WO2024017181A1 - 设备授权方法、装置及网络侧设备 - Google Patents
设备授权方法、装置及网络侧设备 Download PDFInfo
- Publication number
- WO2024017181A1 WO2024017181A1 PCT/CN2023/107674 CN2023107674W WO2024017181A1 WO 2024017181 A1 WO2024017181 A1 WO 2024017181A1 CN 2023107674 W CN2023107674 W CN 2023107674W WO 2024017181 A1 WO2024017181 A1 WO 2024017181A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- matching
- authentication
- network function
- following
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
Definitions
- This application belongs to the field of mobile communication technology, and specifically relates to a device authorization method, device and network side equipment.
- the access device When the access device is connected to the mobile network through the gateway device, because the access device does not support Non Access Stratum (NAS) signaling, the authentication of the access device is not accurate enough and cannot prevent other devices from impersonating. The access device obtains some communication permissions of the access device, causing security risks.
- NAS Non Access Stratum
- Embodiments of the present application provide a device authorization method, device, and network-side equipment, which can solve the problem of inaccurate authentication of access devices.
- a device authorization method applied to the first device, and the method includes:
- the first device receives first information from the first network function
- the first device initiates a first authentication process between the second network function and the second device in response to the first information, and the first authentication process includes authentication of the second device by the second network function. .
- a device authorization device including:
- a transceiver module configured to receive the first information from the first network function
- An authentication module configured to initiate a first authentication process between a second network function and a second device in response to the first information, where the first authentication process includes authentication of the second device by the second network function.
- a device authorization method applied to the first device, and the method includes:
- the first device receives first information from the first network function, the first information including first matching information;
- the first device receives second information from a second network function, the second information is obtained based on a first authentication process for the second device, and the second information includes second matching information;
- the first device performs at least one of the following:
- the third information is used to indicate at least one of the following:
- a device authorization device including:
- a transceiver module configured to receive first information from the first network function, where the first information includes first matching information
- the transceiver module is also configured to receive second information from the second network function, the second information is obtained based on the first authentication process of the second device, and the second information includes second matching information;
- An authentication module that performs at least one of the following:
- the third information is used to indicate at least one of the following:
- a device authorization method applied to the first network function, and the method includes:
- the first network function sends first information to the first device, where the first information is used to indicate at least one of the following:
- the second information is sent by the second network function based on the first authentication process of the second device, and the third information is used to indicate at least one of the following:
- a device authorization device including:
- the acquisition module is used to obtain the first information
- a transmission module configured to send the first information to the first device, where the first information is used to indicate at least one of the following:
- the second information is sent by the second network function based on the first authentication process of the second device, and the third information is used to indicate at least one of the following:
- a device authorization method is provided, applied to the second network function, and the method includes:
- the second network function performs the first authentication process with the second device
- the second network function sends second information to the first device according to the first authentication process
- the second information includes at least one of the following:
- Second matching information the second matching information is used to match the first matching information sent by the first device.
- a device authorization device including:
- An execution module configured to execute the first authentication process with the second device
- a sending module configured to send second information to the first device according to the first authentication process
- the second information includes at least one of the following:
- Second matching information the second matching information is used to match the first matching information sent by the first device.
- a network side device in a ninth aspect, includes a processor and a memory.
- the memory stores programs or instructions that can be run on the processor.
- the program or instructions are executed by the processor.
- a device authorization system including: a first device, a first network function and a second network function.
- the first device can be used to perform the device authorization method as described in the first aspect or the third aspect.
- the first network function may be used to perform the steps of the device authorization method as described in the fifth aspect, and the second network function may be used to perform the steps of the device authorization method as described in the seventh aspect.
- a readable storage medium is provided.
- Programs or instructions are stored on the readable storage medium.
- the steps of the method described in the first aspect are implemented, or the steps of the method are implemented.
- a chip in a twelfth aspect, includes a processor and a communication interface.
- the communication interface is coupled to the processor.
- the processor is used to run programs or instructions to implement the method described in the first aspect. Method, or implement the method as described in the third aspect, or implement the method as described in the fifth aspect, or implement the steps of the method as described in the seventh aspect.
- a computer program/program product is provided, the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement as described in the first aspect
- the device authorization method or implements the device authorization method as described in the third aspect, or implements the device authorization method as described in the fifth aspect, or implements the steps of the device authorization method as described in the seventh aspect.
- the first authentication process includes The second network function authenticates the second device by triggering the first authentication process by the first device responding to the first information, thereby realizing authorization of the second device when accessing the mobile network.
- Figure 1 is a schematic structural diagram of a wireless communication system applicable to the embodiment of the present application.
