WO2024239231A1 - 认证方法及装置 - Google Patents

认证方法及装置 Download PDF

Info

Publication number
WO2024239231A1
WO2024239231A1 PCT/CN2023/095769 CN2023095769W WO2024239231A1 WO 2024239231 A1 WO2024239231 A1 WO 2024239231A1 CN 2023095769 W CN2023095769 W CN 2023095769W WO 2024239231 A1 WO2024239231 A1 WO 2024239231A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
key
response
network element
parameter
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2023/095769
Other languages
English (en)
French (fr)
Inventor
熊丽晖
甘露
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangdong Oppo Mobile Telecommunications Corp Ltd
Original Assignee
Guangdong Oppo Mobile Telecommunications Corp Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Guangdong Oppo Mobile Telecommunications Corp Ltd filed Critical Guangdong Oppo Mobile Telecommunications Corp Ltd
Priority to CN202380098422.4A priority Critical patent/CN121220076A/zh
Priority to PCT/CN2023/095769 priority patent/WO2024239231A1/zh
Priority to EP23937907.6A priority patent/EP4718901A1/en
Publication of WO2024239231A1 publication Critical patent/WO2024239231A1/zh
Priority to MX2025013824A priority patent/MX2025013824A/es
Priority to US19/397,618 priority patent/US20260082224A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys

Definitions

  • the present application relates to the field of communication technology, and more specifically, to an authentication method and device.
  • the terminal device can authenticate and negotiate keys with the network side before communicating with the network side.
  • the first device such as a zero-power terminal
  • the terminal device can authenticate and negotiate keys with the network side before communicating with the network side.
  • the present application provides an authentication method and device. The following is a detailed introduction to various aspects of the present application.
  • an authentication method including: a first device receives a first authentication request from a proxy node, the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element; the first device generates a second message authentication code based on a first key generation algorithm and a first parameter; the first device authenticates the authentication network element based on the first message authentication code and the second message authentication code; when the authentication network element is successfully authenticated, the first device generates a response parameter; the first device sends a first authentication response to the proxy node, the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
  • an authentication method including: a proxy node sends a first authentication request to a first device, the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; the proxy node receives a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
  • an authentication method including: an authentication network element generates a first message authentication code and an expected response, the expected response is used to authenticate a first device, the first message authentication code is generated based on a first key generation algorithm and a first parameter; the authentication network element sends a first authentication request to the proxy node, the first authentication request includes the first message authentication code, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, and the second message authentication code is generated by the first device.
  • an authentication method including: an access network device sends a first authentication request to a first device, the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; the access network device receives a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
  • a device wherein the device is a first device, and the first device includes: a receiving unit, used to receive a first authentication request from a proxy node, the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element; a generating unit, used to generate a second message authentication code based on a first key generation algorithm and a first parameter; an authentication unit, used to authenticate the authentication network element based on the first message authentication code and the second message authentication code; the generating unit is also used to generate a response parameter for the first device when the authentication of the authentication network element is successful; a sending unit, used to send a first authentication response to the proxy node, the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
  • a proxy node including: a sending unit, used to send a first authentication request to a first device, the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; a receiving unit, used to receive a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
  • an authentication network element including: a generating unit, used to generate a first message authentication code and an expected response, the expected response is used to authenticate a first device, the first message authentication code is generated based on a first key generation algorithm and a first parameter; a sending unit, used to send a first authentication request to the proxy node, the first authentication request includes the first message authentication code, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, and the second message authentication code is generated by the first device.
  • an access network device including: a sending unit, configured to send a first authentication request to a first device, wherein the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, and the first message authentication code and a second message authentication code are generated by an authentication network element.
  • the first message authentication code is used to authenticate the authentication network element, the second message authentication code is generated by the first device, the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter; a receiving unit is used to receive a first authentication response from the first device, the first authentication response includes a response parameter, the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication of the authentication network element is successful.
  • a device comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory to execute the method described in the first aspect.
  • a proxy node comprising a memory and a processor, wherein the memory is used to store programs, and the processor is used to call the programs in the memory to execute the method described in the second aspect.
  • an authentication network element comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory to execute the method described in the third aspect.
  • an access network device comprising a memory and a processor, wherein the memory is used to store programs, and the processor is used to call the programs in the memory to execute the method described in the fourth aspect.
  • a device comprising a processor, configured to call a program from a memory to execute a method as described in any one of the first to fourth aspects.
  • a chip comprising a processor for calling a program from a memory so that a device equipped with the chip executes a method as described in any one of the first to fourth aspects.
  • a computer-readable storage medium on which a program is stored, wherein the program enables a computer to execute the method described in any one of the first to fourth aspects.
  • a computer program product comprising a program, wherein the program enables a computer to execute the method described in any one of the first to fourth aspects.
  • a computer program is provided, wherein the computer program enables a computer to execute the method as described in any one of the first to fourth aspects.
  • the first device receives a first authentication request from a proxy node, the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element; the first device generates a second message authentication code based on a first key generation algorithm and a first parameter; the first device authenticates the authentication network element based on the first message authentication code and the second message authentication code; when the authentication network element successfully authenticates, the first device generates a response parameter; the first device sends a first authentication response to the proxy node, the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
  • the present application generates a message authentication code (such as a second message authentication code) based on a first key generation algorithm and a first parameter to authenticate the network element, thereby providing a clear solution for authentication between the first device and the network side.
  • a message authentication code such as a second message authentication code
  • FIG. 1 is a wireless communication system 100 to which an embodiment of the present application is applied.
  • FIG. 2 is a schematic diagram of a process of initial authentication.
  • FIG. 3 is a schematic diagram of a process for generating an AKMA key.
  • FIG. 4 is a schematic diagram of a process of generating an application key.
  • FIG5 is a schematic diagram of the derivation process of various keys involved in an embodiment of the present application.
  • FIG. 6 is a schematic diagram of a method for generating various parameters involved in an embodiment of the present application.
  • FIG. 7 is a schematic diagram of a hybrid communication system provided in an embodiment of the present application.
  • FIG8 is a communication system based on 3GPP security credentials provided in an embodiment of the present application.
  • FIG9 is a communication system based on non-3GPP security credentials provided in an embodiment of the present application.
  • FIG10 is a flow chart of an authentication method provided in an embodiment of the present application.
  • FIG11 is a flow chart of an authentication method based on a proxy node and 3GPP security credentials provided in an embodiment of the present application.
  • FIG. 12 is a schematic diagram of a process of generating an AKMA key based on FIG. 11 .
  • FIG. 13 is a schematic diagram of a process of generating an application key based on FIG. 12 .
  • FIG14 is a flow chart of another authentication method provided in an embodiment of the present application.
  • FIG15 is a flow chart of an authentication method based on 3GPP security credentials provided in an embodiment of the present application.
  • FIG. 16 is a schematic diagram of a process of generating an application key based on FIG. 15 .
  • FIG17 is a flow chart of another authentication method provided in an embodiment of the present application.
  • FIG18 is a flow chart of an authentication method based on a proxy node and non-3GPP security credentials provided in an embodiment of the present application.
  • FIG19 is a flow chart of another authentication method provided in an embodiment of the present application.
  • Figure 20 is a flowchart of an authentication method based on non-3GPP security credentials provided in an embodiment of the present application.
  • Figure 21 is a schematic block diagram of a first device provided in an embodiment of the present application.
  • Figure 22 is a schematic block diagram of a proxy node provided in an embodiment of the present application.
  • Figure 23 is a schematic block diagram of an authentication network element provided in an embodiment of the present application.
  • Figure 24 is a schematic block diagram of an access network device provided in an embodiment of the present application.
  • FIG. 25 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application.
  • FIG1 is a wireless communication system 100 used in an embodiment of the present application.
  • the wireless communication system 100 may include a network device 110 and a terminal device 120.
  • the network device 110 may be a device that communicates with the terminal device 120.
  • the network device 110 may provide communication coverage for a specific geographical area, and may communicate with the terminal device 120 located in the coverage area.
  • FIG1 exemplarily shows a network device and two terminal devices.
  • the wireless communication system 100 may include multiple network devices and each network device may include another number of terminal devices within its coverage area, which is not limited in the embodiments of the present application.
  • the wireless communication system 100 may also include other network entities such as a network controller and a mobility management entity, which is not limited in the embodiments of the present application.
  • network entities such as a network controller and a mobility management entity, which is not limited in the embodiments of the present application.
  • the terminal device in the embodiment of the present application may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device.
  • the terminal device in the embodiment of the present application may be a device that provides voice and/or data connectivity to a user, and can be used to connect people, objects and machines, such as a handheld device with wireless connection function, a vehicle-mounted device, etc.
  • the terminal device in the embodiment of the present application can be a mobile phone, a tablet computer, a laptop, a PDA, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.
  • the UE can be used to act as a base station.
  • the UE can act as a scheduling entity that provides sidelink signals between UEs in V2X or D2D, etc.
  • a cellular phone and a car communicate with each other using sidelink signals.
  • the cellular phone and the smart home device communicate with each other without relaying the communication signal through the base station.
  • Base station can broadly cover various names as follows, or replace with the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, transmitting point (TRP), transmitting point (TP), master station MeNB, auxiliary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, base band unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc.
  • the base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof.
  • the network device in the embodiments of the present application may refer to a CU or a DU, or the network device includes a CU and a DU.
  • the gNB may also include an AAU.
  • K AF The application key
  • AMF access and mobility management function
  • AUSF authentication server function
  • UDM unified data management
  • AAA AKMA anchor function
  • AF AF
  • AMF is mainly used for mobility management and access management. It can be used to implement other functions of the mobility management entity (MME) except session management, such as lawful interception and access authorization/authentication.
  • MME mobility management entity
  • AUSF is used for authentication services, key generation, and bidirectional authentication of UEs, and supports a unified authentication framework.
  • AUSF is mainly used for mutual authentication between UEs and networks, and generates security keys for use in subsequent processes.
  • UDM can be used to process UE identification, access authentication, registration, and mobility management.
  • the UE may first perform initial authentication with the network side, and obtain a key (such as KAUSF) after the initial authentication is completed.
  • the key may be used to generate K AF .
  • the initial authentication process is introduced below in conjunction with FIG. 2 .
  • UDM/ARPF can create a 5G HE AV for each authentication get request message (such as Nudm Authenticate Get Request). UDM/ARPF can first generate an authentication vector with AMF "separation bit" as 1, and then calculate K AUSF and XRES*. Finally, UDM/ARPF can create a 5G HE AV containing RAND, AUTN, XRES* and K AUSF .
  • SEAF sends an authentication request to the UE.
  • the authentication request may be sent via a non-access stratum (NAS) message (such as Auth-Reg).
  • the authentication request may include RANT and an authentication token (AUTN).
  • the message may also include ngKSI, which may be used to identify the UE and AMF K AMF and part of the native security context.
