WO2024239231A1 - 认证方法及装置 - Google Patents
认证方法及装置 Download PDFInfo
- Publication number
- WO2024239231A1 WO2024239231A1 PCT/CN2023/095769 CN2023095769W WO2024239231A1 WO 2024239231 A1 WO2024239231 A1 WO 2024239231A1 CN 2023095769 W CN2023095769 W CN 2023095769W WO 2024239231 A1 WO2024239231 A1 WO 2024239231A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- key
- response
- network element
- parameter
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0433—Key management protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
Definitions
- the present application relates to the field of communication technology, and more specifically, to an authentication method and device.
- the terminal device can authenticate and negotiate keys with the network side before communicating with the network side.
- the first device such as a zero-power terminal
- the terminal device can authenticate and negotiate keys with the network side before communicating with the network side.
- the present application provides an authentication method and device. The following is a detailed introduction to various aspects of the present application.
- an authentication method including: a first device receives a first authentication request from a proxy node, the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element; the first device generates a second message authentication code based on a first key generation algorithm and a first parameter; the first device authenticates the authentication network element based on the first message authentication code and the second message authentication code; when the authentication network element is successfully authenticated, the first device generates a response parameter; the first device sends a first authentication response to the proxy node, the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
- an authentication method including: a proxy node sends a first authentication request to a first device, the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; the proxy node receives a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
- an authentication method including: an authentication network element generates a first message authentication code and an expected response, the expected response is used to authenticate a first device, the first message authentication code is generated based on a first key generation algorithm and a first parameter; the authentication network element sends a first authentication request to the proxy node, the first authentication request includes the first message authentication code, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, and the second message authentication code is generated by the first device.
- an authentication method including: an access network device sends a first authentication request to a first device, the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; the access network device receives a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
- a device wherein the device is a first device, and the first device includes: a receiving unit, used to receive a first authentication request from a proxy node, the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element; a generating unit, used to generate a second message authentication code based on a first key generation algorithm and a first parameter; an authentication unit, used to authenticate the authentication network element based on the first message authentication code and the second message authentication code; the generating unit is also used to generate a response parameter for the first device when the authentication of the authentication network element is successful; a sending unit, used to send a first authentication response to the proxy node, the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
- a proxy node including: a sending unit, used to send a first authentication request to a first device, the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; a receiving unit, used to receive a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
- an authentication network element including: a generating unit, used to generate a first message authentication code and an expected response, the expected response is used to authenticate a first device, the first message authentication code is generated based on a first key generation algorithm and a first parameter; a sending unit, used to send a first authentication request to the proxy node, the first authentication request includes the first message authentication code, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, and the second message authentication code is generated by the first device.
- an access network device including: a sending unit, configured to send a first authentication request to a first device, wherein the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, and the first message authentication code and a second message authentication code are generated by an authentication network element.
- the first message authentication code is used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; a receiving unit is used to receive a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
- a device comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory to execute the method described in the first aspect.
- a proxy node comprising a memory and a processor, wherein the memory is used to store programs, and the processor is used to call the programs in the memory to execute the method described in the second aspect.
- an authentication network element comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory to execute the method described in the third aspect.
- an access network device comprising a memory and a processor, wherein the memory is used to store programs, and the processor is used to call the programs in the memory to execute the method described in the fourth aspect.
- a device comprising a processor, configured to call a program from a memory to execute a method as described in any one of the first to fourth aspects.
- a chip comprising a processor for calling a program from a memory so that a device equipped with the chip executes a method as described in any one of the first to fourth aspects.
- a computer-readable storage medium on which a program is stored, wherein the program enables a computer to execute the method described in any one of the first to fourth aspects.
- a computer program product comprising a program, wherein the program enables a computer to execute the method described in any one of the first to fourth aspects.
- a computer program is provided, wherein the computer program enables a computer to execute the method as described in any one of the first to fourth aspects.
- the first device receives a first authentication request from a proxy node, the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element; the first device generates a second message authentication code based on a first key generation algorithm and a first parameter; the first device authenticates the authentication network element based on the first message authentication code and the second message authentication code; when the authentication network element successfully authenticates, the first device generates a response parameter; the first device sends a first authentication response to the proxy node, the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
- the present application generates a message authentication code (such as a second message authentication code) based on a first key generation algorithm and a first parameter to authenticate the network element, thereby providing a clear solution for authentication between the first device and the network side.
- a message authentication code such as a second message authentication code
- FIG. 1 is a wireless communication system 100 to which an embodiment of the present application is applied.
- FIG. 2 is a schematic diagram of a process of initial authentication.
- FIG. 3 is a schematic diagram of a process for generating an AKMA key.
- FIG. 4 is a schematic diagram of a process of generating an application key.
- FIG5 is a schematic diagram of the derivation process of various keys involved in an embodiment of the present application.
- FIG. 6 is a schematic diagram of a method for generating various parameters involved in an embodiment of the present application.
- FIG. 7 is a schematic diagram of a hybrid communication system provided in an embodiment of the present application.
- FIG8 is a communication system based on 3GPP security credentials provided in an embodiment of the present application.
- FIG9 is a communication system based on non-3GPP security credentials provided in an embodiment of the present application.
- FIG10 is a flow chart of an authentication method provided in an embodiment of the present application.
- FIG11 is a flow chart of an authentication method based on a proxy node and 3GPP security credentials provided in an embodiment of the present application.
- FIG. 12 is a schematic diagram of a process of generating an AKMA key based on FIG. 11 .
- FIG. 13 is a schematic diagram of a process of generating an application key based on FIG. 12 .
- FIG14 is a flow chart of another authentication method provided in an embodiment of the present application.
- FIG15 is a flow chart of an authentication method based on 3GPP security credentials provided in an embodiment of the present application.
- FIG. 16 is a schematic diagram of a process of generating an application key based on FIG. 15 .
- FIG17 is a flow chart of another authentication method provided in an embodiment of the present application.
- FIG18 is a flow chart of an authentication method based on a proxy node and non-3GPP security credentials provided in an embodiment of the present application.
- FIG19 is a flow chart of another authentication method provided in an embodiment of the present application.
- Figure 20 is a flowchart of an authentication method based on non-3GPP security credentials provided in an embodiment of the present application.
- Figure 21 is a schematic block diagram of a first device provided in an embodiment of the present application.
- Figure 22 is a schematic block diagram of a proxy node provided in an embodiment of the present application.
- Figure 23 is a schematic block diagram of an authentication network element provided in an embodiment of the present application.
- Figure 24 is a schematic block diagram of an access network device provided in an embodiment of the present application.
- FIG. 25 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application.
- FIG1 is a wireless communication system 100 used in an embodiment of the present application.
- the wireless communication system 100 may include a network device 110 and a terminal device 120.
- the network device 110 may be a device that communicates with the terminal device 120.
- the network device 110 may provide communication coverage for a specific geographical area, and may communicate with the terminal device 120 located in the coverage area.
- FIG1 exemplarily shows a network device and two terminal devices.
- the wireless communication system 100 may include multiple network devices and each network device may include another number of terminal devices within its coverage area, which is not limited in the embodiments of the present application.
- the wireless communication system 100 may also include other network entities such as a network controller and a mobility management entity, which is not limited in the embodiments of the present application.
- network entities such as a network controller and a mobility management entity, which is not limited in the embodiments of the present application.
- the terminal device in the embodiment of the present application may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device.
- the terminal device in the embodiment of the present application may be a device that provides voice and/or data connectivity to a user, and can be used to connect people, objects and machines, such as a handheld device with wireless connection function, a vehicle-mounted device, etc.
- the terminal device in the embodiment of the present application can be a mobile phone, a tablet computer, a laptop, a PDA, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.
- the UE can be used to act as a base station.
- the UE can act as a scheduling entity that provides sidelink signals between UEs in V2X or D2D, etc.
- a cellular phone and a car communicate with each other using sidelink signals.
- the cellular phone and the smart home device communicate with each other without relaying the communication signal through the base station.
- Base station can broadly cover various names as follows, or replace with the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, transmitting point (TRP), transmitting point (TP), master station MeNB, auxiliary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, base band unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc.
- the base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof.
- the network device in the embodiments of the present application may refer to a CU or a DU, or the network device includes a CU and a DU.
- the gNB may also include an AAU.
- K AF The application key
- AMF access and mobility management function
- AUSF authentication server function
- UDM unified data management
- AAA AKMA anchor function
- AF AF
- AMF is mainly used for mobility management and access management. It can be used to implement other functions of the mobility management entity (MME) except session management, such as lawful interception and access authorization/authentication.
- MME mobility management entity
- AUSF is used for authentication services, key generation, and bidirectional authentication of UEs, and supports a unified authentication framework.
- AUSF is mainly used for mutual authentication between UEs and networks, and generates security keys for use in subsequent processes.
- UDM can be used to process UE identification, access authentication, registration, and mobility management.
- the UE may first perform initial authentication with the network side, and obtain a key (such as KAUSF) after the initial authentication is completed.
- the key may be used to generate K AF .
- the initial authentication process is introduced below in conjunction with FIG. 2 .
- UDM/ARPF can create a 5G HE AV for each authentication get request message (such as Nudm Authenticate Get Request). UDM/ARPF can first generate an authentication vector with AMF "separation bit" as 1, and then calculate K AUSF and XRES*. Finally, UDM/ARPF can create a 5G HE AV containing RAND, AUTN, XRES* and K AUSF .
- SEAF sends an authentication request to the UE.
- the authentication request may be sent via a non-access stratum (NAS) message (such as Auth-Reg).
- the authentication request may include RANT and an authentication token (AUTN).
- the message may also include ngKSI, which may be used to identify the UE and AMF K AMF and part of the native security context.
- the UE may include a mobile equipment (ME) and a universal subscriber identity module (USIM). After the UE receives RANT and AUTN, the ME may forward the RANT and AUTN to the USIM.
- ME mobile equipment
- USIM universal subscriber identity module
- step S214 after receiving RANT and AUTN, USIM can check whether AUTN is accepted to verify whether the authentication vector is up to date to resist replay attacks. If the verification is successful, USIM can calculate the response RES and return RES, encryption key (encryption key, CK) and integrity key (integrity key, IK) to ME. USIM can also calculate Kc (i.e. GPRS Kc) and send the GPRS Kc to ME. If GPRS Kc is calculated based on CK, IK and the conversion function c3 described in the third generation partnership project (3GPP) TS 33.102, ME can ignore the GPRS Kc, and the GPRS Kc should not be stored on USIM or ME.
- 3GPP third generation partnership project
- step S216 the UE sends an authentication response to the SEAF, which may include RES*.
- the authentication response may be sent via a NAS message.
- step S220 SEAF sends a UE authentication request (such as Nausf_UE Authentication_Authenticate Request) message to AUSF, and the UE authentication request message may include SUCI or SUPI.
- UE authentication request such as Nausf_UE Authentication_Authenticate Request
- AUSF receives a UE authentication request message, which may include RES*.
- AUSF may verify whether the AV has expired. If the AV has expired, AUSF may consider the authentication unsuccessful from the perspective of the home domain network.
- AUSF may determine whether the authentication is successful by comparing the received RES* with the stored XRES*. If RES* and XRES* are consistent, AUSF considers the authentication successful from the perspective of the home domain network; if RES* and XRES* are inconsistent, AUSF considers the authentication unsuccessful from the perspective of the home domain network.
- the AUSF indicates to the SEAF whether the authentication is successful through a UE authentication response (e.g., Nausf_UE Authentication_Authenticate Response) message. If the authentication is successful, the AUSF may send K SEAF to the SEAF through the UE authentication response message. If the authentication is successful, and the AUSF receives SUCI from the SEAF when initiating the authentication, the UE authentication response message may also include SUPI.
- a UE authentication response e.g., Nausf_UE Authentication_Authenticate Response
- SEAF may provide ngKSI and KAMF to AMF only after receiving the UE authentication response message containing SUPI. Before knowing SUPI, the service network will not provide communication services to UE.
- step S302 after the initial authentication is completed, the UE and the AUSF may generate K AKMA and A-KID based on K AUSF .
- the AUSF may send an AKMA anchor key registration request (eg, Naanf_AKMA_AnchorKey_Register Request) to the AAnF.
- the AKMA anchor key registration request may include SUPI, A-KID, and K AKMA .
- AAnF may return an AKMA anchor key registration response (such as Naanf_AKMA_AnchorKey_Register Response) to AUSF.
- AKMA anchor key registration response such as Naanf_AKMA_AnchorKey_Register Response
- the UE may send an application session establishment request to the AF.
- the application session establishment request may include the A-KID.
- AAnF may determine the corresponding K AKMA based on A-KID, and generate a key K AF based on K AKMA .
- step S408 the AAnF sends an AKMA application key acquisition response to the AF.
- the application key acquisition response may include K AF , the validity period of K AF (K AF expTime), UE-ID, etc.
- step S410 the AF sends an application session establishment response to the UE.
- the UE can also generate K AF in the same manner as the AAnF, that is, the manner in which the UE generates K AF based on K AKMA is the same as the manner in which the AAnF generates K AF based on K AKMA .
- the UE and the AF can communicate using the same key K AF .
- KDF key derivation function
- KDF can be any key derivation function that can meet the computational security requirements, for example, KDF can be HMAC-SHA-256 or HMAC-SM3.
- KDF uses KDF as an example to illustrate the generation method of the key.
- -FC 0xXX (e.g. 0x80);
- - L0 length of AKMA (e.g. 0x00 0x04);
- the input key is K AUSF .
- -FC 0xXX (e.g. 0x82);
- the key entered is K AKMA .
- AF_ID FQDN of AF
- A-KID may include two parts: a routing indicator (RID) and an AKMA temporary UE identifier (A-TID).
- RID is included in SUPI, and A-TID can be generated based on K AUSF .
- A-TID can be generated based on K AUSF .
- -FC 0xXX (e.g. 0x81);
- -L0 length of "A-TID" (e.g. 0x00 0x05);
- the key entered is K AUSF .
- FIG5 is a schematic diagram of the derivation process of various keys involved in an embodiment of the present application.
- the NAS security context in the embodiment of the present application may include KAMF , subordinate derived keys KNASint and KNASenc , and key identifiers corresponding to the respective keys.
