WO2024036461A1 - 通过非3gpp接入网络接入3gpp网络的认证方法、装置 - Google Patents

通过非3gpp接入网络接入3gpp网络的认证方法、装置 Download PDF

Info

Publication number
WO2024036461A1
WO2024036461A1 PCT/CN2022/112622 CN2022112622W WO2024036461A1 WO 2024036461 A1 WO2024036461 A1 WO 2024036461A1 CN 2022112622 W CN2022112622 W CN 2022112622W WO 2024036461 A1 WO2024036461 A1 WO 2024036461A1
Authority
WO
WIPO (PCT)
Prior art keywords
suci
terminal device
registration
n3iwf
registration operation
Prior art date
Application number
PCT/CN2022/112622
Other languages
English (en)
French (fr)
Inventor
梁浩然
陆伟
Original Assignee
北京小米移动软件有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 北京小米移动软件有限公司 filed Critical 北京小米移动软件有限公司
Priority to CN202280002810.3A priority Critical patent/CN117897978A/zh
Priority to PCT/CN2022/112622 priority patent/WO2024036461A1/zh
Publication of WO2024036461A1 publication Critical patent/WO2024036461A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup

Definitions

  • the present disclosure relates to the field of communication technology, and in particular to an authentication method, device, equipment and storage medium for a non-3rd Generation Partnership Project (3GPP) access network to access a 3GPP network.
  • 3GPP non-3rd Generation Partnership Project
  • the terminal device may access the 3GPP network through the 3GPP access network, for example.
  • the 3GPP specifications do not support direct access to the 3GPP network through non-3GPP access networks.
  • EAP Extensible Authentication Protocol
  • 5G 5th Generation Mobile Communication Technology
  • IANA Internet Assigned Numbers Authority
  • this authentication method does not involve the registration operation performed by the terminal device, making the authentication of accessing the 3GPP network through a non-3GPP access network less accurate.
  • the present disclosure proposes an authentication method, device, equipment and storage medium for accessing a 3GPP network through a non-3GPP access network to send information corresponding to the registration operation to the non-3GPP interworking function ( Non-3GPP InterWorking Function (N3IWF) can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • N3IWF Non-3GPP InterWorking Function
  • An embodiment of the present disclosure proposes an authentication method for accessing a 3GPP network through a non-3GPP access network.
  • the method is executed by a terminal device.
  • the method includes:
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed, the registration type corresponding to the registration operation, the user identification and the non-registration information required by the terminal device are sent. At least one of the public network identifiers to N3IWF.
  • sending the user identification corresponding to the registration operation to N3IWF according to the performed registration operation includes:
  • At least one of the following user identifiers is sent to the N3IWF:
  • sending the user identification corresponding to the registration operation to N3IWF according to the performed registration operation includes:
  • SUPI Subscribescription Permanent Identifier
  • sending a registration type corresponding to the registration operation to the N3IWF according to the performed registration operation includes at least one of the following:
  • a Mobility Registration Update Mobility Registration Update registration type is sent to the N3IWF.
  • sending the user identification corresponding to the registration operation to N3IWF according to the performed registration operation includes:
  • NPN Non-Public Network
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • Another aspect of the present disclosure provides an authentication method for accessing a 3GPP network through a non-3GPP access network.
  • the method is executed by N3IWF, and the method includes:
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed by the terminal device, receive the registration type, user identification and the registration operation corresponding to the registration operation sent by the terminal device. At least one of the non-public network identifiers required to be registered by the terminal device;
  • AMF Access and Mobility Management Function
  • receiving a user identification sent by the terminal device corresponding to the registration operation according to the registration operation performed by the terminal device includes:
  • receiving a user identification sent by the terminal device corresponding to the registration operation according to the registration operation performed by the terminal device includes:
  • receiving a registration type corresponding to the registration operation sent by the terminal device includes at least one of the following: :
  • sending the user identification corresponding to the registration operation sent by the terminal device to the N3IWF according to the performed registration operation includes:
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • mapping relationship between the at least one K n3iwf and the at least one SUCI is stored.
  • the method further includes:
  • the terminal device is authenticated according to the K n3iwf corresponding to the SUCI.
  • the method further includes:
  • the terminal device is authenticated according to the K n3iwf corresponding to the SUCI.
  • the method further includes:
  • the terminal device is authenticated according to the K n3iwf corresponding to the SUCI.
  • Another aspect of the present disclosure provides an authentication method for accessing a 3GPP network through a non-3GPP access network.
  • the method is executed by an AMF.
  • the method includes:
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed by the terminal device, receive the registration type, user identification and the terminal device corresponding to the registration operation sent by the N3IWF At least one of the non-public network identities required to be registered.
  • receiving the user identity corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device includes:
  • receiving the user identity corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device includes:
  • receiving a registration type corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device includes at least one of the following:
  • the method further includes:
  • AMF configuration data is used to limit the network application of the terminal device to only online subscription
  • Indication information is stored in the context of the terminal device in the AMF, where the indication information is used to indicate that the terminal device has signed up online.
  • the method further includes:
  • SNPN Onboarding-SNPN, ON-SNPN
  • a timer for implementing specific logout is started, where the timer is configured for the terminal device's online subscription Onboarding.
  • sending the user identification sent by the N3IWF corresponding to the registration operation to the N3IWF according to the performed registration operation includes:
  • the non-public network NPN scenario in response to the extensible authentication protocol EAP mode to support the privacy protection mechanism of the user permanent identifier SUPI, receive the anonymous SUCI sent by the N3IWF, where the anonymous SUCI is the terminal device according to the The configuration information of the terminal device is sent to the anonymous SUCI of the N3IWF.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • K n3iwf is generated according to the K amf , and the mapping relationship between the SUPI, the SUCI and the K n3iwf is stored.
  • the method further includes:
  • the method further includes:
  • Another aspect of the present disclosure provides an authentication device for accessing a 3GPP network through a non-3GPP access network.
  • the device is provided on the terminal device side, and the device includes:
  • a sending module configured to, if the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, send the registration type, user identification and the terminal device corresponding to the registration operation according to the registration operation performed. At least one of the non-public network identities required to be registered to the non-3GPP interworking function N3IWF.
  • Another aspect of the present disclosure provides an authentication device for accessing a 3GPP network through a non-3GPP access network.
  • the device is provided on the N3IWF side, and the device includes:
  • a receiving module configured to receive a registration type corresponding to the registration operation sent by the terminal device according to the registration operation performed by the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network. , user identification and at least one of the non-public network identification required to be registered by the terminal device;
  • a sending module configured to send at least one of the registration type corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal device to the access and mobility management function AMF.
  • Another aspect of the present disclosure provides an authentication device for accessing a 3GPP network through a non-3GPP access network.
  • the device is provided on the AMF side, and the device includes:
  • a receiving module configured to receive the registration type and user identification sent by the N3IWF corresponding to the registration operation according to the registration operation performed by the terminal equipment when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network. and at least one of the non-public network identities that the terminal device needs to register.
  • the device includes a processor and a memory.
  • a computer program is stored in the memory.
  • the processor executes the computer program stored in the memory so that the The device performs the method proposed in the embodiment of the above aspect.
  • the device includes a processor and a memory.
  • a computer program is stored in the memory.
  • the processor executes the computer program stored in the memory, so that the device Execute the method proposed in the embodiment of the above aspect.
  • the device includes a processor and a memory.
  • a computer program is stored in the memory.
  • the processor executes the computer program stored in the memory so that the device Execute the method proposed in the embodiment of the above aspect.
  • a communication device provided by another embodiment of the present disclosure includes: a processor and an interface circuit
  • the interface circuit is used to receive code instructions and transmit them to the processor
  • the processor is configured to run the code instructions to execute the method proposed in any of the above embodiments.
  • a computer-readable storage medium provided by an embodiment of another aspect of the present disclosure is used to store instructions. When the instructions are executed, the method proposed in any of the above embodiments is implemented.
  • the system includes:
  • a terminal device configured to, when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, send the registration type, user identification and the terminal device corresponding to the registration operation according to the registration operation performed. At least one of the non-public network identities required to be registered to N3IWF;
  • the N3IWF is configured to receive, according to the registration operation performed by the terminal equipment, the registration type and user identification corresponding to the registration operation sent by the terminal equipment and the non-public network identification required to be registered by the terminal equipment. at least one, and send at least one of the registration type corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal device to the AMF;
  • the AMF is configured to receive, according to the registration operation performed by the terminal device, at least one of the registration type sent by the N3IWF corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal equipment. .
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the registration type corresponding to the registration operation is to the non-3GPP interworking function N3IWF.
  • the registration operation performed by the terminal device information corresponding to the registration operation is sent to the N3IWF, reducing the situation where the sent information does not match the registration operation performed by the terminal device, and improving access to the network through non-3GPP
  • the accuracy of authentication for accessing the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to send information corresponding to the registration operation to the N3IWF according to the registration operation performed by the terminal device. Improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 1 is an interactive schematic diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network according to an embodiment of the present disclosure
  • Figure 2 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to an embodiment of the present disclosure
  • Figure 3 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 4 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 5 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 6 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to another embodiment of the present disclosure
  • Figure 7 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 8 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 9 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure.
  • Figure 10 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 11 is a schematic flow chart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to another embodiment of the present disclosure
  • Figure 12 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 13 is a schematic flow chart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 14 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 15 is a schematic flow chart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 16 is an interactive schematic diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure
  • Figure 17 is an interactive schematic diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure
  • Figure 18 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 19 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network according to yet another embodiment of the present disclosure
  • Figure 20 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 21 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 22 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 23 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 24 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by yet another embodiment of the present disclosure
  • Figure 25 is an interactive schematic diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure
  • Figure 26 is an interactive schematic diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure
  • Figure 27 is a schematic architectural diagram of a communication system provided by an embodiment of the present disclosure.
  • Figure 28 is a schematic structural diagram of an authentication device for accessing a 3GPP network through a non-3GPP access network according to an embodiment of the present disclosure
  • Figure 29 is a schematic structural diagram of an authentication device for accessing a 3GPP network through a non-3GPP access network according to another embodiment of the present disclosure.
  • Figure 30 is a schematic structural diagram of an authentication device for accessing a 3GPP network through a non-3GPP access network according to another embodiment of the present disclosure
  • Figure 31 is a block diagram of a terminal device provided by an embodiment of the present disclosure.
  • Figure 32 is a block diagram of a network side device provided by an embodiment of the present disclosure.
  • first, second, third, etc. may be used to describe various information in the embodiments of the present disclosure, the information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other.
  • first information may also be called second information, and similarly, the second information may also be called first information.
  • the words "if” and “if” as used herein may be interpreted as “when” or “when” or “in response to determining.”
  • the network elements or network functions involved in the embodiments of the present disclosure can be implemented by independent hardware devices or by software in the hardware devices. This is not limited in the embodiments of the present disclosure.
  • Figure 1 shows an interactive diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the end device connects to an untrusted non-3GPP access network using procedures outside the scope of 3GPP.
  • the terminal device decides to connect to the 5G core network 5GC network
  • the terminal device can select N3IWF in the 5G Public Land Mobile Network (PLMN).
  • PLMN Public Land Mobile Network
  • the terminal device can continue to establish an IPsec Security Association (SA) with the selected N3IWF by initiating an initial exchange of the network key exchange protocol IKE according to RFC 7296.
  • SA IPsec Security Association
  • the terminal device can initiate an IKE_AUTH exchange by sending an IKE_Authentication AUTH request message.
  • the AUTH payload is not included in the IKE_AUTH request message, which indicates that the IKE_AUTH exchange can use EAP signaling.
  • the EAP signaling can be, for example, EAP-5G signaling.
  • IDi the terminal device should set the identification ID type to ID_KEY-ID in the message and set its value to any random number. Among them, IDi is a data information segment including ID information.
  • the terminal device should not use any of its Globally Unique Temporary UE Identity (GUTI), SUCI and SUPI as the identification ID in this step. If the end device provides the N3IWF root certificate, the end device should include the verification request information CERTREQ payload in the IKE_AUTH request message to request the N3IWF certificate.
  • GUI Globally Unique Temporary UE Identity
  • N3IWF can respond using an IKE_AUTH response message, where the IKE_AUTH response message includes the N3IWF identity, AUTH payload and EAP-Request or 5G-Start data packet, where , the AUTH payload is used to protect the previous message sent by N3IWF to the end device (in the IKE_SA_INIT exchange).
  • the EAP-Request or 5G-Start packet is used to notify the terminal device to start the EAP-5G session, that is, to start sending Network Attached Storage (NAS) messages encapsulated in the EAP-5G packet.
  • NAS Network Attached Storage
  • N3IWF shall also send a CERT payload containing the N3IWF certificate to the terminal device.
  • the end device will verify the N3IWF certificate and confirm that the N3IWF identity matches the N3IWF selected by the end device. If the end device requests a certificate or identity confirmation is unsuccessful, N3IWF's lack of certificate will cause the connection to fail.
  • the end device shall send an IKE_AUTH request that includes an EAP-Response or 5G-NAS packet containing a registration request message containing the end device security capabilities and SUCI/onboarding SUCI /Anonymous value SUCI.
  • N3IWF does not send an EAP-Identity request because the end device includes its identity in the IKE_AUTH request in step five.
  • the N3IWF should select the AMF specified in TS 23.501 section 6.5.3.
  • N3IWF forwards the registration request received from the terminal device to the AMF.
  • the registration request is carried in the N2 message.
  • Seventh perform authentication operations according to the authentication described in TS 23.501 Section 6.1.3.
  • the AUSF shall send the anchor key K SEAF derived from K AUSF to the security anchor function SEAF.
  • SEAF should export K amf from K SEAF and send it to AMF.
  • AMF uses this K amf to derive the NAS security key.
  • the AUSF SHOULD include Extensible Authentication Protocol Success EAP-Success.
  • the end device can also derive the anchor key K SEAF and from that key derive K amf and then the NAS security key.
  • the AMF and the AUSF may be co-located, that is, the AMF and the AUSF are one device.
  • the AMF should send a Security Mode Command (SMC) to the end device to activate NAS security associated with the NAS connection identifier "0x02". This message is first sent to N3IWF (in N2 message). If EAP-AKA' is used for authentication, the AMF shall encapsulate the EAP-Success received from the AUSF in an SMC message.
  • SMC Security Mode Command
  • the N3IWF should forward the NAS SMC to the terminal device in the EAP-Request/5G-NAS data packet.
  • the end device completes authentication (if initiated in step 7) and creates a NAS security context or activates a NAS security context based on the security context identity ngKSI received in the NAS SMC.
  • the end device shall respond to the NAS SMC received from the AMF according to the selected algorithm and parameters described in TS 23.501 section 6.7.2.
  • the UE shall encapsulate the NAS SMC Complete in the EAP-5G response.
  • N3IWF should forward the NAS packet containing NAS SMC Complete to AMF through the N2 interface.
  • the AMF After receiving the NAS SMC Complete or integrity protection verification from the terminal device, the AMF starts the Next Generation Application Protocol (NGAP) process to establish a context.
  • the AMF shall calculate the N3IWF key K N3IWF using the uplink NAS COUNT associated with the defined NAS connection identifier "0x02" to establish the IPsec SA between the end device and N3IWF and send an NGAP initial context setup request to N3IWF, where , K N3IWF is included in the NGAP initial context setup request.
  • N3IWF can send EAP-Success or EAP-5G to the terminal device when receiving the NGAP initial context setting request containing N3IWF key K N3IWF . This completes the EAP-5G session and no more EAP-5G packets are exchanged. If N3IWF does not receive K N3IWF from AMF, N3IWF shall respond with EAP-Failure.
  • the IPsec SA is established between the terminal device and N3IWF by using the N3IWF key K N3IWF , which is a NAS connection identifier defined in the terminal device using The uplink NAS COUNT associated with "0x02" is created and received by the N3IWF from the AMF in step 12.
  • N3IWF will send an NGAP Initial Context Setup Response message to the AMF.
  • AMF receives the NGAP Initial Context Setup Response from the UE, AMF will send the terminal device's NAS registration acceptance message to N3IWF through the N2 message.
  • N3IWF will forward it to the end device through the established IPsec SA. All further NAS messages between the end device and N3IWF should be sent over the established IPsec SA.
  • FIG. 2 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by a terminal device. As shown in Figure 2, the method may include the following steps:
  • Step 201 When the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed, send the registration type corresponding to the registration operation, the user identification, and the non-public network identification that the terminal device needs to register. At least one of the non-3GPP interworking functions N3IWF.
  • the terminal device may be a device that provides voice and/or data connectivity to the user.
  • Terminal devices can communicate with one or more core networks via RAN (Radio Access Network).
  • Terminal devices can be IoT terminals, such as sensor devices, mobile phones (or "cellular" phones) and devices with The computer of the Internet of Things terminal, for example, can be a fixed, portable, pocket-sized, handheld, computer-built-in or vehicle-mounted device.
  • the terminal device may also be a device of an unmanned aerial vehicle.
  • the terminal device may also be a vehicle-mounted device, for example, it may be a driving computer with wireless communication function, or a wireless terminal connected to an external driving computer.
  • the terminal device may also be a roadside device, for example, it may be a street light, a signal light or other roadside device with wireless communication function.
  • the 3GPP network is a non-public network.
  • the non-public network identifier includes (Public Land Mobile Network ID, PLMN ID) and a network identifier (network identifier, NID).
  • PLMN ID Public Land Mobile Network ID
  • NID network identifier
  • sending the user identification corresponding to the registration operation to N3IWF includes:
  • N3IWF In response to the performed registration operation being an independent non-public network online subscription registration (SNPN Onboarding Registration), send at least one of the following user identifiers to N3IWF:
  • sending the user identification corresponding to the registration operation to N3IWF includes:
  • the registration type corresponding to the registration operation is sent to the N3IWF, including at least one of the following:
  • sending the user identification corresponding to the registration operation to N3IWF includes:
  • anonymous SUCI is sent to N3IWF according to the configuration information of the terminal device.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • the SUCI is sent to the N3IWF.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the registration type corresponding to the registration operation is to the non-3GPP interworking function N3IWF.
  • the registration operation performed by the terminal device information corresponding to the registration operation is sent to the N3IWF, reducing the situation where the sent information does not match the registration operation performed by the terminal device, and improving access to the network through non-3GPP
  • the accuracy of authentication for accessing the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to send information corresponding to the registration operation to the N3IWF according to the registration operation performed by the terminal device. Improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • FIG 3 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the method is executed by a terminal device. As shown in Figure 3, the method may include the following steps:
  • Step 301 In response to the execution of the registration operation being independent non-public network online subscription registration (SNPN Onboarding Registration), send at least one of the following user identifiers to N3IWF:
  • the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the performed registration operation, it is an independent non-public network online subscription registration (SNPN Onboarding Registration). ), the terminal device sends at least one of the following user identities to N3IWF: onboarding SUCI; onboarding SUPI. For example, the end device can send onboarding SUCI to N3IWF, or the end device can send onboarding SUPI to N3IWF.
  • N3IWF onboarding SUCI
  • SUPI onboarding SUPI
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the registration operation performed, it is an independent non-public network online subscription registration (SNPN Onboarding). Registration), send at least one of the following user IDs to N3IWF: onboarding SUCI; onboarding SUPI.
  • N3IWF onboarding SUCI
  • SUPI onboarding SUPI
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send the user identification corresponding to the registration operation to the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • FIG 4 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by a terminal device. As shown in Figure 4, the method may include the following steps:
  • Step 401 In response to the execution of the registration operation being initial registration or mobile registration update, send at least one of the following user identities to N3IWF:
  • the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the performed registration operation of performing initial registration or performing mobile registration update, the terminal device sends
  • the user ID to N3IWF can be at least one of the following:
  • the terminal device may send SUCI to N3IWF, or the terminal device may send SUPI to N3IWF.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the following is sent At least one of the user identifications to N3IWF: SUCI; SUPI.
  • the user identification corresponding to the registration operation is sent to the N3IWF, thereby reducing the situation where the sent user identification does not match the registration operation performed by the terminal device, Improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks, so that terminal devices can access 3GPP networks through non-3GPP access networks.
  • the present disclosure provides a processing method for a situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send a message corresponding to the registration operation according to the initial registration or mobile registration update performed by the terminal device.
  • User identification to N3IWF can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • FIG. 5 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by a terminal device. As shown in Figure 5, the method may include the following steps:
  • Step 501 In response to the execution of the registration operation to perform independent non-public network online subscription registration (SNPN Onboarding Registration), send the SNPN Onboarding registration type to N3IWF.
  • SNPN Onboarding Registration independent non-public network online subscription registration
  • the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the execution of the registration operation to perform independent non-public network online subscription registration, send SNPN Onboarding registration type to N3IWF.
  • the registration type corresponding to the registration operation is sent to N3IWF, thereby reducing the situation where the sent registration type does not match the registration operation performed by the terminal device. , improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks, so that terminal devices can access 3GPP networks through non-3GPP access networks.
  • This disclosed embodiment specifically discloses a solution in which the registration type corresponding to the independent non-public network online contract registration is the SNPN Onboarding registration type.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send a message corresponding to the registration operation based on the independent non-public network online signing registration performed by the terminal device.
  • the registration type to N3IWF can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 6 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by a terminal device. As shown in Figure 6, the method may include the following steps:
  • Step 601 In response to the execution of the registration operation being to perform initial registration, send the initial registration Initial Registration registration type to N3IWF.
  • the initial registration Initial Registration registration type is sent to N3IWF.
  • the registration type corresponding to the registration operation is sent to the N3IWF, thereby reducing the situation where the sent registration type does not match the registration operation performed by the terminal device, and improving communication through non-3GPP connections.
