1301, each step of the above device authorization method embodiment is implemented, and the same technical effect can be achieved. To avoid duplication, the details are not repeated here.
  • the embodiment of the present application also provides a network side device.
  • the network side device 1400 includes: a processor 1401, a network interface 1402, and a memory 1403.
  • the network interface 1402 is, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network side device 1400 in this embodiment of the present invention also includes: instructions or programs stored in the memory 1403 and executable on the processor 1401.
  • the processor 1401 calls the instructions or programs in the memory 1403 to execute Figures 6, 8,
  • the methods for executing each module shown in 10 or 12 achieve the same technical effect. To avoid repetition, they will not be repeated here.
  • Embodiments of the present application also provide a readable storage medium.
  • the readable storage medium may be non-transient or non-volatile.
  • the readable storage medium stores programs or instructions.
  • the program or instructions When executed by the processor, each process of the above device authorization method embodiment is implemented and can achieve the same technical effect. To avoid duplication, the details will not be described here.
  • the processor is the processor in the terminal described in the above embodiment.
  • the readable storage medium includes computer readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disk or optical disk, etc.
  • An embodiment of the present application further provides a chip.
  • the chip includes a processor and a communication interface.
  • the communication interface is coupled to the processor.
  • the processor is used to run programs or instructions to implement the above device authorization method embodiment. Each process can achieve the same technical effect. To avoid duplication, it will not be described again here.
  • chips mentioned in the embodiments of this application may also be called system-on-chip, system-on-a-chip, system-on-chip or system-on-chip, etc.
  • Embodiments of the present application further provide a computer program/program product.
  • the computer program/program product is stored in a storage medium.
  • the computer program/program product is executed by at least one processor to implement the above device authorization method embodiment.
  • Each process can achieve the same technical effect. To avoid repetition, we will not go into details here.
  • An embodiment of the present application also provides a device authorization system, including: a first device, a first network function and a second network function.
  • the first device can be used to perform the steps of the device authorization method as described above.
  • the third device One network function may be used to perform the steps of the device authorization method as described above, and the second network function may be used to perform the steps of the device authorization method as described above.
  • the methods of the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is better. implementation.
  • the technical solution of the present application can be embodied in the form of a computer software product that is essentially or contributes to related technologies.
  • the computer software product is stored in a storage medium (such as ROM/RAM, disk, CD), including several instructions to cause a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of this application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Power Engineering (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本申请公开了一种设备授权方法、装置及网络侧设备,属于移动通信领域,本申请实施例的设备授权方法包括:第一设备从第一网络功能接收第一信息;所述第一设备响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。