  • the UE may include a mobile equipment (ME) and a universal subscriber identity module (USIM). After the UE receives RANT and AUTN, the ME may forward the RANT and AUTN to the USIM.
  • ME mobile equipment
  • USIM universal subscriber identity module
  • step S214 after receiving RANT and AUTN, USIM can check whether AUTN is accepted to verify whether the authentication vector is up to date to resist replay attacks. If the verification is successful, USIM can calculate the response RES and return RES, encryption key (encryption key, CK) and integrity key (integrity key, IK) to ME. USIM can also calculate Kc (i.e. GPRS Kc) and send the GPRS Kc to ME. If GPRS Kc is calculated based on CK, IK and the conversion function c3 described in the third generation partnership project (3GPP) TS 33.102, ME can ignore the GPRS Kc, and the GPRS Kc should not be stored on USIM or ME.
  • 3GPP third generation partnership project
  • step S216 the UE sends an authentication response to the SEAF, which may include RES*.
  • the authentication response may be sent via a NAS message.
  • step S220 SEAF sends a UE authentication request (such as Nausf_UE Authentication_Authenticate Request) message to AUSF, and the UE authentication request message may include SUCI or SUPI.
  • UE authentication request such as Nausf_UE Authentication_Authenticate Request
  • AUSF receives a UE authentication request message, which may include RES*.
  • AUSF may verify whether the AV has expired. If the AV has expired, AUSF may consider the authentication unsuccessful from the perspective of the home domain network.
  • AUSF may determine whether the authentication is successful by comparing the received RES* with the stored XRES*. If RES* and XRES* are consistent, AUSF considers the authentication successful from the perspective of the home domain network; if RES* and XRES* are inconsistent, AUSF considers the authentication unsuccessful from the perspective of the home domain network.
  • the AUSF indicates to the SEAF whether the authentication is successful through a UE authentication response (e.g., Nausf_UE Authentication_Authenticate Response) message. If the authentication is successful, the AUSF may send K SEAF to the SEAF through the UE authentication response message. If the authentication is successful, and the AUSF receives SUCI from the SEAF when initiating the authentication, the UE authentication response message may also include SUPI.
  • a UE authentication response e.g., Nausf_UE Authentication_Authenticate Response
  • SEAF may provide ngKSI and KAMF to AMF only after receiving the UE authentication response message containing SUPI. Before knowing SUPI, the service network will not provide communication services to UE.
  • step S302 after the initial authentication is completed, the UE and the AUSF may generate K AKMA and A-KID based on K AUSF .
  • the AUSF may send an AKMA anchor key registration request (eg, Naanf_AKMA_AnchorKey_Register Request) to the AAnF.
  • the AKMA anchor key registration request may include SUPI, A-KID, and K AKMA .
  • AAnF may return an AKMA anchor key registration response (such as Naanf_AKMA_AnchorKey_Register Response) to AUSF.
  • AKMA anchor key registration response such as Naanf_AKMA_AnchorKey_Register Response
  • the UE may send an application session establishment request to the AF.
  • the application session establishment request may include the A-KID.
  • AAnF may determine the corresponding K AKMA based on A-KID, and generate a key K AF based on K AKMA .
  • step S408 the AAnF sends an AKMA application key acquisition response to the AF.
  • the application key acquisition response may include K AF , the validity period of K AF (K AF expTime), UE-ID, etc.
  • step S410 the AF sends an application session establishment response to the UE.
  • the UE can also generate K AF in the same manner as the AAnF, that is, the manner in which the UE generates K AF based on K AKMA is the same as the manner in which the AAnF generates K AF based on K AKMA .
  • the UE and the AF can communicate using the same key K AF .
  • KDF key derivation function
  • KDF can be any key derivation function that can meet the computational security requirements, for example, KDF can be HMAC-SHA-256 or HMAC-SM3.
  • KDF uses KDF as an example to illustrate the generation method of the key.
  • -FC 0xXX (e.g. 0x80);
  • - L0 length of AKMA (e.g. 0x00 0x04);
  • the input key is K AUSF .
  • -FC 0xXX (e.g. 0x82);
  • the key entered is K AKMA .
  • AF_ID FQDN of AF
  • A-KID may include two parts: a routing indicator (RID) and an AKMA temporary UE identifier (A-TID).
  • RID is included in SUPI, and A-TID can be generated based on K AUSF .
  • A-TID can be generated based on K AUSF .
  • -FC 0xXX (e.g. 0x81);
  • -L0 length of "A-TID" (e.g. 0x00 0x05);
  • the key entered is K AUSF .
  • FIG5 is a schematic diagram of the derivation process of various keys involved in an embodiment of the present application.
  • the NAS security context in the embodiment of the present application may include KAMF , subordinate derived keys KNASint and KNASenc , and key identifiers corresponding to the respective keys.
  • the access stratum (AS) security context in the embodiment of the present application may include K gNB , subordinate derived keys K RRCint , K RRCenc , K UPint and K UPenc , and key identifiers corresponding to each key.
  • the keys involved in the embodiments of the present application may also include confidentiality protection keys (or encryption keys) and integrity protection keys.
  • confidentiality protection keys and integrity protection keys can be generated by KAMF or KgNB .
  • KAMF is a shared key between AMF and UE, and is a shared key between gNB and UE.
  • the input parameters can be as follows:
  • -FC 0xXX (e.g. 00x69);
  • -L0 length of algorithm type distinguisher (e.g. 0x00 0x01);
  • -L1 length of algorithm identity (e.g. 0x00 0x01).
  • the value of the input algorithm identifier may also be different.
  • the encryption algorithm used in the embodiment of the present application may include one or more of the following: NIA1, NIA2, NIA3, and the integrity protection algorithm may include one or more of the following: EIA1, EIA2, EIA3.
  • FIG. 6 shows a method for generating various parameters involved in an embodiment of the present application.
  • the UE can store a long-term key K and the public key of the home network, which can be used to encrypt the SUPI.
  • wireless communication systems can be integrated with industrial wireless sensor networks (IWSN).
  • IWSN industrial wireless sensor networks
  • wireless communication systems can be integrated with smart logistics and smart warehousing.
  • smart home networks can be integrated with smart home networks.
  • terminal devices are usually required to have the characteristics of low cost, small size (such as ultra-thin), maintenance-free, long life, etc. Therefore, in order to meet the above conditions, network devices and terminal devices can use zero-power communication technology for communication.
  • the terminal device can also be called "zero-power communication terminal", “zero-power terminal” or tag.
  • the first communication mode is that the zero-power terminal communicates directly with the base station.
  • the base station can provide a wireless power supply signal and a trigger signal to the zero-power terminal.
  • the wireless power supply signal can be used to provide energy to the zero-power terminal.
  • the trigger signal can carry control information sent to the zero-power terminal.
  • the zero-power terminal can transmit information to the base station by backscattering.
  • the second communication mode is a hybrid communication mode, that is, this communication mode includes cellular communication and sideline communication.
  • this communication mode includes cellular communication and sideline communication.
  • zero-power communication systems based on cellular communication and sideline communication can coexist or be used in combination flexibly, thereby matching more potential application scenarios.
  • Fig. 7 shows a hybrid communication system.
  • the communication modes shown in Fig. 7 include four types, which are respectively introduced below.
  • Method 2 The base station provides a wireless power supply signal and sends a trigger signal to the zero-power terminal.
  • the backscattered signal of the zero-power terminal is received by the terminal device, thereby completing the side communication.
  • the terminal device can send air interface data to the base station.
  • Mode 4 The terminal device receives the air interface signaling and data sent by the network device.
  • the terminal device provides power supply signals and trigger signals to the zero-power terminal, and receives the backscattered signals sent by the zero-power terminal to complete the side communication.
  • the security standards for battery efficient security for very low throughput machine type communication devices BEST), machine type communication (MTC), and new radio-internet of things (NB-IoT) designed for low throughput machine type communication devices in the Internet of Things are based on authentication and key negotiation mechanisms such as AKA, generic bootstrapping architecture (GBA), and AKMA.
  • AKA authentication and key negotiation mechanisms
  • GBA generic bootstrapping architecture
  • AKMA AKMA
  • the terminal device needs to support various functions in f1-f5 at the same time.
  • MAC uses f1 function
  • RES uses f2 function
  • CK uses f3 function
  • IK uses f4 function
  • AK uses f5 function. Since the computing power of zero-power terminals is low, this method is not suitable for zero-power terminals.
  • the embodiments of the present application provide an authentication method and device, which can implement the authentication and key negotiation process in a simplified manner, so that it can be applicable to the security authentication between the first device (such as a zero-power terminal) and the network side.
  • the authentication method of the embodiment of the present application only requires the first device to support one or two key generation algorithms to implement the authentication and key negotiation process between the first device and the network side, thereby reducing the complexity of the first device.
  • the first device in the embodiment of the present application may be a zero-power terminal.
  • the first device may be, for example, a tag or an ambient power-enabled internet of things (A-IoT) device.
  • A-IoT ambient power-enabled internet of things
  • the communication mode of the first device and the security credentials involved in this application are first introduced.
  • the first device does not support the application layer protocol, and the first device may be connected to the serving domain network element and/or the AF through a proxy node.
  • the service domain network element in the embodiment of the present application may include, for example, one or more of the following: AMF, service management function (service Management function, SMF), SEAF, A-NF (ambient network function) specific to A-IoT services, etc.
  • the proxy node may include, for example, a terminal device and/or an integrated access and backhaul (IAB) node, etc.
  • the terminal device may be, for example, a UE.
  • the proxy node may forward authentication information between the first device and the network side (such as an authentication network element). In other implementations, the proxy node may also perform some processing on the authentication information. For example, the proxy node may transmit authentication information via a NAS message (such as a NAS security context) or an AS message (such as an AS security context). For another example, the proxy node may decrypt some encrypted information (such as a hidden identity identifier of the first device) during the authentication process.
  • NAS message such as a NAS security context
  • AS message such as an AS security context
  • the proxy node may decrypt some encrypted information (such as a hidden identity identifier of the first device) during the authentication process.
  • the first device may support an application layer protocol (such as hyper text transfer protocol (HTTP)).
  • an application layer protocol such as hyper text transfer protocol (HTTP)
  • MAC media access control
  • PHY physical
  • the first device may be connected to the AF via an application layer protocol.
  • the embodiment of the present application can establish a secure communication link between the first device and the third-party server (such as AF).
  • the third-party server can rely on the core network to authenticate and negotiate keys for the first device.
  • the security credentials in the embodiment of the present application can be divided into two categories. One type of security credentials is 3GPP security credentials, and the other type of security credentials is non-3GPP security credentials.
  • the 3GPP security credential can be understood as a root key (abbreviated as K) shared between the first device and the authentication network element. If the security credential is a 3GPP security credential, the network side (such as UDM) can perform authorization management, such as storing the authentication result.