- the access stratum (AS) security context in the embodiment of the present application may include K gNB , subordinate derived keys K RRCint , K RRCenc , K UPint and K UPenc , and key identifiers corresponding to each key.
- the keys involved in the embodiments of the present application may also include confidentiality protection keys (or encryption keys) and integrity protection keys.
- confidentiality protection keys and integrity protection keys can be generated by KAMF or KgNB .
- KAMF is a shared key between AMF and UE, and is a shared key between gNB and UE.
- the input parameters can be as follows:
- -FC 0xXX (e.g. 00x69);
- -L0 length of algorithm type distinguisher (e.g. 0x00 0x01);
- -L1 length of algorithm identity (e.g. 0x00 0x01).
- the value of the input algorithm identifier may also be different.
- the encryption algorithm used in the embodiment of the present application may include one or more of the following: NIA1, NIA2, NIA3, and the integrity protection algorithm may include one or more of the following: EIA1, EIA2, EIA3.
- FIG. 6 shows a method for generating various parameters involved in an embodiment of the present application.
- the UE can store a long-term key K and the public key of the home network, which can be used to encrypt the SUPI.
- wireless communication systems can be integrated with industrial wireless sensor networks (IWSN).
- IWSN industrial wireless sensor networks
- wireless communication systems can be integrated with smart logistics and smart warehousing.
- smart home networks can be integrated with smart home networks.
- terminal devices are usually required to have the characteristics of low cost, small size (such as ultra-thin), maintenance-free, long life, etc. Therefore, in order to meet the above conditions, network devices and terminal devices can use zero-power communication technology for communication.
- the terminal device can also be called "zero-power communication terminal", “zero-power terminal” or tag.
- the first communication mode is that the zero-power terminal communicates directly with the base station.
- the base station can provide a wireless power supply signal and a trigger signal to the zero-power terminal.
- the wireless power supply signal can be used to provide energy to the zero-power terminal.
- the trigger signal can carry control information sent to the zero-power terminal.
- the zero-power terminal can transmit information to the base station by backscattering.
- the second communication mode is a hybrid communication mode, that is, this communication mode includes cellular communication and sideline communication.
- this communication mode includes cellular communication and sideline communication.
- zero-power communication systems based on cellular communication and sideline communication can coexist or be used in combination flexibly, thereby matching more potential application scenarios.
- Fig. 7 shows a hybrid communication system.
- the communication modes shown in Fig. 7 include four types, which are respectively introduced below.
- Method 2 The base station provides a wireless power supply signal and sends a trigger signal to the zero-power terminal.
- the backscattered signal of the zero-power terminal is received by the terminal device, thereby completing the side communication.
- the terminal device can send air interface data to the base station.
- Mode 4 The terminal device receives the air interface signaling and data sent by the network device.
- the terminal device provides power supply signals and trigger signals to the zero-power terminal, and receives the backscattered signals sent by the zero-power terminal to complete the side communication.
- the security standards for battery efficient security for very low throughput machine type communication devices BEST), machine type communication (MTC), and new radio-internet of things (NB-IoT) designed for low throughput machine type communication devices in the Internet of Things are based on authentication and key negotiation mechanisms such as AKA, generic bootstrapping architecture (GBA), and AKMA.
- AKA authentication and key negotiation mechanisms
- GBA generic bootstrapping architecture
- AKMA AKMA
- the terminal device needs to support various functions in f1-f5 at the same time.
- MAC uses f1 function
- RES uses f2 function
- CK uses f3 function
- IK uses f4 function
- AK uses f5 function. Since the computing power of zero-power terminals is low, this method is not suitable for zero-power terminals.
- the embodiments of the present application provide an authentication method and device, which can implement the authentication and key negotiation process in a simplified manner, so that it can be applicable to the security authentication between the first device (such as a zero-power terminal) and the network side.
- the authentication method of the embodiment of the present application only requires the first device to support one or two key generation algorithms to implement the authentication and key negotiation process between the first device and the network side, thereby reducing the complexity of the first device.
- the first device in the embodiment of the present application may be a zero-power terminal.
- the first device may be, for example, a tag or an ambient power-enabled internet of things (A-IoT) device.
- A-IoT ambient power-enabled internet of things
- the communication mode of the first device and the security credentials involved in this application are first introduced.
- the first device does not support the application layer protocol, and the first device may be connected to the serving domain network element and/or the AF through a proxy node.
- the service domain network element in the embodiment of the present application may include, for example, one or more of the following: AMF, service management function (service Management function, SMF), SEAF, A-NF (ambient network function) specific to A-IoT services, etc.
- the proxy node may include, for example, a terminal device and/or an integrated access and backhaul (IAB) node, etc.
- the terminal device may be, for example, a UE.
- the proxy node may forward authentication information between the first device and the network side (such as an authentication network element). In other implementations, the proxy node may also perform some processing on the authentication information. For example, the proxy node may transmit authentication information via a NAS message (such as a NAS security context) or an AS message (such as an AS security context). For another example, the proxy node may decrypt some encrypted information (such as a hidden identity identifier of the first device) during the authentication process.
- NAS message such as a NAS security context
- AS message such as an AS security context
- the proxy node may decrypt some encrypted information (such as a hidden identity identifier of the first device) during the authentication process.
- the first device may support an application layer protocol (such as hyper text transfer protocol (HTTP)).
- an application layer protocol such as hyper text transfer protocol (HTTP)
- MAC media access control
- PHY physical
- the first device may be connected to the AF via an application layer protocol.
- the embodiment of the present application can establish a secure communication link between the first device and the third-party server (such as AF).
- the third-party server can rely on the core network to authenticate and negotiate keys for the first device.
- the security credentials in the embodiment of the present application can be divided into two categories. One type of security credentials is 3GPP security credentials, and the other type of security credentials is non-3GPP security credentials.
- the 3GPP security credential can be understood as a root key (abbreviated as K) shared between the first device and the authentication network element. If the security credential is a 3GPP security credential, the network side (such as UDM) can perform authorization management, such as storing the authentication result.
- the management authorization can be an authorization management based on the subscription credential.
- the authentication result can, for example, include one or more of the following: a timestamp of the first device authentication, an ID of the first device, an authentication method of the first device, and an identifier of the security context of the first device.
- the non-3GPP security credential may be a security credential provided by a third-party application server, such as a root key (K for short) shared between the first device and the AF or the network application function (NAF).
- the third-party application server (such as the AF or the NAF) may perform authorization management.
- the authorization management may be application layer-based authorization management.
- the third-party application server may manage the mapping between the proxy node and the first device, and provide the security credential K to the authentication network element, or provide the authentication network element with a subordinate key derived from the security credential K.
- Figure 9 shows a communication architecture based on 3GPP security credentials. Different from Figure 8, the third-party server can communicate with the core network to provide the core network with the security credential K or a subordinate key derived from the security credential K.
- security credential in the embodiment of the present application can be understood as a root key.
- the security credential is a 3GPP security credential
- the first device communicates with the network side through the proxy node.
- the embodiment of the present application does not specifically limit the generation method of the first message authentication code.
- the first message authentication code can be generated based on the first key generation algorithm and the first parameter.
- the first key generation algorithm can be any function.
- the function can be any one of the following: f function, KDF or other lightweight functions.
- the f function can be, for example, any one of the f1 function, f2 function, f3 function, f4 function, and f5 function defined by 3GPP.
- KDF can be, for example, HMAC-SHA-256 or HMAC-SM3.
- the lightweight function can be, for example, ASCON.
- the first parameter may include one or more of the following: a security credential, a first random number, a second random number, and a first key.
- the first parameter may include a security credential and a second random number.
- the first parameter may include a security credential, a second random number, and a first key.
- the first parameter may include a security credential, a second random number, and a first random number.
- the first parameter may include a security credential, a second random number, a first random number, and a first key.
- the security credential may be the 3GPP security credential or the non-3GPP security credential described above.
- the first random number (denoted as N2) may be a random number selected by the authentication network element or may be a shared key between the authentication network element and the first device. The first random number may be used to resist replay attacks.
- the second random number (denoted as RAND) may be a random number selected by the authentication network element.
- the first key (denoted as N1) may be one or more of the following: a random number pre-shared by the first device and a network side device (such as an authentication network element), a shared key between the first device and a proxy node, and a shared key between the first device and a base station.
- the shared key may be a physical layer key.
- the first message authentication code and the expected response can be generated based on the same key generation algorithm and different parameters, or the first message authentication code and the expected response can be generated based on different key generation algorithms and the same parameters, which can reduce the time required to generate the first message authentication code.
- a message authentication code and the complexity of the expected response can be generated based on the same key generation algorithm and different parameters, or the first message authentication code and the expected response can be generated based on different key generation algorithms and the same parameters, which can reduce the time required to generate the first message authentication code.
- a message authentication code and the complexity of the expected response can be generated based on the same key generation algorithm and different parameters, or the first message authentication code and the expected response can be generated based on different key generation algorithms and the same parameters, which can reduce the time required to generate the first message authentication code.
- the key generation algorithm used to generate the expected response is the same as the key generation algorithm used to generate the first message authentication code.
- the first message authentication code can be generated based on the first key generation algorithm and the first parameter
- the expected response can be generated based on the first key generation algorithm and the second parameter.
- the parameters used to generate the expected response are the same as the parameters used to generate the first message authentication code.
- the first message authentication code can be generated based on the first key generation algorithm and the first parameters
- the expected response can be generated based on the second key generation algorithm and the first parameters.
- the first key generation algorithm is different from the second key generation algorithm to ensure that the generated expected response is different from the first message authentication code.
- the second key generation algorithm can be any function.
- the second key generation algorithm can be any one of the following: f function, KDF or other lightweight functions.
- the f function can be, for example, any one of the f1 function, f2 function, f3 function, f4 function, and f5 function defined by 3GPP.
- KDF can be, for example, HMAC-SHA-256 or HMAC-SM3.
- the lightweight function can be, for example, ASCON.
- the first device may generate a second message authentication code and/or a response parameter.
- the second message authentication code may be used to authenticate the authentication network element, and the response parameter may be used to authenticate the first device.
- the second message authentication code may be represented by a second MAC, and the response parameter may be represented by a RES.
- the second message authentication code is generated in the same manner as the first message authentication code.
- the second message authentication code may be generated based on the first key generation algorithm and the first parameter.
- the first key generation algorithm and the first parameter may be described in the foregoing description, and will not be described here for brevity.
- MAC represents the first message authentication code or the second message authentication code
- f represents the first key generation algorithm or the second key generation algorithm
- RAND represents the second random number
- N1 represents the first key
- N2 represents the second random number
- K represents the security credential.
- the response parameter is generated in the same manner as the expected response.
- the response parameter can be generated based on the second key generation algorithm and the first parameter, or the response parameter can be generated based on the first key generation algorithm and the second parameter.
- the specific generation method of the response parameter can refer to the generation method of the expected response above, and for the sake of brevity, it will not be repeated here.
- the first device may receive a first message authentication code from the authentication network element.
- the first device may receive the first message authentication code from the authentication network element through a proxy node.
- the first device may compare the first message authentication code with the second message authentication code to authenticate the authentication network element. If the first message authentication code and the second message authentication code are consistent, it indicates that the authentication network element has been successfully authenticated; if the first message authentication code and the second message authentication code are inconsistent, it indicates that the authentication network element has failed to authenticate.
- the authentication network element may receive a response parameter from the first device.
- the authentication network element may receive the response parameter from the first device through a proxy node.
- the authentication network element may compare the response parameter with the expected response to authenticate the first device. If the response parameter is consistent with the expected response, it indicates that the first device is successfully authenticated; if the response parameter is inconsistent with the expected response, it indicates that the first device fails to authenticate.
- step S1020 the authentication network element sends a first authentication request to the proxy node, wherein the first authentication request includes a first message authentication code.
- the authentication network element sending the first authentication request to the proxy node may refer to the authentication network element directly sending the first authentication request to the proxy node, or may refer to the authentication network element sending the first authentication request to the proxy node through other devices.
- the other devices may include, for example, a base station and/or a service domain network element.
- the service domain network element may include an AMF and/or an SMF.
- step S1030 the proxy node sends a first authentication request to the first device.
- step S1040 the first device generates a second message authentication code based on the first key generation algorithm and the first parameter.
- the specific generation method can refer to the above description.
- the first device can generate the second message authentication code before receiving the first authentication request, or the first device can generate the second message authentication code after receiving the first authentication request.
- step S1050 the first device authenticates the authentication network element based on the first message authentication code and the second message authentication code. If the first message authentication code is consistent with the second message authentication code, the first device can determine that the authentication network element is successfully authenticated; if the first message authentication code and the second message authentication code are inconsistent, the first device can determine that the authentication network element fails to authenticate.
- step S1070 the first device sends a first authentication response to the proxy node.
- the first authentication response may include response parameters.
- the proxy node sends a first authentication response to the authentication network element.
- the first authentication response may include response parameters.
- the embodiment of the present application can authenticate the first device from the perspective of the home domain network, the service domain network and the access network.
- the response parameters may include one or more of the following: a first response parameter, a second response parameter and a third response parameter.
- the first response parameter can be used for the home domain network (or home domain network element) to authenticate the first device
- the second response parameter can be used for the service domain network (or service domain network element) to authenticate the first device
- the third response parameter can be used for the access network (or access network device) to authenticate the first device.
- the first response parameter can be recorded as RES1
- the second response parameter can be recorded as RES2
- the third response parameter can be recorded as RES3.
- the expected response may include one or more of the following: a first expected response, a second expected response, and a third expected response.
- the first expected response may be used for the home domain network (or home domain network element) to authenticate the first device
- the second expected response may be used for the service domain network (or service domain network element) to authenticate the first device
- the third expected response may be used for the access network (or access network device) to authenticate the first device.
- the first expected response may be recorded as XRES1
- the second expected response may be recorded as XRES2
- the third expected response may be recorded as XRES3.
- the expected response may include a first expected response and a second expected response to authenticate the first device from the perspective of the home domain network and the service domain network. In some embodiments, the expected response may include a first expected response and a third expected response to authenticate the first device from the perspective of the home domain network and the access network. In some embodiments, the expected response may include a second expected response and a third expected response to authenticate the first device from the perspective of the service domain network and the access network. In some embodiments, the expected response may include a first expected response, a second expected response, and a third expected response to authenticate the first device from the perspective of the home domain network, the service domain network, and the access network.