- Figure 2 is a schematic structural diagram of a device authorization system provided by an embodiment of the present application.
- Figure 3 is a schematic flowchart of a device authorization method provided by an embodiment of the present application.
- Figure 4 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
- Figure 5 is a schematic diagram of the signaling flow of a device authorization method provided by an embodiment of the present application.
- Figure 6 is a schematic structural diagram of a device authorization device provided by an embodiment of the present application.
- Figure 7 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
- Figure 8 is a schematic structural diagram of another device authorization device provided by an embodiment of the present application.
- Figure 9 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
- Figure 10 is a schematic structural diagram of another device authorization device provided by an embodiment of the present application.
- Figure 11 is a schematic flowchart of another device authorization method provided by an embodiment of the present application.
- Figure 12 is a schematic structural diagram of another device authorization device provided by an embodiment of the present application.
- Figure 13 is a schematic structural diagram of a communication device provided by an embodiment of the present application.
- Figure 14 is a schematic structural diagram of a network side device that implements an embodiment of the present application.
- first, second, etc. in the description and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and that "first" and “second” are distinguished objects It is usually one type, and the number of objects is not limited.
- the first object can be one or multiple.
- “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the related objects are in an "or” relationship.
- LTE Long Term Evolution
- LTE-Advanced, LTE-A Long Term Evolution
- LTE-A Long Term Evolution
- CDMA Code Division Multiple Access
- TDMA Time Division Multiple Access
- FDMA Frequency Division Multiple Access
- OFDMA Orthogonal Frequency Division Multiple Access
- SC-FDMA Single-carrier Frequency Division Multiple Access
- NR New Radio
- FIG. 1 shows a block diagram of a wireless communication system to which embodiments of the present application are applicable.
- the wireless communication system includes a terminal (also called User Equipment (UE)) 11 and a network side device 12 .
- the terminal 11 may be Mobile phone, tablet computer (Tablet Personal Computer), laptop computer (Laptop Computer) or notebook computer, personal digital assistant (Personal Digital Assistant, PDA), handheld computer, netbook, ultra-mobile personal computer , UMPC), Mobile Internet Device (MID), augmented reality (AR)/virtual reality (VR) equipment, robots, wearable devices (Wearable Device), vehicle user equipment (Vehicle User) Equipment (VUE), Pedestrian User Equipment (PUE), smart home (home equipment with wireless communication functions, such as refrigerators, TVs, washing machines or furniture, etc.), game consoles, personal computers (PC), teller machines Or terminal-side devices such as self-service machines.
- UE User Equipment
- the network side device 12 may include an access network device or a core network device, where the access network device 12 may also be called a radio access network device, a radio access network (Radio Access Network, RAN), a radio access network function or Wireless access network unit.
- the access network device 12 may include a base station, a Wireless Local Area Network (WLAN) access point or a WiFi node, etc.
- WLAN Wireless Local Area Network
- the base station may be called a Node B, an evolved Node B (eNB), an access point, Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home B-node, home evolved B-node , Transmitting Receiving Point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiment of the present application This introduction only takes the base station in the NR system as an example, and does not limit the specific type of base station.
- eNB evolved Node B
- BTS Base Transceiver Station
- BSS Basic Service Set
- ESS Extended Service Set
- TRP Transmitting Receiving Point
- Core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entities (Mobility Management Entity, MME), access mobility management functions (Access and Mobility Management Function, AMF), session management functions (Session Management Function, SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Service Discovery function (Edge Application Server Discovery Function, EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), centralized network configuration ( Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (Local NEF, or L-NEF), Binding Support Function (Binding Support Function, BSF), application function (Application Function, AF), etc.
- MME mobility management entities
- AMF Access and Mobility Management Function
- SMF Session Management Function
- UPF User Plane Function
- PCF Policy Control Function
- the embodiment of the present application provides a device authorization method, and the execution subject of the method is the first A device, in other words, the method may be executed by software or hardware installed on the first device.
- the method also includes the following steps.
- the first device receives the first information from the first network function.
- the embodiment of this application realizes the authentication of the personal Internet of Things device (PIN Element, PINE) 201 in the Personal Internet of Things (Personal IoT Networks, PIN) through the mobile network.
- PIN personal Internet of Things device
- the PIN also includes a personal IoT device with management functions.
- IoT devices PIN Elements with Management Capability, PEMC
- PIN devices with gateway capabilities PIN Elements with Gateway Capability, PEGC
- the mobile network may include: a personal IoT management function (PIN Management Function, PINMF) 211 connected to the network where the access device is located, a session management function (Session Management Function, SMF) 212 in the mobile network, and a network opening function (Network Exposure Function (NEF), Policy Control Function (PCF), and Unified Data Management Function (Unified Data Management, UDM) 213 or third-party authentication functions, such as Authentication Authorization and Accounting (AAA).