  • the management authorization can be an authorization management based on the subscription credential.
  • the authentication result can, for example, include one or more of the following: a timestamp of the first device authentication, an ID of the first device, an authentication method of the first device, and an identifier of the security context of the first device.
  • the non-3GPP security credential may be a security credential provided by a third-party application server, such as a root key (K for short) shared between the first device and the AF or the network application function (NAF).
  • the third-party application server (such as the AF or the NAF) may perform authorization management.
  • the authorization management may be application layer-based authorization management.
  • the third-party application server may manage the mapping between the proxy node and the first device, and provide the security credential K to the authentication network element, or provide the authentication network element with a subordinate key derived from the security credential K.
  • Figure 9 shows a communication architecture based on 3GPP security credentials. Different from Figure 8, the third-party server can communicate with the core network to provide the core network with the security credential K or a subordinate key derived from the security credential K.
  • security credential in the embodiment of the present application can be understood as a root key.
  • the security credential is a 3GPP security credential
  • the first device communicates with the network side through the proxy node.
  • the embodiment of the present application does not specifically limit the generation method of the first message authentication code.
  • the first message authentication code can be generated based on the first key generation algorithm and the first parameter.
  • the first key generation algorithm can be any function.
  • the function can be any one of the following: f function, KDF or other lightweight functions.
  • the f function can be, for example, any one of the f1 function, f2 function, f3 function, f4 function, and f5 function defined by 3GPP.
  • KDF can be, for example, HMAC-SHA-256 or HMAC-SM3.
  • the lightweight function can be, for example, ASCON.
  • the first parameter may include one or more of the following: a security credential, a first random number, a second random number, and a first key.
  • the first parameter may include a security credential and a second random number.
  • the first parameter may include a security credential, a second random number, and a first key.
  • the first parameter may include a security credential, a second random number, and a first random number.
  • the first parameter may include a security credential, a second random number, a first random number, and a first key.
  • the security credential may be the 3GPP security credential or the non-3GPP security credential described above.
  • the first random number (denoted as N2) may be a random number selected by the authentication network element or may be a shared key between the authentication network element and the first device. The first random number may be used to resist replay attacks.
  • the second random number (denoted as RAND) may be a random number selected by the authentication network element.
  • the first key (denoted as N1) may be one or more of the following: a random number pre-shared by the first device and a network side device (such as an authentication network element), a shared key between the first device and a proxy node, and a shared key between the first device and a base station.
  • the shared key may be a physical layer key.
  • the first message authentication code and the expected response can be generated based on the same key generation algorithm and different parameters, or the first message authentication code and the expected response can be generated based on different key generation algorithms and the same parameters, which can reduce the time required to generate the first message authentication code.
  • a message authentication code and the complexity of the expected response can be generated based on the same key generation algorithm and different parameters, or the first message authentication code and the expected response can be generated based on different key generation algorithms and the same parameters, which can reduce the time required to generate the first message authentication code.
  • a message authentication code and the complexity of the expected response can be generated based on the same key generation algorithm and different parameters, or the first message authentication code and the expected response can be generated based on different key generation algorithms and the same parameters, which can reduce the time required to generate the first message authentication code.
  • the key generation algorithm used to generate the expected response is the same as the key generation algorithm used to generate the first message authentication code.
  • the first message authentication code can be generated based on the first key generation algorithm and the first parameter
  • the expected response can be generated based on the first key generation algorithm and the second parameter.
  • the parameters used to generate the expected response are the same as the parameters used to generate the first message authentication code.
  • the first message authentication code can be generated based on the first key generation algorithm and the first parameters
  • the expected response can be generated based on the second key generation algorithm and the first parameters.
  • the first key generation algorithm is different from the second key generation algorithm to ensure that the generated expected response is different from the first message authentication code.
  • the second key generation algorithm can be any function.
  • the second key generation algorithm can be any one of the following: f function, KDF or other lightweight functions.
  • the f function can be, for example, any one of the f1 function, f2 function, f3 function, f4 function, and f5 function defined by 3GPP.
  • KDF can be, for example, HMAC-SHA-256 or HMAC-SM3.
  • the lightweight function can be, for example, ASCON.
  • the first device may generate a second message authentication code and/or a response parameter.
  • the second message authentication code may be used to authenticate the authentication network element, and the response parameter may be used to authenticate the first device.
  • the second message authentication code may be represented by a second MAC, and the response parameter may be represented by a RES.
  • the second message authentication code is generated in the same manner as the first message authentication code.
  • the second message authentication code may be generated based on the first key generation algorithm and the first parameter.
  • the first key generation algorithm and the first parameter may be described in the foregoing description, and will not be described here for brevity.
  • MAC represents the first message authentication code or the second message authentication code
  • f represents the first key generation algorithm or the second key generation algorithm
  • RAND represents the second random number
  • N1 represents the first key
  • N2 represents the second random number
  • K represents the security credential.
  • the response parameter is generated in the same manner as the expected response.
  • the response parameter can be generated based on the second key generation algorithm and the first parameter, or the response parameter can be generated based on the first key generation algorithm and the second parameter.
  • the specific generation method of the response parameter can refer to the generation method of the expected response above, and for the sake of brevity, it will not be repeated here.
  • the first device may receive a first message authentication code from the authentication network element.
  • the first device may receive the first message authentication code from the authentication network element through a proxy node.
  • the first device may compare the first message authentication code with the second message authentication code to authenticate the authentication network element. If the first message authentication code and the second message authentication code are consistent, it indicates that the authentication network element has been successfully authenticated; if the first message authentication code and the second message authentication code are inconsistent, it indicates that the authentication network element has failed to authenticate.
  • the authentication network element may receive a response parameter from the first device.
  • the authentication network element may receive the response parameter from the first device through a proxy node.
  • the authentication network element may compare the response parameter with the expected response to authenticate the first device. If the response parameter is consistent with the expected response, it indicates that the first device is successfully authenticated; if the response parameter is inconsistent with the expected response, it indicates that the first device fails to authenticate.
  • step S1020 the authentication network element sends a first authentication request to the proxy node, wherein the first authentication request includes a first message authentication code.
  • the authentication network element sending the first authentication request to the proxy node may refer to the authentication network element directly sending the first authentication request to the proxy node, or may refer to the authentication network element sending the first authentication request to the proxy node through other devices.
  • the other devices may include, for example, a base station and/or a service domain network element.
  • the service domain network element may include an AMF and/or an SMF.
  • step S1030 the proxy node sends a first authentication request to the first device.
  • step S1040 the first device generates a second message authentication code based on the first key generation algorithm and the first parameter.
  • the specific generation method can refer to the above description.
  • the first device can generate the second message authentication code before receiving the first authentication request, or the first device can generate the second message authentication code after receiving the first authentication request.
  • step S1050 the first device authenticates the authentication network element based on the first message authentication code and the second message authentication code. If the first message authentication code is consistent with the second message authentication code, the first device can determine that the authentication network element is successfully authenticated; if the first message authentication code and the second message authentication code are inconsistent, the first device can determine that the authentication network element fails to authenticate.
  • step S1070 the first device sends a first authentication response to the proxy node.
  • the first authentication response may include response parameters.
  • the proxy node sends a first authentication response to the authentication network element.
  • the first authentication response may include response parameters.
  • the embodiment of the present application can authenticate the first device from the perspective of the home domain network, the service domain network and the access network.
  • the response parameters may include one or more of the following: a first response parameter, a second response parameter and a third response parameter.
  • the first response parameter can be used for the home domain network (or home domain network element) to authenticate the first device
  • the second response parameter can be used for the service domain network (or service domain network element) to authenticate the first device
  • the third response parameter can be used for the access network (or access network device) to authenticate the first device.
  • the first response parameter can be recorded as RES1
  • the second response parameter can be recorded as RES2
  • the third response parameter can be recorded as RES3.
  • the expected response may include one or more of the following: a first expected response, a second expected response, and a third expected response.
  • the first expected response may be used for the home domain network (or home domain network element) to authenticate the first device
  • the second expected response may be used for the service domain network (or service domain network element) to authenticate the first device
  • the third expected response may be used for the access network (or access network device) to authenticate the first device.
  • the first expected response may be recorded as XRES1
  • the second expected response may be recorded as XRES2
  • the third expected response may be recorded as XRES3.
  • the expected response may include a first expected response and a second expected response to authenticate the first device from the perspective of the home domain network and the service domain network. In some embodiments, the expected response may include a first expected response and a third expected response to authenticate the first device from the perspective of the home domain network and the access network. In some embodiments, the expected response may include a second expected response and a third expected response to authenticate the first device from the perspective of the service domain network and the access network. In some embodiments, the expected response may include a first expected response, a second expected response, and a third expected response to authenticate the first device from the perspective of the home domain network, the service domain network, and the access network.
  • the home domain network element may compare the first response parameter with the first expected response to authenticate the first device.
  • the first expected response may be generated by the home domain network element, and the first response parameter may be generated by the first device.
  • the first device may send the first response parameter to the home domain network element. If the first response parameter is consistent with the first expected response, the home domain network element may consider the authentication to be successful from the perspective of the home domain network. If the first response parameter is inconsistent with the first expected response, the home domain network element may consider the authentication to be failed from the perspective of the home domain network.
  • the home domain network element may include AUSF and/or UDM.
  • the access network device may compare the third response parameter with the third expected response to authenticate the first device. If the third response parameter is consistent with the third expected response, the access network device may consider the authentication successful from the perspective of the access network. If the third response parameter is inconsistent with the third expected response, the access network device may consider the authentication failed from the perspective of the access network.
  • the access network device may be a base station.
  • the third expected response may be generated by the home domain network element, and the home domain network element may send the third expected response to the access network device.
  • the third expected response may be generated by the access network device.
  • the authentication network element may send the first expected response to the access network device, and the access network device generates the third expected response based on the received first expected response. For example, in the case where the first key is a shared key between the first device and the access network device, the access network device may generate the third expected response based on the first expected response and the first key.
  • the third response parameter may be generated by the first device, and the first device may send the third response parameter to the access network device.
  • the first response parameter and the second message authentication code are based on the same key generation algorithm to reduce the computational complexity of the first device.
  • the first response parameter can be generated based on the first key generation algorithm and the second parameter.
  • the first device can generate the first response parameter based on the first key generation algorithm and the second parameter.
  • the first response parameter and the second message authentication code are based on the same parameter to reduce the computational complexity of the first device.
  • the first response parameter can be generated based on the second key generation algorithm and the first parameter.
  • the first device can generate the first response parameter based on the second key generation algorithm and the first parameter.
  • the first response parameter can be generated in the same manner as the expected response described above.
  • RES1 represents the first response parameter
  • f represents the first key generation algorithm or the second key generation algorithm
  • RAND represents the second random number
  • N1 represents the first key
  • N2 represents the second random number
  • K represents the security credential.