  • the accuracy of authentication for accessing the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosed embodiment specifically discloses a solution in which the registration type corresponding to the initial registration is the Initial Registration registration type.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send the registration type corresponding to the registration operation to the N3IWF according to the initial registration performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • FIG. 7 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by a terminal device. As shown in Figure 7, the method may include the following steps:
  • Step 701 In response to the execution of the registration operation being to perform a mobile registration update, send the Mobility Registration Update Mobility Registration Update registration type to N3IWF.
  • the mobile registration update Mobility Registration is sent. Update registration type to N3IWF.
  • the registration type corresponding to the registration operation is sent to the N3IWF, thereby reducing the mismatch between the sent registration type and the registration operation performed by the terminal device, and improving the efficiency of non-3GPP communication.
  • the accuracy of the authentication of the access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosed embodiment specifically discloses a solution in which the registration type corresponding to the mobile registration update is the Mobility Registration Update registration type.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send the registration type corresponding to the registration operation to the N3IWF according to the initial registration performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • FIG 8 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by a terminal device. As shown in Figure 8, the method may include the following steps:
  • Step 801. In the non-public network NPN scenario, respond to the privacy protection mechanism of the Extensible Authentication Protocol EAP method to support the user permanent identifier SUPI, and send the anonymous SUCI to the N3IWF according to the configuration information of the terminal device.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • the SUCI is sent to the N3IWF.
  • the anonymous SUCI is sent to the user according to the configuration information of the terminal device.
  • N3IWF in response to the EAP mode supporting the privacy protection mechanism of SUPI, sending anonymous SUCI to N3IWF according to the configuration information of the terminal device can improve the accuracy of authentication for accessing the 3GPP network through a non-3GPP access network, so that Terminal devices can access the 3GPP network through non-3GPP access networks.
  • the embodiments of the present disclosure specifically disclose a solution for sending anonymous SUCI according to the configuration information of the terminal device.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to send the registration type corresponding to the registration operation to the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • FIG. 9 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the method is executed by N3IWF.
  • the method may include the following steps:
  • Step 901 When the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed by the terminal device, receive the registration type, user identification and information required by the terminal device corresponding to the registration operation and sent by the terminal device. At least one of the registered non-public network identities;
  • Step 902 Send at least one of the registration type corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal device to the access and mobility management function AMF.
  • receiving the user identification corresponding to the registration operation sent by the terminal device includes:
  • receiving the user identification corresponding to the registration operation sent by the terminal device includes:
  • the registration type corresponding to the registration operation sent by the terminal device is received, including at least one of the following:
  • sending the user identification corresponding to the registration operation sent by the terminal device to the N3IWF includes:
  • the anonymous SUCI sent by the terminal device according to the configuration information of the terminal device is received.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • the method further includes:
  • the method further includes:
  • the generation algorithm of SUCI sent by N3IWF to the terminal device is optional every time, that is, N3IWF may send the generation algorithm of SUCI to the terminal device every time, and N3IWF may not send it every time. Send the SUCI generation algorithm to the terminal device.
  • the N3IWF when the N3IWF receives the SUCI sent by the terminal device, the N3IWF can locate K n3iwf through the SUCI and then use the N3IWF key K n3iwf to establish an IPsec SA with the terminal device.
  • the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed by the terminal device, the terminal device receives the information corresponding to the registration operation. At least one of a registration type, a user identification, and a non-public network identification that the terminal device needs to register; sending at least one of a registration type, a user identification, and a non-public network identification that the terminal equipment needs to register corresponding to the registration operation to AMF.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • FIG 10 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the method is executed by N3IWF.
  • the method may include the following steps:
  • Step 1001. In response to the registration operation performed by the terminal device to register SNPN Onboarding Registration for an independent non-public network online subscription, receive at least one of the following user identifiers sent by the terminal device:
  • Step 1002 Send the user ID corresponding to the registration operation to AMF.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the SNPN is registered for the independent non-public network online subscription Onboarding Registration, receiving at least one of the following user IDs sent by the terminal device: onboarding SUCI; onboarding SUPI; sending the user ID corresponding to the registration operation to AMF.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the disclosed embodiment specifically discloses a solution for independent non-public network online signing and registration corresponding user identification.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • FIG 11 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the method is executed by N3IWF.
  • the method may include the following steps:
  • Step 1101. In response to the registration operation being initial registration or mobile registration update, receive at least one of the following user identities sent by the terminal device:
  • Step 1102 Send the user ID corresponding to the registration operation to AMF.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the registration operation being initial registration or mobile registration update
  • the following is received from the terminal device.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the disclosed embodiment specifically discloses a solution for updating the user identity corresponding to initial registration or mobile registration.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • Figure 12 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by N3IWF. As shown in Figure 12, the method may include the following steps:
  • Step 1201. In response to the registration operation performed by the terminal device to perform independent non-public network online subscription registration SNPN Onboarding Registration, receive the SNPN Onboarding registration type sent by the terminal device;
  • Step 1202 Send the registration type corresponding to the registration operation to the AMF.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • an independent non-public network online subscription registration is performed.
  • SNPN Onboarding Registration receives the SNPN Onboarding registration type sent by the terminal device; sends the registration type corresponding to the registration operation to AMF.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the disclosed embodiment specifically discloses a registration type solution corresponding to independent non-public network online contract registration.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • Figure 13 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the method is executed by N3IWF.
  • the method may include the following steps:
  • Step 1301 In response to the registration operation performed by the terminal device to perform initial registration, receive the initial registration Initial Registration registration type sent by the terminal device;
  • Step 1302 Send the registration type corresponding to the registration operation to the AMF.
  • the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the registration operation performed by the terminal device to perform initial registration, the terminal device receives the Initial registration Initial Registration registration type; send the registration type corresponding to the registration operation to AMF.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the embodiments of this disclosure specifically disclose the solution of the registration type corresponding to the initial registration.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • Figure 14 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by N3IWF. As shown in Figure 14, the method may include the following steps:
  • Step 1401 In response to the registration operation performed by the terminal device to perform a mobile registration update, receive the Mobility Registration Update Mobility Registration Update registration type sent by the terminal device;
  • Step 1402 Send the registration type corresponding to the registration operation to the AMF.
  • the receiving terminal device when a terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the registration operation performed by the terminal device to perform a mobile registration update, the receiving terminal device sends Mobility Registration Update Mobility Registration Update registration type; sends the registration type corresponding to the registration operation to AMF.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the embodiments of this disclosure specifically disclose a solution for registration types corresponding to mobile registration updates.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • Figure 15 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the method is executed by N3IWF.
  • the method may include the following steps:
  • Step 1501 In the non-public network NPN scenario, in response to the extensible authentication protocol EAP method to support the privacy protection mechanism of the user permanent identifier SUPI, receive the anonymous SUCI sent by the terminal device according to the configuration information of the terminal device;
  • Step 1502 Send anonymous SUCI to AMF.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • the method further includes:
  • the method further includes:
  • the receiving terminal device in response to the extensible authentication protocol EAP mode to support the privacy protection mechanism of the user permanent identifier SUPI, the receiving terminal device sends according to the configuration information of the terminal device Anonymous SUCI; send anonymous SUCI to AMF.
  • anonymous SUCI in response to the EAP mode supporting the privacy protection mechanism of SUPI, anonymous SUCI is sent to N3IWF according to the configuration information of the terminal device.
  • N3IWF can send anonymous SUCI to AMF, which can improve access to 3GPP through non-3GPP access networks.
  • the accuracy of network authentication enables terminal devices to access 3GPP networks through non-3GPP access networks.
  • the embodiments of the present disclosure specifically disclose a solution for receiving anonymous SUCI sent by a terminal device according to the configuration information of the terminal device.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the registration type and user identification corresponding to the registration operation according to the registration operation performed by the terminal device. and at least one of the non-public network identifiers required to be registered by the terminal device, which can improve the accuracy of authentication for accessing the 3GPP network through a non-3GPP access network.
  • Figure 16 is an interaction diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. As shown in Figure 16, the method may include the following steps:
  • Step 1601 N3IWF sends the SUCI generation algorithm to the terminal device
  • Step 1602 The terminal device generates SUCI according to the SUCI generation algorithm and sends SUCI to N3IWF;
  • Step 1603 N3IWF receives the SUCI sent by the terminal device, where the SUCI is generated according to the SUCI generation algorithm;
  • Step 1604 N3IWF determines the K n3iwf corresponding to the SUCI based on the mapping relationship between the SUCI and at least one K n3iwf and at least one SUCI;
  • Step 1605 N3IWF authenticates the terminal device according to the K n3iwf corresponding to SUCI.
  • the SUCI generation algorithm is sent to the terminal device; the SUCI sent by the terminal device is received, where the SUCI is generated according to the SUCI generation algorithm; according to the SUCI and at least one K n3iwf and at least one SUCI
  • the mapping relationship is determined to determine the K n3iwf corresponding to SUCI; the terminal device is authenticated based on the K n3iwf corresponding to SUCI.
  • determining the K n3iwf corresponding to the SUCI based on the SUCI sent by the terminal device can improve the accuracy of authentication for accessing the 3GPP network through the non-3GPP access network, so that the terminal device can access the 3GPP network through the non-3GPP access network. Enter the 3GPP network.
  • the embodiments of the present disclosure specifically disclose a solution for receiving anonymous SUCI sent by a terminal device according to the configuration information of the terminal device.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the registration type and user identification corresponding to the registration operation according to the registration operation performed by the terminal device. and at least one of the non-public network identifiers required to be registered by the terminal device, which can improve the accuracy of authentication for accessing the 3GPP network through a non-3GPP access network.
  • Figure 17 is an interaction diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. As shown in Figure 17, the method may include the following steps:
  • Step 1701. In response to not receiving the SUCI generation algorithm sent by N3IWF, the terminal device sends SUCI to N3IWF.
  • Step 1702. In response to the SUCI generation algorithm not being sent to the terminal device, N3IWF receives the SUCI sent by the terminal device;
  • Step 1703 N3IWF determines the K n3iwf corresponding to the SUCI based on the mapping relationship between SUCI and at least one K n3iwf and at least one SUCI;
  • Step 1704 N3IWF authenticates the terminal device according to the K n3iwf corresponding to SUCI.
  • the SUCI sent by the terminal device in response to not sending the SUCI generation algorithm to the terminal device, the SUCI sent by the terminal device is received; N3IWF determines the SUCI correspondence according to the mapping relationship between SUCI and at least one K n3iwf and at least one SUCI. K n3iwf ; N3IWF authenticates the terminal device according to the K n3iwf corresponding to the SUCI.
  • the K n3iwf corresponding to the SUCI is determined according to the SUCI sent by the terminal device, which can improve access to the 3GPP network through a non-3GPP access network.
  • the accuracy of authentication enables terminal devices to access 3GPP networks through non-3GPP access networks.
  • the embodiments of the present disclosure specifically disclose a solution for receiving anonymous SUCI sent by a terminal device according to the configuration information of the terminal device.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the registration type and user identification corresponding to the registration operation according to the registration operation performed by the terminal device. and at least one of the non-public network identifiers required to be registered by the terminal device, which can improve the accuracy of authentication for accessing the 3GPP network through a non-3GPP access network.
  • Figure 18 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 18, the method may include the following steps:
  • Step 1801 When the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed by the terminal device, receive the registration type, user identification and required registration of the terminal device corresponding to the registration operation sent by the N3IWF. At least one of the non-public network identifiers.
  • receiving the user identification corresponding to the registration operation sent by N3IWF includes:
  • receiving the user identification corresponding to the registration operation sent by the N3IWF includes:
  • receiving the registration type corresponding to the registration operation sent by the N3IWF includes at least one of the following:
  • the method further includes:
  • Indication information is stored in the context of the terminal device in the AMF, where the indication information is used to indicate that the terminal device has signed up online.
  • the method further includes:
  • sending the user identification corresponding to the registration operation sent by N3IWF to N3IWF includes:
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • the method further includes:
  • the AUSF obtains the SUPI of the terminal device, and at the same time, the AUSF encrypts the user's SUPI into SUCI and generates K seaf .
  • AUSF sends the generated Kseaf, the algorithm used to generate SUCI, SUPI, and SUCI to AMF or SEAF.
  • AMF or SEAF is generally a joint device, that is, AMF or SEAF is a device.
  • SEAF can generate K amf based on K seaf and the user's SUPI.
  • AMF generates K n3iwf based on K amf .
  • the method further includes:
  • the method further includes:
  • N3IWF Receive the SUCI sent by N3IWF, where SUCI is the SUCI of K n3iwf sent by the terminal device to N3IWF, and N3IWF has not determined the SUCI corresponding to K n3iwf ;
  • the N3IWF when the N3IWF receives the SUPI sent by the AUSF for SUCI, the N3IWF can locate K n3iwf through the SUPI, and then use the N3IWF key K n3iwf to establish an IPsec SA with the terminal device.
  • the generation algorithm of SUCI sent by AMF to N3IWF every time is optional, that is, AMF can send the generation algorithm of SUCI to N3IWF every time, and AMF does not need to send the generation algorithm of SUCI to N3IWF every time. Send the SUCI generation algorithm.
  • each time AUSF sends the SUCI generation algorithm to AMF it is optional. That is, AUSF can send SUCI generation algorithm to AMF every time, and AUSF does not need to send SUCI generation algorithm to AMF every time. Send the SUCI generation algorithm.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, according to the registration operation performed by the terminal device, the registration corresponding to the registration operation sent by the N3IWF is received. At least one of a type, a user identity, and a non-public network identity that the terminal device needs to register.
  • the information sent by the N3IWF corresponding to the registration operation is received, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP
  • the accuracy of authentication for network access to the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the information corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 19 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 19, the method may include the following steps:
  • Step 1901 In response to the registration operation performed by the terminal device, register SNPN Onboarding Registration for an independent non-public network online subscription, and receive at least one of the following user identifiers sent by N3IWF:
  • the terminal device in response to the registration operation performed by the terminal device to register SNPN Onboarding Registration for an independent non-public network online subscription, at least one of the following user identities sent by N3IWF is received: onboarding SUCI; onboarding SUPI.
  • the user identification sent by the N3IWF corresponding to the registration operation is received, thereby reducing the mismatch between the received user identification and the registration operation performed by the terminal equipment, and improving the efficiency of communication through non-3GPP
  • the accuracy of the authentication of the access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the disclosed embodiment specifically discloses a solution for independent non-public network online signing and registration corresponding user identification.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the information corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 20 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 20, the method may include the following steps:
  • Step 2001 In response to the registration operation being initial registration or mobile registration update, receive at least one of the following user identities sent by N3IWF:
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the registration operation being initial registration or mobile registration update
  • the following user sent by the N3IWF is received
  • At least one of the identifiers user hidden identifier SUCI; user permanent identifier SUPI.
  • the user identification sent by the N3IWF corresponding to the registration operation is received, thereby reducing the mismatch between the received user identification and the registration operation performed by the terminal equipment, and improving the efficiency of communication through non-3GPP
  • the accuracy of the authentication of the access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the embodiments of this disclosure specifically disclose a solution for updating the user identity corresponding to initial registration or mobile registration.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to receive the information corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 21 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 21, the method may include the following steps:
  • Step 2101 In response to the registration operation performed by the terminal device to perform independent non-public network online subscription registration SNPN Onboarding Registration, receive the SNPN Onboarding registration type sent by N3IWF.
  • the method further includes: AMF applying locally configured AMF configuration data to online subscription, where the AMF configuration data is used to limit the network application of the terminal device to online subscription only; in the AMF Indication information is stored in the context of the terminal device in , where the indication information is used to indicate that the terminal device has signed up online.
  • the method further includes: based on the ON-SNPN policy, the AMF starts a timer for implementing specific logout, wherein the timer is configured for the terminal device to sign online for Onboarding.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • an independent non-public network online subscription registration is performed.
  • SNPN Onboarding Registration receives the SNPN Onboarding registration type sent by N3IWF.
  • the registration type corresponding to the registration operation sent by the N3IWF is received, thereby reducing the mismatch between the received registration type and the registration operation performed by the terminal device, and improving the efficiency of non-3GPP communication.
  • the accuracy of the authentication of the access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the disclosed embodiment specifically discloses a registration type solution corresponding to independent non-public network online contract registration.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the information corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 22 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 22, the method may include the following steps:
  • Step 2201 In response to the registration operation performed by the terminal device to perform initial registration, receive the initial registration Initial Registration registration type sent by N3IWF.
  • the terminal device accesses the 3GPP network through an untrusted non-3GPP access network
  • the initial registration sent by the N3IWF is received.
  • Register the Initial Registration registration type In the embodiments of the present disclosure, according to the registration operation performed by the terminal device, the registration type corresponding to the registration operation sent by the N3IWF is received, thereby reducing the mismatch between the received registration type and the registration operation performed by the terminal device, and improving the efficiency of non-3GPP communication.
  • the accuracy of the authentication of the access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the embodiments of this disclosure specifically disclose the solution of the registration type corresponding to the initial registration.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to receive the registration type corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device. , which can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 23 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 23, the method may include the following steps:
  • Step 2301 In response to the registration operation performed by the terminal device to perform a mobile registration update, receive the Mobility Registration Update Mobility Registration Update registration type sent by the N3IWF.
  • the N3IWF when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, in response to the registration operation performed by the terminal device to perform a mobile registration update, the N3IWF sends Mobility Registration UpdateMobility Registration Update registration type.
  • the registration type corresponding to the registration operation sent by the N3IWF is received, thereby reducing the mismatch between the received registration type and the registration operation performed by the terminal device, and improving the efficiency of non-3GPP communication.
  • the accuracy of the authentication of the access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the embodiments of this disclosure specifically disclose a solution for registration types corresponding to mobile registration updates.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the registration type corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device. , which can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • Figure 24 is a schematic flowchart of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. The method is executed by the AMF. As shown in Figure 24, the method may include the following steps:
  • Step 2401 In the non-public network NPN scenario, respond to the privacy protection mechanism of the Extensible Authentication Protocol EAP mode that supports the user permanent identifier SUPI, and receive the anonymous SUCI sent by the N3IWF, where the anonymous SUCI is the configuration information of the terminal device according to the terminal device Anonymous SUCI sent to N3IWF.
  • the anonymous SUCI is the configuration information of the terminal device according to the terminal device Anonymous SUCI sent to N3IWF.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the method further includes:
  • AMF uses at least one of the following authentication methods to authenticate terminal devices:
  • the method further includes:
  • AMF stores the mapping relationship between SUPI, SUCI and K n3iwf , which is used by AMF to search for K n3iwf based on SUPI or SUCI, thereby improving the convenience of K n3iwf search.
  • the method further includes:
  • the method further includes:
  • N3IWF Receive the SUCI sent by N3IWF, where SUCI is the SUCI of K n3iwf sent by the terminal device to N3IWF, and N3IWF has not determined the SUCI corresponding to K n3iwf ;
  • the N3IWF when the N3IWF receives the SUPI sent by the AUSF for SUCI, the N3IWF can locate K n3iwf through the SUPI, and then use the N3IWF key K n3iwf to establish an IPsec SA with the terminal device.
  • the anonymous SUCI sent by the N3IWF in response to the extensible authentication protocol EAP mode to support the privacy protection mechanism of the user permanent identifier SUPI, the anonymous SUCI sent by the N3IWF is received, where the anonymous SUCI is an anonymous SUCI sent by the terminal device to N3IWF according to the configuration information of the terminal device.
  • the anonymous SUCI sent by N3IWF in response to the EAP mode supporting the privacy protection mechanism of SUPI, the anonymous SUCI sent by N3IWF is received, where the anonymous SUCI is the anonymous SUCI sent by the terminal device to N3IWF according to the configuration information of the terminal device, which can improve the efficiency of communication through non-
  • the accuracy of the authentication of the 3GPP access network to access the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the disclosed embodiment specifically discloses a solution for receiving anonymous SUCI sent by N3IWF.
  • This disclosure provides a processing method for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network” to receive the registration type and user identification corresponding to the registration operation according to the registration operation performed by the terminal device. and at least one of the non-public network identifiers required to be registered by the terminal device, which can improve the accuracy of authentication for accessing the 3GPP network through a non-3GPP access network.
  • Figure 25 is an interaction diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. As shown in Figure 25, the method may include the following steps:
  • Step 2501. In response to not receiving the SUCI generation algorithm sent by N3IWF, the terminal device sends SUCI to N3IWF.
  • Step 2502 In response to the SUCI generation algorithm not being sent to the terminal device, N3IWF receives the SUCI sent by the terminal device;
  • Step 2503 N3IWF sends SUCI to AMF when the K n3iwf corresponding to SUCI is not determined according to the mapping relationship between SUCI and at least one K n3iwf and at least one SUCI;
  • Step 2504 AMF receives the SUCI sent by N3IWF, where the SUCI is the SUCI sent by the terminal device to N3IWF, and N3IWF has not determined the SUCI of K n3iwf corresponding to the SUCI;
  • Step 2505 AMF sends SUCI to the authentication service function AUSF;
  • Step 2506 AUSF decrypts SUPI according to SUCI and sends SUPI to AMF;
  • Step 2507 AMF receives the SUPI sent by AUSF for SUCI, and determines K n3iwf corresponding to SUCI based on SUPI;
  • Step 2508 AMF sends K n3iwf corresponding to SUCI to N3IWF;
  • Step 2509 N3IWF receives the K n3iwf corresponding to the SUCI determined based on the SUCI sent by the AMF;