Description

设备授权方法、装置及网络侧设备
交叉引用
本申请要求在2022年07月22日提交中国专利局、申请号为202210868562.2、发明名称为“设备授权方法、装置及网络侧设备”的中国专利申请的优先权,该申请的全部内容通过引用结合在本申请中。
技术领域
本申请属于移动通信技术领域,具体涉及一种设备授权方法、装置及网络侧设备。
背景技术
在接入设备在通过网关设备接入到移动网络时,由于接入设备不支持非接入层(Non Access Stratum,NAS)信令,使得对接入设备的认证不够准确,无法防止其它设备冒充该接入设备来获得该接入设备的一些通信权限,造成安全隐患。
发明内容
本申请实施例提供一种设备授权方法、装置及网络侧设备,能够解决对接入设备的认证不够准确的问题。
第一方面,提供了一种设备授权方法,应用于第一设备,该方法包括:
第一设备从第一网络功能接收第一信息;
所述第一设备响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
第二方面,提供了一种设备授权装置,包括:
收发模块,用于从第一网络功能接收第一信息;
认证模块,用于响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
第三方面,提供了一种设备授权方法,应用于第一设备,该方法包括:
第一设备从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;
所述第一设备从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;
所述第一设备执行以下至少一项:
匹配所述第一匹配信息和所述第二匹配信息;
向所述第一网络功能发送第三信息;
其中,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一匹配信息和第二信息的匹配结果信息。
第四方面,提供了一种设备授权装置,包括:
收发模块,用于从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;
所述收发模块,还用于从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;
认证模块,用于执行以下至少一项:
匹配所述第一匹配信息和所述第二匹配信息;
向所述第一网络功能发送第三信息;
其中,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一匹配信息和第二信息的匹配结果信息。
第五方面,提供了一种设备授权方法,应用于第一网络功能,该方法包括:
第一网络功能向第一设备发送第一信息,所述第一信息用于指示以下至少一项:
进行第二网络功能与第二设备的第一认证过程;
匹配所述第一信息和第二信息;
向所述第一网络功能发送第三信息;
其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一信息和第二信息的匹配结果信息。
第六方面,提供了一种设备授权装置,包括:
获取模块,用于获取第一信息;
传输模块,用于向第一设备发送所述第一信息,所述第一信息用于指示以下至少一项:
进行第二网络功能与第二设备的第一认证过程;
匹配所述第一信息和第二信息;
向设备授权装置发送第三信息;
其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一信息和第二信息的匹配结果信息。
第七方面,提供了一种设备授权方法,应用于第二网络功能,该方法包括:
第二网络功能执行与第二设备之间的第一认证过程;
所述第二网络功能根据所述第一认证过程向第一设备发送第二信息;
其中,所述第二信息包括以下至少一项:
认证成功指示或认证失败指示;
第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
第八方面,提供了一种设备授权装置,包括:
执行模块,用于执行与第二设备之间的第一认证过程;
发送模块,用于根据所述第一认证过程向第一设备发送第二信息;
其中,所述第二信息包括以下至少一项:
认证成功指示或认证失败指示;
第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
第九方面,提供了一种网络侧设备,该网络侧设备包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面所述的方法,或者实现如第三方面所述的方法,或者实现如第五方面所述的方法,或者实现如第七方面所述的方法的步骤。
第十方面,提供了一种设备授权系统,包括:第一设备、第一网络功能和第二网络功能,所述第一设备可用于执行如第一方面或第三方面所述的设备授权方法的步骤,所述第一网络功能可用于执行如第五方面所述的设备授权方法的步骤,所述第二网络功能可用于执行如第七方面所述的设备授权方法的步骤。
第十一方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面所述的方法的步骤,或者实现如第三方面所述的方法的步骤,或者实现如第五方面所述的方法的步骤,或者实现如第七方面所述的方法的步骤。
第十二方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面所述的方法,或者实现如第三方面所述的方法,或者实现如第五方面所述的方法,或者实现如第七方面所述的方法的步骤。
第十三方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现如第一方面所述的设备授权方法,或者实现如第三方面所述的设备授权方法,或者实现如第五方面所述的设备授权方法,或者实现如第七方面所述的设备授权方法的步骤。
在本申请实施例中,通过从第一网络功能接收第一信息,并响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证,即通过第一设备响应第一信息触发第一认证过程,从而实现了第二设备在接入到移动网络时的授权。
附图说明
图1是本申请实施例可应用的一种无线通信系统的结构示意图;
图2是本申请实施例提供的一种设备授权系统的结构示意图;
图3是本申请实施例提供的一种设备授权方法的流程示意图;
图4是本申请实施例提供的另一种设备授权方法的流程示意图;
图5是本申请实施例提供的一种设备授权方法的信令流程示意图;
图6是本申请实施例提供的一种设备授权装置的结构示意图;