  • the second response parameter may be generated based on the first response parameter and the third parameter.
  • the first device may generate the second response parameter based on the first response parameter and the third parameter.
  • the third parameter may include one or more of the following: security credentials, service domain network name (SN name) (or service domain network identifier).
  • the second response parameter and the first response parameter may be generated based on the same key generation algorithm, or the second response parameter and the second message authentication code (or the first message authentication code) may be generated based on the same key generation algorithm.
  • the second response parameter may be generated based on the first key generation algorithm, the first response parameter, and the third parameter.
  • the second response parameter may be generated based on the second key generation algorithm, the first response parameter, and the third parameter.
  • RES2 represents the second response parameter
  • f represents the first key generation algorithm or the second key generation algorithm
  • RES1 represents the first response parameter
  • SN name represents the service domain network name or identifier
  • K represents the security credential.
  • RES3 represents the third response parameter
  • f represents the first key generation algorithm or the second key generation algorithm
  • RES1 represents the first response parameter
  • N1 represents the first key
  • the first expected response is similar to the first response parameter in generating manner
  • the second expected response is similar to the second response parameter in generating manner
  • the third expected response is similar to the third response parameter in generating manner, which will not be described again for brevity.
  • the authentication network element may generate a first anonymous key.
  • the first anonymous key may be used for secure transmission between the first device and the network side.
  • the first anonymous key in order to reduce the computational complexity of generating the first anonymous key, can be generated based on the first key generation algorithm or the second key generation algorithm.
  • the first anonymous key can be generated based on the first key generation algorithm and the ninth parameter.
  • the first anonymous key can be generated based on the second key generation algorithm and the ninth parameter.
  • the ninth parameter can include one or more of the following parameters: security credentials, a first random number, a second random number, and the first key.
  • AK represents the first anonymous key
  • K represents the security credential
  • RAND represents the second random number
  • f represents the first key generation algorithm or the second key generation algorithm.
  • the first anonymous key in order to reduce the computational complexity of generating the first anonymous key, can be generated by an XOR operation.
  • the first anonymous key can be generated by an XOR operation of the security credential and the first key.
  • AK represents the first anonymous key
  • K represents the security credential
  • N1 represents the first key
  • represents the XOR operation.
  • the authentication network element can generate AK based on the shared key N1.
  • the first device may also generate a second anonymous key.
  • the second anonymous key is generated in the same manner as the first anonymous key, and will not be described in detail for brevity.
  • the hidden identity can be generated based on the identity of the first device and the first key.
  • the hidden identity can be generated based on the identity of the first device, the first key and the security credential.
  • the identity of the first device can be understood as the real identity of the first device.
  • the following describes in detail the method for generating the hidden identity identifier by taking the generation of the hidden identity identifier based on the identity identifier of the first device and the first key as an example.
  • DIDi represents a hidden identity
  • IDi represents an identity of a first device
  • N1 represents a first key
  • represents an exclusive-OR operation
  • DIDi represents a hidden identity
  • IDi represents an identity of a first device
  • N1 represents a first key
  • f represents a third key generation algorithm
  • the first key may be a shared key (or random number) between the first device and the network side (such as an authentication network element), or may be a shared key between the first device and the proxy node, or may be a shared key between the first device and the base station.
  • the shared key may be a physical layer key. If the first key is a physical layer key, the first device may not store the first key in advance, but obtain the first key by extracting physical layer channel characteristics.
  • the authentication network element may send a new first key to the first device to update the hidden identity.
  • the proxy node may send the second authentication request to the authentication network element.
  • the second authentication request sent by the proxy node may include one or more of the following information: the first key, the identity of the first device, the hidden identity, and the identity of the proxy node.
  • the identity of the proxy node may include one or more of the following: GPSI, SUCI, globally unique temporary identifier (GUTI), SUPI.
  • the proxy node may adopt different processing strategies according to the first key.
  • the first key is a shared key between the first device and the network side
  • the second authentication request sent by the proxy node may include one or more of the following: a hidden identity and an identifier of the proxy node.
  • the proxy node may de-anonymize the hidden identity to obtain the identity of the first device. For example, the proxy node may determine the identity of the first device based on the first key and the hidden identity.
  • DIDi represents a hidden identity
  • IDi represents an identity of a first device
  • N1 represents a first key
  • represents an exclusive-OR operation
  • DIDi represents a hidden identity
  • IDi represents an identity of a first device
  • N1 represents a first key
  • f represents a third key generation algorithm
  • the second authentication request sent by the first device may include one or more of the following: the first key, the identity of the first device, and the identity of the proxy node.
  • the proxy node may send the second authentication request message via a NAS message or an AS message.
  • the proxy node may send the second authentication request message via a NAS security context or an AS security context.
  • the authentication network element may use the identity identifier of the first device to generate a fourth key described below.
  • Ks represents the second key
  • AK represents the first anonymous key
  • N1 represents the first key
  • N2 represents the first random number
  • UE ID represents the identifier of the proxy node
  • IDi represents the identity identifier of the first device
  • SN name represents the name of the service domain network
  • f represents the sixth key generation algorithm.
  • the second key can be used to generate an AKMA key. That is, the first device can generate an AKMA key based on the second key. Alternatively, the authentication network element can generate an AKMA key based on the second key.
  • the way the first device generates the AKMA key is the same as the way the authentication network element generates the AKMA key.
  • the way the authentication network element generates the AKMA key can refer to the way the first device generates the AKMA key, and for the sake of brevity, it will not be repeated.
  • the first device may generate an AKMA key based on the second key and the fourth key generation algorithm.
  • the fourth key generation algorithm may be the first key generation algorithm or the second key generation algorithm to reduce the computational complexity of the first device.
  • the first device may generate an AKMA key based on the second key, the fourth key generation algorithm, and a fifth parameter.
  • the fifth parameter may include one or more of the following: AKMA, an identity of the first device.
  • K AKMA represents the AKMA key
  • Ks represents the first anonymous key
  • IDi represents the identity of the first device.
  • the second key can be used to generate a key identifier.
  • the first device can generate a key identifier based on the second key.
  • the key identifier may include, for example, an A-TID and/or an A-KID.
  • the A-TID may be generated based on the identity identifier of the first device, the first anonymous key, and a seventh key generation algorithm.
  • the seventh key generation algorithm may be the first key generation algorithm or the second key generation algorithm.
  • f represents the seventh key generation algorithm
  • Ks represents the first anonymous key
  • IDi represents the identity of the first device.
  • the A-KID may be generated based on the A-TID.
  • the A-KID may be generated based on the A-TID and a seventh parameter.
  • the seventh parameter may include one or more of the following parameters: a RID and a home network identifier (HNI).
  • HNI home network identifier
  • the A-KID may be obtained by cascading the A-TID, the RID, and the seventh parameter.
  • the authentication network element may send key parameters to the AAnF and/or a key management server (KMS), and the key parameters may include one or more of the following: an AKMA key, an A-KID, and an identifier of the first device.
  • KMS key management server
  • the AAnF and/or AMF may generate an application key (denoted as K AF ) based on the AKMA key.
  • the application key may be generated based on an eighth key generation algorithm and an eighth parameter.
  • the eighth parameter may include one or more of the following parameters: AF ID, IDi, an identifier of the proxy node, A-KID.
  • the eighth key generation algorithm may be the first key generation algorithm or the second key generation algorithm to reduce the computational complexity of the first device.
  • K AF represents an application key
  • f represents an eighth key generation algorithm
  • AF ID represents an identifier of AF
  • IDi represents an identity identifier of the first device
  • UE ID represents an identifier of the proxy node.
  • the AAnF may generate an application key after receiving an application key request message from the AF.
  • the first device generates the application key in the same manner as the AAnF generates the application key, which will not be described here for brevity.
  • the first device may generate the application key after sending an application session establishment request message to the AF.
  • the application key can be used to generate a third key, and the third key can be used for secure communication between the first device and the proxy node.
  • the first device and the proxy node can perform secure communication based on the third key.
  • the third key may include an integrity protection key and/or an encryption key. That is, the device and the proxy node may generate an integrity protection key and/or an encryption key based on the application key.
  • the method of generating the integrity protection key and/or the encryption key based on the application key may be a method in the related art, and the embodiments of the present application do not specifically limit this.
  • the third key may be generated based on the application key and the first key.
  • the first key is a shared key between the first device and the proxy node.
  • the third key may be generated by the application key and the first key by means of an exclusive OR.
  • Ku1 represents the third key
  • K AF represents the application key
  • N1 represents the first key
  • represents an exclusive-OR operation.
  • the third key (such as Ku1) can be used to further generate an integrity protection key and/or an encryption key.
  • the embodiment of the present application can provide a simplified way for mobility management of the first device by first generating a third key and then generating an integrity protection key and/or an encryption key. For example, if the first device moves, causing the connected proxy node to change, the first device can directly generate a third key based on the shared key between the first device and the proxy node, and further generate an integrity protection key and/or an encryption key, so that there is no need to perform the authentication and key negotiation process between the first device and the network side.
  • the shared key between the first device and the first proxy node is N1
  • the shared key between the first device and the second proxy node is N3.
  • the first device can generate a third key based on the application key and N1, and further generate an integrity protection key and/or encryption key for secure communication with the first proxy node.
  • the first device and the second proxy node are in a connected state, the first device can generate a third key based on the application key and N3, and further generate an integrity protection key and/or encryption key for secure communication with the second proxy node.
  • the first device can skip the authentication and key negotiation process to generate different integrity protection keys and/or encryption keys, but can generate different integrity protection keys and/or encryption keys based on different first keys to securely communicate with different proxy nodes.
  • the authentication network element may also send the first random number to the first device so that the first device may generate the second message authentication code based on the first random number.
  • the authentication network element may use the first anonymous key to protect the transmission security of the first random number.
  • the authentication network element may perform an XOR operation on the first anonymous key and the first random number to obtain the tenth parameter, that is, the tenth parameter may be N2 ⁇ AK.
  • the authentication network element may send the tenth parameter to the first device, or the authentication network element may send the eleventh parameter to the first device, and the eleventh parameter may be N2 ⁇ AK
  • MAC is the first message authentication code
  • N2 is the first random number
  • AK is the first anonymous key
  • represents cascade.
  • the first device After the first device receives the tenth parameter or the eleventh parameter sent by the authentication network element, it can determine the first random number based on the first anonymous key. Then, based on the first random number, it generates a second message authentication code. Further, the first device can authenticate the authentication network element based on the first message authentication code and the second message authentication code.
  • the authentication network element may also send the second random number to the first device, so that the first device generates a second message authentication code based on the second random number.
  • FIG11 shows the process of authentication between the first device and the authentication network element.
  • the first device may share a key K with the authentication network element, and the key K is the security credential described above.