  • Step 2510 N3IWF authenticates the terminal device according to the K n3iwf corresponding to SUCI.
  • the N3IWF when it does not determine the K n3iwf corresponding to the SUCI according to the mapping relationship, it can receive the K n3iwf sent by the AMF, which can improve the authentication of accessing the 3GPP network through a non-3GPP access network. Accuracy enables terminal devices to access 3GPP networks through non-3GPP access networks.
  • Figure 26 is an interaction diagram of an authentication method for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure. As shown in Figure 26, the method may include the following steps:
  • Step 2601. After completing the authentication of the terminal device on the 3GPP network or the default credential server, AUSF obtains the SUPI of the terminal device, and AUSF encrypts the user's SUPI into SUCI and generates K seaf ;
  • Step 2602 AUSF sends the generated Kseaf, the algorithm used to generate SUCI, SUPI, and SUCI to AMF or SEAF;
  • Step 2603 SEAF can generate K amf based on K seaf and the user's SUPI;
  • Step 2604 AMF generates K n3iwf according to K amf ;
  • Step 2605 AMF sends K n3iwf , SUCI, and SUCI generation algorithm to N3IWF;
  • Step 2606 N3IWF receives SUCI and K n3iwf , and stores the mapping relationship between SUCI and K n3iwf .
  • the AMF or the SEAF are generally co-located, that is, the AMF or the SEAF are one device.
  • the transmission of the SUCI generation algorithm is optional, that is, it can be sent or not.
  • AUSF may send the SUCI generation algorithm to AMF or SEAF, or AUSF may not send the SUCI generation algorithm to AMF or SEAF.
  • AMF or SEAF may send the SUCI generation algorithm to N3IWF, or AMF or SEAF may not send the SUCI generation algorithm to N3IWF.
  • N3IWF may send the SUCI generation algorithm to the terminal device, or N3IWF may not send the SUCI generation algorithm to the terminal device.
  • N3IWF maintains SUCI and K n3iwf , as well as the mapping relationship between SUCI and K n3iwf , which can reduce the problem of N3IWF determining the K n3iwf corresponding to SUCI when it receives the SUCI sent by the terminal device. Duration, improving the convenience of K n3iwf determination corresponding to SUCI can improve the accuracy of authentication for accessing the 3GPP network through non-3GPP access networks, so that terminal devices can access the 3GPP network through non-3GPP access networks.
  • Figure 27 is a schematic architectural diagram of a communication system provided by an embodiment of the present disclosure. As shown in Figure 27, the system includes:
  • the terminal device is used to send the registration type corresponding to the registration operation, the user ID and the non-public information required for registration by the terminal device according to the registration operation performed when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network.
  • N3IWF configured to receive at least one of the registration type, user identification and non-public network identification required to be registered by the terminal equipment and corresponding to the registration operation sent by the terminal equipment according to the registration operation performed by the terminal equipment, and send the information corresponding to the registration operation. At least one of the registration type, user identification and non-public network identification required to be registered by the terminal device to the AMF;
  • AMF is configured to receive, according to the registration operation performed by the terminal device, at least one of the registration type sent by the N3IWF corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal equipment.
  • the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, the terminal device can send a message corresponding to the registration operation according to the registration operation performed. At least one of the registration type, user identification and non-public network identification required to be registered by the terminal device to N3IWF. N3IWF can receive the registration type, user identification and corresponding registration operation sent by the terminal device according to the registration operation performed by the terminal device.
  • information corresponding to the registration operation is sent according to the registration operation performed by the terminal device, thereby reducing the situation where the sent information does not match the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the present disclosure provides a processing device for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • Figure 28 is a schematic structural diagram of an authentication device for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the device 2800 can be provided on the terminal device side, and the device 2800 can include :
  • the sending module 2801 is configured to send, according to the registration operation performed when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, the registration type corresponding to the registration operation, the user identification, and the non-registration information required by the terminal device. At least one of the public network identities to the non-3GPP interworking function N3IWF.
  • the authentication device for accessing a 3GPP network through a non-3GPP access network in the embodiment of the present disclosure, if the terminal device accesses the 3GPP network through an untrusted non-3GPP access network through the sending module, according to the performed registration Operation, sending at least one of the registration type corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal device to the non-3GPP interworking function N3IWF.
  • information corresponding to the registration operation is sent to the N3IWF, reducing the situation where the sent information does not match the registration operation performed by the terminal device, and improving access to the network through non-3GPP
  • the accuracy of authentication for accessing the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosure provides a processing device for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to send information corresponding to the registration operation to the N3IWF according to the registration operation performed by the terminal device. Improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • the sending module 2801 is configured to send the user identification corresponding to the registration operation to the N3IWF according to the executed registration operation, specifically for:
  • the sending module 2801 is configured to send the user identification corresponding to the registration operation to the N3IWF according to the executed registration operation, specifically for:
  • the sending module 2801 is configured to send the registration type corresponding to the registration operation to the N3IWF according to the executed registration operation, specifically for at least one of the following:
  • the sending module 2801 is configured to send the user identification corresponding to the registration operation to the N3IWF according to the executed registration operation, specifically for:
  • anonymous SUCI is sent to N3IWF according to the configuration information of the terminal device.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the sending module 2801 is also used to:
  • the sending module 2801 is also used to:
  • the SUCI is sent to the N3IWF.
  • Figure 29 is a schematic structural diagram of an authentication device for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the device 2900 can be provided on the N3IWF side, and the device 2900 can include:
  • the receiving module 2901 is configured to, when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network, receive the registration type, user identification and terminal corresponding to the registration operation sent by the terminal device according to the registration operation performed by the terminal device. At least one of the non-public network identities that the device needs to register;
  • the sending module 2902 is configured to send at least one of the registration type corresponding to the registration operation, the user identification, and the non-public network identification required to be registered by the terminal device to the access and mobility management function AMF.
  • the authentication device for accessing the 3GPP network through the non-3GPP access network when the terminal device accesses the 3GPP network through the untrusted non-3GPP access network, according to the receiving module
  • the registration operation performed by the terminal device receives at least one of the registration type and user identification sent by the terminal device corresponding to the registration operation and the non-public network identification required to be registered by the terminal device; the sending module sends the registration type and user identification corresponding to the registration operation.
  • At least one of the user identity and the non-public network identity required to be registered by the terminal device is sent to the access and mobility management function AMF.
  • information corresponding to the registration operation is received according to the registration operation performed by the terminal device, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP access networks.
  • the accuracy of the authentication of the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • the present disclosure provides a processing device for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive information corresponding to the registration operation according to the registration operation performed by the terminal device, which can improve the pass-through The accuracy of authentication for non-3GPP access networks to access 3GPP networks.
  • the receiving module 2901 is configured to receive the user identification corresponding to the registration operation sent by the terminal device according to the registration operation performed by the terminal device, specifically for:
  • the receiving module 2901 is configured to receive the user identification corresponding to the registration operation sent by the terminal device according to the registration operation performed by the terminal device, specifically for:
  • the receiving module 2901 is configured to receive the registration type corresponding to the registration operation sent by the terminal device according to the registration operation performed by the terminal device, and is specifically used for at least one of the following: kind:
  • the receiving module 2901 is configured to send the user identification corresponding to the registration operation sent by the terminal device to the N3IWF according to the performed registration operation, specifically for:
  • the anonymous SUCI sent by the terminal device according to the configuration information of the terminal device is received.
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the receiving module 2901 is also used to:
  • the receiving module 2901 is also used to:
  • the receiving module 2901 is also used to:
  • the receiving module 2901 is also used to:
  • Figure 30 is a schematic structural diagram of an authentication device for accessing a 3GPP network through a non-3GPP access network provided by an embodiment of the present disclosure.
  • the device 3000 can be provided on the AMF side, and the device 3000 can include:
  • the receiving module 3001 is used to receive the registration type, user identification and terminal device corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device when the terminal device accesses the 3GPP network through an untrusted non-3GPP access network. At least one of the non-public network identities required to be registered.
  • the terminal device accesses the 3GPP network through the untrusted non-3GPP access network, according to the receiving module
  • the registration operation performed by the terminal device receives at least one of the registration type corresponding to the registration operation sent by the N3IWF, the user identification, and the non-public network identification required to be registered by the terminal equipment.
  • the information sent by the N3IWF corresponding to the registration operation is received, thereby reducing the mismatch between the received information and the registration operation performed by the terminal device, and improving access through non-3GPP
  • the accuracy of authentication for network access to the 3GPP network enables terminal devices to access the 3GPP network through non-3GPP access networks.
  • This disclosure provides a processing device for the situation of "authentication of accessing a 3GPP network through a non-3GPP access network" to receive the information corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, It can improve the accuracy of authentication for accessing 3GPP networks through non-3GPP access networks.
  • the receiving module 3001 is configured to receive the user identification corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, and is specifically used to:
  • the receiving module 3001 is configured to receive the user identification corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, and is specifically used to:
  • the receiving module 3001 is configured to receive the registration type corresponding to the registration operation sent by the N3IWF according to the registration operation performed by the terminal device, and is specifically used for at least one of the following: :
  • the receiving module 3001 is also used to:
  • Indication information is stored in the context of the terminal device in the AMF, where the indication information is used to indicate that the terminal device has signed up online.
  • the receiving module 3001 is also used to:
  • the receiving module 3001 is configured to send the user identification corresponding to the registration operation sent by the N3IWF to the N3IWF according to the performed registration operation, specifically for:
  • the anonymous SUCI is an anonymous SUCI obtained by ignoring the username part of the original user's hidden identifier.
  • the anonymous SUCI is an anonymous SUCI obtained by uniformly setting the username part of the original user's hidden identifier to anonymous.
  • the receiving module 3001 is also used to:
  • the receiving module 3001 is also used to:
  • the receiving module 3001 is also used to:
  • the receiving module 3001 is also used to:
  • N3IWF Receive the SUCI sent by N3IWF, where SUCI is the SUCI of K n3iwf sent by the terminal device to N3IWF, and N3IWF has not determined the SUCI corresponding to K n3iwf ;
  • FIG 31 is a block diagram of a terminal device UE3100 provided by an embodiment of the present disclosure.
  • UE3100 can be a mobile phone, computer, digital broadcast terminal device, messaging device, game console, tablet device, medical device, fitness device, personal digital assistant, etc.
  • UE 3100 may include at least one of the following components: a processing component 3102, a memory 3104, a power component 3106, a multimedia component 3108, an audio component 3110, an input/output (I/O) interface 3112, a sensor component 3114, and a communication component. 3116.
  • Processing component 3102 generally controls the overall operations of UE 3100, such as operations associated with display, phone calls, data communications, camera operations, and recording operations.
  • the processing component 3102 may include at least one processor 3120 to execute instructions to complete all or part of the steps of the above method. Additionally, processing component 3102 may include at least one module that facilitates interaction between processing component 3102 and other components. For example, processing component 3102 may include a multimedia module to facilitate interaction between multimedia component 3108 and processing component 3102.
  • Memory 3104 is configured to store various types of data to support operations at UE 3100. Examples of this data include instructions for any application or method operating on the UE3100, contact data, phonebook data, messages, pictures, videos, etc.
  • Memory 3104 may be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EEPROM), Programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic or optical disk.
  • SRAM static random access memory
  • EEPROM electrically erasable programmable read-only memory
  • EEPROM erasable programmable read-only memory
  • EPROM Programmable read-only memory
  • PROM programmable read-only memory
  • ROM read-only memory
  • magnetic memory flash memory
  • flash memory magnetic or optical disk.
  • Power supply component 3106 provides power to various components of UE 3100.
  • Power component 3106 may include a power management system, at least one power supply, and other components associated with generating, managing, and distributing power to UE 3100.
  • Multimedia component 3108 includes a screen that provides an output interface between the UE 3100 and the user.
  • the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user.
  • the touch panel includes at least one touch sensor to sense touches, slides, and gestures on the touch panel. The touch sensor may not only sense the boundary of the touch or sliding operation, but also detect the wake-up time and pressure related to the touch or sliding operation.
  • multimedia component 3108 includes a front-facing camera and/or a rear-facing camera. When the UE3100 is in an operating mode, such as shooting mode or video mode, the front camera and/or rear camera can receive external multimedia data.
  • Each front-facing camera and rear-facing camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.
  • Audio component 3110 is configured to output and/or input audio signals.
  • audio component 3110 includes a microphone (MIC) configured to receive external audio signals when UE 3100 is in operating modes, such as call mode, recording mode, and voice recognition mode. The received audio signal may be further stored in memory 3104 or sent via communication component 3116.
  • audio component 3110 also includes a speaker for outputting audio signals.
  • the I/O interface 3112 provides an interface between the processing component 3102 and a peripheral interface module.
  • the peripheral interface module may be a keyboard, a click wheel, a button, etc. These buttons may include, but are not limited to: Home button, Volume buttons, Start button, and Lock button.
  • the sensor component 3114 includes at least one sensor for providing various aspects of status assessment for the UE 3100 .
  • the sensor component 3114 can detect the open/closed state of the device 3100, the relative positioning of components, such as the display and keypad of the UE3100, the sensor component 3114 can also detect the position change of the UE3100 or a component of the UE3100, the user The presence or absence of contact with the UE3100, the orientation or acceleration/deceleration of the UE3100 and the temperature change of the UE3100.
  • Sensor assembly 3114 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact.
  • Sensor assembly 3114 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications.
  • the sensor component 3114 may also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
  • the communication component 3116 is configured to facilitate wired or wireless communication between the UE 3100 and other devices.
  • UE3100 can access wireless networks based on communication standards, such as WiFi, 2G or 3G, or a combination thereof.
  • the communication component 3116 receives broadcast signals or broadcast related information from an external broadcast management system via a broadcast channel.
  • the communication component 3116 also includes a near field communication (NFC) module to facilitate short-range communications.
  • NFC near field communication
  • the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
  • RFID radio frequency identification
  • IrDA infrared data association
  • UWB ultra-wideband
  • Bluetooth Bluetooth
  • UE3100 may be configured by at least one Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array ( FPGA), controller, microcontroller, microprocessor or other electronic component implementation for executing the above method.
  • ASIC Application Specific Integrated Circuit
  • DSP Digital Signal Processor
  • DSPD Digital Signal Processing Device
  • PLD Programmable Logic Device
  • FPGA Field Programmable Gate Array
  • controller microcontroller, microprocessor or other electronic component implementation for executing the above method.
  • Figure 32 is a block diagram of a network side device 3200 provided by an embodiment of the present disclosure.
  • the network side device 3200 may be provided as a network side device.
  • the network side device 3200 includes a processing component 3222, which further includes at least one processor, and a memory resource represented by a memory 3232 for storing instructions, such as application programs, that can be executed by the processing component 3222.
  • the application program stored in memory 3232 may include one or more modules, each corresponding to a set of instructions.
  • the processing component 3222 is configured to execute instructions to perform any of the foregoing methods applied to the network side device, for example, the method shown in FIG. 8 .
  • the network side device 3200 may also include a power supply component 3230 configured to perform power management of the network side device 3200, a wired or wireless network interface 3250 configured to connect the network side device 3200 to the network, and an input/output (I/O). O) Interface 3258.
  • the network side device 3200 can operate based on an operating system stored in the memory 3232, such as Windows Server TM, Mac OS X TM, Unix TM, Linux TM, Free BSD TM or similar.
  • the methods provided by the embodiments of the present disclosure are introduced from the perspectives of network side equipment and UE respectively.
  • the network side device and the UE may include a hardware structure and a software module to implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module.
  • a certain function among the above functions can be executed by a hardware structure, a software module, or a hardware structure plus a software module.
  • the methods provided by the embodiments of the present disclosure are introduced from the perspectives of network side equipment and UE respectively.
  • the network side device and the UE may include a hardware structure and a software module to implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module.
  • a certain function among the above functions can be executed by a hardware structure, a software module, or a hardware structure plus a software module.
  • the communication device may include a transceiver module and a processing module.
  • the transceiver module may include a sending module and/or a receiving module.
  • the sending module is used to implement the sending function
  • the receiving module is used to implement the receiving function.
  • the transceiving module may implement the sending function and/or the receiving function.
  • the communication device may be a terminal device (such as the terminal device in the foregoing method embodiment), a device in the terminal device, or a device that can be used in conjunction with the terminal device.
  • the communication device may be a network device, a device in a network device, or a device that can be used in conjunction with the network device.
  • the communication device may be a network device, or may be a terminal device (such as the terminal device in the foregoing method embodiment), or may be a chip, chip system, or processor that supports the network device to implement the above method, or may be a terminal device that supports A chip, chip system, or processor that implements the above method.
  • the device can be used to implement the method described in the above method embodiment. For details, please refer to the description in the above method embodiment.
  • a communications device may include one or more processors.
  • the processor may be a general-purpose processor or a special-purpose processor, etc.
  • it can be a baseband processor or a central processing unit.
  • the baseband processor can be used to process communication protocols and communication data
  • the central processor can be used to control and execute communication devices (such as network side equipment, baseband chips, terminal equipment, terminal equipment chips, DU or CU, etc.)
  • a computer program processes data for a computer program.
  • the communication device may also include one or more memories, on which a computer program may be stored, and the processor executes the computer program, so that the communication device performs the method described in the above method embodiment.
  • data may also be stored in the memory.
  • the communication device and the memory can be provided separately or integrated together.
  • the communication device may also include a transceiver and an antenna.
  • the transceiver can be called a transceiver unit, a transceiver, or a transceiver circuit, etc., and is used to implement transceiver functions.
  • the transceiver can include a receiver and a transmitter.
  • the receiver can be called a receiver or a receiving circuit, etc., and is used to implement the receiving function;
  • the transmitter can be called a transmitter or a transmitting circuit, etc., and is used to implement the transmitting function.
  • one or more interface circuits may also be included in the communication device.
  • Interface circuitry is used to receive code instructions and transmit them to the processor.
  • the processor executes the code instructions to cause the communication device to perform the method described in the above method embodiment.
  • the communication device is a terminal device (such as the terminal device in the foregoing method embodiment): the processor is configured to execute the method shown in any one of Figures 2 to 9.
  • the communication device is N3IWF: the processor is used to execute the method shown in any one of Figures 10-17.
  • the communication device is an AMF: the processor is used to execute the method shown in any one of Figures 18 to 26.
  • a transceiver for implementing receiving and transmitting functions may be included in the processor.
  • the transceiver may be a transceiver circuit, an interface, or an interface circuit.
  • the transceiver circuits, interfaces or interface circuits used to implement the receiving and transmitting functions can be separate or integrated together.
  • the above-mentioned transceiver circuit, interface or interface circuit can be used for reading and writing codes/data, or the above-mentioned transceiver circuit, interface or interface circuit can be used for signal transmission or transfer.
  • the processor may store a computer program, and the computer program runs on the processor, which can cause the communication device to perform the method described in the above method embodiment.
  • the computer program may be embedded in the processor, in which case the processor may be implemented in hardware.
  • the communication device may include a circuit, and the circuit may implement the functions of sending or receiving or communicating in the foregoing method embodiments.
  • the processors and transceivers described in this disclosure may be implemented on integrated circuits (ICs), analog ICs, radio frequency integrated circuits (RFICs), mixed signal ICs, application specific integrated circuits (ASICs), printed circuit boards ( printed circuit board (PCB), electronic equipment, etc.
  • the processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), n-type metal oxide-semiconductor (NMOS), P-type Metal oxide semiconductor (positive channel metal oxide semiconductor, PMOS), bipolar junction transistor (BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.
  • CMOS complementary metal oxide semiconductor
  • NMOS n-type metal oxide-semiconductor
  • PMOS P-type Metal oxide semiconductor
  • BJT bipolar junction transistor
  • BiCMOS bipolar CMOS
  • SiGe silicon germanium
  • GaAs gallium arsenide
  • the communication device described in the above embodiments may be a network device or a terminal device (such as the terminal device in the foregoing method embodiment), but the scope of the communication device described in the present disclosure is not limited thereto, and the structure of the communication device may not be limited to limits.
  • the communication device may be a stand-alone device or may be part of a larger device.
  • the communication device may be:
  • the IC collection may also include storage components for storing data and computer programs;
  • the communication device may be a chip or a system on a chip
  • the chip includes a processor and an interface.
  • the number of processors may be one or more, and the number of interfaces may be multiple.
  • the chip also includes a memory for storing necessary computer programs and data.
  • the present disclosure also provides a readable storage medium on which instructions are stored. When the instructions are executed by a computer, the functions of any of the above method embodiments are implemented.
  • the present disclosure also provides a computer program product, which, when executed by a computer, implements the functions of any of the above method embodiments.
  • the above embodiments it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof.
  • software it may be implemented in whole or in part in the form of a computer program product.
  • the computer program product includes one or more computer programs.
  • the computer program When the computer program is loaded and executed on a computer, the processes or functions described in accordance with the embodiments of the present disclosure are generated in whole or in part.
  • the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
  • the computer program may be stored in or transferred from one computer-readable storage medium to another, for example, the computer program may be transferred from a website, computer, server, or data center Transmission to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means.
  • the computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that contains one or more available media integrated.
  • the usable media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVD)), or semiconductor media (e.g., solid state disks, SSD)) etc.
  • magnetic media e.g., floppy disks, hard disks, magnetic tapes
  • optical media e.g., high-density digital video discs (DVD)
  • DVD digital video discs
  • semiconductor media e.g., solid state disks, SSD
  • At least one in the present disclosure can also be described as one or more, and the plurality can be two, three, four or more, and the present disclosure is not limited.
  • the technical feature is distinguished by “first”, “second”, “third”, “A”, “B”, “C” and “D” etc.
  • the technical features described in “first”, “second”, “third”, “A”, “B”, “C” and “D” are in no particular order or order.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开提出一种通过非3GPP接入网络接入3GPP网络的认证方法、装置、设备及存储介质,属于通信技术领域。该方法包括当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。本公开针对一种"通过非3GPP接入网络接入3GPP网络的认证"这一情形提供了一种处理方法,以根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。