图7是本申请实施例提供的另一种设备授权方法的流程示意图;
图8是本申请实施例提供的另一种设备授权装置的结构示意图;
图9是本申请实施例提供的另一种设备授权方法的流程示意图;
图10是本申请实施例提供的另一种设备授权装置的结构示意图;
图11是本申请实施例提供的另一种设备授权方法的流程示意图;
图12是本申请实施例提供的另一种设备授权装置的结构示意图;
图13是本申请实施例提供的一种通信设备结构示意图;
图14为实现本申请实施例的一种网络侧设备的结构示意图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统应用以外的应用,如第6代(6th Generation,6G)通信系统。
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端(也称为用户设备(User Equipment,UE))11和网络侧设备12。其中,终端11可以是 手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(augmented reality,AR)/虚拟现实(virtual reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(personal computer,PC)、柜员机或者自助机等终端侧设备,可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以包括接入网设备或核心网设备,其中,接入网设备12也可以称为无线接入网设备、无线接入网(Radio Access Network,RAN)、无线接入网功能或无线接入网单元。接入网设备12可以包括基站、无线局域网(Wireless Local Area Network,WLAN)接入点或WiFi节点等,基站可被称为节点B、演进节点B(evolved Node B,eNB)、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点、家用演进型B节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM),统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF),网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的设备授权方法、装置及网络侧设备进行详细地说明。
如图2和图3所示,本申请实施例提供了一种设备授权方法,该方法的执行主体为第 一设备,换言之,该方法可以由安装在第一设备的软件或硬件来执行。所述方法还包括以下步骤。
S310、第一设备从第一网络功能接收第一信息。
本申请实施例通过移动网络实现对个人物联网(Personal IoT Networks,PIN)中个人物联网设备(PIN Element,PINE)201进行认证,如图2所示,所述PIN还包括具有管理功能的个人物联网设备(PIN Elements with Management Capability,PEMC)202和具有网关功能的个人物联网设备(PIN Elements with Gateway Capability,PEGC)203。所述移动网络可以包括:与接入设备所在网络连接的个人物联网管理功能(PIN Management Function,PINMF)211、移动网络中的会话管理功能(Session Management Function,SMF)212、网络开放功能(Network Exposure Function,NEF)、策略控制功能(Policy Control Function,PCF)以及统一数据管理功能(Unified Data Management,UDM)213或第三方认证功能,例如认证授权和计费(Authentication Authorization Accounting,AAA)。
所述第一设备可以是终端也可以是网络设备或网络功能,如图2所示,所述第一设备可以为PEMC,也可以为SMF。为了简便起见,在下面的实施例中均以第一设备为SMF为例进行举例说明。相应地,在下面的实施例中所述第二设备可以为PINE,第三设备可以为PMEC,第四设备为PEGC,所述第一网络功能可以为PINMF,也可以为NEF或PCF,所述第二网络功能可以为UDM或AAA等。
第一网络功能在从第三设备和/或第四设备接收到第二设备的数据转发或认证等请求消息后,将向第一设备发送第一信息。
所述第一信息可以包括认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
S320、所述第一设备响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
所述第一认证过程可以为单向或双向两种,其中单向认证为第二网络功能对第二设备的认证,所述双向认证则还包括第二设备对第二网络功能的认证,为了简便起见,在下面实施例中均以第二网络功能对第二设备的认证为例进行举例说明。
可选的,如图4所示,在步骤S320之后,所述方法还包括:
S330、所述第一设备从所述第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的。
所述第二网络功能可以完成对第二设备的第一认证过程后向所述第一设备发送第二信息,所述第二信息可以包括第一认证过程的认证结果,具体可以包括:认证成功指示或认证失败指示。或者,所述第二网络功能也可以在第一认证过程的认证结果为认证成功的情况下向第一设备发送包括认证成功指示的第二信息,而在认证结果为认证失败的情况下不发送相应的第二信息,相应地,所述第一设备也可以在预设时间段内未接收第二信息的情况下判定对第二设备认证失败。
S340、所述第一设备执行以下至少一项:
匹配所述第一信息和所述第二信息,根据匹配结果可以确认所述第二信息和第一信息是否对应于同一个设备,即第一认证过程执行对象是否为第二设备;
向所述第一网络功能发送第三信息;
其中,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息,例如,可以包括认证成功指示或认证失败指示等;
所述第一信息和所述第二信息的匹配结果信息。