  • the first device may share a key N1 with the base station and/or the proxy node, and the key N1 is the first key described above.
  • the key N1 may be a physical layer key.
  • the first device sends an authentication request to the proxy node.
  • the authentication request may include a hidden identity DIDi of the first device.
  • the hidden identity DIDi may be generated based on the identity IDi of the first device.
  • the proxy node sends an authentication request to the service domain network element.
  • the proxy node may send the authentication request to the service domain network element through a base station.
  • the service domain network element may include one or more of AMF, SEAF, SMF, and A-NF.
  • the authentication request may include the DIDi and the identification of the proxy node.
  • the authentication request may include the DIDi and the identification of the proxy node.
  • the proxy node may DIDi de-anonymizes and obtains the identity identifier IDi of the first device.
  • the authentication request sent by the proxy node may include one or more of the following: IDi, the identifier of the proxy node, and N1.
  • the identification of the proxy node may include one or more of GPSI, SUCI, and GUTI.
  • the service domain network element sends an authentication request to the authentication network element, and the authentication request may include the name of the service domain network (SN name).
  • the authentication request may also include DIDi and the identifier of the proxy node.
  • the authentication request may include IDi, N1 and the identifier of the proxy node.
  • the authentication request may include an identifier that can indicate the authentication type.
  • the authentication type identifier may be indicated by one or more of the following: BSF ID, the identification type of the A-NF, the type of IDi, and the authentication type identifier (Auth_type_ID).
  • the authentication network element may confirm the authentication type.
  • the authentication network element may query the subscription credentials of the first device and the proxy node through the core network element (such as UDM).
  • the core network element may check the subscription credentials of the first device and the proxy node based on IDi and the identity of the proxy node to determine whether the first device is entitled to use the A-IoT service.
  • the authentication network element can determine the authentication type based on an identifier that can indicate the authentication type, such as determining whether the authentication type is A-IoT authentication.
  • the authentication network element may generate a first message authentication code (referred to as MAC) and a first expected response (referred to as XRES1).
  • N2 may be a key shared between the first device and the authentication network element, or N2 may be a random number selected by the authentication network element.
  • the parameters introduced in the above-mentioned generation method of MAC and XRES1 include RAND, N1 and N2, but this is only an example and is not specifically limited in the embodiments of the present application.
  • the parameters introduced in MAC and XRES1 may only include RAND, or RAND and N1, or RAND and N2.
  • MAC and XRES1 are generated in different ways so that the obtained MAC and XRES1 values are different. For example, if the same function f is used when calculating MAC and XRES1, the introduced parameters can be different. For another example, if the same parameters are introduced when calculating MAC and XRES1, different functions f can be used.
  • function f may be any function f1-f5 defined by 3GPP.
  • function f may be a KDF (such as HMAC-SHA256).
  • function f may be other lightweight functions (such as ASCON).
  • the authentication network element may generate a second expected response XRES2, where XRES2 is material for the serving domain network to authenticate the first device.
  • the authentication network element may generate a third expected response XRES3, where XRES3 is material for the base station to authenticate the first device.
  • the authentication network element may generate an authentication vector.
  • the authentication vector may include multiple parameters generated and/or selected by the authentication network element.
  • the authentication vector may include one or more of the following: RAND, N2, AK, MAC, XRES1, XRES2, and XRES3. If N2 is selected by the authentication network element, the authentication vector may include N2; if N2 is shared between the first device and the authentication network element, the authentication vector may not include N2.
  • the authentication network element sends an authentication response to the serving domain network element.
  • the authentication response includes an authentication vector AV.
  • the authentication response may also include IDi.
  • the serving domain network element sends an authentication request (or authentication response) to the base station.
  • the authentication request includes an authentication vector.
  • the authentication vector may not include XRES2.
  • the authentication response may also include IDi.
  • step S1116 if the authentication vector includes XRES3, the base station stores XRES3; if the authentication vector does not include XRES3, the base station may generate XRES3 based on XRES1.
  • the base station sends an authentication request to the first device through the proxy node.
  • the authentication request may include RAND and MAC.
  • the authentication request may include RAND and N2 ⁇ AK
  • the first device may verify the MAC. After the verification is successful, the first device may calculate the first response parameter RES1, the second response parameter RES2, and the third response parameter RES3. In addition, the first device may also generate a key Ks.
  • step S1122 the first device sends an authentication response to the base station through the proxy node.
  • the authentication response includes RES1, RES2 and RES3.
  • step S1124 the base station compares RES3 and XRES3 to authenticate the first device. If RES3 and XRES3 are consistent, the first device is successfully authenticated. From the perspective of the access network, the base station considers that the first device is successfully authenticated.
  • step S1126 after the first device is successfully authenticated, the base station sends an authentication response to the serving domain network element, which includes RES2 and RES1.
  • the service domain network element can obtain RES2 from the authentication response.
  • the service domain network element compares RES2 and XRES2 to authenticate the first device. After the authentication is successful, the service domain network element considers that the first device is successfully authenticated from the perspective of the service domain network.
  • step S1130 the serving domain network element sends an authentication request (or authentication response) to the authentication network element, and the authentication request includes RES1.
  • the authentication network element may also generate a key Ks.
  • step S1134 the authentication network element sends a response message to the proxy node or the authentication network element sends a response message to the serving domain network element.
  • the authentication network element may send a response message to the proxy node via the serving domain network element and the base station.
  • the authentication response may include a key Ks.
  • the key Ks may be used by the proxy node to generate an integrity protection key and/or an encryption key.
  • FIG. 12 shows the process of generating an AKMA key after the initial authentication (or lightweight initial authentication) is completed.
  • step S1202 the authentication network element generates a key Ks, an A-KID and an AKMA key.
  • the first device generates a key Ks, an A-KID and an AKMA key.
  • the authentication network element may generate an A-TID based on a key Ks.
  • the A-TID may be generated based on Ks and IDi.
  • the authentication network element may generate an A-KID based on the A-TID.
  • the A-KID may be generated based on the A-TID, the RID, and the HNI.
  • the authentication network element may generate an AKMA key (denoted as K AKMA ).
  • K AKMA AKMA key
  • the AKMA key may be generated based on Ks, in which case the role of Ks is the same as that of K AUSF in the related art.
  • the AKMA key may be generated based on Ks, IDi, and AKMA.
  • the authentication network element may send a registration request to AAnF or KMS, and the registration request may include one or more of the following information: AKMA key, A-KID and the identifier IDi of the first device.
  • the registration request may be, for example, an AKMA anchor key registration request (such as Naanf_AKMA_AnchorKey_Register Request).
  • the first device may generate a key Ks, an A-KID, and an AKMA key.
  • the first device generates an A-KID in a manner similar to the manner in which the authentication network element generates an A-KID, and the first device generates an AKMA key in a manner similar to the manner in which the authentication network element generates an AKMA key, which will not be described here for brevity.
  • FIG. 13 shows the process of generating an application key.
  • the first device sends an application session establishment request to the AF.
  • the application session establishment request may include the A-KID.
  • the application session establishment request may also be other communication requests.
  • the application session establishment request may include UE ID and DIDi.
  • UE ID may be, for example, GPSI.
  • UE ID is the identifier of the proxy node.
  • step S1304 after receiving the application session establishment request, the AF sends an application key request to the AAnF or KMS.
  • the application key request may include the A-KID.
  • the application key request may also include the UE ID and the DIDi.
  • the application key K AF may be generated based on Ks, AF ID, IDi, UE ID and A-KID.
  • the AAnF or the KMS may store the K AF and the validity period of the K AF to facilitate mobility management of the first device.
  • step S1310 the AF sends an application key response to the proxy node, wherein the application key response includes K AF and the validity period of K AF .
  • the proxy node In step S1312, the proxy node generates a key Ku1.
  • the key Ku1 may be generated based on K AF .
  • Ku1 may be generated based on K AF and N1.
  • step S1314 the proxy node sends an application session establishment response to the first device.
  • step S1316 the first device generates an application key K AF and a key Ku1.
  • the first device generates K AF in a similar manner to AAnF or KMS.
  • the first device generates key Ku1 in a similar manner to the proxy node, which is not described here for brevity.
  • the first device may send a response message to the proxy node.
  • the key Ku1 can be used to generate an integrity protection key and/or an encryption key, which can be used to ensure secure communication between the first device and the proxy node.
  • the first device uses another device (such as UEx) as a proxy node, the shared key Nx between the first device and UEx, and K AF , can be used to generate a subordinate key Kux.
  • the Kux can be used to further generate an integrity protection key and/or an encryption key. In this way, when the proxy node changes, the first device does not necessarily need to perform the authentication and key negotiation process of the first device, thereby reducing the complexity of the first device.
  • the security credential is a 3GPP security credential
  • the first device does not need to communicate with the network side through a proxy node, that is, the first device can communicate directly with the network side.
  • Example 2 The difference between Example 2 and Example 1 is: 1. There is no proxy node involved, and 2.
  • the authentication information does not include the proxy node information (such as the proxy node identifier or UE ID).
  • Example 2 is basically similar to the solution of Example 1. For the contents not described in detail in Example 2, please refer to the description of Example 1.
  • FIG 14 is a flow chart of an authentication method provided by an embodiment of the present application.
  • the authentication network element in step S1410, the authentication network element generates a first message authentication code and/or an expected response.
  • the generation method of the first message authentication code and the expected response can refer to the description of Example 1.
  • the authentication network element sends a first authentication request to the access network device.
  • the first authentication request may include a first message authentication code.
  • the authentication network element sends the first authentication request to the access network device, which may refer to the authentication network element directly sending the first authentication request to the access network device, or may refer to the authentication network element sending the first authentication request to the access network device through other devices.
  • the other devices may include, for example, service domain network elements.
  • the service domain network elements may include, for example, AMF and/or SMF.
  • step S1430 the access network device sends a first authentication request to the first device.
  • step S1440 the first device generates a second message authentication code based on the first key generation algorithm and the second parameter.
  • step S1450 the first device authenticates the network element based on the first message authentication code and the second message authentication code.
  • step S1460 when the authentication network element is successfully authenticated, the first device generates a response parameter.
  • step S1470 the first device sends a first authentication response to the access network device, wherein the first authentication response includes a response parameter.
  • step S1480 the access network device sends a first authentication response to the authentication network element.
  • the first authentication response includes a response parameter.
  • the access network device may send a response parameter to the authentication network element. After receiving the response parameter, the authentication network element may compare the response parameter with an expected response to authenticate the first device.
  • the first device before receiving the first authentication request from the access network device, may send a second authentication request to the access network device.
  • the first device may trigger an authentication process between the first device and the network side by sending the second authentication request.
  • the second authentication request may include a hidden identity of the first device.
  • the first device may perform anonymization on the identity of the first device to obtain a hidden identity.
  • the access network device may send the second authentication request to the authentication network element.