Description

通过非3GPP接入网络接入3GPP网络的认证方法、装置 技术领域
本公开涉及通信技术领域,尤其涉及一种非第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)接入网络接入3GPP网络的认证方法、装置、设备及存储介质。
背景技术
在通信系统中,终端设备例如可以通过3GPP接入网络接入3GPP网络。但是,相关技术中,3GPP规范不支持通过非3GPP接入网络直接接入3GPP网络。例如可以使用称为“可扩展认证协议(Extensible Authentication Protocol,EAP)-第五代移动通信技术(5th Generation Mobile Communication Technology,5G)”的供应商特定EAP方法,利用“扩展”EAP类型和现有的3GPP网络供应商编号Vendor-Id,在管理信息结构SMI私有企业代码注册表下向互联网数字分配机构(The Internet Assigned Numbers Authority,IANA)注册。但是,该认证方式中并未涉及终端设备执行的注册操作,使得通过非3GPP接入网络接入3GPP网络的认证的准确性较低。
发明内容
本公开提出的一种通过非3GPP接入网络接入3GPP网络的认证方法、装置、设备及存储介质,以根据终端设备执行的注册操作,发送与该注册操作对应的信息至非3GPP互通功能(Non-3GPP InterWorking Function,N3IWF),可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
本公开一方面实施例提出的一种通过非3GPP接入网络接入3GPP网络的认证方法,所述方法由终端设备执行,所述方法包括:
当所述终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至N3IWF。
可选地,在本公开的一个实施例之中,所述根据执行的注册操作,发送与所述注册操作对应的用户标识至N3IWF,包括:
响应于所述执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送以下用户标识中的至少一种至所述N3IWF:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
可选地,在本公开的一个实施例之中,所述根据执行的注册操作,发送与所述注册操作对应的用户标识至N3IWF,包括:
响应于所述执行的注册操作为执行初始注册或执行移动注册更新,发送以下用户标识中的至少一种至所述N3IWF:
用户隐藏标识符(Subscription Concealed Identifier,SUCI);
用户永久标识符(Subscription Permanent Identifier,SUPI)。
可选地,在本公开的一个实施例之中,所述根据执行的注册操作,发送与所述注册操作对应的注册类型至所述N3IWF,包括以下中的至少一种:
响应于所述执行的注册操作为执行独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送SNPN Onboarding注册类型至所述N3IWF;
响应于所述执行的注册操作为执行初始注册,发送初始注册Initial Registration注册类型至所述N3IWF;
响应于所述执行的注册操作为执行移动注册更新,发送移动注册更新Mobility Registration Update注册类型至所述N3IWF。
可选地,在本公开的一个实施例之中,所述根据执行的注册操作,发送与所述注册操作对应的用户标识至N3IWF,包括:
在非公共网络(Non-Public Network,NPN)场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,根据所述终端设备的配置信息发送匿名SUCI至所述N3IWF。
可选地,在本公开的一个实施例之中,其中,所述匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,所述匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
可选地,在本公开的一个实施例之中,所述方法还包括:
接收所述N3IWF发送的SUCI生成算法;
根据所述SUCI生成算法生成SUCI,并发送所述SUCI至所述N3IWF。
可选地,在本公开的一个实施例之中,所述方法还包括:
响应于未接收到所述N3IWF发送的SUCI生成算法,发送所述SUCI至所述N3IWF。
本公开另一方面实施例提出的一种通过非3GPP接入网络接入3GPP网络的认证方法,所述方法由N3IWF执行,所述方法包括:
当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种;
发送所述与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能(Access and Mobility Management Function,AMF)。
可选地,在本公开的一个实施例之中,所述根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的用户标识,包括:
响应于所述终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述终端设备发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
可选地,在本公开的一个实施例之中,所述根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的用户标识,包括:
响应于所述注册操作为初始注册或移动注册更新,接收所述终端设备发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
可选地,在本公开的一个实施例之中,所述根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型,包括以下中的至少一种:
响应于所述终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述终端设备发送的SNPN Onboarding注册类型;
响应于所述终端设备执行的注册操作为执行初始注册,接收所述终端设备发送的初始注册Initial Registration注册类型;
响应于所述终端设备执行的注册操作为执行移动注册更新,接收所述终端设备发送的移动注册更新Mobility Registration Update注册类型。
可选地,在本公开的一个实施例之中,所述根据执行的注册操作,发送所述终端设备发送的与所述注册操作对应的用户标识至N3IWF,包括:
在非公共网络NPN场景下,响应于可扩展认证协议(Extensible Authentication Protocol,EAP)方式支持用户永久标识符SUPI的隐私保护机制,接收所述终端设备根据所述终端设备的配置信息发送的匿名anonymousSUCI。
可选地,在本公开的一个实施例之中,其中,所述匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,所述匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
可选地,在本公开的一个实施例之中,所述方法还包括:
接收AMF发送的至少一个K n3iwf、至少一个SUCI和/或所述至少一个SUCI的生成算法;
存储所述至少一个K n3iwf和至少一个SUCI的映射关系。
可选地,在本公开的一个实施例之中,所述方法还包括:
发送SUCI生成算法至所述终端设备;
接收所述终端设备发送的SUCI,其中,所述SUCI是根据所述SUCI生成算法生成的;
根据所述SUCI与所述至少一个K n3iwf和至少一个SUCI的映射关系,确定所述SUCI对应的K n3iwf
根据所述SUCI对应的K n3iwf对所述终端设备进行认证。
可选地,在本公开的一个实施例之中,所述方法还包括:
响应于未发送SUCI生成算法至所述终端设备,接收所述终端设备发送的SUCI;
根据所述SUCI与所述至少一个K n3iwf和至少一个SUCI的映射关系,确定所述SUCI对应的K n3iwf
根据所述SUCI对应的K n3iwf对所述终端设备进行认证。
可选地,在本公开的一个实施例之中,所述方法还包括:
响应于未发送SUCI生成算法至所述终端设备,接收所述终端设备发送的SUCI;
根据所述SUCI与所述至少一个K n3iwf和至少一个SUCI的映射关系,未确定所述SUCI对应的K n3iwf时,发送所述SUCI至所述AMF;
接收所述AMF发送的根据所述SUCI确定的所述SUCI对应的K n3iwf
根据所述SUCI对应的K n3iwf对所述终端设备进行认证。
本公开另一方面实施例提出的一种通过非3GPP接入网络接入3GPP网络的认证方法,所述方法由AMF执行,所述方法包括:
当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收N3IWF发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种。
可选地,在本公开的一个实施例之中,所述根据所述终端设备执行的注册操作,接收所述N3IWF发送的与所述注册操作对应的用户标识,包括:
响应于所述终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述N3IWF发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
可选地,在本公开的一个实施例之中,所述根据所述终端设备执行的注册操作,接收所述N3IWF发送的与所述注册操作对应的用户标识,包括:
响应于所述注册操作为初始注册或移动注册更新,接收所述N3IWF发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
可选地,在本公开的一个实施例之中,所述根据所述终端设备执行的注册操作,接收所述N3IWF发送的与所述注册操作对应的注册类型,包括以下中的至少一种:
响应于所述终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述N3IWF发送的SNPN Onboarding注册类型;
响应于所述终端设备执行的注册操作为执行初始注册,接收所述N3IWF发送的初始注册Initial Registration注册类型;
响应于所述终端设备执行的注册操作为执行移动注册更新,接收所述N3IWF发送的移动注册更新Mobility Registration Update注册类型。
可选地,在本公开的一个实施例之中,所述方法还包括:
将本地配置的AMF配置数据应用于在线签约,其中,所述AMF配置数据用于限制所述终端设备的网络应用仅为在线签约;
在所述AMF中的所述终端设备的上下文中存储指示信息,其中,所述指示信息用于指示所述终端设备已在线签约注册。
可选地,在本公开的一个实施例之中,所述方法还包括:
基于在线签约SNPN(Onboarding-SNPN,ON-SNPN)策略,启动用于实现特定注销的计时器,其中,所述计时器为所述终端设备在线签约Onboarding配置的。
可选地,在本公开的一个实施例之中,所述根据执行的注册操作,发送所述N3IWF发送的与所述注册操作对应的用户标识至N3IWF,包括:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收所述N3IWF发送的匿名SUCI,其中,所述匿名SUCI为所述终端设备根据所述终端设备的配置信息发送至所述N3IWF的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,所述匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,所述匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
可选地,在本公开的一个实施例之中,所述方法还包括:
采用以下至少一种认证方式对所述终端设备进行认证:
5G AKA认证方式;
EAP-AKA'认证方式;
任何其他生成密钥的EAP认证方式。
可选地,在本公开的一个实施例之中,所述方法还包括:
接收鉴权服务功能AUSF发送的安全锚功能SEAF密钥K seaf、SUPI、SUCI和/或SUCI的生成算法;
根据所述K seaf、所述SUPI,生成AMF密钥K amf
根据所述K amf生成K n3iwf,并存储所述SUPI、所述SUCI和所述K n3iwf之间的映射关系。
可选地,在本公开的一个实施例之中,所述方法还包括:
发送至少一个K n3iwf、至少一个SUCI和/或所述至少一个SUCI的生成算法至所述N3IWF。
可选地,在本公开的一个实施例之中,所述方法还包括:
接收所述N3IWF发送的SUCI,其中,所述SUCI为所述终端设备发送至所述N3IWF,且所述N3IWF未确定所述SUCI对应的K n3iwf的SUCI;
发送所述SUCI至鉴权服务功能(Authentication Service Function,AUSF);
接收所述AUSF针对所述SUCI发送的SUPI,并根据所述SUPI确定所述SUCI对应的K n3iwf
发送所述SUCI对应的K n3iwf至所述N3IWF。
本公开又一方面实施例提出的一种通过非3GPP接入网络接入3GPP网络的认证装置,所述装置设置于终端设备侧,所述装置包括:
发送模块,用于如果所述终端设备通过不受信任的非3GPP接入网络接入3GPP网络,则根据执行的注册操作,发送与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。
本公开又一方面实施例提出的一种通过非3GPP接入网络接入3GPP网络的认证装置,所述装置设置于N3IWF侧,所述装置包括:
接收模块,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种;
发送模块,用于发送所述与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能AMF。
本公开又一方面实施例提出的一种通过非3GPP接入网络接入3GPP网络的认证装置,所述装置设置于AMF侧,所述装置包括:
接收模块,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收N3IWF发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种。
本公开又一方面实施例提出的一种终端设备,所述设备包括处理器和存储器,所述存储器中存储有计算机程序,所述处理器执行所述存储器中存储的计算机程序,以使所述装置执行如上一方面实施例提出的方法。
本公开又一方面实施例提出的一种N3IWF,所述设备包括处理器和存储器,所述存储器中存储有计算机程序,所述处理器执行所述存储器中存储的计算机程序,以使所述装置执行如上一方面实施例提出的方法。
本公开又一方面实施例提出的一种AMF,所述设备包括处理器和存储器,所述存储器中存储有计算机程序,所述处理器执行所述存储器中存储的计算机程序,以使所述装置执行如上一方面实施例提出的方法。
本公开又一方面实施例提出的通信装置,包括:处理器和接口电路;
所述接口电路,用于接收代码指令并传输至所述处理器;
所述处理器,用于运行所述代码指令以执行如上任一方面实施例提出的方法。
本公开又一方面实施例提出的计算机可读存储介质,用于存储有指令,当所述指令被执行时,使如上任一方面实施例提出的方法被实现。
本公开又一方面实施例提出的一种通信系统,所述系统包括:
终端设备,用于当所述终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至N3IWF;
所述N3IWF,用于根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种,并发送所述与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至AMF;
所述AMF,用于根据所述终端设备执行的注册操作,接收N3IWF发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与注册操作对应的注册类型,用户标识以及终端所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。在本公开实施例之中,根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,减少发送的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
附图说明
本公开上述的和/或附加的方面和优点从下面结合附图对实施例的描述中将变得明显和容易理解,其中:
图1为本公开一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图;
图2为本公开一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图3为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图4为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图5为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图6为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图7为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图8为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图9为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图10为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图11为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图12为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图13为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图14为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图15为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图16为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图;
图17为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图;
图18为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图19为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图20为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图21为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图22为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图23为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图24为本公开又一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图;
图25为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图;
图26为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图;
图27为本公开实施例所提供的一种通信系统的架构示意图;
图28为本公开一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证装置的结构示意图;
图29为本公开另一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证装置的结构示意图;
图30为本公开另一个实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证装置的结构示意图;
图31为本公开一个实施例所提供的一种终端设备的框图;
图32为本公开一个实施例所提供的一种网络侧设备的框图。
具体实施方式
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本公开实施例相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本公开实施例的一些方面相一致的装置和方法的例子。
在本公开实施例使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本公开实施例。在本公开实施例和所附权利要求书中所使用的单数形式的“一种”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本公开实施例可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本公开实施例范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”及“若”可以被解释成为“在……时”或“当……时”或“响应于确定”。
在本公开实施例中涉及的网元或是网络功能,其既可以是独立的硬件设备实现,也可以通过硬件设备中的软件实现,本公开实施例中并不对此做出限定。
图1示出为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图。如图1所示,第一,终端设备使用3GPP范围之外的过程连接到不受信任的非3GPP接入网络。当终端设备决定连接到5G核心网5GC网络时,终端设备可以在5G公共陆地移动网(Public Land Mobile Network,PLMN)中选择N3IWF。第二,终端设备可以通过根据RFC 7296发起网络密匙交换协议IKE初始交换,继续与所选的N3IWF建立IPsec安全联盟(Security Association,SA)。其中,在第二步之后的所有IKE消息都可以使用在此步骤中建立的IKE SA进行加密和完整性保护。第三,终端设备可以通过发送IKE_鉴权AUTH请求消息来发起IKE_AUTH交换。其中,AUTH有效载荷不包含在IKE_AUTH请求消息中,这表明IKE_AUTH交换可以使用EAP信令,在本公开的实施例之中,EAP信令例如可以为EAP-5G信令。根据RFC7296,在数据信息段IDi中,终端设备应在该消息中将标识ID类型设置为ID_KEY-ID,并将其值设置为任意随机数。其中,IDi为包括ID信息的数据信息段。终端设备在此步骤中不应使用其全球唯一临时UE标识(Globally Unique Temporary UE Identity,GUTI)、SUCI和SUPI中任意一种作为标识Id。如果终端设备提供了N3IWF根证书,终端设备应在IKE_AUTH请求消息中包含验证请求信息CERTREQ有效负载以请求N3IWF的证书。
其中,在本公开的一个实施例之中,第四,N3IWF可以使用IKE_AUTH响应消息进行响应,其中,该IKE_AUTH响应消息中包括N3IWF身份、AUTH有效负载和EAP-Request或5G-Start数据包,其中,AUTH有效负载用于保护N3IWF发送给终端设备的先前消息(在IKE_SA_INIT交换中)。EAP-Request或5G-Start数据包用于通知终端设备启动EAP-5G会话,即开始发送封装在EAP-5G数据包中的网络附属存储(Network Attached Storage,NAS)消息。如果终端在第三步中发送了CERTREQ有效载荷,则N3IWF还应发送包含N3IWF证书的CERT有效载荷至终端设备。第五,终端设备将验证N3IWF证书并确认N3IWF身份与终端设备选择的N3IWF匹配。如果终端设备请求证书或身份确认不成功,则N3IWF缺少证书将导致连接失败。在N3IWF的身份确认时,终端设备应发送一个IKE_AUTH请求,该请求包括一个EAP-Response或5G-NAS数据包,该数据包包含一个注册请求消息,该消息包含终端设备安全能力和SUCI/入职SUCI/匿名值SUCI。其中,N3IWF不发送EAP-Identity请求,因为终端设备在第五步中的IKE_AUTH请求中包含其身份。
以及,在本公开的一个实施例之中,第六,N3IWF应选择TS 23.501第6.5.3节中规定的AMF。N3IWF将从终端设备接收到的注册请求转发给AMF。该注册请求携带与N2消息中。其中,终端设备与AMF之间的物理接口N2。第七,根据TS 23.501第6.1.3节中描述的认证执行认证操作。在来自归属网络的最终认证消息中,AUSF应将源自K AUSF的锚密钥K SEAF发送给安全锚功能SEAF。SEAF应从K SEAF导出K amf,并将其发送到AMF。AMF使用该K amf导出NAS安全密钥。如果使用EAP-AKA'或生成密钥的EAP验证方法进行验证,则AUSF应包括可扩展认证协议成功EAP-Success。终端设备还可以导出锚密钥K SEAF,并从该密钥导出K amf,然后是NAS安全密钥。在终端设备和AMF处设置与NAS连接标识符“0x02”相关的NAS COUNT。其中,AMF和AUSF例如可以是合设的,即AMF和AUSF为一个设备。第八,AMF应向终端设备发送安全模式命令(SMC),以激活与NAS连接标识符“0x02”相关的NAS安全。该消息首先发送到N3IWF(在N2消息中)。如果EAP-AKA'用于认证,AMF应将从AUSF接收到的EAP-Success封装在SMC消息中。