- the home domain network element may compare the first response parameter with the first expected response to authenticate the first device.
- the first expected response may be generated by the home domain network element, and the first response parameter may be generated by the first device.
- the first device may send the first response parameter to the home domain network element. If the first response parameter is consistent with the first expected response, the home domain network element may consider the authentication to be successful from the perspective of the home domain network. If the first response parameter is inconsistent with the first expected response, the home domain network element may consider the authentication to be failed from the perspective of the home domain network.
- the home domain network element may include AUSF and/or UDM.
- the access network device may compare the third response parameter with the third expected response to authenticate the first device. If the third response parameter is consistent with the third expected response, the access network device may consider the authentication successful from the perspective of the access network. If the third response parameter is inconsistent with the third expected response, the access network device may consider the authentication failed from the perspective of the access network.
- the access network device may be a base station.
- the third expected response may be generated by the home domain network element, and the home domain network element may send the third expected response to the access network device.
- the third expected response may be generated by the access network device.
- the authentication network element may send the first expected response to the access network device, and the access network device generates the third expected response based on the received first expected response. For example, in the case where the first key is a shared key between the first device and the access network device, the access network device may generate the third expected response based on the first expected response and the first key.
- the third response parameter may be generated by the first device, and the first device may send the third response parameter to the access network device.
- the first response parameter and the second message authentication code are based on the same key generation algorithm to reduce the computational complexity of the first device.
- the first response parameter can be generated based on the first key generation algorithm and the second parameter.
- the first device can generate the first response parameter based on the first key generation algorithm and the second parameter.
- the first response parameter and the second message authentication code are based on the same parameter to reduce the computational complexity of the first device.
- the first response parameter can be generated based on the second key generation algorithm and the first parameter.
- the first device can generate the first response parameter based on the second key generation algorithm and the first parameter.
- the first response parameter can be generated in the same manner as the expected response described above.
- RES1 represents the first response parameter
- f represents the first key generation algorithm or the second key generation algorithm
- RAND represents the second random number
- N1 represents the first key
- N2 represents the second random number
- K represents the security credential.
- the second response parameter may be generated based on the first response parameter and the third parameter.
- the first device may generate the second response parameter based on the first response parameter and the third parameter.
- the third parameter may include one or more of the following: security credentials, service domain network name (SN name) (or service domain network identifier).
- the second response parameter and the first response parameter may be generated based on the same key generation algorithm, or the second response parameter and the second message authentication code (or the first message authentication code) may be generated based on the same key generation algorithm.
- the second response parameter may be generated based on the first key generation algorithm, the first response parameter, and the third parameter.
- the second response parameter may be generated based on the second key generation algorithm, the first response parameter, and the third parameter.
- RES2 represents the second response parameter
- f represents the first key generation algorithm or the second key generation algorithm
- RES1 represents the first response parameter
- SN name represents the service domain network name or identifier
- K represents the security credential.
- RES3 represents the third response parameter
- f represents the first key generation algorithm or the second key generation algorithm
- RES1 represents the first response parameter
- N1 represents the first key
- the first expected response is similar to the first response parameter in generating manner
- the second expected response is similar to the second response parameter in generating manner
- the third expected response is similar to the third response parameter in generating manner, which will not be described again for brevity.
- the authentication network element may generate a first anonymous key.
- the first anonymous key may be used for secure transmission between the first device and the network side.
- the first anonymous key in order to reduce the computational complexity of generating the first anonymous key, can be generated based on the first key generation algorithm or the second key generation algorithm.
- the first anonymous key can be generated based on the first key generation algorithm and the ninth parameter.
- the first anonymous key can be generated based on the second key generation algorithm and the ninth parameter.
- the ninth parameter can include one or more of the following parameters: security credentials, a first random number, a second random number, and the first key.
- AK represents the first anonymous key
- K represents the security credential
- RAND represents the second random number
- f represents the first key generation algorithm or the second key generation algorithm.
- the first anonymous key in order to reduce the computational complexity of generating the first anonymous key, can be generated by an XOR operation.
- the first anonymous key can be generated by an XOR operation of the security credential and the first key.
- AK represents the first anonymous key
- K represents the security credential
- N1 represents the first key
- ⁇ represents the XOR operation.
- the authentication network element can generate AK based on the shared key N1.
- the first device may also generate a second anonymous key.
- the second anonymous key is generated in the same manner as the first anonymous key, and will not be described in detail for brevity.
- the hidden identity can be generated based on the identity of the first device and the first key.
- the hidden identity can be generated based on the identity of the first device, the first key and the security credential.
- the identity of the first device can be understood as the real identity of the first device.
- the following describes in detail the method for generating the hidden identity identifier by taking the generation of the hidden identity identifier based on the identity identifier of the first device and the first key as an example.
- DIDi represents a hidden identity
- IDi represents an identity of a first device
- N1 represents a first key
- ⁇ represents an exclusive-OR operation
- DIDi represents a hidden identity
- IDi represents an identity of a first device
- N1 represents a first key
- f represents a third key generation algorithm
- the first key may be a shared key (or random number) between the first device and the network side (such as an authentication network element), or may be a shared key between the first device and the proxy node, or may be a shared key between the first device and the base station.
- the shared key may be a physical layer key. If the first key is a physical layer key, the first device may not store the first key in advance, but obtain the first key by extracting physical layer channel characteristics.
- the authentication network element may send a new first key to the first device to update the hidden identity.
- the proxy node may send the second authentication request to the authentication network element.
- the second authentication request sent by the proxy node may include one or more of the following information: the first key, the identity of the first device, the hidden identity, and the identity of the proxy node.
- the identity of the proxy node may include one or more of the following: GPSI, SUCI, globally unique temporary identifier (GUTI), SUPI.
- the proxy node may adopt different processing strategies according to the first key.
- the first key is a shared key between the first device and the network side
- the second authentication request sent by the proxy node may include one or more of the following: a hidden identity and an identifier of the proxy node.
- the proxy node may de-anonymize the hidden identity to obtain the identity of the first device. For example, the proxy node may determine the identity of the first device based on the first key and the hidden identity.
- DIDi represents a hidden identity
- IDi represents an identity of a first device
- N1 represents a first key
- ⁇ represents an exclusive-OR operation
- DIDi represents a hidden identity
- IDi represents an identity of a first device
- N1 represents a first key
- f represents a third key generation algorithm
- the second authentication request sent by the first device may include one or more of the following: the first key, the identity of the first device, and the identity of the proxy node.
- the proxy node may send the second authentication request message via a NAS message or an AS message.
- the proxy node may send the second authentication request message via a NAS security context or an AS security context.
- the authentication network element may use the identity identifier of the first device to generate a fourth key described below.
- Ks represents the second key
- AK represents the first anonymous key
- N1 represents the first key
- N2 represents the first random number
- UE ID represents the identifier of the proxy node
- IDi represents the identity identifier of the first device
- SN name represents the name of the service domain network
- f represents the sixth key generation algorithm.
- the second key can be used to generate an AKMA key. That is, the first device can generate an AKMA key based on the second key. Alternatively, the authentication network element can generate an AKMA key based on the second key.
- the way the first device generates the AKMA key is the same as the way the authentication network element generates the AKMA key.
- the way the authentication network element generates the AKMA key can refer to the way the first device generates the AKMA key, and for the sake of brevity, it will not be repeated.
- the first device may generate an AKMA key based on the second key and the fourth key generation algorithm.
- the fourth key generation algorithm may be the first key generation algorithm or the second key generation algorithm to reduce the computational complexity of the first device.
- the first device may generate an AKMA key based on the second key, the fourth key generation algorithm, and a fifth parameter.
- the fifth parameter may include one or more of the following: AKMA, an identity of the first device.
- K AKMA represents the AKMA key
- Ks represents the first anonymous key
- IDi represents the identity of the first device.
- the second key can be used to generate a key identifier.
- the first device can generate a key identifier based on the second key.
- the key identifier may include, for example, an A-TID and/or an A-KID.
- the A-TID may be generated based on the identity identifier of the first device, the first anonymous key, and a seventh key generation algorithm.
- the seventh key generation algorithm may be the first key generation algorithm or the second key generation algorithm.
- f represents the seventh key generation algorithm
- Ks represents the first anonymous key
- IDi represents the identity of the first device.
- the A-KID may be generated based on the A-TID.
- the A-KID may be generated based on the A-TID and a seventh parameter.
- the seventh parameter may include one or more of the following parameters: a RID and a home network identifier (HNI).
- HNI home network identifier
- the A-KID may be obtained by cascading the A-TID, the RID, and the seventh parameter.
- the authentication network element may send key parameters to the AAnF and/or a key management server (KMS), and the key parameters may include one or more of the following: an AKMA key, an A-KID, and an identifier of the first device.
- KMS key management server
- the AAnF and/or AMF may generate an application key (denoted as K AF ) based on the AKMA key.
- the application key may be generated based on an eighth key generation algorithm and an eighth parameter.
- the eighth parameter may include one or more of the following parameters: AF ID, IDi, an identifier of the proxy node, A-KID.
- the eighth key generation algorithm may be the first key generation algorithm or the second key generation algorithm to reduce the computational complexity of the first device.
- K AF represents an application key
- f represents an eighth key generation algorithm
- AF ID represents an identifier of AF
- IDi represents an identity identifier of the first device
- UE ID represents an identifier of the proxy node.
- the AAnF may generate an application key after receiving an application key request message from the AF.
- the first device generates the application key in the same manner as the AAnF generates the application key, which will not be described here for brevity.
- the first device may generate the application key after sending an application session establishment request message to the AF.
- the application key can be used to generate a third key, and the third key can be used for secure communication between the first device and the proxy node.
- the first device and the proxy node can perform secure communication based on the third key.
- the third key may include an integrity protection key and/or an encryption key. That is, the device and the proxy node may generate an integrity protection key and/or an encryption key based on the application key.
- the method of generating the integrity protection key and/or the encryption key based on the application key may be a method in the related art, and the embodiments of the present application do not specifically limit this.
- the third key may be generated based on the application key and the first key.
- the first key is a shared key between the first device and the proxy node.
- the third key may be generated by the application key and the first key by means of an exclusive OR.
- Ku1 represents the third key
- K AF represents the application key
- N1 represents the first key
- ⁇ represents an exclusive-OR operation.
- the third key (such as Ku1) can be used to further generate an integrity protection key and/or an encryption key.
- the embodiment of the present application can provide a simplified way for mobility management of the first device by first generating a third key and then generating an integrity protection key and/or an encryption key. For example, if the first device moves, causing the connected proxy node to change, the first device can directly generate a third key based on the shared key between the first device and the proxy node, and further generate an integrity protection key and/or an encryption key, so that there is no need to perform the authentication and key negotiation process between the first device and the network side.
- the shared key between the first device and the first proxy node is N1
- the shared key between the first device and the second proxy node is N3.
- the first device can generate a third key based on the application key and N1, and further generate an integrity protection key and/or encryption key for secure communication with the first proxy node.
- the first device and the second proxy node are in a connected state, the first device can generate a third key based on the application key and N3, and further generate an integrity protection key and/or encryption key for secure communication with the second proxy node.
- the first device can skip the authentication and key negotiation process to generate different integrity protection keys and/or encryption keys, but can generate different integrity protection keys and/or encryption keys based on different first keys to securely communicate with different proxy nodes.
- the authentication network element may also send the first random number to the first device so that the first device may generate the second message authentication code based on the first random number.
- the authentication network element may use the first anonymous key to protect the transmission security of the first random number.
- the authentication network element may perform an XOR operation on the first anonymous key and the first random number to obtain the tenth parameter, that is, the tenth parameter may be N2 ⁇ AK.
- the authentication network element may send the tenth parameter to the first device, or the authentication network element may send the eleventh parameter to the first device, and the eleventh parameter may be N2 ⁇ AK
- MAC is the first message authentication code
- N2 is the first random number
- AK is the first anonymous key
- represents cascade.
- the first device After the first device receives the tenth parameter or the eleventh parameter sent by the authentication network element, it can determine the first random number based on the first anonymous key. Then, based on the first random number, it generates a second message authentication code. Further, the first device can authenticate the authentication network element based on the first message authentication code and the second message authentication code.
- the authentication network element may also send the second random number to the first device, so that the first device generates a second message authentication code based on the second random number.
- FIG11 shows the process of authentication between the first device and the authentication network element.
- the first device may share a key K with the authentication network element, and the key K is the security credential described above.
- the first device may share a key N1 with the base station and/or the proxy node, and the key N1 is the first key described above.
- the key N1 may be a physical layer key.
- the first device sends an authentication request to the proxy node.
- the authentication request may include a hidden identity DIDi of the first device.
- the hidden identity DIDi may be generated based on the identity IDi of the first device.
- the proxy node sends an authentication request to the service domain network element.
- the proxy node may send the authentication request to the service domain network element through a base station.
- the service domain network element may include one or more of AMF, SEAF, SMF, and A-NF.
- the authentication request may include the DIDi and the identification of the proxy node.
- the authentication request may include the DIDi and the identification of the proxy node.
- the proxy node may DIDi de-anonymizes and obtains the identity identifier IDi of the first device.
- the authentication request sent by the proxy node may include one or more of the following: IDi, the identifier of the proxy node, and N1.
- the identification of the proxy node may include one or more of GPSI, SUCI, and GUTI.
- the service domain network element sends an authentication request to the authentication network element, and the authentication request may include the name of the service domain network (SN name).
- the authentication request may also include DIDi and the identifier of the proxy node.
- the authentication request may include IDi, N1 and the identifier of the proxy node.
- the authentication request may include an identifier that can indicate the authentication type.
- the authentication type identifier may be indicated by one or more of the following: BSF ID, the identification type of the A-NF, the type of IDi, and the authentication type identifier (Auth_type_ID).
- the authentication network element may confirm the authentication type.
- the authentication network element may query the subscription credentials of the first device and the proxy node through the core network element (such as UDM).
- the core network element may check the subscription credentials of the first device and the proxy node based on IDi and the identity of the proxy node to determine whether the first device is entitled to use the A-IoT service.