- PIN Management Function PIN Management Function
- SMF Session Management Function
- NEF Network Exposure Function
- PCF Policy Control Function
- UDM Unified Data Management Function
- the first device may be a terminal, a network device or a network function.
- the first device may be a PEMC or an SMF.
- the first device is an SMF as an example.
- the second device may be PINE
- the third device may be PMEC
- the fourth device may be PEGC.
- the first network function may be PINMF, NEF or PCF.
- the second network function may be UDM or AAA, etc.
- the first network function After receiving a data forwarding or authentication request message from the second device from the third device and/or the fourth device, the first network function will send the first information to the first device.
- the first information may include authentication instruction information, used to instruct a first authentication process between the second network function and the second device.
- the first device In response to the first information, the first device initiates a first authentication process between the second network function and the second device.
- the first authentication process includes the second network function authenticating the second device to the second network function. certification.
- the first authentication process may be one-way or two-way.
- the one-way authentication is the authentication of the second network function to the second device
- the two-way authentication also includes the authentication of the second network function by the second device.
- the authentication of the second device by the second network function is used as an example for illustration.
- the method further includes:
- the first device receives second information from the second network function, where the second information is obtained based on the first authentication process of the second device.
- the second network function may send second information to the first device after completing the first authentication process on the second device.
- the second information may include the authentication result of the first authentication process. Specifically, it may include: authentication successful. indication or authentication failure indication.
- the second network function may also send the second information including the authentication success indication to the first device when the authentication result of the first authentication process is authentication success, but does not send the second information when the authentication result is authentication failure.
- the first device may determine that the authentication of the second device has failed.
- the first device performs at least one of the following:
- the third information is used to indicate at least one of the following:
- the authentication result information for the second device may, for example, include an authentication success indication or an authentication failure indication, etc.
- the first device may perform matching of the first information and the second information according to the matching result information. If the matching result information is that the first information and the second information match, That is, corresponding to the same device, the third information including the matching success indication or the authentication success indication is sent to the first network function.
- the first network function can determine whether the second device is suitable for the second device according to the received third information. Authorization is successful, and a response message indicating successful authentication or successful access is sent to the second device through the third device and/or the fourth device; if the matching result information is that the first information and the second information do not match , that is, corresponding to different devices, the third information is not sent to the first network function.
- the first network function may also determine whether the third information is received within the preset time period. Second device authorization failed.
- the first device may match the first information and the second information in various ways.
- the first information includes first matching information
- the second information includes second matching information.
- the matching of the first information and the second information includes:
- the first matching information and the second matching information can be set according to actual needs.
- the first matching information and the second matching information include at least one of the following information:
- Identification information such as device identification PINE ID or UE ID
- IP Internet Protocol
- the first network function determines whether to authorize the second device based on the received third information, and sends the authorization result to the third device and the fourth device through the feedback information, and then the third device and the fourth device send the authorization result to the second device.
- the device authorization method mainly includes the following steps.
- A1.PINE sends a relay request (PINE Relay Request) message to PINEMF through PEGC and PEMC.
- the relay request message may include PINE's personal IoT identification (PIN ID) on the network, the personal IoT device of the second device Identification (PINE ID), data filtering rules (Packet filters), data network related identification (Data Network specific Identifier, DN-specific ID), etc.
- the first information sends the first information to the SMF through NEF and PCF.
- the first information can be activated by the relay.
- the first information may include first matching information and authentication indication information, where the first matching information may be represented as authentication assistance information (Authentication Assistance Info),
- the first information may also include: an optional User Permanent Identifier (Subscription Permanent Identifier, SUPI) or a Generic Public Subscription Identifier (GPSI), a terminal address (UE address), an optional data network Name (Data Network Name, DNN) or slice related information (such as Single Network Slice Selection Assistance Information (S-NSSAI), Network Slicing Identifier (NSI)), PIN ID, PINE ID , routing information between devices (Device to Device Routing Information, D2D Routing Info), routing information between devices and networks (Device to Network Routing Information, D2N Routing Info), routing information between networks (Network to Network Routing Information, N2N Routing Info) , downlink data process rules (Downlink Packet Filters, DL Pack
- A4.SMF initiates the first authentication process between UDM and PINE or between AAA and PINE.
- SMF performs authentication based on the EAP framework by sending an Extensible Authentication Protocol request message (Extensible Authentication Protocol, EAP Identity Request) to PINE. and authorization.