以及,在本公开的一个实施例之中,第九,N3IWF应在EAP-Request/5G-NAS数据包中将NAS SMC转发给终端设备。第十,终端设备完成认证(如果在步骤7中启动)并创建一个NAS安全上下文或基于NAS SMC中接收到的安全上下文标识ngKSI激活一个NAS安全上下文。终端设备应根据TS 23.501第6.7.2节中描述的所选算 法和参数响应从AMF接收到的NAS SMC。UE应将NAS SMC完成Complete封装在EAP-5G响应中。第十一,N3IWF应通过N2接口将包含NAS SMC Complete的NAS数据包转发给AMF。第十二,AMF在接收到来自终端设备的NAS SMC Complete或完整性保护验证成功后,启动下一代应用协议(Next Generation Application Protocol,NGAP)过程以建立一个上下文。AMF应使用定义的NAS连接标识符“0x02”相关联的上行链路NAS COUNT计算N3IWF密钥K N3IWF,以在终端设备和N3IWF之间建立IPsec SA,并发送NGAP初始上下文设置请求至N3IWF,其中,该NGAP初始上下文设置请求中包括K N3IWF。第十三,N3IWF在接收到包含N3IWF密钥K N3IWF的NGAP初始上下文设置请求时,可以向终端设备发送EAP-Success或EAP-5G。这样就完成了EAP-5G会话,不再交换EAP-5G数据包。如果N3IWF没有从AMF接收到K N3IWF,则N3IWF应以EAP-Failure响应。
以及,在本公开的一个实施例之中,第十四,IPsec SA通过使用N3IWF密钥K N3IWF在终端设备和N3IWF之间建立,该密钥是在终端设备中使用与定义的NAS连接标识符“0x02”相关联的上行链路NAS COUNT创建的,并且由N3IWF在第十二步从AMF接收的。第十五,在终端设备和N3IWF之间成功建立IPsec SA后,N3IWF将向AMF发送NGAP初始上下文设置响应NGAP Initial Context Setup Response消息。第十六,当AMF接收到UE的NGAP Initial Context Setup Response时,AMF将通过N2消息向N3IWF发送终端设备的NAS注册接受消息。第十七,在收到来自AMF的NAS注册接受消息后,N3IWF将通过已建立的IPsec SA将其转发给终端设备。终端设备和N3IWF之间的所有进一步NAS消息都应通过已建立的IPsec SA发送。
下面参考附图对本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法、装置、设备及存储介质进行详细描述。
图2为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图2所示,该方法可以包括以下步骤:
步骤201、当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。
需要说明的是,在本公开的一个实施例之中,终端设备可以是指向用户提供语音和/或数据连通性的设备。终端设备可以经RAN(Radio Access Network,无线接入网)与一个或多个核心网进行通信,终端设备可以是物联网终端,如传感器设备、移动电话(或称为“蜂窝”电话)和具有物联网终端的计算机,例如,可以是固定式、便携式、袖珍式、手持式、计算机内置的或者车载的装置。例如,订户站(Station,STA)、订户单元(subscriber unit)、订户站(subscriber station),移动站(mobile station)、移动台(mobile)、远程站(remote station)、接入点、远程终端(remoteterminal)、接入终端(access terminal)、用户终端(user terminal)或用户代理(user agent)。或者,终端设备也可以是无人飞行器的设备。或者,终端设备也可以是车载设备,比如,可以是具有无线通信功能的行车电脑,或者是外接行车电脑的无线终端。或者,终端设备也可以是路边设备,比如,可以是具有无线通信功能的路灯、信号灯或者其它路边设备等。
其中,在本公开的一个实施例之中,该3GPP网络为非公共网络。
其中,在本公开的一个实施例之中,该非公共网络标识包括(公共陆地移动网络标识Public Land Mobile Network ID,PLMN ID)和网络标识符(network identifier,NID)。
其中,在本公开的一个实施例之中,根据执行的注册操作,发送与注册操作对应的用户标识至N3IWF,包括:
响应于执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送以下用户标识中的至少一种至N3IWF:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
以及,在本公开的一个实施例之中,根据执行的注册操作,发送与注册操作对应的用户标识至N3IWF,包括:
响应于执行的注册操作为执行初始注册或执行移动注册更新,发送以下用户标识中的至少一种至N3IWF:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
示例地,在本公开的一个实施例之中,根据执行的注册操作,发送与注册操作对应的注册类型至N3IWF,包括以下中的至少一种:
响应于执行的注册操作为执行独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送SNPN Onboarding注册类型至N3IWF;
响应于执行的注册操作为执行初始注册,发送初始注册Initial Registration注册类型至N3IWF;
响应于执行的注册操作为执行移动注册更新,发送移动注册更新Mobility Registration Update注册类型至N3IWF。
以及,在本公开的一个实施例之中,根据执行的注册操作,发送与注册操作对应的用户标识至N3IWF,包括:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,根据终端设备的配置信息发送匿名SUCI至N3IWF。
进一步地,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
进一步地,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
进一步地,在本公开的一个实施例之中,方法还包括:
接收N3IWF发送的SUCI生成算法;
根据SUCI生成算法生成SUCI,并发送SUCI至N3IWF。
进一步地,在本公开的一个实施例之中,方法还包括:
响应于未接收到N3IWF发送的SUCI生成算法,发送SUCI至N3IWF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与注册操作对应的注册类型,用户标识以及终端所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。在本公开实施例之中,根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,减少发送的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图3为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图3所示,该方法可以包括以下步骤:
步骤301、响应于执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送以下用户标识中的至少一种至N3IWF:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
其中,在本公开的一个实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),终端设备发送以下用户标识中的至少一种至N3IWF:onboarding SUCI;onboarding SUPI。例如,终端设备可以发送onboarding SUCI至N3IWF,或者终端设备可以发送onboarding SUPI至N3IWF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送以下用户标识中的至少一种至N3IWF:onboarding SUCI;onboarding SUPI。在本公开实施例之中,根据终端设备执行的独立的非公共网络在线签约注册,发送与该注册操作对应的用户标识至N3IWF,减少发送的用户标识与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,发送与该注册操作对应的用户标识至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图4为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图4所示,该方法可以包括以下步骤:
步骤401、响应于执行的注册操作为执行初始注册或执行移动注册更新,发送以下用户标识中的至少一种至N3IWF:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
其中,在本公开的一个实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为执行初始注册或执行移动注册更新,终端设备发送至N3IWF的用户标识可以以下至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。例如,终端设备可以发送SUCI至N3IWF,或者终端设备可以发送SUPI至N3IWF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为执行初始注册或执行移动注册更新,发送以下用户标识中的至少一种至N3IWF:SUCI;SUPI。在 本公开实施例之中,根据终端设备执行的初始注册或执行移动注册更新,发送与该注册操作对应的用户标识至N3IWF,减少发送的用户标识与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的初始注册或执行移动注册更新,发送与该注册操作对应的用户标识至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图5为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图5所示,该方法可以包括以下步骤:
步骤501、响应于执行的注册操作为执行独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送SNPN Onboarding注册类型至N3IWF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为执行独立的非公共网络在线签约注册,发送SNPN Onboarding注册类型至N3IWF。在本公开实施例之中,根据终端设备执行的独立的非公共网络在线签约注册,发送与该注册操作对应的注册类型至N3IWF,减少发送的注册类型与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了独立的非公共网络在线签约注册对应的注册类型为SNPN Onboarding注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的独立的非公共网络在线签约注册,发送与该注册操作对应的注册类型至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图6为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图6所示,该方法可以包括以下步骤:
步骤601、响应于执行的注册操作为执行初始注册,发送初始注册Initial Registration注册类型至N3IWF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为执行初始注册,发送初始注册Initial Registration注册类型至N3IWF。在本公开实施例之中,根据终端设备执行的初始注册,发送与该注册操作对应的注册类型至N3IWF,减少发送的注册类型与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了初始注册对应的注册类型为Initial Registration注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的初始注册,发送与该注册操作对应的注册类型至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图7为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图7所示,该方法可以包括以下步骤:
步骤701、响应于执行的注册操作为执行移动注册更新,发送移动注册更新Mobility Registration Update注册类型至N3IWF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于执行的注册操作为执行移动注册更新,发送移动注册更新Mobility Registration Update注册类型至N3IWF。在本公开实施例之中,根据终端设备执行的移动注册更新,发送与该注册操作对应的注册类型至N3IWF,减少发送的注册类型与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了移动注册更新对应的注册类型为移动注册更新Mobility Registration Update注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的初始注册,发送与该注册操作对应的注册类型至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图8为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由终端设备执行,如图8所示,该方法可以包括以下步骤:
步骤801、在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,根据终端设备的配置信息发送匿名SUCI至N3IWF。
其中,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
其中,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
进一步地,在本公开的一个实施例之中,方法还包括:
接收N3IWF发送的SUCI生成算法;
根据SUCI生成算法生成SUCI,并发送SUCI至N3IWF。
进一步地,在本公开的一个实施例之中,方法还包括:
响应于未接收到N3IWF发送的SUCI生成算法,发送SUCI至N3IWF。
综上所述,在本公开实施例之中,在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,根据终端设备的配置信息发送匿名SUCI至N3IWF。在本公开实施例之中,响应于EAP方式支持SUPI的隐私保护机制,根据终端设备的配置信息发送匿名SUCI至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了根据终端设备的配置信息发送匿名SUCI的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,发送与该注册操作对应的注册类型至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图9为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图9所示,该方法可以包括以下步骤:
步骤901、当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种;
步骤902、发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能AMF。
其中,在本公开的一个实施例之中,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的用户标识,包括:
响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
示例地,在本公开的一个实施例之中,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的用户标识,包括:
响应于注册操作为初始注册或移动注册更新,接收终端设备发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
示例地,在本公开的一个实施例之中,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型,包括以下中的至少一种:
响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的SNPN Onboarding注册类型;
响应于终端设备执行的注册操作为执行初始注册,接收终端设备发送的初始注册Initial Registration注册类型;
响应于终端设备执行的注册操作为执行移动注册更新,接收终端设备发送的移动注册更新Mobility Registration Update注册类型。
示例地,在本公开的一个实施例之中,根据执行的注册操作,发送终端设备发送的与注册操作对应的用户标识至N3IWF,包括:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收终端设备根据终端设备的配置信息发送的匿名anonymousSUCI。
进一步地,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
进一步地,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
以及,在本公开的一个实施例之中,方法还包括:
接收AMF发送的至少一个K n3iwf、至少一个SUCI和/或至少一个SUCI的生成算法;
存储至少一个K n3iwf和至少一个SUCI的映射关系。
以及,在本公开的一个实施例之中,方法还包括:
发送SUCI生成算法至终端设备;
接收终端设备发送的SUCI,其中,SUCI是根据SUCI生成算法生成的;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
以及,在本公开的一个实施例之中,方法还包括:
响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
以及,在本公开的一个实施例之中,方法还包括:
响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,未确定SUCI对应的K n3iwf时,发送SUCI至AMF;
接收AMF发送的根据SUCI确定的SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
示例地,在本公开的一个实施例之中,N3IWF每次向终端设备发送SUCI的生成算法都是可选的,即N3IWF每次可以向终端设备发送SUCI的生成算法,N3IWF每次也可以不向终端设备发送SUCI的生成算法。
示例地,在本公开的一个实施例之中,N3IWF接收到终端设备发送的SUCI时,N3IWF可以通过SUCI定位到K n3iwf之后,用N3IWF密钥K n3iwf与终端设备建立IPsec SA。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种;发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图10为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图10所示,该方法可以包括以下步骤:
步骤1001、响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI);
步骤1002、发送与注册操作对应的用户标识至AMF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的以下用户标识中的至少一种:onboarding SUCI;onboarding SUPI;发送与注册操作对应的用户标识至AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了独立的非公共网络在线签约注册对应的用户标识的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图11为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图11所示,该方法可以包括以下步骤:
步骤1101、响应于注册操作为初始注册或移动注册更新,接收终端设备发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI;
步骤1102、发送与注册操作对应的用户标识至AMF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于注册操作为初始注册或移动注册更新,接收终端设备发送的以下用户标识中的至少一种:用户隐藏标识符SUCI;用户永久标识符SUPI;发送与注册操作对应的用户标识至AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施 例具体公开了初始注册或移动注册更新对应的用户标识的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图12为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图12所示,该方法可以包括以下步骤:
步骤1201、响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的SNPN Onboarding注册类型;
步骤1202、发送与注册操作对应的注册类型至AMF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的SNPN Onboarding注册类型;发送与注册操作对应的注册类型至AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了独立的非公共网络在线签约注册对应的注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图13为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图13所示,该方法可以包括以下步骤:
步骤1301、响应于终端设备执行的注册操作为执行初始注册,接收终端设备发送的初始注册Initial Registration注册类型;
步骤1302、发送与注册操作对应的注册类型至AMF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为执行初始注册,接收终端设备发送的初始注册Initial Registration注册类型;发送与注册操作对应的注册类型至AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了初始注册对应的注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图14为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图14所示,该方法可以包括以下步骤:
步骤1401、响应于终端设备执行的注册操作为执行移动注册更新,接收终端设备发送的移动注册更新Mobility Registration Update注册类型;
步骤1402、发送与注册操作对应的注册类型至AMF。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为执行移动注册更新,接收终端设备发送的移动注册更新Mobility Registration Update注册类型;发送与注册操作对应的注册类型至AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了移动注册更新对应的注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图15为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由N3IWF执行,如图15所示,该方法可以包括以下步骤:
步骤1501、在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收终端设备根据终端设备的配置信息发送的匿名SUCI;
步骤1502、发送匿名SUCI至AMF。