在一种实施方式中,所述第一设备可以在执行匹配所述第一信息和第二信息后根据匹配结果信息,若所述匹配结果信息为所述第一信息和第二信息相匹配,即对应于同一个设备,则向所述第一网络功能发送包括匹配成功指示或认证成功指示的第三信息,相应地,第一网络功能则可以根据接收到的第三信息判定对第二设备授权成功,并通过第三设备和/或第四设备向第二设备发送用于指示认证成功或接入成功的响应消息;若所述匹配结果信息为所述第一信息和第二信息不匹配,即对应于不同的设备,则不向所述第一网络功能发送第三信息,相应地,所述第一网络功能也可以在预设时间段内未接收到第三信息的情况下判定对第二设备授权失败。
所述第一设备匹配所述第一信息与第二信息的方式可以多种多样,在一种实施方式中,所述第一信息包括第一匹配信息,所述第二信息包括第二匹配信息,所述匹配所述第一信息和所述第二信息包括:
匹配所述第一匹配信息和第二匹配信息。
所述第一匹配信息和第二匹配信息可以根据实际的需要进行设定,在一种实施方式中,所述第一匹配信息和第二匹配信息包括以下至少一种信息:
媒体接入控制(Medium Access Control,MAC)地址;
号码信息;
标识信息,例如设备标识PINE ID或UE ID;
互联网协议(Internet Protocol,IP)地址信息;
其它匹配信息,例如令牌(token)、预置的匹配字符串等。
所述第一网络功能根据接收到的第三信息确定是否实现对第二设备的授权,并通过反馈信息将授权结果发送给第三设备和第四设备,再由第三设备和第四设备发送给第二设备。
基于上述实施例,如图5所示,本申请实施例给出了一种具体的信令流程示意图,所述设备授权方法主要包括以下步骤。
A1.PINE通过PEGC和PEMC向PINEMF发送中继请求(PINE Relay Request)消息,所述中继请求消息可以包括PINE处在网络的个人物联网标识(PIN ID),第二设备的个人物联网设备标识(PINE ID),数据过滤规则(Packet filters),数据网相关标识(Data Network specific Identifier,DN-specific ID)等。
A2-A3.PINMF通过NEF和PCF向SMF发送第一信息,所述第一信息可以由中继激 活或去激活请求(Relay Activate/Deactivate Request)消息承载,所述第一信息可以包括第一匹配信息和认证指示信息,其中所述第一匹配信息可以表示为认证辅助信息(Authentication Assistance Info),另外,所述第一信息还可以包括:可选的用户永久标识(Subscription Permanent Identifier,SUPI)或通用公共用户标识(Generic Public Subscription Identifier,GPSI),终端地址(UE address),可选的数据网络名称(Data Network Name,DNN)或切片相关信息(比如单网络切片选择辅助信息(Single Network Slice Selection Assistance Information,S-NSSAI)、网络切片标识(Network Slicing Identifier,NSI)),PIN ID,PINE ID,设备间路由信息(Device to Device Routing Information,D2D Routing Info),设备与网间路由信息(Device to Network Routing Information,D2N Routing Info),网间路由信息(Network to Network Routing Information,N2N Routing Info),下行数据过程规则(Downlink Packet Filters,DL Packet filters),上行数据过滤规则(Uplink Packet filter,UL Packet filters),框架路由信息(Framed Route Info),服务质量参考(Quality of Service reference,QoS reference)等。所述认证辅助信息可以包括:MAC地址、号码信息、标识信息、IP地址和其它匹配信息中的至少一项。
A4.SMF发起UDM与PINE之间或者AAA与PINE之间的第一认证过程,例如,SMF通过向PINE发送可拓展认证协议请求消息(Extensible Authentication Protocol,EAP Identity Request),从而基于EAP框架执行认证和授权。在认证成功的情况下,AAA或UDM将向SMF发送第二信息,所述第二信息可以包括认证成功指示和第二匹配信息,所述第二匹配信息可以包括:MAC地址、号码信息、标识信息、IP地址和其它匹配信息中的至少一项。SMF匹配第一匹配信息和第二匹配信息。
A5-A6.SMF通过PCF、NEF向PINMF发送第三信息,所述第三信息包括第一匹配信息和第二匹配信息的匹配结果信息用于指示匹配是否成功。所述第三信息还可以包括中继辅助信息(Relay Assistance Info),具体包括PINE的相关信息,例如,PINE的转换的IPv6地址,转换的IPv4地址和PI端口(port)范围。
A7-A8.PINEMF向PEMC、PEGC、PINE发送反馈信息,用于指示请求结果。
由上述实施例的技术方案可知,本申请实施例通过从第一网络功能接收第一信息,并响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证,从而实现了第二设备在接入到移动网络时的授权。
本申请实施例提供的设备授权方法,执行主体可以为设备授权装置。本申请实施例中以设备授权装置执行设备授权方法为例,说明本申请实施例提供的设备授权装置。
如图6所示,所述设备授权装置包括:收发模块601和认证模块602。
所述收发模块601用于从第一网络功能接收第一信息;所述认证模块602用于响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
可选的,所述收发模块601还用于从所述第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的;
所述认证模块602还用于执行以下至少一项:
匹配所述第一信息和所述第二信息;
向所述第一网络功能发送第三信息;
其中,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一信息和所述第二信息的匹配结果信息。
可选的,所述第一信息包括第一匹配信息,所述第二信息包括第二匹配信息,所述认证模块602用于匹配所述第一匹配信息和第二匹配信息。
可选的,所述第一信息包括以下至少一项:
第一匹配信息;