- the authentication network element can determine the authentication type based on an identifier that can indicate the authentication type, such as determining whether the authentication type is A-IoT authentication.
- the authentication network element may generate a first message authentication code (referred to as MAC) and a first expected response (referred to as XRES1).
- N2 may be a key shared between the first device and the authentication network element, or N2 may be a random number selected by the authentication network element.
- the parameters introduced in the above-mentioned generation method of MAC and XRES1 include RAND, N1 and N2, but this is only an example and is not specifically limited in the embodiments of the present application.
- the parameters introduced in MAC and XRES1 may only include RAND, or RAND and N1, or RAND and N2.
- MAC and XRES1 are generated in different ways so that the obtained MAC and XRES1 values are different. For example, if the same function f is used when calculating MAC and XRES1, the introduced parameters can be different. For another example, if the same parameters are introduced when calculating MAC and XRES1, different functions f can be used.
- function f may be any function f1-f5 defined by 3GPP.
- function f may be a KDF (such as HMAC-SHA256).
- function f may be other lightweight functions (such as ASCON).
- the authentication network element may generate a second expected response XRES2, where XRES2 is material for the serving domain network to authenticate the first device.
- the authentication network element may generate a third expected response XRES3, where XRES3 is material for the base station to authenticate the first device.
- the authentication network element may generate an authentication vector.
- the authentication vector may include multiple parameters generated and/or selected by the authentication network element.
- the authentication vector may include one or more of the following: RAND, N2, AK, MAC, XRES1, XRES2, and XRES3. If N2 is selected by the authentication network element, the authentication vector may include N2; if N2 is shared between the first device and the authentication network element, the authentication vector may not include N2.
- the authentication network element sends an authentication response to the serving domain network element.
- the authentication response includes an authentication vector AV.
- the authentication response may also include IDi.
- the serving domain network element sends an authentication request (or authentication response) to the base station.
- the authentication request includes an authentication vector.
- the authentication vector may not include XRES2.
- the authentication response may also include IDi.
- step S1116 if the authentication vector includes XRES3, the base station stores XRES3; if the authentication vector does not include XRES3, the base station may generate XRES3 based on XRES1.
- the base station sends an authentication request to the first device through the proxy node.
- the authentication request may include RAND and MAC.
- the authentication request may include RAND and N2 ⁇ AK
- the first device may verify the MAC. After the verification is successful, the first device may calculate the first response parameter RES1, the second response parameter RES2, and the third response parameter RES3. In addition, the first device may also generate a key Ks.
- step S1122 the first device sends an authentication response to the base station through the proxy node.
- the authentication response includes RES1, RES2 and RES3.
- step S1124 the base station compares RES3 and XRES3 to authenticate the first device. If RES3 and XRES3 are consistent, the first device is successfully authenticated. From the perspective of the access network, the base station considers that the first device is successfully authenticated.
- step S1126 after the first device is successfully authenticated, the base station sends an authentication response to the serving domain network element, which includes RES2 and RES1.
- the service domain network element can obtain RES2 from the authentication response.
- the service domain network element compares RES2 and XRES2 to authenticate the first device. After the authentication is successful, the service domain network element considers that the first device is successfully authenticated from the perspective of the service domain network.
- step S1130 the serving domain network element sends an authentication request (or authentication response) to the authentication network element, and the authentication request includes RES1.
- the authentication network element may also generate a key Ks.
- step S1134 the authentication network element sends a response message to the proxy node or the authentication network element sends a response message to the serving domain network element.
- the authentication network element may send a response message to the proxy node via the serving domain network element and the base station.
- the authentication response may include a key Ks.
- the key Ks may be used by the proxy node to generate an integrity protection key and/or an encryption key.
- FIG. 12 shows the process of generating an AKMA key after the initial authentication (or lightweight initial authentication) is completed.
- step S1202 the authentication network element generates a key Ks, an A-KID and an AKMA key.
- the first device generates a key Ks, an A-KID and an AKMA key.
- the authentication network element may generate an A-TID based on a key Ks.
- the A-TID may be generated based on Ks and IDi.
- the authentication network element may generate an A-KID based on the A-TID.
- the A-KID may be generated based on the A-TID, the RID, and the HNI.
- the authentication network element may generate an AKMA key (denoted as K AKMA ).
- K AKMA AKMA key
- the AKMA key may be generated based on Ks, in which case the role of Ks is the same as that of K AUSF in the related art.
- the AKMA key may be generated based on Ks, IDi, and AKMA.
- the authentication network element may send a registration request to AAnF or KMS, and the registration request may include one or more of the following information: AKMA key, A-KID and the identifier IDi of the first device.
- the registration request may be, for example, an AKMA anchor key registration request (such as Naanf_AKMA_AnchorKey_Register Request).
- the first device may generate a key Ks, an A-KID, and an AKMA key.
- the first device generates an A-KID in a manner similar to the manner in which the authentication network element generates an A-KID, and the first device generates an AKMA key in a manner similar to the manner in which the authentication network element generates an AKMA key, which will not be described here for brevity.
- FIG. 13 shows the process of generating an application key.
- the first device sends an application session establishment request to the AF.
- the application session establishment request may include the A-KID.
- the application session establishment request may also be other communication requests.
- the application session establishment request may include UE ID and DIDi.
- UE ID may be, for example, GPSI.
- UE ID is the identifier of the proxy node.
- step S1304 after receiving the application session establishment request, the AF sends an application key request to the AAnF or KMS.
- the application key request may include the A-KID.
- the application key request may also include the UE ID and the DIDi.
- the application key K AF may be generated based on Ks, AF ID, IDi, UE ID and A-KID.
- the AAnF or the KMS may store the K AF and the validity period of the K AF to facilitate mobility management of the first device.
- step S1310 the AF sends an application key response to the proxy node, wherein the application key response includes K AF and the validity period of K AF .
- the proxy node In step S1312, the proxy node generates a key Ku1.
- the key Ku1 may be generated based on K AF .
- Ku1 may be generated based on K AF and N1.
- step S1314 the proxy node sends an application session establishment response to the first device.
- step S1316 the first device generates an application key K AF and a key Ku1.
- the first device generates K AF in a similar manner to AAnF or KMS.
- the first device generates key Ku1 in a similar manner to the proxy node, which is not described here for brevity.
- the first device may send a response message to the proxy node.
- the key Ku1 can be used to generate an integrity protection key and/or an encryption key, which can be used to ensure secure communication between the first device and the proxy node.
- the first device uses another device (such as UEx) as a proxy node, the shared key Nx between the first device and UEx, and K AF , can be used to generate a subordinate key Kux.
- the Kux can be used to further generate an integrity protection key and/or an encryption key. In this way, when the proxy node changes, the first device does not necessarily need to perform the authentication and key negotiation process of the first device, thereby reducing the complexity of the first device.
- the security credential is a 3GPP security credential
- the first device does not need to communicate with the network side through a proxy node, that is, the first device can communicate directly with the network side.
- Example 2 The difference between Example 2 and Example 1 is: 1. There is no proxy node involved, and 2.
- the authentication information does not include the proxy node information (such as the proxy node identifier or UE ID).
- Example 2 is basically similar to the solution of Example 1. For the contents not described in detail in Example 2, please refer to the description of Example 1.
- FIG 14 is a flow chart of an authentication method provided by an embodiment of the present application.
- the authentication network element in step S1410, the authentication network element generates a first message authentication code and/or an expected response.
- the generation method of the first message authentication code and the expected response can refer to the description of Example 1.
- the authentication network element sends a first authentication request to the access network device.
- the first authentication request may include a first message authentication code.
- the authentication network element sends the first authentication request to the access network device, which may refer to the authentication network element directly sending the first authentication request to the access network device, or may refer to the authentication network element sending the first authentication request to the access network device through other devices.
- the other devices may include, for example, service domain network elements.
- the service domain network elements may include, for example, AMF and/or SMF.
- step S1430 the access network device sends a first authentication request to the first device.
- step S1440 the first device generates a second message authentication code based on the first key generation algorithm and the second parameter.
- step S1450 the first device authenticates the network element based on the first message authentication code and the second message authentication code.
- step S1460 when the authentication network element is successfully authenticated, the first device generates a response parameter.
- step S1470 the first device sends a first authentication response to the access network device, wherein the first authentication response includes a response parameter.
- step S1480 the access network device sends a first authentication response to the authentication network element.
- the first authentication response includes a response parameter.
- the access network device may send a response parameter to the authentication network element. After receiving the response parameter, the authentication network element may compare the response parameter with an expected response to authenticate the first device.
- the first device before receiving the first authentication request from the access network device, may send a second authentication request to the access network device.
- the first device may trigger an authentication process between the first device and the network side by sending the second authentication request.
- the second authentication request may include a hidden identity of the first device.
- the first device may perform anonymization on the identity of the first device to obtain a hidden identity.
- the access network device may send the second authentication request to the authentication network element.
- the second authentication request sent by the access network device may include one or more of the following information: the first key, the identity of the first device, and the hidden identity.
- the access network device may adopt different processing strategies according to different first keys.
- the first key is a shared key between the first device and the network side
- the second authentication request sent by the access network device may include a hidden identity.
- the access network device can determine the identity of the first device by the following formula:
- DIDi represents a hidden identity
- IDi represents an identity of a first device
- N1 represents a first key
- ⁇ represents an exclusive-OR operation
- DIDi represents a hidden identity
- IDi represents an identity of a first device
- N1 represents a first key
- f represents a third key generation algorithm
- the second authentication request sent by the first device may include one or more of the following: the first key and the identity of the first device.
- a second key Ks can be generated.
- the second key can also be understood as a shared key between the first device and the authentication network element.
- the second key can be generated based on a sixth key generation algorithm and a sixth parameter.
- the sixth key generation algorithm can be a first key generation algorithm or a second key generation algorithm to reduce the computational complexity of the first device.
- the sixth parameter may include one or more of the following parameters: a first anonymous key, a first key, a first random number, an identifier of the first device, and a name of the service domain network.
- FIG15 shows the process of authentication between the first device and the authentication network element.
- the first device can share a key K with the authentication network element, and the key K is the security credential described above.
- the first device can share a key N1 with the base station, and the key N1 is the first key described above.
- the key N1 can be a physical layer key.
- FIG. 15 The method shown in FIG. 15 is substantially similar to the solution shown in FIG. 11 .
- the first device sends an authentication request to the base station.
- the authentication request may include a hidden identity DIDi of the first device.
- the hidden identity DIDi may be generated based on the identity IDi of the first device.
- step S1504 the base station sends an authentication request to the serving domain network element.
- the authentication request may include DIDi.
- N1 is a shared key between the first device and the authentication network element
- the authentication request may include DIDi.
- the base station may de-anonymize DIDi based on N1 to obtain the identity IDi of the first device.
- the authentication request sent by the base station may include one or more of the following: IDi and N1.
- the service domain network element sends an authentication request to the authentication network element, and the authentication request may include the name of the service domain network (SN name).
- the authentication request may also include DIDi, or the authentication request may include IDi and N1.
- the authentication network element may confirm the authentication type.
- the authentication network element may de-anonymize DIDi to obtain IDi.
- the authentication network element may generate a first anonymous key AK, a first message authentication code, a first expected response, a second expected response, and a third expected response.
- the authentication network element may generate an authentication vector.
- the authentication vector may include multiple parameters generated and/or selected by the authentication network element.
- the authentication vector may include one or more of the following: RAND, N2, AK, MAC, XRES1, XRES2, and XRES3. If N2 is selected by the authentication network element, the authentication vector may include N2; if N2 is shared between the first device and the authentication network element, the authentication vector may not include N2.
- XRES3. In other embodiments, the authentication vector may be AV RAND
- the authentication vector may also include one or more of the following parameters: IDi, UE ID, SN name.
- step S1510 the authentication network element sends an authentication response to the serving domain network element, wherein the authentication response includes an authentication vector AV.
- the serving domain network element may store XRES2 in the authentication vector.
- the serving domain network element sends an authentication request (or authentication response) to the base station.
- the authentication request includes an authentication vector.
- the authentication vector may not include XRES2.
- step S1516 if the authentication vector includes XRES3, the base station stores XRES3; if the authentication vector does not include XRES3, the base station may generate XRES3 based on XRES1.
- the base station sends an authentication request to the first device.
- the authentication request may include RAND and MAC.
- the authentication request may include RAND and N2 ⁇ AK
- the first device can verify the MAC. After the verification is successful, the first device can calculate the first response parameter RES1, the second response parameter RES2 and the third response parameter RES3. In addition, the first device can also generate a key Ks.
- step S1522 the first device sends an authentication response to the base station, which includes RES1, RES2 and RES3.
- step S1524 the base station compares RES3 and XRES3 to authenticate the first device. If RES3 and XRES3 are consistent, the first device is successfully authenticated. From the perspective of the access network, the base station considers that the first device is successfully authenticated.
- step S1526 after the first device is successfully authenticated, the base station sends an authentication response to the serving domain network element, which includes RES2 and RES1.
- the service domain network element can obtain RES2 from the authentication response.
- the service domain network element compares RES2 and XRES2 to authenticate the first device. After the authentication is successful, the service domain network element considers that the first device is successfully authenticated from the perspective of the service domain network.
- step S1530 the serving domain network element sends an authentication request (or authentication response) to the authentication network element, and the authentication request includes RES1.
- step S1532 the authentication network element compares RES1 and XRES1 to authenticate the first device. After the authentication is successful, the authentication network element considers that the first device is successfully authenticated from the perspective of the home domain network.
- the authentication network element may also generate a key Ks.
- the authentication network element may send a response message to the serving domain network element.
- the authentication network element and the first device may generate an AKMA key according to the method shown in Figure 12.
- the authentication network element may send a registration request to AAnF or KMS, and the registration request may include one or more of the following information: AKMA key, A-KID and the identification IDi of the first device.
- FIG. 16 shows the process of generating an application key.
- the first device sends an application session establishment request to the AF.
- the application session establishment request may include an A-KID.
- the application session establishment request may also be other communication requests.
- the application session establishment request may include a DIDi.
- step S1604 after receiving the application session establishment request, the AF sends an application key request to the AAnF or KMS.