其中,在本公开的一个实施例之中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
其中,在本公开的一个实施例之中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
其中,在本公开的一个实施例之中,方法还包括:
接收AMF发送的至少一个K n3iwf、至少一个SUCI和/或至少一个SUCI的生成算法;
存储至少一个K n3iwf和至少一个SUCI的映射关系。
其中,在本公开的一个实施例之中,方法还包括:
发送SUCI生成算法至终端设备;
接收终端设备发送的SUCI,其中,SUCI是根据SUCI生成算法生成的;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
其中,在本公开的一个实施例之中,方法还包括:
响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
其中,在本公开的一个实施例之中,方法还包括:
响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,未确定SUCI对应的K n3iwf时,发送SUCI至AMF;
接收AMF发送的根据SUCI确定的SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
综上所述,在本公开实施例之中,在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收终端设备根据终端设备的配置信息发送的匿名SUCI;发送匿名SUCI至AMF。在本公开实施例之中,响应于EAP方式支持SUPI的隐私保护机制,根据终端设备的配置信息发送匿名SUCI至N3IWF,N3IWF可以发送匿名SUCI至AMF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了接收终端设备根据终端设备的配置信息发送的匿名SUCI的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图16为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图,如图16所示,该方法可以包括以下步骤:
步骤1601、N3IWF发送SUCI生成算法至终端设备;
步骤1602、终端设备根据SUCI生成算法生成的SUCI,并发送SUCI至N3IWF;
步骤1603、N3IWF接收终端设备发送的SUCI,其中,SUCI是根据SUCI生成算法生成的;
步骤1604、N3IWF根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
步骤1605、N3IWF根据SUCI对应的K n3iwf对终端设备进行认证。
综上所述,在本公开实施例之中,发送SUCI生成算法至终端设备;接收终端设备发送的SUCI,其中,SUCI是根据SUCI生成算法生成的;根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf;根据SUCI对应的K n3iwf对终端设备进行认证。在本公开实施例之中,根据终端设备发送的SUCI确定SUCI对应的K n3iwf,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了接收终端设备根据终端设备的配置信息发送的匿名SUCI的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图17为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图,如图17所示,该方法可以包括以下步骤:
步骤1701、响应于未接收到N3IWF发送的SUCI生成算法,终端设备发送SUCI至N3IWF
步骤1702、响应于未发送SUCI生成算法至终端设备,N3IWF接收终端设备发送的SUCI;
步骤1703、N3IWF根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
步骤1704、N3IWF根据SUCI对应的K n3iwf对终端设备进行认证。
综上所述,在本公开实施例之中,响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;N3IWF 根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf;N3IWF根据SUCI对应的K n3iwf对终端设备进行认证在本公开实施例之中,根据终端设备发送的SUCI确定SUCI对应的K n3iwf,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了接收终端设备根据终端设备的配置信息发送的匿名SUCI的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图18为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图18所示,该方法可以包括以下步骤:
步骤1801、当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种。
其中,在本公开的一个实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的用户标识,包括:
响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
以及,在本公开的一个实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的用户标识,包括:
响应于注册操作为初始注册或移动注册更新,接收N3IWF发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
以及,在本公开的一个实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型,包括以下中的至少一种:
响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的SNPN Onboarding注册类型;
响应于终端设备执行的注册操作为执行初始注册,接收N3IWF发送的初始注册Initial Registration注册类型;
响应于终端设备执行的注册操作为执行移动注册更新,接收N3IWF发送的移动注册更新Mobility Registration Update注册类型。
以及,在本公开的一个实施例之中,方法还包括:
将本地配置的AMF配置数据应用于在线签约,其中,AMF配置数据用于限制终端设备的网络应用仅为在线签约;
在AMF中的终端设备的上下文中存储指示信息,其中,指示信息用于指示终端设备已在线签约注册。
以及,在本公开的一个实施例之中,方法还包括:
基于ON-SNPN策略,启动用于实现特定注销的计时器,其中,计时器为终端设备在线签约Onboarding配置的。
示例地,在本公开的一个实施例之中,根据执行的注册操作,发送N3IWF发送的与注册操作对应的用户标识至N3IWF,包括:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收N3IWF发送的匿名SUCI,其中,匿名SUCI为终端设备根据终端设备的配置信息发送至N3IWF的匿名SUCI。
进一步地,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
进一步地,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
进一步地,在本公开的一个实施例之中,方法还包括:
采用以下至少一种认证方式对终端设备进行认证:
5G AKA认证方式;
EAP-AKA'认证方式;
任何其他生成密钥的EAP认证方式。
进一步地,在本公开的一个实施例之中,方法还包括:
接收AUSF发送的安全锚功能SEAF密钥K seaf、SUPI、SUCI和/或SUCI的生成算法;
根据K seaf、SUPI,生成AMF密钥K amf
根据K amf生成K n3iwf,并存储SUPI、SUCI和K n3iwf之间的映射关系。
进一步地,在本公开的一个实施例之中,在完成3GPP网络或者默认凭证服务器完成终端设备的认证之后,AUSF获得终端设备的SUPI,同时AUSF将用户的SUPI加密成SUCI,并生成K seaf。AUSF将生成的Kseaf,用于生成SUCI的算法,SUPI,SUCI发送给AMF或SEAF,其中,AMF或SEAF一般是合设的,就是AMF或SEAF为一个设备。SEAF可以根据K seaf以及用户的SUPI,生成K amf。AMF根据K amf生成K n3iwf
进一步地,在本公开的一个实施例之中,方法还包括:
发送至少一个K n3iwf、至少一个SUCI和/或至少一个SUCI的生成算法至N3IWF。
进一步地,在本公开的一个实施例之中,方法还包括:
接收N3IWF发送的SUCI,其中,SUCI为终端设备发送至N3IWF,且N3IWF未确定SUCI对应的K n3iwf的SUCI;
发送SUCI至鉴权服务功能AUSF;
接收AUSF针对SUCI发送的SUPI,并根据SUPI确定SUCI对应的K n3iwf
发送SUCI对应的K n3iwf至N3IWF。
示例地,在本公开的一个实施例之中,N3IWF接收到AUSF针对SUCI发送的SUPI时,N3IWF可以通过SUPI定位到K n3iwf之后,用N3IWF密钥K n3iwf与终端设备建立IPsec SA。
示例地,在本公开的一个实施例之中,AMF每次向N3IWF发送SUCI的生成算法都是可选的,即AMF每次可以向N3IWF发送SUCI的生成算法,AMF每次也可以不向N3IWF发送SUCI的生成算法。
示例地,在本公开的一个实施例之中,AUSF每次向AMF发送SUCI的生成算法都是可选的,即AUSF每次可以向AMF发送SUCI的生成算法,AUSF每次也可以不向AMF发送SUCI的生成算法。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图19为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图19所示,该方法可以包括以下步骤:
步骤1901、响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
综上所述,在本公开实施例之中,响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的以下用户标识中的至少一种:onboarding SUCI;onboarding SUPI。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的用户标识,减少接收的用户标识与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了独立的非公共网络在线签约注册对应的用户标识的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图20为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图20所示,该方法可以包括以下步骤:
步骤2001、响应于注册操作为初始注册或移动注册更新,接收N3IWF发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于注册操作为初始注册或移动注册更新,接收N3IWF发送的以下用户标识中的至少一种:用户隐藏标识符SUCI;用户永久标识符SUPI。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的 用户标识,减少接收的用户标识与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了初始注册或移动注册更新对应的用户标识的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图21为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图21所示,该方法可以包括以下步骤:
步骤2101、响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的SNPN Onboarding注册类型。
其中,在本公开的一个实施例之中,该方法还包括:AMF将本地配置的AMF配置数据应用于在线签约,其中,AMF配置数据用于限制终端设备的网络应用仅为在线签约;在AMF中的终端设备的上下文中存储指示信息,其中,指示信息用于指示终端设备已在线签约注册。
以及,在本公开的一个实施例之中,该方法还包括:基于ON-SNPN策略,AMF启动用于实现特定注销的计时器,其中,计时器为终端设备在线签约Onboarding配置的。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的SNPN Onboarding注册类型。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的注册类型,减少接收的注册类型与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了独立的非公共网络在线签约注册对应的注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图22为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图22所示,该方法可以包括以下步骤:
步骤2201、响应于终端设备执行的注册操作为执行初始注册,接收N3IWF发送的初始注册Initial Registration注册类型。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为执行初始注册,接收N3IWF发送的初始注册Initial Registration注册类型。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的注册类型,减少接收的注册类型与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了初始注册对应的注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的注册类型,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图23为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图23所示,该方法可以包括以下步骤:
步骤2301、响应于终端设备执行的注册操作为执行移动注册更新,接收N3IWF发送的移动注册更新Mobility Registration Update注册类型。
综上所述,在本公开实施例之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,响应于终端设备执行的注册操作为执行移动注册更新,接收N3IWF发送的移动注册更新Mobility Registration Update注册类型。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的注册类型,减少接收的注册类型与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了移动注册更新对应的注册类型的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的注册类型,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图24为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的流程示意图,该方法由AMF执行,如图24所示,该方法可以包括以下步骤:
步骤2401、在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保 护机制,接收N3IWF发送的匿名SUCI,其中,匿名SUCI为终端设备根据终端设备的配置信息发送至N3IWF的匿名SUCI。
其中,在本公开的一个实施例之中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
其中,在本公开的一个实施例之中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
以及,在本公开的一个实施例之中,该方法还包括:
AMF采用以下至少一种认证方式对终端设备进行认证:
5G AKA认证方式;
EAP-AKA'认证方式;
任何其他生成密钥的EAP认证方式。
进一步地,在本公开的一个实施例之中,方法还包括:
接收鉴权服务功能AUSF发送的安全锚功能SEAF密钥K seaf、SUPI、SUCI和/或SUCI的生成算法;
根据K seaf、SUPI,生成AMF密钥K amf
根据K amf生成K n3iwf,并存储SUPI、SUCI和K n3iwf之间的映射关系。
其中,在本公开的一个实施例之中,AMF存储SUPI、SUCI和K n3iwf之间的映射关系,用于AMF根据SUPI或者SUCI查找K n3iwf,提高K n3iwf查找的便利性。
进一步地,在本公开的一个实施例之中,方法还包括:
发送至少一个K n3iwf、至少一个SUCI和/或至少一个SUCI的生成算法至N3IWF。
进一步地,在本公开的一个实施例之中,方法还包括:
接收N3IWF发送的SUCI,其中,SUCI为终端设备发送至N3IWF,且N3IWF未确定SUCI对应的K n3iwf的SUCI;
发送SUCI至鉴权服务功能AUSF;
接收AUSF针对SUCI发送的SUPI,并根据SUPI确定SUCI对应的K n3iwf
发送SUCI对应的K n3iwf至N3IWF。
示例地,在本公开的一个实施例之中,N3IWF接收到AUSF针对SUCI发送的SUPI时,N3IWF可以通过SUPI定位到K n3iwf之后,用N3IWF密钥K n3iwf与终端设备建立IPsec SA。
综上所述,在本公开实施例之中,在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收N3IWF发送的匿名SUCI,其中,匿名SUCI为终端设备根据终端设备的配置信息发送至N3IWF的匿名SUCI。在本公开实施例之中,响应于EAP方式支持SUPI的隐私保护机制,接收N3IWF发送的匿名SUCI,其中,匿名SUCI为终端设备根据终端设备的配置信息发送至N3IWF的匿名SUCI,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开实施例具体公开了接收N3IWF发送的匿名SUCI的方案。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理方法,以根据终端设备执行的注册操作,接收与该注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图25为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图,如图25所示,该方法可以包括以下步骤:
步骤2501、响应于未接收到N3IWF发送的SUCI生成算法,终端设备发送SUCI至N3IWF
步骤2502、响应于未发送SUCI生成算法至终端设备,N3IWF接收终端设备发送的SUCI;
步骤2503、N3IWF根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,未确定SUCI对应的K n3iwf时,发送SUCI至AMF;
步骤2504、AMF接收N3IWF发送的SUCI,其中,SUCI为终端设备发送至N3IWF,且N3IWF未确定SUCI对应的K n3iwf的SUCI;
步骤2505、AMF发送SUCI至鉴权服务功能AUSF;
步骤2506、AUSF根据SUCI解密为SUPI,并发送SUPI至AMF;
步骤2507、AMF接收AUSF针对SUCI发送的SUPI,并根据SUPI确定SUCI对应的K n3iwf
步骤2508、AMF发送SUCI对应的K n3iwf至N3IWF;
步骤2509、N3IWF接收AMF发送的根据SUCI确定的SUCI对应的K n3iwf
步骤2510、N3IWF根据SUCI对应的K n3iwf对终端设备进行认证。
综上所述,在本公开实施例之中,在N3IWF根据映射关系未确定SUCI对应的K n3iwf时,可以接收AMF发送的K n3iwf,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。
图26为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证方法的交互示意图,如图26所示,该方法可以包括以下步骤:
步骤2601、在完成3GPP网络或者默认凭证服务器完成终端设备的认证之后,AUSF获得终端设备的SUPI,AUSF将用户的SUPI加密成SUCI,并生成K seaf
步骤2602、AUSF将生成的Kseaf,用于生成SUCI的算法,SUPI,SUCI发送给AMF或SEAF;
步骤2603、SEAF可以根据K seaf以及用户的SUPI,生成K amf
步骤2604、AMF根据K amf生成K n3iwf
步骤2605、AMF将K n3iwf,SUCI,SUCI生成算法发送给N3IWF;
步骤2606、N3IWF接收SUCI和K n3iwf,以及存储SUCI和K n3iwf之间的映射关系。
其中,在本公开的一个实施例之中,AMF或SEAF一般是合设的,就是AMF或SEAF为一个设备。
以及,在本公开的一个实施例之中,SUCI生成算法的发送都是可选,即可发可不发。例如AUSF可以发送SUCI生成算法至AMF或SEAF,AUSF也可以不发送SUCI生成算法至AMF或SEAF。例如AMF或SEAF可以发送SUCI生成算法至N3IWF,AMF或SEAF也可以不发送SUCI生成算法至N3IWF。例如N3IWF可以发送SUCI生成算法至终端设备,N3IWF也可以不发送SUCI生成算法至终端设备。
综上所述,在本公开实施例之中,N3IWF保持SUCI和K n3iwf,以及SUCI和K n3iwf之间的映射关系,可以减少N3IWF接收到终端设备发送的SUCI时确定与SUCI对应的K n3iwf的时长,提高SUCI对应的K n3iwf确定的便利性,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。
图27为本公开实施例所提供的一种通信系统的架构示意图,如图27所示,该系统包括:
终端设备,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至N3IWF;
N3IWF,用于根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种,并发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至AMF;
AMF,用于根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种。
综上所述,在本公开实施例的通信系统之中,当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,终端设备可以根据执行的注册操作,发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至N3IWF,N3IWF可以根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种,并发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至AMF;AMF可以根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种。在本公开实施例之中,根据终端设备执行的注册操作,发送与该注册操作对应的信息,减少发送的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理装置,以根据终端设备执行的注册操作,发送与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
图28为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证装置的结构示意图,如图28所示,该装置2800可以设置于终端设备侧,该装置2800可以包括:
发送模块2801,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。
综上所述,在本公开实施例的通过非3GPP接入网络接入3GPP网络的认证装置之中,通过发送模块如果终端设备通过不受信任的非3GPP接入3GPP网络,则根据执行的注册操作,发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。在本公开实施例之中,根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,减少发送的信息与终端设备执行的注册操作不 匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理装置,以根据终端设备执行的注册操作,发送与该注册操作对应的信息至N3IWF,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