- EAP Identity Request Extensible Authentication Protocol
- AAA or UDM will send second information to the SMF.
- the second information may include an authentication success indication and second matching information.
- the second matching information may include: MAC address, number information, identification At least one of information, IP address and other matching information.
- the SMF matches the first matching information and the second matching information.
- A5-A6 SMF sends third information to PINMF through PCF and NEF, where the third information includes matching result information of the first matching information and the second matching information to indicate whether the matching is successful.
- the third information may also include relay assistance information (Relay Assistance Info), specifically including PINE-related information, such as PINE's converted IPv6 address, converted IPv4 address and PI port range.
- A7-A8.PINEMF sends feedback information to PEMC, PEGC, and PINE to indicate the request result.
- the embodiments of the present application receive the first information from the first network function and initiate the first authentication process between the second network function and the second device in response to the first information.
- the first authentication process includes authentication of the second device by the second network function, thereby realizing authorization of the second device when accessing the mobile network.
- the execution subject may be a device authorization device.
- the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
- the device authorization device includes: a transceiver module 601 and an authentication module 602.
- the transceiver module 601 is configured to receive first information from the first network function; the authentication module 602 is configured to initiate a first authentication process between the second network function and the second device in response to the first information.
- the first authentication process includes authentication of the second device by the second network function.
- the transceiver module 601 is also configured to receive second information from the second network function, where the second information is obtained based on the first authentication process of the second device;
- the authentication module 602 is also used to perform at least one of the following:
- the third information is used to indicate at least one of the following:
- the first information includes first matching information
- the second information includes second matching information
- the authentication module 602 is used to match the first matching information and the second matching information.
- the first information includes at least one of the following:
- Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
- the second information includes at least one of the following:
- the first matching information and the second matching information include at least one of the following information:
- the second network function is one of the following:
- the embodiments of the present application receive the first information from the first network function and initiate the first authentication process between the second network function and the second device in response to the first information.
- the first authentication process includes authentication of the second device by the second network function, thereby realizing authorization of the second device when accessing the mobile network.
- the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
- the electronic device may be a terminal or other devices other than the terminal.
- terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
- NAS Network Attached Storage
- the device authorization device provided by the embodiment of the present application can implement various processes implemented by the method embodiments of Figures 3 to 5, And achieve the same technical effect, to avoid repetition, they will not be described again here.
- an embodiment of the present application provides a device authorization method.
- the execution subject of the method is the first device.
- the method can be executed by software or hardware installed on the first device.
- the method also includes the following steps.
- the first device receives first information from the first network function, where the first information includes first matching information;
- the first device receives second information from the second network function, the second information is obtained based on the first authentication process of the second device, and the second information includes second matching information;
- the first device performs at least one of the following:
- the third information is used to indicate at least one of the following:
- the first information also includes
- Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
- the second information also includes:
- the first matching information and the second matching information include at least one of the following information:
- the second network function is one of the following:
- Steps S710-730 can implement the method embodiment of steps S330-340 as shown in Figure 4, and obtain the same technical effect, and the repeated parts will not be repeated here.
- the embodiments of the present application receive first information from the first network function, where the first information includes first matching information; receive second information from the second network function, and the second information including second matching information; and matching the first matching information and the second matching information; sending third information to the first network function, thereby realizing the second matching when the second device accesses the mobile network.
- Device authentication and authorization
- the execution subject may be a device authorization device.
- the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
- the device authorization device includes: a transceiver module 801 and an authentication module 802.
- the transceiver module 801 is configured to receive first information from a first network function, where the first information includes a first matching information. information; the transceiver module 801 is also configured to receive second information from the second network function, the second information is obtained based on the first authentication process of the second device, and the second information includes second matching information;
- the authentication module 802 is used to perform at least one of the following:
- the third information is used to indicate at least one of the following:
- the first information also includes
- Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
- the second information also includes:
- the first matching information and the second matching information include at least one of the following information:
- the second network function is one of the following:
- the embodiments of the present application receive first information from the first network function, where the first information includes first matching information; receive second information from the second network function, and the second information including second matching information; and matching the first matching information and the second matching information; sending third information to the first network function, thereby realizing the second matching when the second device accesses the mobile network.
- Device authentication and authorization
- the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
- the electronic device may be a terminal or other devices other than the terminal.
- terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
- NAS Network Attached Storage
- the device authorization device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 7 and achieve the same technical effect. To avoid duplication, the details will not be described here.
- this embodiment of the present application provides a device authorization method.
- the execution subject of the method is the first network function.
- the method can be executed by software or hardware installed in the first network function.