认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
可选的,所述第二信息包括以下至少一项:
认证成功指示或认证失败指示;
第二匹配信息。
可选的,所述第一匹配信息和第二匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理功能;
第三方认证功能。
由上述实施例的技术方案可知,本申请实施例通过从第一网络功能接收第一信息,并响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证,从而实现了第二设备在接入到移动网络时的授权。
本申请实施例中的设备授权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的设备授权装置能够实现图3至图5的方法实施例实现的各个过程, 并达到相同的技术效果,为避免重复,这里不再赘述。
如图7所述,本申请实施例提供了一种设备授权方法,该方法的执行主体为第一设备,换言之,该方法可以由安装在第一设备的软件或硬件来执行。所述方法还包括以下步骤。
S710、第一设备从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;
S720、所述第一设备从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;
S730、所述第一设备执行以下至少一项:
匹配所述第一匹配信息和所述第二匹配信息;
向所述第一网络功能发送第三信息;
其中,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一匹配信息和第二信息的匹配结果信息。
可选的,所述第一信息还包括
认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
可选的,所述第二信息还包括:
认证成功指示或认证失败指示。
可选的,所述第一匹配信息和第二匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理实体;
第三方认证功能。
步骤S710-730可以实现如图4所示的步骤S330-340的方法实施例,并得到相同的技术效果,重复部分此处不再赘述。
由上述实施例的技术方案可知,本申请实施例通过从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;从第二网络功能接收第二信息,所述第二信息包括第二匹配信息;并匹配所述第一匹配信息和所述第二匹配信息;向所述第一网络功能发送第三信息,从而在第二设备接入到移动网络时实现了对第二设备的认证和授权。
本申请实施例提供的设备授权方法,执行主体可以为设备授权装置。本申请实施例中以设备授权装置执行设备授权方法为例,说明本申请实施例提供的设备授权装置。
如图8所示,所述设备授权装置包括:收发模块801和认证模块802。
所述收发模块801用于从第一网络功能接收第一信息,所述第一信息包括第一匹配信 息;所述收发模块801还用于从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;所述认证模块802用于执行以下至少一项:
匹配所述第一匹配信息和所述第二匹配信息;
向所述第一网络功能发送第三信息;
其中,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一匹配信息和第二信息的匹配结果信息。
可选的,所述第一信息还包括
认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
可选的,所述第二信息还包括:
认证成功指示或认证失败指示。
可选的,所述第一匹配信息和第二匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理实体;
第三方认证功能。
由上述实施例的技术方案可知,本申请实施例通过从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;从第二网络功能接收第二信息,所述第二信息包括第二匹配信息;并匹配所述第一匹配信息和所述第二匹配信息;向所述第一网络功能发送第三信息,从而在第二设备接入到移动网络时实现了对第二设备的认证和授权。
本申请实施例中的设备授权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的设备授权装置能够实现图7的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
如图9所述,本申请实施例提供了一种设备授权方法,该方法的执行主体为第一网络功能,换言之,该方法可以由安装在第一网络功能的软件或硬件来执行。所述方法还包括以下步骤。
S910、第一网络功能向第一设备发送第一信息,所述第一信息用于指示以下至少一项:
进行第二网络功能与第二设备的第一认证过程;
匹配所述第一信息和第二信息;
向所述第一网络功能发送第三信息;
其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一信息和第二信息的匹配结果信息。
可选的,所述第一信息包括以下至少一项:
第一匹配信息;
认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
可选的,所述第一匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理实体;
第三方认证功能。
步骤S910可以实现如图3和图4所示的方法实施例,并得到相同的技术效果,重复部分此处不再赘述。
由上述实施例的技术方案可知,本申请实施例通过向第一设备发送第一信息,所述第一信息用于指示以下至少一项:进行第二网络功能与第二设备的第一认证过程;匹配所述第一信息和第二信息;向所述第一网络功能发送第三信息,从而在第二设备接入移动网络时实现对第二设备的认证和授权。
本申请实施例提供的设备授权方法,执行主体可以为设备授权装置。本申请实施例中以设备授权装置执行设备授权方法为例,说明本申请实施例提供的设备授权装置。
如图10所示,所述设备授权装置包括:获取模块1001和传输模块1002。
所述获取模块1001用于获取第一信息;所述传输模块1002用于向第一设备发送所述第一信息,所述第一信息用于指示以下至少一项:
进行第二网络功能与第二设备的第一认证过程;
匹配所述第一信息和第二信息;
向设备授权装置发送第三信息;