可选地,在本公开的一个实施例之中,发送模块2801,用于根据执行的注册操作,发送与注册操作对应的用户标识至N3IWF时,具体用于:
响应于执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送以下用户标识中的至少一种至所述N3IWF:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
可选地,在本公开的一个实施例之中,发送模块2801,用于根据执行的注册操作,发送与注册操作对应的用户标识至N3IWF时,具体用于:
响应于执行的注册操作为执行初始注册或执行移动注册更新,发送以下用户标识中的至少一种至N3IWF:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
可选地,在本公开的一个实施例之中,发送模块2801,用于根据执行的注册操作,发送与注册操作对应的注册类型至N3IWF时,具体用于以下中的至少一种:
响应于执行的注册操作为执行独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送SNPN Onboarding注册类型至N3IWF;
响应于执行的注册操作为执行初始注册,发送初始注册Initial Registration注册类型至N3IWF;
响应于执行的注册操作为执行移动注册更新,发送移动注册更新Mobility Registration Update注册类型至N3IWF。
可选地,在本公开的一个实施例之中,发送模块2801,用于根据执行的注册操作,发送与注册操作对应的用户标识至N3IWF时,具体用于:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,根据终端设备的配置信息发送匿名SUCI至N3IWF。
可选地,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
可选地,在本公开的一个实施例之中,发送模块2801,还用于:
接收N3IWF发送的SUCI生成算法;
根据SUCI生成算法生成SUCI,并发送SUCI至N3IWF。
可选地,在本公开的一个实施例之中,发送模块2801,还用于:
响应于未接收到N3IWF发送的SUCI生成算法,发送SUCI至N3IWF。
图29为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证装置的结构示意图,如图29所示,该装置2900可以设置于N3IWF侧,该装置2900可以包括:
接收模块2901,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种;
发送模块2902,用于发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能AMF。
综上所述,在本公开实施例的通过非3GPP接入网络接入3GPP网络的认证装置之中,通过接收模块当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种;发送模块发送与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能AMF。在本公开实施例之中,根据终端设备执行的注册操作,接收与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理装置,以根据终端设备执行的注册操作,接收与该注册操作对应的信息,可以提高通过非3GPP接入网 络接入3GPP网络的认证的准确性。
可选地,在本公开的一个实施例之中,接收模块2901,用于根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的用户标识时,具体用于:
响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
可选地,在本公开的一个实施例之中,接收模块2901,用于根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的用户标识时,具体用于:
响应于注册操作为初始注册或移动注册更新,接收终端设备发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
可选地,在本公开的一个实施例之中,接收模块2901,用于根据终端设备执行的注册操作,接收终端设备发送的与注册操作对应的注册类型时,具体用于以下中的至少一种:
响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收终端设备发送的SNPN Onboarding注册类型;
响应于终端设备执行的注册操作为执行初始注册,接收终端设备发送的初始注册Initial Registration注册类型;
响应于终端设备执行的注册操作为执行移动注册更新,接收终端设备发送的移动注册更新Mobility Registration Update注册类型。
可选地,在本公开的一个实施例之中,接收模块2901,用于根据执行的注册操作,发送终端设备发送的与注册操作对应的用户标识至N3IWF时,具体用于:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收终端设备根据终端设备的配置信息发送的匿名anonymousSUCI。
可选地,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
可选地,在本公开的一个实施例之中,接收模块2901,还用于:
接收AMF发送的至少一个K n3iwf、至少一个SUCI和/或至少一个SUCI的生成算法;
存储至少一个K n3iwf和至少一个SUCI的映射关系。
可选地,在本公开的一个实施例之中,接收模块2901,还用于:
发送SUCI生成算法至终端设备;
接收终端设备发送的SUCI,其中,SUCI是根据SUCI生成算法生成的;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
可选地,在本公开的一个实施例之中,接收模块2901,还用于:
响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,确定SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
可选地,在本公开的一个实施例之中,接收模块2901,还用于:
响应于未发送SUCI生成算法至终端设备,接收终端设备发送的SUCI;
根据SUCI与至少一个K n3iwf和至少一个SUCI的映射关系,未确定SUCI对应的K n3iwf时,发送SUCI至AMF;
接收AMF发送的根据SUCI确定的SUCI对应的K n3iwf
根据SUCI对应的K n3iwf对终端设备进行认证。
图30为本公开实施例所提供的一种通过非3GPP接入网络接入3GPP网络的认证装置的结构示意图,如图30所示,该装置3000可以设置于AMF侧,该装置3000可以包括:
接收模块3001,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种。
综上所述,在本公开实施例的通过非3GPP接入网络接入3GPP网络的认证装置之中,通过接收模块当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型、用户标识以及终端设备所需注册的非公共网络标识中的至少一种。在本公开实施例之中,根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,减少接收的信息与终端设备执行的注册操作不匹配的情况,提高通过非3GPP接入网络接入3GPP网络的认证的准确性,使得终端设备可以通过非3GPP接入网络接入3GPP网络。本公开针对一种“通过非3GPP接入网络接入3GPP网络的认证”这一情形提供了一种处理装置,以根据终端设备执行的注册操作,接收N3IWF发送的与该注册操作对应的信息,可以提高通过非3GPP接入网络接入3GPP网络的认证的准确性。
可选地,在本公开的一个实施例之中,接收模块3001,用于根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的用户标识时,具体用于:
响应于终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的以下用户标识中的至少一种:
在线签约用户隐藏标识符(onboarding SUCI);
在线签约用户永久标识符(onboarding SUPI)。
可选地,在本公开的一个实施例之中,接收模块3001,用于根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的用户标识时,具体用于:
响应于注册操作为初始注册或移动注册更新,接收N3IWF发送的以下用户标识中的至少一种:
用户隐藏标识符SUCI;
用户永久标识符SUPI。
可选地,在本公开的一个实施例之中,接收模块3001,用于根据终端设备执行的注册操作,接收N3IWF发送的与注册操作对应的注册类型时,具体用于以下中的至少一种:
响应于终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收N3IWF发送的SNPN Onboarding注册类型;
响应于终端设备执行的注册操作为执行初始注册,接收N3IWF发送的初始注册Initial Registration注册类型;
响应于终端设备执行的注册操作为执行移动注册更新,接收N3IWF发送的移动注册更新Mobility Registration Update注册类型。
可选地,在本公开的一个实施例之中,接收模块3001,还用于:
将本地配置的AMF配置数据应用于在线签约,其中,AMF配置数据用于限制终端设备的网络应用仅为在线签约;
在AMF中的终端设备的上下文中存储指示信息,其中,指示信息用于指示终端设备已在线签约注册。
可选地,在本公开的一个实施例之中,接收模块3001,还用于:
基于ON-SNPN策略,启动用于实现特定注销的计时器,其中,计时器为终端设备在线签约Onboarding配置的。
可选地,在本公开的一个实施例之中,接收模块3001,用于根据执行的注册操作,发送N3IWF发送的与注册操作对应的用户标识至N3IWF时,具体用于:
在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收N3IWF发送的匿名SUCI,其中,匿名SUCI为终端设备根据终端设备的配置信息发送至N3IWF的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
可选地,在本公开的一个实施例之中,其中,匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
可选地,在本公开的一个实施例之中,接收模块3001,还用于:
采用以下至少一种认证方式对终端设备进行认证:
5G AKA认证方式;
EAP-AKA'认证方式;
任何其他生成密钥的EAP认证方式。
可选地,在本公开的一个实施例之中,接收模块3001,还用于:
接收AUSF发送的安全锚功能SEAF密钥K seaf、SUPI、SUCI和/或SUCI的生成算法;
根据K seaf、SUPI,生成AMF密钥K amf
根据K amf生成K n3iwf,并存储SUPI、SUCI和K n3iwf之间的映射关系。
可选地,在本公开的一个实施例之中,接收模块3001,还用于:
发送至少一个K n3iwf、至少一个SUCI和至少一个SUCI的生成算法至N3IWF。
可选地,在本公开的一个实施例之中,接收模块3001,还用于:
接收N3IWF发送的SUCI,其中,SUCI为终端设备发送至N3IWF,且N3IWF未确定SUCI对应的K n3iwf的SUCI;
发送SUCI至鉴权服务功能AUSF;
接收AUSF针对SUCI发送的SUPI,并根据SUPI确定SUCI对应的K n3iwf
发送SUCI对应的K n3iwf至N3IWF。
图31是本公开一个实施例所提供的一种终端设备UE3100的框图。例如,UE3100可以是移动电话,计算机,数字广播终端设备,消息收发设备,游戏控制台,平板设备,医疗设备,健身设备,个人数字助理等。
参照图31,UE3100可以包括以下至少一个组件:处理组件3102,存储器3104,电源组件3106,多媒体组件3108,音频组件3110,输入/输出(I/O)的接口3112,传感器组件3114,以及通信组件3116。
处理组件3102通常控制UE3100的整体操作,诸如与显示,电话呼叫,数据通信,相机操作和记录操作相关联的操作。处理组件3102可以包括至少一个处理器3120来执行指令,以完成上述的方法的全部或部分步骤。此外,处理组件3102可以包括至少一个模块,便于处理组件3102和其他组件之间的交互。例如,处理组件3102可以包括多媒体模块,以方便多媒体组件3108和处理组件3102之间的交互。
存储器3104被配置为存储各种类型的数据以支持在UE3100的操作。这些数据的示例包括用于在UE3100上操作的任何应用程序或方法的指令,联系人数据,电话簿数据,消息,图片,视频等。存储器3104可以由任何类型的易失性或非易失性存储设备或者它们的组合实现,如静态随机存取存储器(SRAM),电可擦除可编程只读存储器(EEPROM),可擦除可编程只读存储器(EPROM),可编程只读存储器(PROM),只读存储器(ROM),磁存储器,快闪存储器,磁盘或光盘。
电源组件3106为UE3100的各种组件提供电力。电源组件3106可以包括电源管理系统,至少一个电源,及其他与为UE3100生成、管理和分配电力相关联的组件。
多媒体组件3108包括在所述UE3100和用户之间的提供一个输出接口的屏幕。在一些实施例中,屏幕可以包括液晶显示器(LCD)和触摸面板(TP)。如果屏幕包括触摸面板,屏幕可以被实现为触摸屏,以接收来自用户的输入信号。触摸面板包括至少一个触摸传感器以感测触摸、滑动和触摸面板上的手势。所述触摸传感器可以不仅感测触摸或滑动动作的边界,而且还检测与所述触摸或滑动操作相关的唤醒时间和压力。在一些实施例中,多媒体组件3108包括一个前置摄像头和/或后置摄像头。当UE3100处于操作模式,如拍摄模式或视频模式时,前置摄像头和/或后置摄像头可以接收外部的多媒体数据。每个前置摄像头和后置摄像头可以是一个固定的光学透镜系统或具有焦距和光学变焦能力。
音频组件3110被配置为输出和/或输入音频信号。例如,音频组件3110包括一个麦克风(MIC),当UE3100处于操作模式,如呼叫模式、记录模式和语音识别模式时,麦克风被配置为接收外部音频信号。所接收的音频信号可以被进一步存储在存储器3104或经由通信组件3116发送。在一些实施例中,音频组件3110还包括一个扬声器,用于输出音频信号。
I/O接口3112为处理组件3102和外围接口模块之间提供接口,上述外围接口模块可以是键盘,点击轮,按钮等。这些按钮可包括但不限于:主页按钮、音量按钮、启动按钮和锁定按钮。
传感器组件3114包括至少一个传感器,用于为UE3100提供各个方面的状态评估。例如,传感器组件3114可以检测到设备3100的打开/关闭状态,组件的相对定位,例如所述组件为UE3100的显示器和小键盘,传感器组件3114还可以检测UE3100或UE3100的一个组件的位置改变,用户与UE3100接触的存在或不存在,UE3100方位或加速/减速和UE3100的温度变化。传感器组件3114可以包括接近传感器,被配置用来在没有任何的物理接触时检测附近物体的存在。传感器组件3114还可以包括光传感器,如CMOS或CCD图像传感器,用于在成像应用中使用。在一些实施例中,该传感器组件3114还可以包括加速度传感器,陀螺仪传感器,磁传感器,压力传感器或温度传感器。
通信组件3116被配置为便于UE3100和其他设备之间有线或无线方式的通信。UE3100可以接入基于通信标准的无线网络,如WiFi,2G或3G,或它们的组合。在一个示例性实施例中,通信组件3116经由广播信道接收来自外部广播管理系统的广播信号或广播相关信息。在一个示例性实施例中,所述通信组件3116还包括近场通信(NFC)模块,以促进短程通信。例如,在NFC模块可基于射频识别(RFID)技术,红外数据协会(IrDA)技术,超宽带(UWB)技术,蓝牙(BT)技术和其他技术来实现。
在示例性实施例中,UE3100可以被至少一个应用专用集成电路(ASIC)、数字信号处理器(DSP)、数字信号处理设备(DSPD)、可编程逻辑器件(PLD)、现场可编程门阵列(FPGA)、控制器、微控制器、微处理器或其他电子元件实 现,用于执行上述方法。
图32是本公开实施例所提供的一种网络侧设备3200的框图。例如,网络侧设备3200可以被提供为一网络侧设备。参照图32,网络侧设备3200包括处理组件3222,其进一步包括至少一个处理器,以及由存储器3232所代表的存储器资源,用于存储可由处理组件3222的执行的指令,例如应用程序。存储器3232中存储的应用程序可以包括一个或一个以上的每一个对应于一组指令的模块。此外,处理组件3222被配置为执行指令,以执行上述方法前述应用在所述网络侧设备的任意方法,例如,如图8所示方法。
网络侧设备3200还可以包括一个电源组件3230被配置为执行网络侧设备3200的电源管理,一个有线或无线网络接口3250被配置为将网络侧设备3200连接到网络,和一个输入/输出(I/O)接口3258。网络侧设备3200可以操作基于存储在存储器3232的操作系统,例如Windows Server TM,Mac OS XTM,Unix TM,Linux TM,Free BSDTM或类似。
上述本公开提供的实施例中,分别从网络侧设备、UE的角度对本公开实施例提供的方法进行了介绍。为了实现上述本公开实施例提供的方法中的各功能,网络侧设备和UE可以包括硬件结构、软件模块,以硬件结构、软件模块、或硬件结构加软件模块的形式来实现上述各功能。上述各功能中的某个功能可以以硬件结构、软件模块、或者硬件结构加软件模块的方式来执行。
上述本公开提供的实施例中,分别从网络侧设备、UE的角度对本公开实施例提供的方法进行了介绍。为了实现上述本公开实施例提供的方法中的各功能,网络侧设备和UE可以包括硬件结构、软件模块,以硬件结构、软件模块、或硬件结构加软件模块的形式来实现上述各功能。上述各功能中的某个功能可以以硬件结构、软件模块、或者硬件结构加软件模块的方式来执行。
本公开实施例提供的一种通信装置。通信装置可包括收发模块和处理模块。收发模块可包括发送模块和/或接收模块,发送模块用于实现发送功能,接收模块用于实现接收功能,收发模块可以实现发送功能和/或接收功能。
通信装置可以是终端设备(如前述方法实施例中的终端设备),也可以是终端设备中的装置,还可以是能够与终端设备匹配使用的装置。或者,通信装置可以是网络设备,也可以是网络设备中的装置,还可以是能够与网络设备匹配使用的装置。
本公开实施例提供的另一种通信装置。通信装置可以是网络设备,也可以是终端设备(如前述方法实施例中的终端设备),也可以是支持网络设备实现上述方法的芯片、芯片系统、或处理器等,还可以是支持终端设备实现上述方法的芯片、芯片系统、或处理器等。该装置可用于实现上述方法实施例中描述的方法,具体可以参见上述方法实施例中的说明。
通信装置可以包括一个或多个处理器。处理器可以是通用处理器或者专用处理器等。例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,网络侧设备、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行计算机程序,处理计算机程序的数据。
可选地,通信装置中还可以包括一个或多个存储器,其上可以存有计算机程序,处理器执行所述计算机程序,以使得通信装置执行上述方法实施例中描述的方法。可选地,所述存储器中还可以存储有数据。通信装置和存储器可以单独设置,也可以集成在一起。
可选地,通信装置还可以包括收发器、天线。收发器可以称为收发单元、收发机、或收发电路等,用于实现收发功能。收发器可以包括接收器和发送器,接收器可以称为接收机或接收电路等,用于实现接收功能;发送器可以称为发送机或发送电路等,用于实现发送功能。
可选地,通信装置中还可以包括一个或多个接口电路。接口电路用于接收代码指令并传输至处理器。处理器运行所述代码指令以使通信装置执行上述方法实施例中描述的方法。
通信装置为终端设备(如前述方法实施例中的终端设备):处理器用于执行图2-图9任一所示的方法。
通信装置为N3IWF:处理器用于执行图10-图17任一所示的方法。
通信装置为AMF:处理器用于执行图18-图26任一所示的方法。
在一种实现方式中,处理器中可以包括用于实现接收和发送功能的收发器。例如该收发器可以是收发电路,或者是接口,或者是接口电路。用于实现接收和发送功能的收发电路、接口或接口电路可以是分开的,也可以集成在一起。上述收发电路、接口或接口电路可以用于代码/数据的读写,或者,上述收发电路、接口或接口电路可以用于信号的传输或传递。
在一种实现方式中,处理器可以存有计算机程序,计算机程序在处理器上运行,可使得通信装置执行上述方法实施例中描述的方法。计算机程序可能固化在处理器中,该种情况下,处理器可能由硬件实现。
在一种实现方式中,通信装置可以包括电路,所述电路可以实现前述方法实施例中发送或接收或者通信的功能。 本公开中描述的处理器和收发器可实现在集成电路(integrated circuit,IC)、模拟IC、射频集成电路RFIC、混合信号IC、专用集成电路(application specific integrated circuit,ASIC)、印刷电路板(printed circuit board,PCB)、电子设备等上。该处理器和收发器也可以用各种IC工艺技术来制造,例如互补金属氧化物半导体(complementary metal oxide semiconductor,CMOS)、N型金属氧化物半导体(nMetal-oxide-semiconductor,NMOS)、P型金属氧化物半导体(positive channel metal oxide semiconductor,PMOS)、双极结型晶体管(bipolar junction transistor,BJT)、双极CMOS(BiCMOS)、硅锗(SiGe)、砷化镓(GaAs)等。
以上实施例描述中的通信装置可以是网络设备或者终端设备(如前述方法实施例中的终端设备),但本公开中描述的通信装置的范围并不限于此,而且通信装置的结构可以不受的限制。通信装置可以是独立的设备或者可以是较大设备的一部分。例如所述通信装置可以是:
(1)独立的集成电路IC,或芯片,或,芯片系统或子系统;
(2)具有一个或多个IC的集合,可选地,该IC集合也可以包括用于存储数据,计算机程序的存储部件;
(3)ASIC,例如调制解调器(Modem);
(4)可嵌入在其他设备内的模块;
(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;
(6)其他等等。
对于通信装置可以是芯片或芯片系统的情况,芯片包括处理器和接口。其中,处理器的数量可以是一个或多个,接口的数量可以是多个。
可选地,芯片还包括存储器,存储器用于存储必要的计算机程序和数据。
本领域技术人员还可以了解到本公开实施例列出的各种说明性逻辑块(illustrative logical block)和步骤(step)可以通过电子硬件、电脑软件,或两者的结合进行实现。这样的功能是通过硬件还是软件来实现取决于特定的应用和整个系统的设计要求。本领域技术人员可以对于每种特定的应用,可以使用各种方法实现所述的功能,但这种实现不应被理解为超出本公开实施例保护的范围。
本公开还提供一种可读存储介质,其上存储有指令,该指令被计算机执行时实现上述任一方法实施例的功能。
本公开还提供一种计算机程序产品,该计算机程序产品被计算机执行时实现上述任一方法实施例的功能。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机程序。在计算机上加载和执行所述计算机程序时,全部或部分地产生按照本公开实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机程序可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机程序可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质(例如,软盘、硬盘、磁带)、光介质(例如,高密度数字视频光盘(digital video disc,DVD))、或者半导体介质(例如,固态硬盘(solid state disk,SSD))等。
本领域普通技术人员可以理解:本公开中涉及的第一、第二等各种数字编号仅为描述方便进行的区分,并不用来限制本公开实施例的范围,也表示先后顺序。
本公开中的至少一个还可以描述为一个或多个,多个可以是两个、三个、四个或者更多个,本公开不做限制。在本公开实施例中,对于一种技术特征,通过“第一”、“第二”、“第三”、“A”、“B”、“C”和“D”等区分该种技术特征中的技术特征,该“第一”、“第二”、“第三”、“A”、“B”、“C”和“D”描述的技术特征间无先后顺序或者大小顺序。
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本发明的其它实施方案。本公开旨在涵盖本发明的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本发明的一般性原理并包括本公开未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本公开的真正范围和精神由下面的权利要求指出。
应当理解的是,本公开并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本公开的范围仅由所附的权利要求来限制。