- the method also includes the following steps.
- the first network function sends first information to the first device, where the first information is used to indicate at least one of the following:
- the second information is sent by the second network function based on the first authentication process of the second device, and the third information is used to indicate at least one of the following:
- the first information includes at least one of the following:
- Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
- the first matching information includes at least one of the following information:
- the second network function is one of the following:
- Step S910 can implement the method embodiments shown in Figure 3 and Figure 4 and obtain the same technical effect, and the repeated parts will not be described again here.
- the embodiments of the present application send first information to the first device, and the first information is used to indicate at least one of the following: performing the first authentication process between the second network function and the second device. ; Match the first information and the second information; send third information to the first network function, thereby realizing authentication and authorization of the second device when the second device accesses the mobile network.
- the execution subject may be a device authorization device.
- the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
- the device authorization device includes: an acquisition module 1001 and a transmission module 1002.
- the acquisition module 1001 is used to acquire first information; the transmission module 1002 is used to send the first information to a first device, where the first information is used to indicate at least one of the following:
- the second information is sent by the second network function based on the first authentication process of the second device,
- the third information is used to indicate at least one of the following:
- the first information includes at least one of the following:
- Authentication instruction information is used to instruct the first authentication process between the second network function and the second device.
- the first matching information includes at least one of the following information:
- the second network function is one of the following:
- the embodiments of the present application send first information to the first device, and the first information is used to indicate at least one of the following: performing the first authentication process between the second network function and the second device. ; Match the first information and the second information; send third information to the first network function, thereby realizing authentication and authorization of the second device when the second device accesses the mobile network.
- the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
- the electronic device may be a terminal or other devices other than the terminal.
- terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
- NAS Network Attached Storage
- the device authorization device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 9 and achieve the same technical effect. To avoid duplication, details will not be described here.
- this embodiment of the present application provides a device authorization method.
- the execution subject of the method is the second network function.
- the method can be executed by software or hardware installed in the second network function.
- the method also includes the following steps.
- the second network function sends second information to the first device according to the first authentication process
- the second information includes at least one of the following:
- Second matching information the second matching information is used to match the first matching information sent by the first device.
- the first authentication process is initiated by the first device.
- the first matching information and the second matching information include at least one of the following information:
- the second network function is one of the following:
- Steps S1110-S1120 can implement the method embodiment shown in Figure 3 or Figure 4, and obtain the same technical effect, and the repeated parts will not be described again here.
- the embodiments of the present application perform a first authentication process with the second device and send second information to the first device according to the first authentication process; wherein, the second The information includes at least one of the following: an authentication success indication or an authentication failure indication; second matching information, the second matching information is used to match the first matching information sent by the first device, so that when the second device accesses the mobile network Implement authentication and authorization of the second device.
- the execution subject may be a device authorization device.
- the device authorization device executing the device authorization method is taken as an example to illustrate the device authorization device provided by the embodiment of this application.
- the device authorization device includes: an execution module 1201 and a sending module 1202.
- the execution module 1201 is used to execute a first authentication process with a second device; the sending module 1202 is used to send second information to the first device according to the first authentication process;
- the second information includes at least one of the following:
- Second matching information the second matching information is used to match the first matching information sent by the first device.
- the first authentication process is initiated by the first device.
- the first matching information and the second matching information include at least one of the following information:
- the second network function is one of the following:
- the embodiments of the present application perform the first authentication process with the second device. process, and sends second information to the first device according to the first authentication process; wherein the second information includes at least one of the following: an authentication success indication or an authentication failure indication; second matching information, the second matching The information is used to match the first matching information sent by the first device, thereby realizing authentication and authorization of the second device when the second device accesses the mobile network.
- the device authorization device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or may be a component in the electronic device, such as an integrated circuit or chip.
- the electronic device may be a terminal or other devices other than the terminal.
- terminals may include but are not limited to the types of terminals 11 listed above, and other devices may be servers, network attached storage (Network Attached Storage, NAS), etc., which are not specifically limited in the embodiment of this application.
- NAS Network Attached Storage
- the device authorization device provided by the embodiment of the present application can implement each process implemented by the method embodiment in Figure 11 and achieve the same technical effect. To avoid duplication, the details will not be described here.
- this embodiment of the present application also provides a communication device 1300, which includes a processor 1301 and a memory 1302.
- the memory 1302 stores programs or instructions that can be run on the processor 1301, such as , when the communication device 1300 is a terminal, when the program or instruction is executed by the processor 1301, each step of the above device authorization method embodiment is implemented, and the same technical effect can be achieved.