其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的, 所述第三信息用于指示以下至少一项:
对所述第二设备的认证结果信息;
所述第一信息和第二信息的匹配结果信息。
可选的,所述第一信息包括以下至少一项:
第一匹配信息;
认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
可选的,所述第一匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理实体;
第三方认证功能。
由上述实施例的技术方案可知,本申请实施例通过向第一设备发送第一信息,所述第一信息用于指示以下至少一项:进行第二网络功能与第二设备的第一认证过程;匹配所述第一信息和第二信息;向所述第一网络功能发送第三信息,从而在第二设备接入移动网络时实现对第二设备的认证和授权。
本申请实施例中的设备授权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的设备授权装置能够实现图9的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
如图11所述,本申请实施例提供了一种设备授权方法,该方法的执行主体为第二网络功能,换言之,该方法可以由安装在第二网络功能的软件或硬件来执行。所述方法还包括以下步骤。
S1110、第二网络功能执行与第二设备之间的第一认证过程;
S1120、所述第二网络功能根据所述第一认证过程向第一设备发送第二信息;
其中,所述第二信息包括以下至少一项:
认证成功指示或认证失败指示;
第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
可选的,所述第一认证过程由所述第一设备发起。
可选的,第一匹配信息和第二匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理实体;
第三方认证功能。
步骤S1110-S1120可以实现如图3或图4所示的方法实施例,并得到相同的技术效果,重复部分此处不再赘述。
由上述实施例的技术方案可知,本申请实施例通过执行与第二设备之间的第一认证过程,并根据所述第一认证过程向第一设备发送第二信息;其中,所述第二信息包括以下至少一项:认证成功指示或认证失败指示;第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息,从而在第二设备接入移动网络时实现对第二设备的认证和授权。
本申请实施例提供的设备授权方法,执行主体可以为设备授权装置。本申请实施例中以设备授权装置执行设备授权方法为例,说明本申请实施例提供的设备授权装置。
如图12所示,所述设备授权装置包括:执行模块1201和发送模块1202。
所述执行模块1201用于执行与第二设备之间的第一认证过程;所述发送模块1202用于根据所述第一认证过程向第一设备发送第二信息;
其中,所述第二信息包括以下至少一项:
认证成功指示或认证失败指示;
第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
可选的,所述第一认证过程由所述第一设备发起。
可选的,第一匹配信息和第二匹配信息包括以下至少一种信息:
媒体接入控制地址;
号码信息;
标识信息;
互联网协议地址信息;
其它匹配信息。
可选的,所述第二网络功能为以下之一:
统一数据管理实体;
第三方认证功能。
由上述实施例的技术方案可知,本申请实施例通过执行与第二设备之间的第一认证过 程,并根据所述第一认证过程向第一设备发送第二信息;其中,所述第二信息包括以下至少一项:认证成功指示或认证失败指示;第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息,从而在第二设备接入移动网络时实现对第二设备的认证和授权。
本申请实施例中的设备授权装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的设备授权装置能够实现图11的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
可选的,如图13所示,本申请实施例还提供一种通信设备1300,包括处理器1301和存储器1302,存储器1302上存储有可在所述处理器1301上运行的程序或指令,例如,该通信设备1300为终端时,该程序或指令被处理器1301执行时实现上述设备授权方法实施例的各个步骤,且能达到相同的技术效果。该通信设备1300为网络侧设备时,该程序或指令被处理器1301执行时实现上述设备授权方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。
具体地,本申请实施例还提供了一种网络侧设备。如图14所示,该网络侧设备1400包括:处理器1401、网络接口1402和存储器1403。其中,网络接口1402例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本发明实施例的网络侧设备1400还包括:存储在存储器1403上并可在处理器1401上运行的指令或程序,处理器1401调用存储器1403中的指令或程序执行图6、8、10或12所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质可以是非瞬态的,也可以是非易失性的,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述设备授权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述设备授权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述设备授权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种设备授权系统,包括:第一设备、第一网络功能和第二网络功能,所述第一设备可用于执行如上所述的设备授权方法的步骤,所述第一网络功能可用于执行如上所述的设备授权方法的步骤,所述第二网络功能可用于执行如上所述的设备授权方法的步骤。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对相关技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (26)