Claims (42)

  1. 一种通过非第三代合作伙伴计划3GPP接入网络接入3GPP网络的认证方法,其特征在于,所述方法由终端设备执行,所述方法包括:
    当所述终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。
  2. 根据权利要求1所述的方法,其特征在于,所述根据执行的注册操作,发送与所述注册操作对应的用户标识至N3IWF,包括:
    响应于所述执行的注册操作为独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送以下用户标识中的至少一种至所述N3IWF:
    在线签约用户隐藏标识符(onboarding SUCI);
    在线签约用户永久标识符(onboarding SUPI)。
  3. 根据权利要求1所述的方法,其特征在于,所述根据执行的注册操作,发送与所述注册操作对应的用户标识至N3IWF,包括:
    响应于所述执行的注册操作为执行初始注册或执行移动注册更新,发送以下用户标识中的至少一种至所述N3IWF:
    用户隐藏标识符SUCI;
    用户永久标识符SUPI。
  4. 根据权利要求1所述的方法,其特征在于,所述根据执行的注册操作,发送与所述注册操作对应的注册类型至所述N3IWF,包括以下中的至少一种:
    响应于所述执行的注册操作为执行独立的非公共网络在线签约注册(SNPN Onboarding Registration),发送SNPN Onboarding注册类型至所述N3IWF;
    响应于所述执行的注册操作为执行初始注册,发送初始注册Initial Registration注册类型至所述N3IWF;
    响应于所述执行的注册操作为执行移动注册更新,发送移动注册更新Mobility Registration Update注册类型至所述N3IWF。
  5. 根据权利要求1所述的方法,其特征在于,所述根据执行的注册操作,发送与所述注册操作对应的用户标识至N3IWF,包括:
    在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,根据所述终端设备的配置信息发送匿名SUCI至所述N3IWF。
  6. 根据权利要求5所述的方法,其特征在于,其中,所述匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
  7. 根据权利要求5所述的方法,其特征在于,其中,所述匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
  8. 根据权利要求5所述的方法,其特征在于,所述方法还包括:
    接收所述N3IWF发送的SUCI生成算法;
    根据所述SUCI生成算法生成SUCI,并发送所述SUCI至所述N3IWF。
  9. 根据权利要求8所述的方法,其特征在于,所述方法还包括:
    响应于未接收到所述N3IWF发送的SUCI生成算法,发送所述SUCI至所述N3IWF。
  10. 一种通过非3GPP接入网络接入3GPP网络的认证方法,其特征在于,所述方法由N3IWF执行,所述方法包括:
    当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种;
    发送所述与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能AMF。
  11. 根据权利要求10所述的方法,其特征在于,所述根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的用户标识,包括:
    响应于所述终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所 述终端设备发送的以下用户标识中的至少一种:
    在线签约用户隐藏标识符(onboarding SUCI);
    在线签约用户永久标识符(onboarding SUPI)。
  12. 根据权利要求10所述的方法,其特征在于,所述根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的用户标识,包括:
    响应于所述注册操作为初始注册或移动注册更新,接收所述终端设备发送的以下用户标识中的至少一种:
    用户隐藏标识符SUCI;
    用户永久标识符SUPI。
  13. 根据权利要求10所述的方法,其特征在于,所述根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型,包括以下中的至少一种:
    响应于所述终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述终端设备发送的SNPN Onboarding注册类型;
    响应于所述终端设备执行的注册操作为执行初始注册,接收所述终端设备发送的初始注册Initial Registration注册类型;
    响应于所述终端设备执行的注册操作为执行移动注册更新,接收所述终端设备发送的移动注册更新MobilityRegistration Update注册类型。
  14. 根据权利要求10所述的方法,其特征在于,所述根据执行的注册操作,发送所述终端设备发送的与所述注册操作对应的用户标识至N3IWF,包括:
    在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收所述终端设备根据所述终端设备的配置信息发送的匿名anonymous SUCI。
  15. 根据权利要求14所述的方法,其特征在于,其中,所述匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
  16. 根据权利要求14所述的方法,其特征在于,其中,所述匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
  17. 根据权利要求14所述的方法,其特征在于,所述方法还包括:
    接收AMF发送的至少一个密钥K n3iwf、至少一个SUCI和/或所述至少一个SUCI的生成算法;
    存储所述至少一个K n3iwf和至少一个SUCI的映射关系。
  18. 根据权利要求17所述的方法,其特征在于,所述方法还包括:
    发送SUCI生成算法至所述终端设备;
    接收所述终端设备发送的SUCI,其中,所述SUCI是根据所述SUCI生成算法生成的;
    根据所述SUCI与所述至少一个K n3iwf和至少一个SUCI的映射关系,确定所述SUCI对应的K n3iwf
    根据所述SUCI对应的K n3iwf对所述终端设备进行认证。
  19. 根据权利要求17所述的方法,其特征在于,所述方法还包括:
    响应于未发送SUCI生成算法至所述终端设备,接收所述终端设备发送的SUCI;
    根据所述SUCI与所述至少一个K n3iwf和至少一个SUCI的映射关系,确定所述SUCI对应的K n3iwf
    根据所述SUCI对应的K n3iwf对所述终端设备进行认证。
  20. 根据权利要求18所述的方法,其特征在于,所述方法还包括:
    响应于未发送SUCI生成算法至所述终端设备,接收所述终端设备发送的SUCI;
    根据所述SUCI与所述至少一个K n3iwf和至少一个SUCI的映射关系,未确定所述SUCI对应的K n3iwf时,发送所述SUCI至所述AMF;
    接收所述AMF发送的根据所述SUCI确定的所述SUCI对应的K n3iwf
    根据所述SUCI对应的K n3iwf对所述终端设备进行认证。
  21. 一种通过非3GPP接入网络接入3GPP网络的认证方法,其特征在于,所述方法由AMF执行,所述方法包括:
    当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收N3IWF发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种。
  22. 根据权利要求21所述的方法,其特征在于,所述根据所述终端设备执行的注册操作,接收所述N3IWF发送的与所述注册操作对应的用户标识,包括:
    响应于所述终端设备执行的注册操作为独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述N3IWF发送的以下用户标识中的至少一种:
    在线签约用户隐藏标识符(onboarding SUCI);
    在线签约用户永久标识符(onboarding SUPI)。
  23. 根据权利要求21所述的方法,其特征在于,所述根据所述终端设备执行的注册操作,接收所述N3IWF发送的与所述注册操作对应的用户标识,包括:
    响应于所述注册操作为初始注册或移动注册更新,接收所述N3IWF发送的以下用户标识中的至少一种:
    用户隐藏标识符SUCI;
    用户永久标识符SUPI。
  24. 根据权利要求21所述的方法,其特征在于,所述根据所述终端设备执行的注册操作,接收所述N3IWF发送的与所述注册操作对应的注册类型,包括以下中的至少一种:
    响应于所述终端设备执行的注册操作为执行独立的非公共网络在线签约注册SNPN Onboarding Registration,接收所述N3IWF发送的SNPN Onboarding注册类型;
    响应于所述终端设备执行的注册操作为执行初始注册,接收所述N3IWF发送的初始注册Initial Registration注册类型;
    响应于所述终端设备执行的注册操作为执行移动注册更新,接收所述N3IWF发送的移动注册更新MobilityRegistration Update注册类型。
  25. 根据权利要求24所述的方法,其特征在于,所述方法还包括:
    将本地配置的AMF配置数据应用于在线签约,其中,所述AMF配置数据用于限制所述终端设备的网络应用仅为在线签约;
    在所述AMF中的所述终端设备的上下文中存储指示信息,其中,所述指示信息用于指示所述终端设备已在线签约注册。
  26. 根据权利要求24所述的方法,其特征在于,所述方法还包括:
    基于在线签约SNPNON-SNPN策略,启动用于实现特定注销的计时器,其中,所述计时器为所述终端设备在线签约Onboarding配置的。
  27. 根据权利要求21所述的方法,其特征在于,所述根据执行的注册操作,发送所述N3IWF发送的与所述注册操作对应的用户标识至N3IWF,包括:
    在非公共网络NPN场景下,响应于可扩展认证协议EAP方式支持用户永久标识符SUPI的隐私保护机制,接收所述N3IWF发送的匿名SUCI,其中,所述匿名SUCI为所述终端设备根据所述终端设备的配置信息发送至所述N3IWF的匿名SUCI。
  28. 根据权利要求27所述的方法,其特征在于,其中,所述匿名SUCI为通过忽略原用户隐藏标识符中的用户名部分username得到的匿名SUCI。
  29. 根据权利要求27所述的方法,其特征在于,其中,所述匿名SUCI为将原用户隐藏标识符中的用户名部分username统一设置为anonymous得到的匿名SUCI。
  30. 根据权利要求27所述的方法,其特征在于,所述方法还包括:
    采用以下至少一种认证方式对所述终端设备进行认证:
    5G AKA认证方式;
    EAP-AKA'认证方式;
    任何其他生成密钥的EAP认证方式。
  31. 根据权利要求27所述的方法,其特征在于,所述方法还包括:
    接收鉴权服务功能AUSF发送的安全锚功能SEAF密钥K seaf、SUPI、SUCI和/或SUCI的生成算法;
    根据所述K seaf、所述SUPI,生成AMF密钥K amf
    根据所述K amf生成K n3iwf,并存储所述SUPI、所述SUCI和所述K n3iwf之间的映射关系。
  32. 根据权利要求31所述的方法,其特征在于,所述方法还包括:
    发送至少一个K n3iwf、至少一个SUCI和/或所述至少一个SUCI的生成算法至所述N3IWF。
  33. 根据权利要求31所述的方法,其特征在于,所述方法还包括:
    接收所述N3IWF发送的SUCI,其中,所述SUCI为所述终端设备发送至所述N3IWF,且所述N3IWF未确定所述SUCI对应的K n3iwf的SUCI;
    发送所述SUCI至AUSF;
    接收所述AUSF针对所述SUCI发送的SUPI,并根据所述SUPI确定所述SUCI对应的K n3iwf
    发送所述SUCI对应的K n3iwf至所述N3IWF。
  34. 一种通过非3GPP接入网络接入3GPP网络的认证装置,其特征在于,所述装置设置于终端设备侧,所述装置包括:
    发送模块,用于如果所述终端设备通过不受信任的非3GPP接入网络接入3GPP网络,则根据执行的注册操作,发送与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至非3GPP互通功能N3IWF。
  35. 一种通过非3GPP接入网络接入3GPP网络的认证装置,其特征在于,所述装置设置于N3IWF侧,所述装置包括:
    接收模块,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种;
    发送模块,用于发送所述与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至接入与移动性管理功能AMF。
  36. 一种通过非3GPP接入网络接入3GPP网络的认证装置,其特征在于,所述装置设置于AMF侧,所述装置包括:
    接收模块,用于当终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据所述终端设备执行的注册操作,接收N3IWF发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种。
  37. 一种终端设备,其特征在于,所述设备包括处理器和存储器,其中,所述存储器中存储有计算机程序,所述处理器执行所述存储器中存储的计算机程序,以使所述装置执行如权利要求1至9中任一项所述的方法。
  38. 一种N3IWF,其特征在于,所述设备包括处理器和存储器,其中,所述存储器中存储有计算机程序,所述处理器执行所述存储器中存储的计算机程序,以使所述装置执行如权利要求10至20中任一项所述的方法。
  39. 一种AMF,其特征在于,所述设备包括处理器和存储器,其中,所述存储器中存储有计算机程序,所述处理器执行所述存储器中存储的计算机程序,以使所述装置执行如权利要求21至33中任一项所述的方法。
  40. 一种通信装置,其特征在于,包括:处理器和接口电路,其中
    所述接口电路,用于接收代码指令并传输至所述处理器;
    所述处理器,用于运行所述代码指令以执行如权利要求1至9或10至20或21至33中任一项所述的方法。
  41. 一种计算机可读存储介质,其特征在于,用于存储有指令,当所述指令被执行时,使如权利要求1至9或10至20或21至33中任一项所述的方法被实现。
  42. 一种通信系统,其特征在于,所述系统包括:
    终端设备,用于当所述终端设备通过不受信任的非3GPP接入网络接入3GPP网络时,根据执行的注册操作,发送与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至N3IWF;
    所述N3IWF,用于根据所述终端设备执行的注册操作,接收所述终端设备发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种,并发送所述与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种至AMF;
    所述AMF,用于根据所述终端设备执行的注册操作,接收N3IWF发送的与所述注册操作对应的注册类型、用户标识以及所述终端设备所需注册的非公共网络标识中的至少一种。
PCT/CN2022/112622 2022-08-15 2022-08-15 通过非3gpp接入网络接入3gpp网络的认证方法、装置 WO2024036461A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202280002810.3A CN117897978A (zh) 2022-08-15 2022-08-15 通过非3gpp接入网络接入3gpp网络的认证方法、装置
PCT/CN2022/112622 WO2024036461A1 (zh) 2022-08-15 2022-08-15 通过非3gpp接入网络接入3gpp网络的认证方法、装置

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2022/112622 WO2024036461A1 (zh) 2022-08-15 2022-08-15 通过非3gpp接入网络接入3gpp网络的认证方法、装置

Publications (1)

Publication Number Publication Date
WO2024036461A1 true WO2024036461A1 (zh) 2024-02-22

Family

ID=89940352

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/112622 WO2024036461A1 (zh) 2022-08-15 2022-08-15 通过非3gpp接入网络接入3gpp网络的认证方法、装置

Country Status (2)

Country Link
CN (1) CN117897978A (zh)
WO (1) WO2024036461A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20190037516A1 (en) * 2016-11-10 2019-01-31 Lg Electronics Inc. Registration method through network access belonging to identical plmn in wireless communication system, and device therefor
WO2020034449A1 (en) * 2018-11-06 2020-02-20 Zte Corporation Methods and systems for user equipment mobility management and registration
WO2021066788A1 (en) * 2019-09-30 2021-04-08 Nokia Technologies Oy Non-3gpp interworking function (n3iwf) selection for stand-alone non-public networks (snpn)
CN114423074A (zh) * 2020-10-28 2022-04-29 华为技术有限公司 一种通信方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20190037516A1 (en) * 2016-11-10 2019-01-31 Lg Electronics Inc. Registration method through network access belonging to identical plmn in wireless communication system, and device therefor
WO2020034449A1 (en) * 2018-11-06 2020-02-20 Zte Corporation Methods and systems for user equipment mobility management and registration
WO2021066788A1 (en) * 2019-09-30 2021-04-08 Nokia Technologies Oy Non-3gpp interworking function (n3iwf) selection for stand-alone non-public networks (snpn)
CN114423074A (zh) * 2020-10-28 2022-04-29 华为技术有限公司 一种通信方法及装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
[INTEL, ERICSSON, MEDIATEK INC.], HUAWEI: "Registration Procedure for UE Onboarding", 3GPP DRAFT; S2-2104229, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20210517 - 20210528, 10 May 2021 (2021-05-10), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP052004544 *

Also Published As

Publication number Publication date
CN117897978A (zh) 2024-04-16

Similar Documents

Publication Publication Date Title
WO2021027554A1 (zh) 信息共享方法、终端设备、存储介质及计算机程序产品
WO2019104124A1 (en) Secure authentication of devices for internet of things
US20070254630A1 (en) Methods, devices and modules for secure remote access to home networks
KR20060049882A (ko) 무선 근거리 네트워크 관계용 디바이스 및 방법과, 이에대응하는 제품
WO2023280194A1 (zh) 网络连接管理方法、装置、可读介质、程序产品及电子设备
KR20070039034A (ko) 무선 근거리 네트워크를 연결하기 위한 장치 및 방법
WO2016015509A1 (zh) 用于移动通信系统中的终端认证方法和装置
CN112640385B (zh) 用于在si系统中使用的非si设备和si设备以及相应的方法
US11956626B2 (en) Cryptographic key generation for mobile communications device
CN112640387B (zh) 用于无线连接的非si设备、si设备、方法和计算机可读介质和/或微处理器可执行介质
CN116325664A (zh) 一种智能设备配网的方法和装置
WO2019122495A1 (en) Authentication for wireless communications system
WO2021239098A1 (zh) 业务获取方法、装置、通信设备及可读存储介质
CN116830524A (zh) 蜂窝网络中的置备服务器选择
WO2024036461A1 (zh) 通过非3gpp接入网络接入3gpp网络的认证方法、装置
WO2022237693A1 (zh) Nswo业务的认证方法、设备和存储介质
WO2022237561A1 (zh) 一种通信方法及装置
WO2016003310A1 (en) Bootstrapping a device to a wireless network
WO2023240659A1 (zh) 认证方法、装置、通信设备和存储介质
WO2024021137A1 (zh) Api调用者认证方法以及装置、通信设备及存储介质
WO2024065565A1 (zh) 授权撤销方法及装置
WO2023240661A1 (zh) 认证与授权方法、装置、通信设备及存储介质
WO2023070433A1 (en) Authentication between wireless devices and edge servers
US11974339B2 (en) Provisioning headless WiFi devices and related systems, methods and devices
WO2023202631A1 (zh) 签约方法、装置、通信设备、物联网设备及网元

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 202280002810.3

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22955243

Country of ref document: EP

Kind code of ref document: A1