- the communication device 1300 is a network-side device, when the program or instruction is executed by the processor 1301, each step of the above device authorization method embodiment is implemented, and the same technical effect can be achieved. To avoid duplication, the details are not repeated here.
- the embodiment of the present application also provides a network side device.
- the network side device 1400 includes: a processor 1401, a network interface 1402, and a memory 1403.
- the network interface 1402 is, for example, a common public radio interface (CPRI).
- CPRI common public radio interface
- the network side device 1400 in this embodiment of the present invention also includes: instructions or programs stored in the memory 1403 and executable on the processor 1401.
- the processor 1401 calls the instructions or programs in the memory 1403 to execute Figures 6, 8,
- the methods for executing each module shown in 10 or 12 achieve the same technical effect. To avoid repetition, they will not be repeated here.
- Embodiments of the present application also provide a readable storage medium.
- the readable storage medium may be non-transient or non-volatile.
- the readable storage medium stores programs or instructions.
- the program or instructions When executed by the processor, each process of the above device authorization method embodiment is implemented and can achieve the same technical effect. To avoid duplication, the details will not be described here.
- the processor is the processor in the terminal described in the above embodiment.
- the readable storage medium includes computer readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disk or optical disk, etc.
- An embodiment of the present application further provides a chip.
- the chip includes a processor and a communication interface.
- the communication interface is coupled to the processor.
- the processor is used to run programs or instructions to implement the above device authorization method embodiment. Each process can achieve the same technical effect. To avoid duplication, it will not be described again here.
- chips mentioned in the embodiments of this application may also be called system-on-chip, system-on-a-chip, system-on-chip or system-on-chip, etc.
- Embodiments of the present application further provide a computer program/program product.
- the computer program/program product is stored in a storage medium.
- the computer program/program product is executed by at least one processor to implement the above device authorization method embodiment.
- Each process can achieve the same technical effect. To avoid repetition, we will not go into details here.
- An embodiment of the present application also provides a device authorization system, including: a first device, a first network function and a second network function.
- the first device can be used to perform the steps of the device authorization method as described above.
- the third device One network function may be used to perform the steps of the device authorization method as described above, and the second network function may be used to perform the steps of the device authorization method as described above.
- the methods of the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is better. implementation.
- the technical solution of the present application can be embodied in the form of a computer software product that is essentially or contributes to related technologies.