- the application key request may include the A-KID. In some embodiments, the application key request may also include the DIDi.
- step S1606 after receiving the application key request, the AAnF or KMS may generate an application key based on the A-KID.
- the application key K AF may be generated based on Ks, AF ID, IDi and A-KID.
- step S1608 the AAnF or KMS sends an application key response to the AF, which includes K AF and the validity period of K AF .
- the AAnF or the KMS may store the K AF and the validity period of the K AF to facilitate mobility management of the first device.
- step S1610 the AF sends an application session establishment response to the first device.
- the first device and the AF may establish a secure connection (eg, a TLS connection) based on the K AF .
- a secure connection eg, a TLS connection
- the security credential is a non-3GPP security credential, such as the security credential is a shared key between the first device and the application function network element, and the first device communicates with the network side through the proxy node.
- FIG 17 is a flowchart of an authentication method provided by an embodiment of the present application.
- the first device sends an authentication request to the application function network element.
- the first device may send the authentication request to the application function network element through a proxy node.
- the authentication request may include one or more of the following information: a hidden identity of the first device, an identity of the first device, an identity of the proxy node, and a first key.
- the authentication request may include a hidden identity of the first device and an identity of the proxy node.
- the authentication request may include an identity of the first device, an identity of the proxy node, and a first key.
- the application function network element performs an authorization check on the first device and/or the proxy node. For example, the application function network element may check whether the first device is authorized to use a certain service (such as an A-IoT service). For another example, the application function network element may check whether the proxy node is authorized to provide a service (such as an A-IoT service) as a proxy for the first device.
- a certain service such as an A-IoT service
- the application function network element may check whether the proxy node is authorized to provide a service (such as an A-IoT service) as a proxy for the first device.
- the application function network element may manage a mapping between a whitelist of the first device and the proxy node.
- the application function network element When the application function network element performs an authorization check on the first device, it can perform an authorization check on the first device based on the identity identifier IDi of the first device. When the application function network element performs an authorization check on the proxy node, it can perform an authorization check on the proxy node based on the identifier of the proxy node (such as UE ID).
- the identity identifier of the first device and the identifier of the proxy node may be sent by the proxy node to the application function network element.
- the first device may send an authentication request to the proxy node, and the authentication request may include the hidden identity DIDi of the first device.
- the proxy node may de-anonymize the hidden identity DIDi to obtain the identity of the first device.
- the proxy node may send an authentication request to the application function network element, and the authentication request may include the identity identifier IDi of the first device and the proxy node. To ensure information security, the proxy node can send an authentication request through the NAS security context or the AS security context.
- step S1730 when the authorization check of the first device and/or the proxy node succeeds, the application function network element sends an authentication request to the authentication network element.
- the application function network element may not send an authentication request to the authentication network element, that is, the subsequent authentication and key negotiation process may not be performed.
- the application function network element can first perform an authorization check on the first device and the proxy node, and only perform the subsequent authentication and key negotiation process when the authorization check is successful, which is conducive to reducing the computational complexity of the first device. For example, if the authorization check is performed after the authentication and key negotiation process is completed, the authorization check fails, which will make the authentication and key negotiation process of the first device invalid, thereby causing a waste of resources and not conducive to reducing the computational complexity of the first device.
- the hidden identity may be generated based on the first key N1.
- the first key may be a shared key between the first device and the application function network element, or the first key may be a shared key (such as a physical layer key) between the first device and the proxy node.
- the proxy node can de-anonymize the hidden identity based on the first key to obtain the identity of the first device. If the first key is a shared key between the first device and the application function network element, the application function network element can de-anonymize the hidden identity to obtain the identity of the first device.
- the authentication request sent by the proxy node to the application function network element may include the identity of the first device, the identity of the proxy node, and the first key. If the first key is a shared key between the first device and the application function network element, the authentication request sent by the proxy node to the application function network element may include the hidden identity of the first device and the identity of the proxy node.
- the application function network element may send the security credential K to the authentication network element, or the application function network element may send the subordinate key (denoted as Kb) of the security credential K to the authentication network element.
- the subordinate key is a key generated based on the security credential K.
- the authentication network element may determine the security credential K based on the subordinate key.
- the subordinate key may be generated based on one or more of the security credential K, the first key (denoted as N1), and the first random number (denoted as N2).
- N2 may be a shared key between the first device and the AF, or, N2 may be a random number selected by the AF.
- the authentication network element may generate the parameters required in the authentication process based on the security credential K.
- the parameters may be, for example, parameters contained in the authentication vector.
- the parameters may include, for example, one or more of the following: a first anonymous key, a first message authentication code, an expected response, a key Ks, etc.
- the key Ks is a shared key generated after the first device and the authentication network element are successfully authenticated.
- the first anonymous key may be generated based on the security credential K and a target parameter.
- the target parameter may include RAND and/or N1.
- the first message authentication code may be generated based on the security credential K and a target parameter.
- the target parameter may include one or more of the following: RAND, N1, and N2.
- the target parameter includes RAND.
- the target parameter includes RAND and N1.
- the target parameter includes RAND and N2.
- the target parameter includes RAND, N1, and N2.
- the expected response may be generated based on the security credentials K and target parameters.
- the target parameters may include one or more of the following: RAND, N1, and N2.
- the target parameters include RAND.
- the target parameters include RAND and N1.
- the target parameters include RAND and N2.
- the target parameters include RAND, N1, and N2.
- the key Ks may be generated based on the security credential K and the target parameters.
- the target parameters may include one or more of the following: AK, N1, N2, IDi, UE ID, AF ID, HNI, SN name.
- the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, HNI.
- the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, SN name.
- the authentication network element can generate the parameters required in the authentication process based on the key Kb.
- the parameters can be, for example, parameters included in the authentication vector.
- the parameters can include, for example, one or more of the following: a first message authentication code, an expected response, a key Ks, etc.
- the first message authentication code may be generated based on the key Kb and the target parameter.
- the target parameter may include one or more of the following: RAND, N1, and N2.
- the target parameter includes RAND.
- the target parameter includes RAND and N1.
- the target The parameters include RAND and N2.
- the target parameters include RAND, N1 and N2.
- the expected response may be generated based on the security credentials K and target parameters.
- the target parameters may include one or more of the following: RAND, N1, and N2.
- the target parameters include RAND.
- the target parameters include RAND and N1.
- the target parameters include RAND and N2.
- the target parameters include RAND, N1, and N2.
- the key Ks may be generated based on the security credential K and the target parameters.
- the target parameters may include one or more of the following: AK, N1, N2, IDi, UE ID, AF ID, HNI, SN name.
- the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, HNI.
- the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, SN name.
- the first device may generate one or more of the following parameters in the same manner as the authentication network element: a first anonymous key, a second message authentication code, a response parameter, a key Ks, etc.
- the second message authentication code is generated in the same manner as the first message authentication code.
- the response parameter is generated in the same manner as the expected response.
- the above-mentioned expected response may include a first expected response, a second expected response, and a third expected response.
- the first expected response may be generated in the above-mentioned expected response.
- the second expected response and the third expected response may be generated based on the first expected response, and the specific generation method may refer to the description in other examples.
- the above response parameters may include a first response parameter, a second response parameter, and a third response parameter.
- the first response parameter may be generated in the manner described above.
- the second response parameter and the third response parameter may be generated based on the first response parameter, and the specific generation method may refer to the description in other examples.
- the f in the above formula may be the same key generation algorithm, or the f in the above formula may include a first key generation algorithm and a second key generation algorithm.
- the first key generation algorithm is used to generate a first message authentication code or a second message authentication code
- the second key generation algorithm is used to generate an expected response or a response parameter.
- the first device and the authentication network element may generate one or more of A-TID, A-KID and AKMA key based on Ks.
- A-TID A-TID
- A-KID A-KID
- AKMA key a key that is generated by the first device and the authentication network element.
- the application function network element can directly receive the application key sent by AAnF. For example, after generating the application key, AAnF can directly send the application key to AF without the need for AF to send an application key request to trigger it.
- the AF may send the application key to the proxy node.
- the application key may be used by the proxy node to generate a third key (such as Ku1).
- the first device may share a key K with the AF.
- the first device sends an authentication request to the proxy node.
- the authentication request includes the hidden identity DIDi of the first device.
- the hidden identity DIDi can be generated based on the identity IDi of the first device.
- DIDi IDi ⁇ N1.
- step S1804 the proxy node sends an authentication request to the AF.
- the authentication request may include the DIDi and the identification of the proxy node.
- the authentication request may include the DIDi and the identification of the proxy node.
- the proxy node can de-anonymize DIDi based on N1 to obtain the identity IDi of the first device.
- the authentication request sent by the proxy node may include one or more of the following: IDi, the identity of the proxy node, and N1.
- the proxy node may send an authentication request via a NAS message.
- the proxy node may send an authentication request via a NAS security context.
- step S1806 AF may perform authorization management.
- the AF can de-anonymize the first device according to N1 to obtain the identity IDi of the first device.
- the AF may check whether the first device is authorized. In some embodiments, the AF may check whether the proxy node is authorized to provide services (such as A-IoT services) for the first device. In some embodiments, the AF may also check the mapping relationship between the first device and the proxy node. The AF may manage the mapping between the whitelist of the first device and the proxy node list.
- the AF may directly perform an authorization check and manage the mapping between the first device and the proxy node.
- the authentication request may include one or more of the following: K, K
- N1 may be a shared key between the first device and the proxy node, or N1 may be a shared key between the first device and the AF.
- N2 may be a shared key between the first device and the AF, or N2 may be a random number selected by the AF.
- the authentication request may include one or more of the following: Kb, Kb
- the authentication request may include Kb
- the authentication request may include an identifier that can indicate the authentication type.
- the authentication type identifier can be indicated by one or more of the following: AF ID, type of IDi, authentication type identifier (Auth_type_ID).
- step S1810 the first device performs authentication (such as AKA authentication) with the authentication network element.
- authentication such as AKA authentication
- the authentication method can refer to the above description, such as the description of FIG. 11 above.
- the proxy node may forward the authentication message between the first device and the authentication network element.
- the authentication network element may query the subscription credentials of the first device and the proxy node through the core network element (such as UDM).
- the core network element may check the subscription credentials of the first device and the proxy node based on IDi and the identity of the proxy node to determine whether the first device is entitled to use the A-IoT service.
- the authentication network element generates an authentication vector.
- the authentication network element may select a random number RAND, which may be used to generate the authentication vector.
- the authentication network element can generate authentication parameters based on K and RAND.
- the authentication parameters include one or more of the following: a first anonymous key AK, a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
- the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
- the authentication network element can generate authentication parameters based on Kb and RAND.
- the authentication parameters include one or more of the following: a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
- the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
- the first device may calculate the second message authentication code and compare the first message authentication code with the second message authentication code to authenticate the network element. After successful authentication, the first device may generate a key Ks.
- the first device may generate an A-TID.
- the first device may generate a response parameter RES, and the calculation method of RES is the same as the calculation method of XRES.
- the first device may send an authentication response to the authentication network element through the proxy node, and the authentication response may include a response parameter RES.
- the authentication network element may compare RES and XRES to authenticate the first device. If RES and XRES are consistent, the first device authentication is successful; if RES and XRES are inconsistent, the first device authentication fails. After the first device is successfully authenticated, the authentication network element may generate one or more of the following parameters: Ks, A-TID, A-KID, and AKMA key. The authentication network element generates these parameters in the same way as the first device generates the corresponding parameters.
- the authentication network element provides key material to the AAnF, where the key material may include an AKMA key and an A-KID.
- step S1814 the AAnF generates an application key K AF based on the AKMA key.
- the AAnF sends a response message to the AF and/or the proxy node.
- the message may be a successful response message.
- the response message may include the application key and/or the validity period of the application key.
- the response message may also include a newly selected first key (or random number), and the new first key may be used to update the hidden identity.
- step S1818 the proxy node generates a key Ku1.
- step S1820 the first device generates a key Ku1.
- the key Ku1 can be generated based on the application key.
- the specific generation method can refer to the above description.
- the proxy node may send a response message to the first device.
- the response message includes one or more of the following information: A-KID, validity period of the application key, newly selected first key, message integrity check (MIC).
- the response message may be protected by a key, such as integrity protection and/or encryption protection.
- the key may include one or more of the following: K AF , Ku1, a subordinate key derived from K AF , and a subordinate key derived from Ku1.
- the shared key N1 between the first device and the proxy node can be used for mobility management.
- the first device and the proxy node can generate a key Ku1 based on N1 and K AF , and then generate an integrity protection key and/or an encryption key based on Ku1.
- the first device uses another device (such as UEx) as a proxy node
- the shared key Nx between the first device and UEx, and K AF can be used to generate a subordinate key Kux.
- the Kux can be used to further generate an integrity protection key and/or an encryption key. In this way, when the proxy node changes, the first device does not necessarily need to perform the authentication and key negotiation process of the first device, thereby reducing the complexity of the first device.
- the authentication network element may also generate XRES1, XRES2 and XRES3 in the manner described above, and the first device may generate RES1, RES2 and RES3 in the manner described above.
- the security credential is a non-3GPP security credential, such as the security credential is a shared key between the first device and the application function network element, and the first device communicates directly with the network side.
- Fig. 19 is a flow chart of an authentication method provided by an embodiment of the present application. Referring to Fig. 19, in step S1910, the first device sends an authentication request to the application function network element.
- the authentication request may include one or more of the following information: a hidden identity of the first device, an identity of the first device, and a first key. In some embodiments, the authentication request may include a hidden identity of the first device. In other embodiments, the authentication request may include an identity of the first device and a first key.
- the hidden identity may be generated based on the first key N1.
- the first key may be a shared key between the first device and the application function network element.
- step S1920 the application function network element performs an authorization check on the first device.
- the application function network element may check whether the first device is authorized to use a certain service (such as an A-IoT service).
- the application function network element may manage a whitelist of the first device.
- the application function network element When the application function network element performs an authorization check on the first device, it may perform an authorization check on the first device based on the identity identifier IDi of the first device.
- the authentication request may include a hidden identity identifier DIDi of the first device.
- the application function network element may de-anonymize the hidden identity identifier DIDi to obtain the identity identifier of the first device.