  • the second authentication request sent by the access network device may include one or more of the following information: the first key, the identity of the first device, and the hidden identity.
  • the access network device may adopt different processing strategies according to different first keys.
  • the first key is a shared key between the first device and the network side
  • the second authentication request sent by the access network device may include a hidden identity.
  • the access network device can determine the identity of the first device by the following formula:
  • DIDi represents a hidden identity
  • IDi represents an identity of a first device
  • N1 represents a first key
  • represents an exclusive-OR operation
  • DIDi represents a hidden identity
  • IDi represents an identity of a first device
  • N1 represents a first key
  • f represents a third key generation algorithm
  • the second authentication request sent by the first device may include one or more of the following: the first key and the identity of the first device.
  • a second key Ks can be generated.
  • the second key can also be understood as a shared key between the first device and the authentication network element.
  • the second key can be generated based on a sixth key generation algorithm and a sixth parameter.
  • the sixth key generation algorithm can be a first key generation algorithm or a second key generation algorithm to reduce the computational complexity of the first device.
  • the sixth parameter may include one or more of the following parameters: a first anonymous key, a first key, a first random number, an identifier of the first device, and a name of the service domain network.
  • FIG15 shows the process of authentication between the first device and the authentication network element.
  • the first device can share a key K with the authentication network element, and the key K is the security credential described above.
  • the first device can share a key N1 with the base station, and the key N1 is the first key described above.
  • the key N1 can be a physical layer key.
  • FIG. 15 The method shown in FIG. 15 is substantially similar to the solution shown in FIG. 11 .
  • the first device sends an authentication request to the base station.
  • the authentication request may include a hidden identity DIDi of the first device.
  • the hidden identity DIDi may be generated based on the identity IDi of the first device.
  • step S1504 the base station sends an authentication request to the serving domain network element.
  • the authentication request may include DIDi.
  • N1 is a shared key between the first device and the authentication network element
  • the authentication request may include DIDi.
  • the base station may de-anonymize DIDi based on N1 to obtain the identity IDi of the first device.
  • the authentication request sent by the base station may include one or more of the following: IDi and N1.
  • the service domain network element sends an authentication request to the authentication network element, and the authentication request may include the name of the service domain network (SN name).
  • the authentication request may also include DIDi, or the authentication request may include IDi and N1.
  • the authentication network element may confirm the authentication type.
  • the authentication network element may de-anonymize DIDi to obtain IDi.
  • the authentication network element may generate a first anonymous key AK, a first message authentication code, a first expected response, a second expected response, and a third expected response.
  • the authentication network element may generate an authentication vector.
  • the authentication vector may include multiple parameters generated and/or selected by the authentication network element.
  • the authentication vector may include one or more of the following: RAND, N2, AK, MAC, XRES1, XRES2, and XRES3. If N2 is selected by the authentication network element, the authentication vector may include N2; if N2 is shared between the first device and the authentication network element, the authentication vector may not include N2.
  • XRES3. In other embodiments, the authentication vector may be AV RAND
  • the authentication vector may also include one or more of the following parameters: IDi, UE ID, SN name.
  • step S1510 the authentication network element sends an authentication response to the serving domain network element, wherein the authentication response includes an authentication vector AV.
  • the serving domain network element may store XRES2 in the authentication vector.
  • the serving domain network element sends an authentication request (or authentication response) to the base station.
  • the authentication request includes an authentication vector.
  • the authentication vector may not include XRES2.
  • step S1516 if the authentication vector includes XRES3, the base station stores XRES3; if the authentication vector does not include XRES3, the base station may generate XRES3 based on XRES1.
  • the base station sends an authentication request to the first device.
  • the authentication request may include RAND and MAC.
  • the authentication request may include RAND and N2 ⁇ AK
  • the first device can verify the MAC. After the verification is successful, the first device can calculate the first response parameter RES1, the second response parameter RES2 and the third response parameter RES3. In addition, the first device can also generate a key Ks.
  • step S1522 the first device sends an authentication response to the base station, which includes RES1, RES2 and RES3.
  • step S1524 the base station compares RES3 and XRES3 to authenticate the first device. If RES3 and XRES3 are consistent, the first device is successfully authenticated. From the perspective of the access network, the base station considers that the first device is successfully authenticated.
  • step S1526 after the first device is successfully authenticated, the base station sends an authentication response to the serving domain network element, which includes RES2 and RES1.
  • the service domain network element can obtain RES2 from the authentication response.
  • the service domain network element compares RES2 and XRES2 to authenticate the first device. After the authentication is successful, the service domain network element considers that the first device is successfully authenticated from the perspective of the service domain network.
  • step S1530 the serving domain network element sends an authentication request (or authentication response) to the authentication network element, and the authentication request includes RES1.
  • step S1532 the authentication network element compares RES1 and XRES1 to authenticate the first device. After the authentication is successful, the authentication network element considers that the first device is successfully authenticated from the perspective of the home domain network.
  • the authentication network element may also generate a key Ks.
  • the authentication network element may send a response message to the serving domain network element.
  • the authentication network element and the first device may generate an AKMA key according to the method shown in Figure 12.
  • the authentication network element may send a registration request to AAnF or KMS, and the registration request may include one or more of the following information: AKMA key, A-KID and the identification IDi of the first device.
  • FIG. 16 shows the process of generating an application key.
  • the first device sends an application session establishment request to the AF.
  • the application session establishment request may include an A-KID.
  • the application session establishment request may also be other communication requests.
  • the application session establishment request may include a DIDi.
  • step S1604 after receiving the application session establishment request, the AF sends an application key request to the AAnF or KMS.
  • the application key request may include the A-KID. In some embodiments, the application key request may also include the DIDi.
  • step S1606 after receiving the application key request, the AAnF or KMS may generate an application key based on the A-KID.
  • the application key K AF may be generated based on Ks, AF ID, IDi and A-KID.
  • step S1608 the AAnF or KMS sends an application key response to the AF, which includes K AF and the validity period of K AF .
  • the AAnF or the KMS may store the K AF and the validity period of the K AF to facilitate mobility management of the first device.
  • step S1610 the AF sends an application session establishment response to the first device.
  • the first device and the AF may establish a secure connection (eg, a TLS connection) based on the K AF .
  • a secure connection eg, a TLS connection
  • the security credential is a non-3GPP security credential, such as the security credential is a shared key between the first device and the application function network element, and the first device communicates with the network side through the proxy node.
  • FIG 17 is a flowchart of an authentication method provided by an embodiment of the present application.
  • the first device sends an authentication request to the application function network element.
  • the first device may send the authentication request to the application function network element through a proxy node.
  • the authentication request may include one or more of the following information: a hidden identity of the first device, an identity of the first device, an identity of the proxy node, and a first key.
  • the authentication request may include a hidden identity of the first device and an identity of the proxy node.
  • the authentication request may include an identity of the first device, an identity of the proxy node, and a first key.
  • the application function network element performs an authorization check on the first device and/or the proxy node. For example, the application function network element may check whether the first device is authorized to use a certain service (such as an A-IoT service). For another example, the application function network element may check whether the proxy node is authorized to provide a service (such as an A-IoT service) as a proxy for the first device.
  • a certain service such as an A-IoT service
  • the application function network element may check whether the proxy node is authorized to provide a service (such as an A-IoT service) as a proxy for the first device.
  • the application function network element may manage a mapping between a whitelist of the first device and the proxy node.
  • the application function network element When the application function network element performs an authorization check on the first device, it can perform an authorization check on the first device based on the identity identifier IDi of the first device. When the application function network element performs an authorization check on the proxy node, it can perform an authorization check on the proxy node based on the identifier of the proxy node (such as UE ID).
  • the identity identifier of the first device and the identifier of the proxy node may be sent by the proxy node to the application function network element.
  • the first device may send an authentication request to the proxy node, and the authentication request may include the hidden identity DIDi of the first device.
  • the proxy node may de-anonymize the hidden identity DIDi to obtain the identity of the first device.
  • the proxy node may send an authentication request to the application function network element, and the authentication request may include the identity identifier IDi of the first device and the proxy node. To ensure information security, the proxy node can send an authentication request through the NAS security context or the AS security context.
  • step S1730 when the authorization check of the first device and/or the proxy node succeeds, the application function network element sends an authentication request to the authentication network element.
  • the application function network element may not send an authentication request to the authentication network element, that is, the subsequent authentication and key negotiation process may not be performed.
  • the application function network element can first perform an authorization check on the first device and the proxy node, and only perform the subsequent authentication and key negotiation process when the authorization check is successful, which is conducive to reducing the computational complexity of the first device. For example, if the authorization check is performed after the authentication and key negotiation process is completed, the authorization check fails, which will make the authentication and key negotiation process of the first device invalid, thereby causing a waste of resources and not conducive to reducing the computational complexity of the first device.
  • the hidden identity may be generated based on the first key N1.
  • the first key may be a shared key between the first device and the application function network element, or the first key may be a shared key (such as a physical layer key) between the first device and the proxy node.
  • the proxy node can de-anonymize the hidden identity based on the first key to obtain the identity of the first device. If the first key is a shared key between the first device and the application function network element, the application function network element can de-anonymize the hidden identity to obtain the identity of the first device.
  • the authentication request sent by the proxy node to the application function network element may include the identity of the first device, the identity of the proxy node, and the first key. If the first key is a shared key between the first device and the application function network element, the authentication request sent by the proxy node to the application function network element may include the hidden identity of the first device and the identity of the proxy node.
  • the application function network element may send the security credential K to the authentication network element, or the application function network element may send the subordinate key (denoted as Kb) of the security credential K to the authentication network element.
  • the subordinate key is a key generated based on the security credential K.
  • the authentication network element may determine the security credential K based on the subordinate key.
  • the subordinate key may be generated based on one or more of the security credential K, the first key (denoted as N1), and the first random number (denoted as N2).
  • N2 may be a shared key between the first device and the AF, or, N2 may be a random number selected by the AF.
  • the authentication network element may generate the parameters required in the authentication process based on the security credential K.
  • the parameters may be, for example, parameters contained in the authentication vector.
  • the parameters may include, for example, one or more of the following: a first anonymous key, a first message authentication code, an expected response, a key Ks, etc.
  • the key Ks is a shared key generated after the first device and the authentication network element are successfully authenticated.
  • the first anonymous key may be generated based on the security credential K and a target parameter.
  • the target parameter may include RAND and/or N1.
  • the first message authentication code may be generated based on the security credential K and a target parameter.
  • the target parameter may include one or more of the following: RAND, N1, and N2.
  • the target parameter includes RAND.
  • the target parameter includes RAND and N1.
  • the target parameter includes RAND and N2.
  • the target parameter includes RAND, N1, and N2.
  • the expected response may be generated based on the security credentials K and target parameters.
  • the target parameters may include one or more of the following: RAND, N1, and N2.
  • the target parameters include RAND.