- the computer software product is stored in a storage medium (such as ROM/RAM, disk, CD), including several instructions to cause a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of this application.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Power Engineering (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
Claims (26)
- 一种设备授权方法,包括:第一设备从第一网络功能接收第一信息;所述第一设备响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
- 根据权利要求1所述的方法,其中,所述方法还包括:所述第一设备从所述第二网络功能接收第二信息,所述第二信息为基于对所述第二设备的第一认证过程得到的;所述第一设备执行以下至少一项:匹配所述第一信息和所述第二信息;向所述第一网络功能发送第三信息;其中,所述第三信息用于指示以下至少一项:对所述第二设备的认证结果信息;所述第一信息和所述第二信息的匹配结果信息。
- 根据权利要求2所述的方法,其中,所述第一信息包括第一匹配信息,所述第二信息包括第二匹配信息,所述匹配所述第一信息和所述第二信息包括:匹配所述第一匹配信息和第二匹配信息。
- 根据权利要求2所述的方法,其中,所述第一信息包括以下至少一项:第一匹配信息;认证指示信息,用于指示进行所述第二网络功能与所述第二设备的第一认证过程。
- 根据权利要求2所述的方法,所述第二信息包括以下至少一项:认证成功指示或认证失败指示;第二匹配信息。
- 根据权利要求3所述的方法,其中,所述第一匹配信息和第二匹配信息包括以下至少一种信息:媒体接入控制地址;号码信息;标识信息;互联网协议地址信息;其它匹配信息。
- 根据权利要求1所述的方法,其中,所述第二网络功能为以下之一:统一数据管理功能;第三方认证功能。
- 一种设备授权装置,包括:收发模块,用于从第一网络功能接收第一信息;认证模块,用于响应于所述第一信息发起第二网络功能与第二设备之间的第一认证过程,所述第一认证过程包括所述第二网络功能对所述第二设备的认证。
- 一种设备授权方法,包括:第一设备从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;所述第一设备从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;所述第一设备执行以下至少一项:匹配所述第一匹配信息和所述第二匹配信息;向所述第一网络功能发送第三信息;其中,所述第三信息用于指示以下至少一项:对所述第二设备的认证结果信息;所述第一匹配信息和第二信息的匹配结果信息。
- 根据权利要求9所述的方法,其中,所述第一信息还包括认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
- 根据权利要求9所述的方法,其中,所述第二信息还包括:认证成功指示或认证失败指示。
- 根据权利要求9任一所述的方法,其中,所述第一匹配信息和第二匹配信息包括以下至少一种信息:媒体接入控制地址;号码信息;标识信息;互联网协议地址信息;其它匹配信息。
- 根据权利要求9所述的方法,其中,所述第二网络功能为以下之一:统一数据管理实体;第三方认证功能。
- 一种设备授权装置,包括:收发模块,用于从第一网络功能接收第一信息,所述第一信息包括第一匹配信息;所述收发模块,还用于从第二网络功能接收第二信息,所述第二信息为基于对第二设备的第一认证过程得到的,所述第二信息包括第二匹配信息;认证模块,用于执行以下至少一项:匹配所述第一匹配信息和所述第二匹配信息;向所述第一网络功能发送第三信息;其中,所述第三信息用于指示以下至少一项:对所述第二设备的认证结果信息;所述第一匹配信息和第二信息的匹配结果信息。
- 一种设备授权方法,包括:第一网络功能向第一设备发送第一信息,所述第一信息用于指示以下至少一项:进行第二网络功能与第二设备的第一认证过程;匹配所述第一信息和第二信息;向所述第一网络功能发送第三信息;其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:对所述第二设备的认证结果信息;所述第一信息和第二信息的匹配结果信息。
- 根据权利要求15所述的方法,其中,所述第一信息包括以下至少一项:第一匹配信息;认证指示信息,用于指示进行第二网络功能与所述第二设备的第一认证过程。
- 根据权利要求16所述的方法,其中,所述第一匹配信息包括以下至少一种信息:媒体接入控制地址;号码信息;标识信息;互联网协议地址信息;其它匹配信息。
- 根据权利要求15所述的方法,其中,所述第二网络功能为以下之一:统一数据管理实体;第三方认证功能。
- 一种设备授权装置,包括:获取模块,用于获取第一信息;传输模块,用于向第一设备发送所述第一信息,所述第一信息用于指示以下至少一项:进行第二网络功能与第二设备的第一认证过程;匹配所述第一信息和第二信息;向设备授权装置发送第三信息;其中,所述第二信息为所述第二网络功能基于对所述第二设备的第一认证过程发送的,所述第三信息用于指示以下至少一项:对所述第二设备的认证结果信息;所述第一信息和第二信息的匹配结果信息。
- 一种设备授权方法,包括:第二网络功能执行与第二设备之间的第一认证过程;所述第二网络功能根据所述第一认证过程向第一设备发送第二信息;其中,所述第二信息包括以下至少一项:认证成功指示或认证失败指示;第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
- 根据权利要求20所述的方法,其中,所述第一认证过程由所述第一设备发起。
- 根据权利要求20所述的方法,其中,第一匹配信息和第二匹配信息包括以下至少一种信息:媒体接入控制地址;号码信息;标识信息;互联网协议地址信息;其它匹配信息。
- 根据权利要求20所述的方法,其中,所述第二网络功能为以下之一:统一数据管理实体;第三方认证功能。
- 一种设备授权装置,包括:执行模块,用于执行与第二设备之间的第一认证过程;发送模块,用于根据所述第一认证过程向第一设备发送第二信息;其中,所述第二信息包括以下至少一项:认证成功指示或认证失败指示;第二匹配信息,所述第二匹配信息用于匹配由第一设备发送的第一匹配信息。
- 一种网络侧设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至7任一项所述的设备授权方法,或者实现如权利要求9至13任一项所述的设备授权方法,或者实现如权利要求15至18任一项所述的设备授权方法,或者实现如权利要求20至23任一项所述的设备授权方法的步骤。
- 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至7任一项所述的设备授权方法,或者实现如权利要求9至13任一项所述的设备授权方法,或者实现如权利要求15至18任一项所述的设备授权方法,或者实现如权利要求20至23任一项所述的设备授权方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202210868562.2 | 2022-07-22 | ||
| CN202210868562.2A CN117479158A (zh) | 2022-07-22 | 2022-07-22 | 设备授权方法、装置及网络侧设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024017181A1 true WO2024017181A1 (zh) | 2024-01-25 |
Family
ID=89617145
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/107674 Ceased WO2024017181A1 (zh) | 2022-07-22 | 2023-07-17 | 设备授权方法、装置及网络侧设备 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117479158A (zh) |
| WO (1) | WO2024017181A1 (zh) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2019017836A1 (zh) * | 2017-07-20 | 2019-01-24 | 华为国际有限公司 | 一种会话处理方法及设备 |