- the application function network element may use the first key N1 to de-anonymize the hidden identity identifier DIDi to obtain the identity identifier of the first device.
- step S1930 when the first device authorization check succeeds, the application function network element sends an authentication request to the authentication network element.
- the application function network element may not send an authentication request to the authentication network element, that is, the subsequent authentication and key negotiation process may not be performed.
- the application function network element can first perform an authorization check on the first device, and only perform the subsequent authentication and key negotiation process when the authorization check is successful, which is conducive to reducing the computational complexity of the first device. For example, if the authorization check is performed after the authentication and key negotiation process is completed, the authorization check fails, which will invalidate the authentication and key negotiation process of the first device, thereby causing a waste of resources and not being conducive to reducing the computational complexity of the first device.
- the application function network element may send the security credential K to the authentication network element, or the application function network element may send the subordinate key (denoted as Kb) of the security credential K to the authentication network element.
- the subordinate key is a key generated based on the security credential K.
- the authentication network element may determine the security credential K based on the subordinate key.
- the subordinate key may be generated based on one or more of the security credential K, the first key (denoted as N1), and the first random number (denoted as N2).
- N2 may be a shared key between the first device and the AF, or, N2 may be a random number selected by the AF.
- the authentication network element can generate the parameters required in the authentication process based on the security credential K.
- the parameter can be, for example, a parameter contained in an authentication vector.
- the parameter can include, for example, one or more of the following: a first anonymous key, a first message authentication code, an expected response, a key Ks, etc.
- the key Ks is a shared key generated after the first device and the authentication network element are successfully authenticated. The specific generation method of these parameters can be found in the description of Example 3, and for the sake of brevity, it will not be repeated here.
- the authentication network element can generate the parameters required in the authentication process based on the key Kb.
- the parameters can be, for example, parameters contained in the authentication vector.
- the parameters can include, for example, one or more of the following: a first message authentication code, an expected response, a key Ks, etc.
- the specific generation method of these parameters can refer to the description of Example 3, and for the sake of brevity, they will not be repeated here.
- the first device may generate one or more of the following parameters in the same manner as the authentication network element: a first anonymous key, a second message authentication code, a response parameter, a key Ks, etc.
- the second message authentication code is generated in the same manner as the first message authentication code.
- the response parameter is generated in the same manner as the expected response.
- the above-mentioned expected response may include a first expected response, a second expected response, and a third expected response.
- the first expected response may be generated in the above-mentioned expected response.
- the second expected response and the third expected response may be generated based on the first expected response, and the specific generation method may refer to the description in other examples.
- the above response parameters may include a first response parameter, a second response parameter, and a third response parameter.
- the first response parameter may be generated in the manner described above.
- the second response parameter and the third response parameter may be generated based on the first response parameter, and the specific generation method may refer to the description in other examples.
- the f in the above formula may be the same key generation algorithm, or the f in the above formula may include a first key generation algorithm and a second key generation algorithm.
- the first key generation algorithm is used to generate a first message authentication code or a second message authentication code
- the second key generation algorithm is used to generate an expected response or a response parameter.
- the first device and the authentication network element may generate one or more of A-TID, A-KID and AKMA key based on Ks.
- A-TID A-TID
- A-KID A-KID
- AKMA key a key that is generated by the first device and the authentication network element.
- the application function network element can directly receive the application key sent by AAnF. For example, after generating the application key, AAnF can directly send the application key to AF without the need for AF to send an application key request to trigger it.
- the AF may send the application key to the proxy node.
- the application key may be used by the proxy node to generate a third key (such as Ku1).
- the first device can share a key K with the AF.
- the first device sends an authentication request to the AF.
- the authentication request includes the hidden identity DIDi of the first device.
- the hidden identity DIDi can be generated based on the identity IDi of the first device.
- step S2004 AF may perform authorization management.
- the AF can de-anonymize the first device according to N1 to obtain the identity IDi of the first device.
- the AF can check whether the first device is authorized. In some embodiments, the AF can also manage the first device Whitelist.
- the AF sends an authentication request to the authentication network element.
- the authentication request may include the security credential K or a subordinate key Kb derived from the security credential K.
- the authentication request may also include the AF ID and IDi.
- the authentication request may include one or more of the following: Kb, Kb
- the authentication request may include Kb
- the authentication request may include an identifier that can indicate the authentication type.
- the authentication type identifier can be indicated by one or more of the following: AF ID, type of IDi, authentication type identifier (Auth_type_ID).
- step S2008 the first device performs authentication (such as AKA authentication) with the authentication network element.
- authentication such as AKA authentication
- the authentication method can refer to the above description, such as the description of FIG. 11 above.
- the authentication network element may query the subscription credentials of the first device and the proxy node through the core network element (such as UDM).
- the core network element may check the subscription credentials of the first device and the proxy node based on IDi and the identity of the proxy node to determine whether the first device is entitled to use the A-IoT service.
- the authentication network element generates an authentication vector.
- the authentication network element may select a random number RAND, which may be used to generate the authentication vector.
- the authentication network element can generate authentication parameters based on K and RAND.
- the authentication parameters include one or more of the following: a first anonymous key AK, a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
- the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
- the authentication network element can generate authentication parameters based on Kb and RAND.
- the authentication parameters include one or more of the following: a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
- the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
- the authentication network element may send an authentication response to the first device through the proxy node.
- the authentication response may include RAND and the first message authentication code.
- the authentication response may also include AK ⁇ N2 or Kb ⁇ N2, where AK and Kb are used to protect N2 to ensure that N2 is transmitted securely.
- the authentication response may include AF ID and IDi.
- the first device may calculate the second message authentication code and compare the first message authentication code with the second message authentication code to authenticate the network element. After successful authentication, the first device may generate a key Ks.
- the first device may generate an A-TID.
- the first device may generate a response parameter RES, and the calculation method of RES is the same as the calculation method of XRES.
- the first device may send an authentication response to the authentication network element through the proxy node, and the authentication response may include a response parameter RES.
- the authentication network element may compare RES and XRES to authenticate the first device. If RES and XRES are consistent, the first device is successfully authenticated; if RES and XRES are inconsistent, the first device fails to be authenticated. After the first device is successfully authenticated, the authentication network element may generate one of the following parameters: or more: Ks, A-TID, A-KID and AKMA key. The authentication network element generates these parameters in the same way as the first device generates the corresponding parameters.
- step S2010 the authentication network element provides key material to the AAnF, where the key material may include an AKMA key and an A-KID.
- step S2012 the AAnF generates an application key K AF based on the AKMA key.
- the first device generates an application key K AF based on the AKMA key.
- AAnF sends a response message to AF.
- the response message may be a success response message.
- the response message includes the application key and/or the validity period of the application key.
- the response message may also include a newly selected first key (or random number), and the new first key may be used to update the hidden identity.
- step S2016 AF sends a response message to the first device.
- the response message includes one or more of the following information: A-KID, validity period of the application key, newly selected first key, message integrity check (MIC).
- the response message can be protected by a key, such as integrity protection and/or encryption protection.
- the key can include one or more of the following: K AF , Ku1, a subordinate key derived from K AF , and a subordinate key derived from Ku1.
- the authentication network element may send Ks to the proxy node so that the proxy node protects the information transmitted in the air interface based on Ks.
- the proxy node may generate an integrity protection key and/or an encryption key based on Ks, and the integrity protection key and/or the encryption key are used for secure communication between the first device and the proxy node.
- the authentication network element may send Ks to the AF, and the AF and the first device may establish a secure connection (such as a transport layer security (TLS) connection) based on Ks to protect information transmitted in the air interface.
- a secure connection such as a transport layer security (TLS) connection
- the first device before triggering authentication and key negotiation between the first device and the network side, can perform mutual authentication with the proxy node to prevent a malicious first device from using the proxy node to launch a distributed denial of service (DDOS) attack on the network, affecting network quality, or a malicious proxy node from launching a man-in-the-middle attack to steal communication data between the first device and the network or a third-party application, or the authentication signaling of the first device is carried on a malicious proxy node, resulting in failure of successful authentication and key negotiation.
- DDOS distributed denial of service
- the authentication method between the first device and the proxy node may include one or more of the following: pairing, activation of the first device by the proxy node, physical unclonable function (PUF) and physical layer authentication.
- PAF physical unclonable function
- the proxy node can use its own security context to protect the authentication message of the first device. For example, after receiving the authentication request or response message of the first device, the proxy node can transmit the authentication container (such as Tag_authentication_container) of the first device using the NAS security context or AS security context of the first device to interact with the network side.
- the authentication container such as Tag_authentication_container
- the information transmission between the AF and the authentication network element mentioned above can be realized through the network exposure function (NEF).
- the NEF can forward the transmission message between the AF and the authentication network element.
- the security credentials mentioned above may also be referred to as keys or root keys, etc.
- the key Ks can be directly used to protect the secure transmission between the first device and the proxy node.
- the key Ks is equivalent to the function of the key K AF .
- the authentication network element can send the key Ks to the proxy node, and the proxy node can generate an integrity protection key and/or an encryption key based on the key Ks.
- the first device can also generate an integrity protection key and/or an encryption key based on the key Ks.
- the key Ks may be used to generate a NAS security context and/or an AS security context.
- the authentication network element may generate KAMF based on Ks and provide KAMF to AMF. In this case, Ks is equivalent to the function of KAUSF .
- AMF may generate a NAS security context based on KAMF .
- the authentication network element may provide Ks to AMF, in which case Ks is equivalent to the function of KAMF .
- AMF may generate a NAS security context based on Ks.
- the NAS security context may include, for example, Knas-int and Knas-enc.
- the authentication network element may generate Kgnb based on Ks and provide Kgnb to the base station. In this case, Ks is equivalent to the function of K AUSF .
- the base station may generate an AS security context based on Kgnb.
- the authentication network element may provide Ks to the base station, in which case Ks is equivalent to the function of Kgnb.
- the base station may generate an AS security context based on Ks.
- the relay mode of the proxy node may include L2 relay and L3 relay. That is, when the proxy node is used for relay communication, the protocol stack used by the relay may belong to the L2 layer or the L3 layer.
- L2 relay there is a separate context between the first device and the core network. There is a hop-by-hop and end-to-end secure connection between the first device and the network.
- L3 relay the first device only needs to implement a secure connection with the proxy node.
- the security context may include a security context between the first device and the proxy node.
- the security context includes a security context between the first device and the proxy node, a NAS security context, and an AS security context.
- the function f in the above formula can be any function among f1-f5 defined by 3GPP.
- the function f can be KDF (such as HMAC-SHA256).
- the function f can be other lightweight functions (such as ASCON).
- the home domain network element or authentication network element mentioned above may include one or more of the following network elements: UDM, AUSF, KMS, ARPF.
- the service domain network element mentioned above may include one or more of the following: AMF, SMF, SEAF, and A-NF, a core network element specific to A-IoT services.
- the identification of the proxy node can be represented by UE ID.
- the first key N1 mentioned above has three uses: first, it can be used to protect the identity of the first device; second, it can be used to calculate the authentication vector and the shared key Ks; third, it can be used for mobility management, that is, to generate Ku1.
- the embodiment of the present application does not limit the generation of the generated key, which can be of any length.
- the key generation process may introduce values such as number FC and parameter length, and the embodiment of the present application does not specifically limit the size of these values.
- FIG21 is a schematic block diagram of a first device provided in an embodiment of the present application.
- the first device 2100 shown in FIG21 may be any of the first devices described above.
- the first device 2100 may include a receiving unit 2110, a generating unit 2120, an authenticating unit 2130, and a sending unit 2140. These units are described in detail below.
- the receiving unit 2110 is configured to receive a first authentication request from a proxy node, where the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element.
- the generating unit 2120 is configured to generate a second message authentication code based on the first key generation algorithm and the first parameter.
- the generating unit 2120 is further configured to, when the authentication network element is successfully authenticated, generate a response parameter by the first device.
- the sending unit 2140 is configured to send a first authentication response to the proxy node, where the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
- the response parameter includes a first response parameter
- the first response parameter is used for the home domain network element to authenticate the first device
- the generating unit is used to generate the first response parameter based on the first key generation algorithm and a second parameter.
- the response parameter includes a first response parameter
- the first response parameter is used for the home domain network element to authenticate the first device
- the generating unit is used to generate the first response parameter based on a second key generation algorithm and the first parameter.
- the response parameters include a second response parameter
- the second response parameter is used for the service domain network element to authenticate the first device
- the generating unit is used to generate the second response parameter based on the first response parameter and a third parameter.
- the response parameters include a third response parameter
- the third response parameter is used by the access network device to authenticate the first device.
- the generating unit is used to generate the third response parameter based on the first response parameter and a fourth parameter.
- the generating unit is further used to: before receiving a first authentication request from a proxy node, perform an XOR operation on the identity of the first device and a first key to generate a hidden identity of the first device; the sending unit is further used to: send a second authentication request to the proxy node, wherein the second authentication request includes the hidden identity.
- the generating unit is further used to: before receiving a first authentication request from a proxy node, generate a hidden identity of the first device based on the identity of the first device, a first key, and a third key generation algorithm, wherein the third key generation algorithm is the first key generation algorithm or the second key generation algorithm; the sending unit is further used to: send a second authentication request to the proxy node, wherein the second authentication request includes the hidden identity.
- the first key is a shared key between the first device and the authentication network element, or the first key is a physical layer key between the first device and the proxy node.
- the generating unit is further used to: generate a second key when the authentication network element is successfully authenticated; and generate an application layer authentication and key management key based on the second key and a fourth key generation algorithm.
- the sending unit is also used to: send an application session establishment request message to the proxy node; the receiving unit is also used to: receive an application session establishment response message from the proxy node; the generating unit is also used to: in response to receiving the application session establishment response message, generate an application key based on the authentication and key management key of the application layer; and generate a third key based on the application key, a first key and a fifth key generation algorithm, wherein the first key is a physical layer key between the first device and the proxy node, and the fifth key generation algorithm is the first key generation algorithm or the second key generation algorithm; the device also includes a communication unit for securely communicating with the proxy node based on the third key.
- FIG22 is a schematic block diagram of a proxy node provided in an embodiment of the present application.
- the proxy node 2200 shown in FIG22 may be any of the proxy nodes described above.