  • the target parameters include RAND and N1.
  • the target parameters include RAND and N2.
  • the target parameters include RAND, N1, and N2.
  • the key Ks may be generated based on the security credential K and the target parameters.
  • the target parameters may include one or more of the following: AK, N1, N2, IDi, UE ID, AF ID, HNI, SN name.
  • the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, HNI.
  • the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, SN name.
  • the authentication network element can generate the parameters required in the authentication process based on the key Kb.
  • the parameters can be, for example, parameters included in the authentication vector.
  • the parameters can include, for example, one or more of the following: a first message authentication code, an expected response, a key Ks, etc.
  • the first message authentication code may be generated based on the key Kb and the target parameter.
  • the target parameter may include one or more of the following: RAND, N1, and N2.
  • the target parameter includes RAND.
  • the target parameter includes RAND and N1.
  • the target The parameters include RAND and N2.
  • the target parameters include RAND, N1 and N2.
  • the expected response may be generated based on the security credentials K and target parameters.
  • the target parameters may include one or more of the following: RAND, N1, and N2.
  • the target parameters include RAND.
  • the target parameters include RAND and N1.
  • the target parameters include RAND and N2.
  • the target parameters include RAND, N1, and N2.
  • the key Ks may be generated based on the security credential K and the target parameters.
  • the target parameters may include one or more of the following: AK, N1, N2, IDi, UE ID, AF ID, HNI, SN name.
  • the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, HNI.
  • the target parameters may include AK, N1, N2, IDi, UE ID, AF ID, SN name.
  • the first device may generate one or more of the following parameters in the same manner as the authentication network element: a first anonymous key, a second message authentication code, a response parameter, a key Ks, etc.
  • the second message authentication code is generated in the same manner as the first message authentication code.
  • the response parameter is generated in the same manner as the expected response.
  • the above-mentioned expected response may include a first expected response, a second expected response, and a third expected response.
  • the first expected response may be generated in the above-mentioned expected response.
  • the second expected response and the third expected response may be generated based on the first expected response, and the specific generation method may refer to the description in other examples.
  • the above response parameters may include a first response parameter, a second response parameter, and a third response parameter.
  • the first response parameter may be generated in the manner described above.
  • the second response parameter and the third response parameter may be generated based on the first response parameter, and the specific generation method may refer to the description in other examples.
  • the f in the above formula may be the same key generation algorithm, or the f in the above formula may include a first key generation algorithm and a second key generation algorithm.
  • the first key generation algorithm is used to generate a first message authentication code or a second message authentication code
  • the second key generation algorithm is used to generate an expected response or a response parameter.
  • the first device and the authentication network element may generate one or more of A-TID, A-KID and AKMA key based on Ks.
  • A-TID A-TID
  • A-KID A-KID
  • AKMA key a key that is generated by the first device and the authentication network element.
  • the application function network element can directly receive the application key sent by AAnF. For example, after generating the application key, AAnF can directly send the application key to AF without the need for AF to send an application key request to trigger it.
  • the AF may send the application key to the proxy node.
  • the application key may be used by the proxy node to generate a third key (such as Ku1).
  • the first device may share a key K with the AF.
  • the first device sends an authentication request to the proxy node.
  • the authentication request includes the hidden identity DIDi of the first device.
  • the hidden identity DIDi can be generated based on the identity IDi of the first device.
  • DIDi IDi ⁇ N1.
  • step S1804 the proxy node sends an authentication request to the AF.
  • the authentication request may include the DIDi and the identification of the proxy node.
  • the authentication request may include the DIDi and the identification of the proxy node.
  • the proxy node can de-anonymize DIDi based on N1 to obtain the identity IDi of the first device.
  • the authentication request sent by the proxy node may include one or more of the following: IDi, the identity of the proxy node, and N1.
  • the proxy node may send an authentication request via a NAS message.
  • the proxy node may send an authentication request via a NAS security context.
  • step S1806 AF may perform authorization management.
  • the AF can de-anonymize the first device according to N1 to obtain the identity IDi of the first device.
  • the AF may check whether the first device is authorized. In some embodiments, the AF may check whether the proxy node is authorized to provide services (such as A-IoT services) for the first device. In some embodiments, the AF may also check the mapping relationship between the first device and the proxy node. The AF may manage the mapping between the whitelist of the first device and the proxy node list.
  • the AF may directly perform an authorization check and manage the mapping between the first device and the proxy node.
  • the authentication request may include one or more of the following: K, K
  • N1 may be a shared key between the first device and the proxy node, or N1 may be a shared key between the first device and the AF.
  • N2 may be a shared key between the first device and the AF, or N2 may be a random number selected by the AF.
  • the authentication request may include one or more of the following: Kb, Kb
  • the authentication request may include Kb
  • the authentication request may include an identifier that can indicate the authentication type.
  • the authentication type identifier can be indicated by one or more of the following: AF ID, type of IDi, authentication type identifier (Auth_type_ID).
  • step S1810 the first device performs authentication (such as AKA authentication) with the authentication network element.
  • authentication such as AKA authentication
  • the authentication method can refer to the above description, such as the description of FIG. 11 above.
  • the proxy node may forward the authentication message between the first device and the authentication network element.
  • the authentication network element may query the subscription credentials of the first device and the proxy node through the core network element (such as UDM).
  • the core network element may check the subscription credentials of the first device and the proxy node based on IDi and the identity of the proxy node to determine whether the first device is entitled to use the A-IoT service.
  • the authentication network element generates an authentication vector.
  • the authentication network element may select a random number RAND, which may be used to generate the authentication vector.
  • the authentication network element can generate authentication parameters based on K and RAND.
  • the authentication parameters include one or more of the following: a first anonymous key AK, a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
  • the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
  • the authentication network element can generate authentication parameters based on Kb and RAND.
  • the authentication parameters include one or more of the following: a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
  • the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
  • the first device may calculate the second message authentication code and compare the first message authentication code with the second message authentication code to authenticate the network element. After successful authentication, the first device may generate a key Ks.
  • the first device may generate an A-TID.
  • the first device may generate a response parameter RES, and the calculation method of RES is the same as the calculation method of XRES.
  • the first device may send an authentication response to the authentication network element through the proxy node, and the authentication response may include a response parameter RES.
  • the authentication network element may compare RES and XRES to authenticate the first device. If RES and XRES are consistent, the first device authentication is successful; if RES and XRES are inconsistent, the first device authentication fails. After the first device is successfully authenticated, the authentication network element may generate one or more of the following parameters: Ks, A-TID, A-KID, and AKMA key. The authentication network element generates these parameters in the same way as the first device generates the corresponding parameters.
  • the authentication network element provides key material to the AAnF, where the key material may include an AKMA key and an A-KID.
  • step S1814 the AAnF generates an application key K AF based on the AKMA key.
  • the AAnF sends a response message to the AF and/or the proxy node.
  • the message may be a successful response message.
  • the response message may include the application key and/or the validity period of the application key.
  • the response message may also include a newly selected first key (or random number), and the new first key may be used to update the hidden identity.
  • step S1818 the proxy node generates a key Ku1.
  • step S1820 the first device generates a key Ku1.
  • the key Ku1 can be generated based on the application key.
  • the specific generation method can refer to the above description.
  • the proxy node may send a response message to the first device.
  • the response message includes one or more of the following information: A-KID, validity period of the application key, newly selected first key, message integrity check (MIC).
  • the response message may be protected by a key, such as integrity protection and/or encryption protection.
  • the key may include one or more of the following: K AF , Ku1, a subordinate key derived from K AF , and a subordinate key derived from Ku1.
  • the shared key N1 between the first device and the proxy node can be used for mobility management.
  • the first device and the proxy node can generate a key Ku1 based on N1 and K AF , and then generate an integrity protection key and/or an encryption key based on Ku1.
  • the first device uses another device (such as UEx) as a proxy node
  • the shared key Nx between the first device and UEx, and K AF can be used to generate a subordinate key Kux.
  • the Kux can be used to further generate an integrity protection key and/or an encryption key. In this way, when the proxy node changes, the first device does not necessarily need to perform the authentication and key negotiation process of the first device, thereby reducing the complexity of the first device.
  • the authentication network element may also generate XRES1, XRES2 and XRES3 in the manner described above, and the first device may generate RES1, RES2 and RES3 in the manner described above.
  • the security credential is a non-3GPP security credential, such as the security credential is a shared key between the first device and the application function network element, and the first device communicates directly with the network side.
  • Fig. 19 is a flow chart of an authentication method provided by an embodiment of the present application. Referring to Fig. 19, in step S1910, the first device sends an authentication request to the application function network element.
  • the authentication request may include one or more of the following information: a hidden identity of the first device, an identity of the first device, and a first key. In some embodiments, the authentication request may include a hidden identity of the first device. In other embodiments, the authentication request may include an identity of the first device and a first key.
  • the hidden identity may be generated based on the first key N1.
  • the first key may be a shared key between the first device and the application function network element.
  • step S1920 the application function network element performs an authorization check on the first device.
  • the application function network element may check whether the first device is authorized to use a certain service (such as an A-IoT service).
  • the application function network element may manage a whitelist of the first device.
  • the application function network element When the application function network element performs an authorization check on the first device, it may perform an authorization check on the first device based on the identity identifier IDi of the first device.
  • the authentication request may include a hidden identity identifier DIDi of the first device.
  • the application function network element may de-anonymize the hidden identity identifier DIDi to obtain the identity identifier of the first device.
  • the application function network element may use the first key N1 to de-anonymize the hidden identity identifier DIDi to obtain the identity identifier of the first device.
  • step S1930 when the first device authorization check succeeds, the application function network element sends an authentication request to the authentication network element.
  • the application function network element may not send an authentication request to the authentication network element, that is, the subsequent authentication and key negotiation process may not be performed.
  • the application function network element can first perform an authorization check on the first device, and only perform the subsequent authentication and key negotiation process when the authorization check is successful, which is conducive to reducing the computational complexity of the first device. For example, if the authorization check is performed after the authentication and key negotiation process is completed, the authorization check fails, which will invalidate the authentication and key negotiation process of the first device, thereby causing a waste of resources and not being conducive to reducing the computational complexity of the first device.
  • the application function network element may send the security credential K to the authentication network element, or the application function network element may send the subordinate key (denoted as Kb) of the security credential K to the authentication network element.
  • the subordinate key is a key generated based on the security credential K.
  • the authentication network element may determine the security credential K based on the subordinate key.
  • the subordinate key may be generated based on one or more of the security credential K, the first key (denoted as N1), and the first random number (denoted as N2).
  • N2 may be a shared key between the first device and the AF, or, N2 may be a random number selected by the AF.
  • the authentication network element can generate the parameters required in the authentication process based on the security credential K.
  • the parameter can be, for example, a parameter contained in an authentication vector.