| CN109511115A (zh) * | 2017-09-14 | 2019-03-22 | 华为技术有限公司 | 一种授权方法和网元 |
| WO2022148619A1 (en) * | 2021-01-11 | 2022-07-14 | Telefonaktiebolaget Lm Ericsson (Publ) | User equipment (ue) identifier request |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2933981B1 (en) * | 2014-04-17 | 2018-08-01 | Comptel OY | Method and system of user authentication |
| US20190287110A1 (en) * | 2016-02-03 | 2019-09-19 | Cloudwear, Inc. | Method and apparatus for facilitating multi-element bidding for influencing a position on a payment list generated by an automated authentication engine |
| CN113923650A (zh) * | 2017-04-18 | 2022-01-11 | 华为技术有限公司 | 网络接入方法、装置和通信系统 |
| CN110995759A (zh) * | 2019-12-23 | 2020-04-10 | 中国联合网络通信集团有限公司 | 物联网的接入方法以及装置 |
| CN112492597B (zh) * | 2020-12-14 | 2023-03-24 | 中国联合网络通信集团有限公司 | 一种认证方法及装置 |
-
2022
- 2022-07-22 CN CN202210868562.2A patent/CN117479158A/zh active Pending
-
2023
- 2023-07-17 WO PCT/CN2023/107674 patent/WO2024017181A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2019017836A1 (zh) * | 2017-07-20 | 2019-01-24 | 华为国际有限公司 | 一种会话处理方法及设备 |
| CN109511115A (zh) * | 2017-09-14 | 2019-03-22 | 华为技术有限公司 | 一种授权方法和网元 |
| WO2022148619A1 (en) * | 2021-01-11 | 2022-07-14 | Telefonaktiebolaget Lm Ericsson (Publ) | User equipment (ue) identifier request |
Non-Patent Citations (2)
| Title |
|---|
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on architecture enhancements for Personal IoT Network (PIN) (Release 18)", 3GPP TR 23.700-88, no. V0.2.0, 16 April 2022 (2022-04-16), pages 1 - 60, XP052145987 * |
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on architecture enhancements for Personal IoT Network (PIN) (Release 18)", 3GPP TR 23.700-88, no. V1.3.0, 25 January 2023 (2023-01-25), pages 1 - 165, XP052235384 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117479158A (zh) | 2024-01-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113748694B (zh) | 用于服务发现的方法和装置 | |
| US11950175B2 (en) | Communication method and communications apparatus | |
| EP3981199B1 (en) | Performing service delivery for multi-user mobile terminals cross-reference to related application | |
| US20230099786A1 (en) | Methods and Apparatus for Provisioning Private Network Devices During Onboarding | |
| CN116391377A (zh) | 用于ue接入的使用数字标识符的认证 | |
| CN115299168B (zh) | 用于切换的方法和装置 | |
| US20250168635A1 (en) | Authentication and authorization for localized services | |
| CN113348690A (zh) | 用于安全的方法和装置 | |
| CN112672336A (zh) | 实现外部认证的方法、通信装置及通信系统 | |
| CN116567625A (zh) | 设备鉴权方法、装置、终端及网络功能 | |
| CN116567626B (zh) | 设备鉴权方法、装置及通信设备 | |
| WO2023143412A1 (zh) | Ip地址分配方法、设备及可读存储介质 | |
| CN117560790A (zh) | 会话建立方法、装置、通信设备及网元 | |
| JP2024541831A (ja) | 鍵の再ネゴシエーションの必要性を示すための汎用ブートストラッピングアーキテクチャ(gba)シグナリング | |
| EP4162715B1 (en) | Method and apparatus for authentication and authorization | |
| WO2024017181A1 (zh) | 设备授权方法、装置及网络侧设备 | |
| WO2023213236A1 (zh) | 策略配置方法及装置 | |
| WO2024061091A1 (zh) | 一种网络通信的方法、装置、网络侧设备、终端及介质 | |
| WO2024027578A1 (zh) | 流量路由方法、装置及设备 | |
| CN117177229A (zh) | 数据传输方法、装置、通信设备及网元 | |
| JP2024507269A (ja) | 認証のための方法及び装置 | |
| CN116567593B (zh) | 通知方法、第一网络功能及第二网络功能 | |
| CN116567591B (zh) | 直连空口配置方法、终端及网络侧设备 | |
| CN116567777B (zh) | 接入参数使用方法、终端及网络侧 | |
| WO2023143441A1 (zh) | 通知方法、第一网络功能及第二网络功能 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23842244 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23842244 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 11-07-2025) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23842244 Country of ref document: EP Kind code of ref document: A1 |