- the proxy node 2200 may include a sending unit 2210 and a receiving unit 2220. These units are described in detail below.
- the sending unit 2210 is configured to send a first authentication request to a first device, wherein the first authentication request includes a first message authentication code.
- the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, and the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter.
- the receiving unit 2220 is used to receive a first authentication response from the first device, where the first authentication response includes a response parameter, and the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication network element successfully authenticates.
- the response parameters include a first response parameter
- the first response parameter is used for the home domain network element to authenticate the first device
- the first response parameter is generated based on the first key generation algorithm and a second parameter.
- the response parameters include a first response parameter
- the first response parameter is used for the home domain network element to authenticate the first device
- the first response parameter is generated based on a second key generation algorithm and the first parameter
- the response parameters include a second response parameter
- the second response parameter is used for the service domain network element to authenticate the first device
- the second response parameter is generated based on the first response parameter and a third parameter.
- the response parameters include a third response parameter
- the third response parameter is used by the access network device to authenticate the first device
- the third response parameter is generated based on the first response parameter and a fourth parameter.
- the first key is a physical layer key between the first device and the proxy node
- the proxy node also includes a determination unit for determining the identity of the first device based on the first key and the hidden identity; the sending unit is also used to: send the second authentication request to the authentication network element, and the second authentication request includes one or more of the following information: the first key, the identity of the first device, and the identity of the proxy node.
- the first key is a shared key between the first device and the authentication network element
- the sending unit is further used to: send the second authentication request to the authentication network element, and the second authentication request includes one or more of the following information: the hidden identity identifier and the identifier of the proxy node.
- the receiving unit is also used to: receive an application key from an application function network element;
- the proxy node also includes: a generation unit, used to generate a third key based on the application key, a first key and a fifth key generation algorithm, wherein the first key is a physical layer key between the first device and the proxy node, and the fifth key generation algorithm is the first key generation algorithm or the second key generation algorithm; a communication unit, used to communicate securely with the first device based on the third key.
- FIG23 is a schematic block diagram of an authentication network element provided in an embodiment of the present application.
- the authentication network element 2300 shown in FIG23 may be any authentication network element described above.
- the authentication network element 2300 may include a generating unit 2310 and a sending unit 2320. These units are described in detail below.
- the generating unit 2310 is configured to generate a first message authentication code and an expected response, where the expected response is used to authenticate the first device, and the first message authentication code is generated based on a first key generation algorithm and a first parameter.
- the sending unit 2320 is used to send a first authentication request to the proxy node, where the first authentication request includes the first message authentication code, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, and the second message authentication code is generated by the first device.
- the expected response includes a first expected response
- the first expected response is used for the home domain network element to authenticate the first device
- the generating unit is used to generate the first expected response based on the first key generation algorithm and a second parameter.
- the expected response includes a first expected response
- the first expected response is used for a home domain network element to authenticate the first device
- the generating unit is used to generate the first expected response based on a second key generation algorithm and the first parameter.
- the expected response includes a second expected response, where the second expected response is used for serving a domain network element to authenticate the first device, and the generating unit is used to generate the second expected response based on the first expected response and a third parameter.
- the expected response includes a third expected response
- the third expected response is used by the access network device to authenticate the first device
- the generating unit is used to generate the third expected response based on the first expected response and a fourth parameter.
- the authentication network element further includes: a receiving unit, used to: receive a second authentication request from the proxy node before the authentication network element generates a first message authentication code and an expected response, the second authentication request including a hidden identity of the first device, and a determination unit, used to determine the identity of the first device based on the hidden identity and a first key.
- the first key is a shared key between the first device and the authentication network element, or the first key is a physical layer key between the first device and the proxy node.
- the generating unit is used to: generate a second key when the first device is authenticated successfully; and generate an application layer authentication and key management key based on the second key and a fourth key generation algorithm.
- the first parameter includes a first random number, which is selected by the authentication network element, or the first random number is pre-shared by the authentication network element and the first device.
- FIG24 is a schematic block diagram of an access network device provided in an embodiment of the present application.
- the access network device 2400 shown in FIG24 may be any of the access network devices described above.
- the access network device 2400 may include a sending unit 2410 and a receiving unit 2420. These units are described in detail below.
- the sending unit 2410 is used to send a first authentication request to a first device, wherein the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, and the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter.
- the receiving unit 2420 is used to receive a first authentication response from the first device, where the first authentication response includes a response parameter, and the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication network element successfully authenticates.
- the response parameters include a first response parameter
- the first response parameter is used for the home domain network element to authenticate the first device
- the first response parameter is generated based on the first key generation algorithm and a second parameter.
- the response parameters include a first response parameter
- the first response parameter is used for the home domain network element to authenticate the first device
- the first response parameter is generated based on a second key generation algorithm and the first parameter
- the response parameters include a second response parameter
- the second response parameter is used for the service domain network element to authenticate the first device
- the second response parameter is generated based on the first response parameter and a third parameter.
- the response parameters include a third response parameter
- the third response parameter is used by the access network device to authenticate the first device
- the third response parameter is generated based on the first response parameter and a fourth parameter.
- the receiving unit is further used to: before the access network device sends a first authentication request to the first device, receive a second authentication request from the first device, the second authentication request including a hidden identity of the first device, and the hidden identity is generated by an exclusive OR operation of the identity of the first device and a first key.
- the receiving unit is further used to: before the access network device sends a first authentication request to the first device, receive a second authentication request from the first device, the second authentication request including a hidden identity of the first device, the hidden identity being generated by the hidden identity of the first device, a first key, and a third key generation algorithm, the third key generation algorithm being the first key generation algorithm or the second key generation algorithm.
- the first key is a physical layer key between the first device and the access network device
- the access network device also includes a determination unit for determining the identity of the first device based on the first key and the hidden identity; the sending unit is also used to: send the second authentication request to the authentication network element, and the second authentication request includes one or more of the following information: the first key and the identity of the first device.
- the first key is a shared key between the first device and the authentication network element
- the sending unit is further used to: send the second authentication request to the authentication network element, where the second authentication request includes the hidden identity.
- the first authentication response includes a third response parameter
- the receiving unit is further used to: receive a second authentication response from the authentication network element, the second authentication response including a third expected response;
- the access network device also includes: a comparison unit, used to compare the third response parameter and the third authentication response to authenticate the first device.
- FIG25 is a schematic structural diagram of a communication device according to an embodiment of the present application.
- the dotted line in FIG25 indicates that the unit or module is optional.
- the device 2500 may be used to implement the method described in the above method embodiment.
- the device 2500 may be a chip, a first device, a proxy node, an authentication network element, an access network device, or an application function network element.
- the device 2500 may include one or more processors 2510.
- the processor 2510 may support the device 2500 to implement the method described in the method embodiment above.
- the processor 2510 may be a general-purpose processor or a special-purpose processor.
- the processor may be a central processing unit (CPU).
- the processor may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
- DSP digital signal processor
- ASIC application specific integrated circuits
- FPGA field programmable gate arrays
- a general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
- the apparatus 2500 may further include one or more memories 2520.
- the memory 2520 stores a program, which can be executed by the processor 2510, so that the processor 2510 executes the method described in the above method embodiment.
- the memory 2520 may be independent of the processor 2510 or integrated in the processor 2510.
- the apparatus 2500 may further include a transceiver 2530.
- the processor 2510 may communicate with other devices or chips through the transceiver 2530.
- the processor 2510 may transmit and receive data with other devices or chips through the transceiver 2530.
- the present application also provides a computer-readable storage medium for storing a program.
- the computer-readable storage medium can be applied to the present application.
- the first device, proxy node, authentication network element, access network device or application function network element provided in the application embodiment, and the program enables the computer to execute the methods performed by the first device, proxy node, authentication network element, access network device or application function network element in each embodiment of the present application.
- the embodiment of the present application also provides a computer program product.
- the computer program product includes a program.
- the computer program product can be applied to the first device, proxy node, authentication network element, access network device or application function network element provided in the embodiment of the present application, and the program enables the computer to execute the method performed by the first device, proxy node, authentication network element, access network device or application function network element in each embodiment of the present application.
- the embodiment of the present application also provides a computer program.
- the computer program can be applied to the first device, proxy node, authentication network element, access network device or application function network element provided in the embodiment of the present application, and the computer program enables the computer to execute the method performed by the first device, proxy node, authentication network element, access network device or application function network element in each embodiment of the present application.
- the "include” mentioned may refer to direct inclusion or indirect inclusion.
- the “include” mentioned in the embodiments of the present application may be replaced with “indicate” or “used to determine”.
- a includes B which may be replaced with A indicates B, or A is used to determine B.
- the term "corresponding" may indicate that there is a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship of indication and being indicated, configuration and being configured, etc.
- the term "and/or" is only a description of the association relationship of the associated objects, indicating that there can be three relationships.
- a and/or B can represent: A exists alone, A and B exist at the same time, and B exists alone.
- the character "/" in this article generally indicates that the associated objects before and after are in an "or" relationship.
- the size of the serial numbers of the above-mentioned processes does not mean the order of execution.
- the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
- Small-Scale Networks (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
MAC=f1K(SQN||RAND||AMF);
RES=f2K(RAND);
CK=f3K(RAND);
IK=f4K(RAND);
AK=f5K(RAND)。
RES1=fK(RAND,N1,N2)
RES2=fK(RES1,SN name)
RES3=fN1(XRES1)
AK=fK(RAND)