  1. 一种设备授权方法,包括:
    第一设备从第一网络功能接收第一信息;
    所述第一设备响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
  2. 根据权利要求1所述的方法,其中,所述方法还包括:
    所述第一设备从所述第二网络功能接收第二信息,所述第二信息为基于对所述第二设备的第一认证过程得到的;
    所述第一设备执行以下至少一项:
    匹配所述第一信息和所述第二信息;
    向所述第一网络功能发送第三信息;
    其中,所述第三信息用于指示以下至少一项:
    对所述第二设备的认证结果信息;
    所述第一信息和所述第二信息的匹配结果信息。
  3. 根据权利要求2所述的方法,其中,所述第一信息包括第一匹配信息,所述第二信息包括第二匹配信息,所述匹配所述第一信息和所述第二信息包括:
    匹配所述第一匹配信息和第二匹配信息。
  4. 根据权利要求2所述的方法,其中,所述第一信息包括以下至少一项:
    第一匹配信息;
    认证指示信息,用于指示进行所述第二网络功能与所述第二设备的第一认证过程。
  5. 根据权利要求2所述的方法,所述第二信息包括以下至少一项:
    认证成功指示或认证失败指示;
    第二匹配信息。
  6. 根据权利要求3所述的方法,其中,所述第一匹配信息和第二匹配信息包括以下至少一种信息:
    媒体接入控制地址;
    号码信息;
    标识信息;
    互联网协议地址信息;
    其它匹配信息。
  7. 根据权利要求1所述的方法,其中,所述第二网络功能为以下之一:
    统一数据管理功能;
    第三方认证功能。
  8. 一种设备授权装置,包括:
    收发模块,用于从第一网络功能接收第一信息;
    认证模块,用于响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
  9. 一种设备授权方法,包括:
    第一设备从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;
    所述第一设备从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;
    所述第一设备执行以下至少一项:
    匹配所述第一匹配信息和所述第二匹配信息;
    向所述第一网络功能发送第三信息;
    其中,所述第三信息用于指示以下至少一项:
    对所述第二设备的认证结果信息;
    所述第一匹配信息和第二信息的匹配结果信息。
  10. 根据权利要求9所述的方法,其中,所述第一信息还包括
    认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
  11. 根据权利要求9所述的方法,其中,所述第二信息还包括:
    认证成功指示或认证失败指示。
  12. 根据权利要求9任一所述的方法,其中,所述第一匹配信息和第二匹配信息包括以下至少一种信息:
    媒体接入控制地址;
    号码信息;
    标识信息;
    互联网协议地址信息;
    其它匹配信息。
  13. 根据权利要求9所述的方法,其中,所述第二网络功能为以下之一:
    统一数据管理实体;
    第三方认证功能。
  14. 一种设备授权装置,包括:
    收发模块,用于从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;
    所述收发模块,还用于从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;
    认证模块,用于执行以下至少一项:
    匹配所述第一匹配信息和所述第二匹配信息;
    向所述第一网络功能发送第三信息;
    其中,所述第三信息用于指示以下至少一项:
    对所述第二设备的认证结果信息;
    所述第一匹配信息和第二信息的匹配结果信息。
  15. 一种设备授权方法,包括:
    第一网络功能向第一设备发送第一信息,所述第一信息用于指示以下至少一项:
    进行第二网络功能与第二设备的第一认证过程;
    匹配所述第一信息和第二信息;
    向所述第一网络功能发送第三信息;
    其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:
    对所述第二设备的认证结果信息;
    所述第一信息和第二信息的匹配结果信息。
  16. 根据权利要求15所述的方法,其中,所述第一信息包括以下至少一项:
    第一匹配信息;
    认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
  17. 根据权利要求16所述的方法,其中,所述第一匹配信息包括以下至少一种信息:
    媒体接入控制地址;
    号码信息;
    标识信息;
    互联网协议地址信息;
    其它匹配信息。
  18. 根据权利要求15所述的方法,其中,所述第二网络功能为以下之一:
    统一数据管理实体;
    第三方认证功能。
  19. 一种设备授权装置,包括:
    获取模块,用于获取第一信息;
    传输模块,用于向第一设备发送所述第一信息,所述第一信息用于指示以下至少一项:
    进行第二网络功能与第二设备的第一认证过程;
    匹配所述第一信息和第二信息;
    向设备授权装置发送第三信息;
    其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:
    对所述第二设备的认证结果信息;
    所述第一信息和第二信息的匹配结果信息。
  20. 一种设备授权方法,包括:
    第二网络功能执行与第二设备之间的第一认证过程;
    所述第二网络功能根据所述第一认证过程向第一设备发送第二信息;
    其中,所述第二信息包括以下至少一项:
    认证成功指示或认证失败指示;
    第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
  21. 根据权利要求20所述的方法,其中,所述第一认证过程由所述第一设备发起。
  22. 根据权利要求20所述的方法,其中,第一匹配信息和第二匹配信息包括以下至少一种信息:
    媒体接入控制地址;
    号码信息;
    标识信息;
    互联网协议地址信息;
    其它匹配信息。
  23. 根据权利要求20所述的方法,其中,所述第二网络功能为以下之一:
    统一数据管理实体;
    第三方认证功能。
  24. 一种设备授权装置,包括:
    执行模块,用于执行与第二设备之间的第一认证过程;
    发送模块,用于根据所述第一认证过程向第一设备发送第二信息;
    其中,所述第二信息包括以下至少一项:
    认证成功指示或认证失败指示;
    第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
  25. 一种网络侧设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至7任一项所述的设备授权方法,或者实现如权利要求9至13任一项所述的设备授权方法,或者实现如权利要求15至18任一项所述的设备授权方法,或者实现如权利要求20至23任一项所述的设备授权方法的步骤。
  26. 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至7任一项所述的设备授权方法,或者实现如权利要求9至13任一项所述的设备授权方法,或者实现如权利要求15至18任一项所述的设备授权方法,或者实现如权利要求20至23任一项所述的设备授权方法的步骤。
PCT/CN2023/107674 2022-07-22 2023-07-17 设备授权方法、装置及网络侧设备 Ceased WO2024017181A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202210868562.2 2022-07-22
CN202210868562.2A CN117479158A (zh) 2022-07-22 2022-07-22 设备授权方法、装置及网络侧设备