AK=K⊕N1
DIDi=IDi⊕N1
DIDi=fN1(IDi)
IDi=DIDi⊕N1
IDi=fN1(DIDi)
Ks=fAK(N1,N2,UE ID,IDi,SN name)
KAKMA=fKs(“AKMA”,“IDi”)
A-TID=fKs(IDi)
A-KID=A-TID||RID||HNI
KAF=fKs(AF ID,IDi,UE ID,A-KID)
Ku1=KAF⊕N1
IDi=fN1(DIDi)
Ks=fAK(N1,N2,IDi,SN name)
Claims (87)
- 一种认证方法,其特征在于,包括:第一设备接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;所述第一设备基于第一密钥生成算法和第一参数生成第二消息认证码;所述第一设备基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;在所述认证网元认证成功的情况下,所述第一设备生成响应参数;所述第一设备向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
- 根据权利要求1所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一设备生成响应参数,包括:所述第一设备基于所述第一密钥生成算法和第二参数生成所述第一响应参数。
- 根据权利要求1所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一设备生成响应参数,包括:所述第一设备基于第二密钥生成算法和所述第一参数生成所述第一响应参数。
- 根据权利要求2或3所述的方法,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第一设备生成响应参数,包括:所述第一设备基于所述第一响应参数和第三参数,生成所述第二响应参数。
- 根据权利要求2-4中任一项所述的方法,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第一设备生成响应参数,包括:所述第一设备基于所述第一响应参数和第四参数,生成所述第三响应参数。
- 根据权利要求1-5中任一项所述的方法,其特征在于,在所述第一设备接收来自代理节点的第一认证请求之前,所述方法还包括:所述第一设备对所述第一设备的身份标识以及第一密钥进行异或运算,生成所述第一设备的隐藏身份标识;所述第一设备向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
- 根据权利要求1所述的方法,其特征在于,在所述第一设备接收来自代理节点的第一认证请求之前,所述方法还包括:所述第一设备基于所述第一设备的身份标识、第一密钥以及第三密钥生成算法,生成所述第一设备的隐藏身份标识,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述第一设备向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
- 根据权利要求6或7所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
- 根据权利要求1-8中任一项所述的方法,其特征在于,所述方法还包括:在所述认证网元认证成功的情况下,所述第一设备生成第二密钥;所述第一设备基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
- 根据权利要求9所述的方法,其特征在于,所述方法还包括:所述第一设备向所述代理节点发送应用会话建立请求消息;所述第一设备接收来自所述代理节点的应用会话建立响应消息;响应于接收到所述应用会话建立响应消息,所述第一设备基于所述应用层的认证和密钥管理密钥,生成应用密钥;所述第一设备基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述第一设备基于所述第三密钥,与所述代理节点进行安全通信。
- 一种认证方法,其特征在于,包括:代理节点向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;所述代理节点接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
- 根据权利要求11所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
- 根据权利要求11所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
- 根据权利要求12或13所述的方法,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
- 根据权利要求12-14中任一项所述的方法,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
- 根据权利要求11-15中任一项所述的方法,其特征在于,在所述代理节点向第一设备发送第一认证请求之前,所述方法还包括:所述代理节点接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
- 根据权利要求11-15中任一项所述的方法,其特征在于,在所述代理节点向第一设备发送第一认证请求之前,所述方法还包括:所述代理节点接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
- 根据权利要求16或17所述的方法,其特征在于,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述方法还包括:所述代理节点基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;所述代理节点向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥、所述第一设备的身份标识和所述代理节点的标识。
- 根据权利要求16或17所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述方法还包括:所述代理节点向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述隐藏身份标识和所述代理节点的标识。
- 根据权利要求11-19中任一项所述的方法,其特征在于,所述方法还包括:所述代理节点接收来自应用功能网元的应用密钥;所述代理节点基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述代理节点基于所述第三密钥,与所述第一设备进行安全通信。
- 一种认证方法,其特征在于,包括:认证网元生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成;所述认证网元向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
- 根据权利要求21所述的方法,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述认证网元生成期望响应,包括:所述认证网元基于所述第一密钥生成算法和第二参数生成所述第一期望响应。
- 根据权利要求21所述的方法,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述认证网元生成期望响应,包括:所述认证网元基于第二密钥生成算法和所述第一参数生成所述第一期望响应。
- 根据权利要求22或23所述的方法,其特征在于,所述期望响应包括第二期望响应,所述第二期望响应用于服务域网元认证所述第一设备,所述方法还包括:所述认证网元基于所述第一期望响应和第三参数,生成所述第二期望响应。
- 根据权利要求22-24中任一项所述的方法,其特征在于,所述期望响应包括第三期望响应,所 述第三期望响应用于接入网设备认证所述第一设备,所述方法还包括:所述认证网元基于所述第一期望响应和第四参数,生成所述第三期望响应。
- 根据权利要求21-25中任一项所述的方法,其特征在于,在所述认证网元生成第一消息认证码和期望响应之前,所述方法还包括:所述认证网元接收来自所述代理节点的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述认证网元基于所述隐藏身份标识与第一密钥,确定所述第一设备的身份标识。
- 根据权利要求26所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
- 根据权利要求21-27中任一项所述的方法,其特征在于,所述方法还包括:在所述第一设备认证成功的情况下,所述认证网元生成第二密钥;所述认证网元基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
- 根据权利要求21-28中任一项所述的方法,其特征在于,所述第一参数包括第一随机数,所述第一随机数由所述认证网元选择,或所述第一随机数由所述认证网元与所述第一设备预共享。
- 一种认证方法,其特征在于,包括:接入网设备向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;所述接入网设备接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
- 根据权利要求30所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
- 根据权利要求30所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
- 根据权利要求31或32所述的方法,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
- 根据权利要求31-33中任一项所述的方法,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
- 根据权利要求30-34中任一项所述的方法,其特征在于,在所述接入网设备向第一设备发送第一认证请求之前,所述方法还包括:所述接入网设备接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
- 根据权利要求30-34中任一项所述的方法,其特征在于,在所述接入网设备向第一设备发送第一认证请求之前,所述方法还包括:所述接入网设备接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
- 根据权利要求35或36所述的方法,其特征在于,所述第一密钥为所述第一设备与所述接入网设备之间的物理层密钥,所述方法还包括:所述接入网设备基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;所述接入网设备向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥和所述第一设备的身份标识。
- 根据权利要求35或36所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述方法还包括:所述接入网设备向所述认证网元发送所述第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
- 根据权利要求30-38中任一项所述的方法,其特征在于,所述第一认证响应中包括第三响应参 数,所述方法还包括:所述接入网设备接收来自所述认证网元的第二认证响应,所述第二认证响应中包括第三期望响应;所述接入网设备比较所述第三响应参数和所述第三认证响应,以认证所述第一设备。
- 一种设备,其特征在于,所述设备为第一设备,所述第一设备包括:接收单元,用于接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;生成单元,用于基于第一密钥生成算法和第一参数生成第二消息认证码;认证单元,用于基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;所述生成单元,还用于在所述认证网元认证成功的情况下,所述第一设备生成响应参数;发送单元,用于向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
- 根据权利要求40所述的设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述生成单元用于:基于所述第一密钥生成算法和第二参数生成所述第一响应参数。
- 根据权利要求40所述的设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述生成单元用于:基于第二密钥生成算法和所述第一参数生成所述第一响应参数。
- 根据权利要求41或42所述的设备,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述生成单元用于:基于所述第一响应参数和第三参数,生成所述第二响应参数。
- 根据权利要求41-43中任一项所述的设备,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述生成单元用于:基于所述第一响应参数和第四参数,生成所述第三响应参数。
- 根据权利要求40-44中任一项所述的设备,其特征在于,所述生成单元还用于:在接收来自代理节点的第一认证请求之前,对所述第一设备的身份标识以及第一密钥进行异或运算,生成所述第一设备的隐藏身份标识;所述发送单元还用于:向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
- 根据权利要求40所述的设备,其特征在于,所述生成单元还用于:在接收来自代理节点的第一认证请求之前,基于所述第一设备的身份标识、第一密钥以及第三密钥生成算法,生成所述第一设备的隐藏身份标识,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述发送单元还用于:向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
- 根据权利要求45或46所述的设备,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
- 根据权利要求40-47中任一项所述的设备,其特征在于,所述生成单元还用于:在所述认证网元认证成功的情况下,生成第二密钥;基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
- 根据权利要求48所述的设备,其特征在于,所述发送单元还用于:向所述代理节点发送应用会话建立请求消息;所述接收单元还用于:接收来自所述代理节点的应用会话建立响应消息;所述生成单元还用于:响应于接收到所述应用会话建立响应消息,基于所述应用层的认证和密钥管理密钥,生成应用密钥;以及基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述设备还包括通信单元,用于基于所述第三密钥,与所述代理节点进行安全通信。
- 一种代理节点,其特征在于,包括:发送单元,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;接收单元,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述 响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
- 根据权利要求50所述的代理节点,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
- 根据权利要求50所述的代理节点,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
- 根据权利要求51或52所述的代理节点,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
- 根据权利要求51-53中任一项所述的代理节点,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
- 根据权利要求50-54中任一项所述的代理节点,其特征在于,所述接收单元还用于:在向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
- 根据权利要求50-54中任一项所述的代理节点,其特征在于,所述接收单元还用于:在向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
- 根据权利要求55或56所述的代理节点,其特征在于,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述代理节点还包括确定单元,用于基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥、所述第一设备的身份标识和所述代理节点的标识。
- 根据权利要求55或56所述的代理节点,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述隐藏身份标识和所述代理节点的标识。
- 根据权利要求50-58中任一项所述的代理节点,其特征在于,所述接收单元还用于:接收来自应用功能网元的应用密钥;所述代理节点还包括:生成单元,用于基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;通信单元,用于基于所述第三密钥,与所述第一设备进行安全通信。
- 一种认证网元,其特征在于,包括:生成单元,用于生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成;发送单元,用于向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
- 根据权利要求60所述的认证网元,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述生成单元用于:基于所述第一密钥生成算法和第二参数生成所述第一期望响应。
- 根据权利要求60所述的认证网元,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述生成单元用于:基于第二密钥生成算法和所述第一参数生成所述第一期望响应。
- 根据权利要求61或62所述的认证网元,其特征在于,所述期望响应包括第二期望响应,所述第二期望响应用于服务域网元认证所述第一设备,所述生成单元用于:基于所述第一期望响应和第三参数,生成所述第二期望响应。
- 根据权利要求61-63中任一项所述的认证网元,其特征在于,所述期望响应包括第三期望响应,所述第三期望响应用于接入网设备认证所述第一设备,所述生成单元用于:基于所述第一期望响应和第四参数,生成所述第三期望响应。
- 根据权利要求60-64中任一项所述的认证网元,其特征在于,所述认证网元还包括:接收单元,用于:在所述认证网元生成第一消息认证码和期望响应之前,接收来自所述代理节点的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,确定单元,用于基于所述隐藏身份标识与第一密钥,确定所述第一设备的身份标识。
- 根据权利要求65所述的认证网元,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
- 根据权利要求60-66中任一项所述的认证网元,其特征在于,所述生成单元用于:在所述第一设备认证成功的情况下,生成第二密钥;基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
- 根据权利要求60-67中任一项所述的认证网元,其特征在于,所述第一参数包括第一随机数,所述第一随机数由所述认证网元选择,或所述第一随机数由所述认证网元与所述第一设备预共享。
- 一种接入网设备,其特征在于,包括:发送单元,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;接收单元,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
- 根据权利要求69所述的接入网设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
- 根据权利要求69所述的接入网设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
- 根据权利要求70或71所述的接入网设备,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
- 根据权利要求70-72中任一项所述的接入网设备,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
- 根据权利要求69-73中任一项所述的接入网设备,其特征在于,所述接收单元还用于:在所述接入网设备向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
- 根据权利要求69-73中任一项所述的接入网设备,其特征在于,所述接收单元还用于:在所述接入网设备向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
- 根据权利要求74或75所述的接入网设备,其特征在于,所述第一密钥为所述第一设备与所述接入网设备之间的物理层密钥,所述接入网设备还包括确定单元,用于基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥和所述第一设备的身份标识。
- 根据权利要求74或75所述的接入网设备,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
- 根据权利要求69-77中任一项所述的接入网设备,其特征在于,所述第一认证响应中包括第三 响应参数,所述接收单元还用于:接收来自所述认证网元的第二认证响应,所述第二认证响应中包括第三期望响应;所述接入网设备还包括:比较单元,用于比较所述第三响应参数和所述第三认证响应,以认证所述第一设备。
- 一种设备,其特征在于,所述设备为第一设备,所述第一设备包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述第一设备执行如权利要求1-10中任一项所述的方法。
- 一种代理节点,其特征在于,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述代理节点执行如权利要求11-20中任一项所述的方法。
- 一种认证网元,其特征在于,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述认证网元执行如权利要求21-29中任一项所述的方法。
- 一种接入网设备,其特征在于,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述接入网设备执行如权利要求30-39中任一项所述的方法。
- 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求1-10中任一项所述的方法。
- 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求11-20中任一项所述的方法。
- 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求21-29中任一项所述的方法。
- 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求30-39中任一项所述的方法。
- 一种芯片,其特征在于,包括处理器,用于从存储器调用程序,使得安装有所述芯片的设备执行如权利要求1-10中任一项所述的方法。
Priority Applications (5)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202380098422.4A CN121220076A (zh) | 2023-05-23 | 2023-05-23 | 认证方法及装置 |
| PCT/CN2023/095769 WO2024239231A1 (zh) | 2023-05-23 | 2023-05-23 | 认证方法及装置 |
| EP23937907.6A EP4718901A1 (en) | 2023-05-23 | 2023-05-23 | Method and apparatus for authentication |
| MX2025013824A MX2025013824A (es) | 2023-05-23 | 2025-11-19 | Metodo y aparato para autenticacion |
| US19/397,618 US20260082224A1 (en) | 2023-05-23 | 2025-11-21 | Method and apparatus for authentication |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2023/095769 WO2024239231A1 (zh) | 2023-05-23 | 2023-05-23 | 认证方法及装置 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US19/397,618 Continuation US20260082224A1 (en) | 2023-05-23 | 2025-11-21 | Method and apparatus for authentication |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024239231A1 true WO2024239231A1 (zh) | 2024-11-28 |
Family
ID=93588762
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/095769 Ceased WO2024239231A1 (zh) | 2023-05-23 | 2023-05-23 | 认证方法及装置 |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20260082224A1 (zh) |
| EP (1) | EP4718901A1 (zh) |
| CN (1) | CN121220076A (zh) |
| MX (1) | MX2025013824A (zh) |
| WO (1) | WO2024239231A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170353859A1 (en) * | 2016-06-07 | 2017-12-07 | Sears Brands, L.L.C. | System and method for automatically and securely registering an internet of things device |
| CN110012467A (zh) * | 2019-04-18 | 2019-07-12 | 苏州博联科技有限公司 | 窄带物联网的分组认证方法 |
| CN111669276A (zh) * | 2019-03-07 | 2020-09-15 | 华为技术有限公司 | 一种网络验证方法、装置及系统 |
| CN115380570A (zh) * | 2020-03-29 | 2022-11-22 | 华为技术有限公司 | 一种通信方法、装置及系统 |
| CN115776398A (zh) * | 2022-11-18 | 2023-03-10 | 华润数字科技有限公司 | 一种IoT边缘设备认证方法及系统 |
-
2023
- 2023-05-23 EP EP23937907.6A patent/EP4718901A1/en active Pending
- 2023-05-23 CN CN202380098422.4A patent/CN121220076A/zh active Pending
- 2023-05-23 WO PCT/CN2023/095769 patent/WO2024239231A1/zh not_active Ceased
-
2025
- 2025-11-19 MX MX2025013824A patent/MX2025013824A/es unknown
- 2025-11-21 US US19/397,618 patent/US20260082224A1/en active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170353859A1 (en) * | 2016-06-07 | 2017-12-07 | Sears Brands, L.L.C. | System and method for automatically and securely registering an internet of things device |
| CN111669276A (zh) * | 2019-03-07 | 2020-09-15 | 华为技术有限公司 | 一种网络验证方法、装置及系统 |
| CN110012467A (zh) * | 2019-04-18 | 2019-07-12 | 苏州博联科技有限公司 | 窄带物联网的分组认证方法 |
| CN115380570A (zh) * | 2020-03-29 | 2022-11-22 | 华为技术有限公司 | 一种通信方法、装置及系统 |
| CN115776398A (zh) * | 2022-11-18 | 2023-03-10 | 华润数字科技有限公司 | 一种IoT边缘设备认证方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| MX2025013824A (es) | 2025-12-01 |
| EP4718901A1 (en) | 2026-04-01 |
| US20260082224A1 (en) | 2026-03-19 |
| CN121220076A (zh) | 2025-12-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11785510B2 (en) | Communication system | |
| US11805409B2 (en) | System and method for deriving a profile for a target endpoint device | |
| CN101500229B (zh) | 建立安全关联的方法和通信网络系统 | |
| US20230379700A1 (en) | Security parameter obtaining method, apparatus, and system | |
| CN109691154B (zh) | 基于密钥刷新的按需网络功能重新认证 | |
| CN117544947A (zh) | 通信方法、装置及可读存储介质 | |
| WO2022253083A1 (zh) | 一种公私网业务的隔离方法、装置及系统 | |
| EP4447511A1 (en) | Method and apparatus for data processing in random access process | |
| EP4718901A1 (en) | Method and apparatus for authentication | |
| WO2023213191A1 (zh) | 安全保护方法及通信装置 | |
| US20260128857A1 (en) | User-level homomorphic encryption management method and apparatus | |
| EP4712529A1 (en) | Communication method and device | |
| CN114208240A (zh) | 数据传输方法、装置及系统 | |
| US20240380742A1 (en) | Information protection mrthod and device | |
| WO2026073511A1 (zh) | 通信方法、装置、设备以及存储介质 | |
| WO2026025341A1 (zh) | 传输方法、终端设备和网络设备 | |
| CN118830225A (zh) | 生成密钥的方法及装置 | |
| CN118402262A (zh) | 中继通信的方法及设备 | |
| CN120390213A (zh) | 信息处理方法及装置、系统 | |
| WO2023178530A1 (zh) | 生成密钥的方法及装置 | |
| WO2025066757A1 (zh) | 一种通信方法及装置 | |
| WO2023205978A1 (zh) | 邻近通信业务的密钥生成方法、装置、设备及存储介质 | |
| WO2025025060A1 (zh) | 认证方法和设备 | |
| CN119729457A (zh) | Nas消息的安全保护方法、装置及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23937907 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: MX/A/2025/013824 Country of ref document: MX |
|
| WWP | Wipo information: published in national office |
Ref document number: MX/A/2025/013824 Country of ref document: MX |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023937907 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| ENP | Entry into the national phase |
Ref document number: 2023937907 Country of ref document: EP Effective date: 20251223 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2023937907 Country of ref document: EP |