Publications (1)

Publication Number Publication Date
WO2024017181A1 true WO2024017181A1 (zh) 2024-01-25

Family

ID=89617145

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/107674 Ceased WO2024017181A1 (zh) 2022-07-22 2023-07-17 设备授权方法、装置及网络侧设备

Country Status (2)

Country Link
CN (1) CN117479158A (zh)
WO (1) WO2024017181A1 (zh)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2019017836A1 (zh) * 2017-07-20 2019-01-24 华为国际有限公司 一种会话处理方法及设备
CN109511115A (zh) * 2017-09-14 2019-03-22 华为技术有限公司 一种授权方法和网元
WO2022148619A1 (en) * 2021-01-11 2022-07-14 Telefonaktiebolaget Lm Ericsson (Publ) User equipment (ue) identifier request

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2933981B1 (en) * 2014-04-17 2018-08-01 Comptel OY Method and system of user authentication
US20190287110A1 (en) * 2016-02-03 2019-09-19 Cloudwear, Inc. Method and apparatus for facilitating multi-element bidding for influencing a position on a payment list generated by an automated authentication engine
CN113923650A (zh) * 2017-04-18 2022-01-11 华为技术有限公司 网络接入方法、装置和通信系统
CN110995759A (zh) * 2019-12-23 2020-04-10 中国联合网络通信集团有限公司 物联网的接入方法以及装置
CN112492597B (zh) * 2020-12-14 2023-03-24 中国联合网络通信集团有限公司 一种认证方法及装置

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2019017836A1 (zh) * 2017-07-20 2019-01-24 华为国际有限公司 一种会话处理方法及设备
CN109511115A (zh) * 2017-09-14 2019-03-22 华为技术有限公司 一种授权方法和网元
WO2022148619A1 (en) * 2021-01-11 2022-07-14 Telefonaktiebolaget Lm Ericsson (Publ) User equipment (ue) identifier request

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on architecture enhancements for Personal IoT Network (PIN) (Release 18)", 3GPP TR 23.700-88, no. V0.2.0, 16 April 2022 (2022-04-16), pages 1 - 60, XP052145987 *
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on architecture enhancements for Personal IoT Network (PIN) (Release 18)", 3GPP TR 23.700-88, no. V1.3.0, 25 January 2023 (2023-01-25), pages 1 - 165, XP052235384 *

Also Published As

Publication number Publication date
CN117479158A (zh) 2024-01-30

Similar Documents

Publication Publication Date Title
CN113748694B (zh) 用于服务发现的方法和装置
US11950175B2 (en) Communication method and communications apparatus
EP3981199B1 (en) Performing service delivery for multi-user mobile terminals cross-reference to related application
US20230099786A1 (en) Methods and Apparatus for Provisioning Private Network Devices During Onboarding
CN116391377A (zh) 用于ue接入的使用数字标识符的认证
CN115299168B (zh) 用于切换的方法和装置
US20250168635A1 (en) Authentication and authorization for localized services
CN113348690A (zh) 用于安全的方法和装置
CN112672336A (zh) 实现外部认证的方法、通信装置及通信系统
CN116567625A (zh) 设备鉴权方法、装置、终端及网络功能
CN116567626B (zh) 设备鉴权方法、装置及通信设备
WO2023143412A1 (zh) Ip地址分配方法、设备及可读存储介质
CN117560790A (zh) 会话建立方法、装置、通信设备及网元
JP2024541831A (ja) 鍵の再ネゴシエーションの必要性を示すための汎用ブートストラッピングアーキテクチャ(gba)シグナリング
EP4162715B1 (en) Method and apparatus for authentication and authorization
WO2024017181A1 (zh) 设备授权方法、装置及网络侧设备
WO2023213236A1 (zh) 策略配置方法及装置
WO2024061091A1 (zh) 一种网络通信的方法、装置、网络侧设备、终端及介质
WO2024027578A1 (zh) 流量路由方法、装置及设备
CN117177229A (zh) 数据传输方法、装置、通信设备及网元
JP2024507269A (ja) 認証のための方法及び装置
CN116567593B (zh) 通知方法、第一网络功能及第二网络功能
CN116567591B (zh) 直连空口配置方法、终端及网络侧设备
CN116567777B (zh) 接入参数使用方法、终端及网络侧
WO2023143441A1 (zh) 通知方法、第一网络功能及第二网络功能

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23842244

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 23842244

Country of ref document: EP

Kind code of ref document: A1

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 11-07-2025)

122 Ep: pct application non-entry in european phase

Ref document number: 23842244

Country of ref document: EP

Kind code of ref document: A1