  • the parameter can include, for example, one or more of the following: a first anonymous key, a first message authentication code, an expected response, a key Ks, etc.
  • the key Ks is a shared key generated after the first device and the authentication network element are successfully authenticated. The specific generation method of these parameters can be found in the description of Example 3, and for the sake of brevity, it will not be repeated here.
  • the authentication network element can generate the parameters required in the authentication process based on the key Kb.
  • the parameters can be, for example, parameters contained in the authentication vector.
  • the parameters can include, for example, one or more of the following: a first message authentication code, an expected response, a key Ks, etc.
  • the specific generation method of these parameters can refer to the description of Example 3, and for the sake of brevity, they will not be repeated here.
  • the first device may generate one or more of the following parameters in the same manner as the authentication network element: a first anonymous key, a second message authentication code, a response parameter, a key Ks, etc.
  • the second message authentication code is generated in the same manner as the first message authentication code.
  • the response parameter is generated in the same manner as the expected response.
  • the above-mentioned expected response may include a first expected response, a second expected response, and a third expected response.
  • the first expected response may be generated in the above-mentioned expected response.
  • the second expected response and the third expected response may be generated based on the first expected response, and the specific generation method may refer to the description in other examples.
  • the above response parameters may include a first response parameter, a second response parameter, and a third response parameter.
  • the first response parameter may be generated in the manner described above.
  • the second response parameter and the third response parameter may be generated based on the first response parameter, and the specific generation method may refer to the description in other examples.
  • the f in the above formula may be the same key generation algorithm, or the f in the above formula may include a first key generation algorithm and a second key generation algorithm.
  • the first key generation algorithm is used to generate a first message authentication code or a second message authentication code
  • the second key generation algorithm is used to generate an expected response or a response parameter.
  • the first device and the authentication network element may generate one or more of A-TID, A-KID and AKMA key based on Ks.
  • A-TID A-TID
  • A-KID A-KID
  • AKMA key a key that is generated by the first device and the authentication network element.
  • the application function network element can directly receive the application key sent by AAnF. For example, after generating the application key, AAnF can directly send the application key to AF without the need for AF to send an application key request to trigger it.
  • the AF may send the application key to the proxy node.
  • the application key may be used by the proxy node to generate a third key (such as Ku1).
  • the first device can share a key K with the AF.
  • the first device sends an authentication request to the AF.
  • the authentication request includes the hidden identity DIDi of the first device.
  • the hidden identity DIDi can be generated based on the identity IDi of the first device.
  • step S2004 AF may perform authorization management.
  • the AF can de-anonymize the first device according to N1 to obtain the identity IDi of the first device.
  • the AF can check whether the first device is authorized. In some embodiments, the AF can also manage the first device Whitelist.
  • the AF sends an authentication request to the authentication network element.
  • the authentication request may include the security credential K or a subordinate key Kb derived from the security credential K.
  • the authentication request may also include the AF ID and IDi.
  • the authentication request may include one or more of the following: Kb, Kb
  • the authentication request may include Kb
  • the authentication request may include an identifier that can indicate the authentication type.
  • the authentication type identifier can be indicated by one or more of the following: AF ID, type of IDi, authentication type identifier (Auth_type_ID).
  • step S2008 the first device performs authentication (such as AKA authentication) with the authentication network element.
  • authentication such as AKA authentication
  • the authentication method can refer to the above description, such as the description of FIG. 11 above.
  • the authentication network element may query the subscription credentials of the first device and the proxy node through the core network element (such as UDM).
  • the core network element may check the subscription credentials of the first device and the proxy node based on IDi and the identity of the proxy node to determine whether the first device is entitled to use the A-IoT service.
  • the authentication network element generates an authentication vector.
  • the authentication network element may select a random number RAND, which may be used to generate the authentication vector.
  • the authentication network element can generate authentication parameters based on K and RAND.
  • the authentication parameters include one or more of the following: a first anonymous key AK, a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
  • the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
  • the authentication network element can generate authentication parameters based on Kb and RAND.
  • the authentication parameters include one or more of the following: a first message authentication code MAC, an expected response XRES, and an authentication vector AV.
  • the MAC and XRES can be calculated using the same function f and different parameters. Alternatively, the MAC and XRES can be calculated using the same parameters and different functions f.
  • the authentication network element may send an authentication response to the first device through the proxy node.
  • the authentication response may include RAND and the first message authentication code.
  • the authentication response may also include AK ⁇ N2 or Kb ⁇ N2, where AK and Kb are used to protect N2 to ensure that N2 is transmitted securely.
  • the authentication response may include AF ID and IDi.
  • the first device may calculate the second message authentication code and compare the first message authentication code with the second message authentication code to authenticate the network element. After successful authentication, the first device may generate a key Ks.
  • the first device may generate an A-TID.
  • the first device may generate a response parameter RES, and the calculation method of RES is the same as the calculation method of XRES.
  • the first device may send an authentication response to the authentication network element through the proxy node, and the authentication response may include a response parameter RES.
  • the authentication network element may compare RES and XRES to authenticate the first device. If RES and XRES are consistent, the first device is successfully authenticated; if RES and XRES are inconsistent, the first device fails to be authenticated. After the first device is successfully authenticated, the authentication network element may generate one of the following parameters: or more: Ks, A-TID, A-KID and AKMA key. The authentication network element generates these parameters in the same way as the first device generates the corresponding parameters.
  • step S2010 the authentication network element provides key material to the AAnF, where the key material may include an AKMA key and an A-KID.
  • step S2012 the AAnF generates an application key K AF based on the AKMA key.
  • the first device generates an application key K AF based on the AKMA key.
  • AAnF sends a response message to AF.
  • the response message may be a success response message.
  • the response message includes the application key and/or the validity period of the application key.
  • the response message may also include a newly selected first key (or random number), and the new first key may be used to update the hidden identity.
  • step S2016 AF sends a response message to the first device.
  • the response message includes one or more of the following information: A-KID, validity period of the application key, newly selected first key, message integrity check (MIC).
  • the response message can be protected by a key, such as integrity protection and/or encryption protection.
  • the key can include one or more of the following: K AF , Ku1, a subordinate key derived from K AF , and a subordinate key derived from Ku1.
  • the authentication network element may send Ks to the proxy node so that the proxy node protects the information transmitted in the air interface based on Ks.
  • the proxy node may generate an integrity protection key and/or an encryption key based on Ks, and the integrity protection key and/or the encryption key are used for secure communication between the first device and the proxy node.
  • the authentication network element may send Ks to the AF, and the AF and the first device may establish a secure connection (such as a transport layer security (TLS) connection) based on Ks to protect information transmitted in the air interface.
  • a secure connection such as a transport layer security (TLS) connection
  • the first device before triggering authentication and key negotiation between the first device and the network side, can perform mutual authentication with the proxy node to prevent a malicious first device from using the proxy node to launch a distributed denial of service (DDOS) attack on the network, affecting network quality, or a malicious proxy node from launching a man-in-the-middle attack to steal communication data between the first device and the network or a third-party application, or the authentication signaling of the first device is carried on a malicious proxy node, resulting in failure of successful authentication and key negotiation.
  • DDOS distributed denial of service
  • the authentication method between the first device and the proxy node may include one or more of the following: pairing, activation of the first device by the proxy node, physical unclonable function (PUF) and physical layer authentication.
  • PAF physical unclonable function
  • the proxy node can use its own security context to protect the authentication message of the first device. For example, after receiving the authentication request or response message of the first device, the proxy node can transmit the authentication container (such as Tag_authentication_container) of the first device using the NAS security context or AS security context of the first device to interact with the network side.
  • the authentication container such as Tag_authentication_container
  • the information transmission between the AF and the authentication network element mentioned above can be realized through the network exposure function (NEF).
  • the NEF can forward the transmission message between the AF and the authentication network element.
  • the security credentials mentioned above may also be referred to as keys or root keys, etc.
  • the key Ks can be directly used to protect the secure transmission between the first device and the proxy node.
  • the key Ks is equivalent to the function of the key K AF .
  • the authentication network element can send the key Ks to the proxy node, and the proxy node can generate an integrity protection key and/or an encryption key based on the key Ks.
  • the first device can also generate an integrity protection key and/or an encryption key based on the key Ks.
  • the key Ks may be used to generate a NAS security context and/or an AS security context.
  • the authentication network element may generate KAMF based on Ks and provide KAMF to AMF. In this case, Ks is equivalent to the function of KAUSF .
  • AMF may generate a NAS security context based on KAMF .
  • the authentication network element may provide Ks to AMF, in which case Ks is equivalent to the function of KAMF .
  • AMF may generate a NAS security context based on Ks.
  • the NAS security context may include, for example, Knas-int and Knas-enc.
  • the authentication network element may generate Kgnb based on Ks and provide Kgnb to the base station. In this case, Ks is equivalent to the function of K AUSF .
  • the base station may generate an AS security context based on Kgnb.
  • the authentication network element may provide Ks to the base station, in which case Ks is equivalent to the function of Kgnb.
  • the base station may generate an AS security context based on Ks.
  • the relay mode of the proxy node may include L2 relay and L3 relay. That is, when the proxy node is used for relay communication, the protocol stack used by the relay may belong to the L2 layer or the L3 layer.
  • L2 relay there is a separate context between the first device and the core network. There is a hop-by-hop and end-to-end secure connection between the first device and the network.
  • L3 relay the first device only needs to implement a secure connection with the proxy node.
  • the security context may include a security context between the first device and the proxy node.
  • the security context includes a security context between the first device and the proxy node, a NAS security context, and an AS security context.
  • the function f in the above formula can be any function among f1-f5 defined by 3GPP.
  • the function f can be KDF (such as HMAC-SHA256).
  • the function f can be other lightweight functions (such as ASCON).
  • the home domain network element or authentication network element mentioned above may include one or more of the following network elements: UDM, AUSF, KMS, ARPF.
  • the service domain network element mentioned above may include one or more of the following: AMF, SMF, SEAF, and A-NF, a core network element specific to A-IoT services.
  • the identification of the proxy node can be represented by UE ID.
  • the first key N1 mentioned above has three uses: first, it can be used to protect the identity of the first device; second, it can be used to calculate the authentication vector and the shared key Ks; third, it can be used for mobility management, that is, to generate Ku1.
  • the embodiment of the present application does not limit the generation of the generated key, which can be of any length.
  • the key generation process may introduce values such as number FC and parameter length, and the embodiment of the present application does not specifically limit the size of these values.
  • FIG21 is a schematic block diagram of a first device provided in an embodiment of the present application.
  • the first device 2100 shown in FIG21 may be any of the first devices described above.
  • the first device 2100 may include a receiving unit 2110, a generating unit 2120, an authenticating unit 2130, and a sending unit 2140. These units are described in detail below.
  • the receiving unit 2110 is configured to receive a first authentication request from a proxy node, where the first authentication request includes a first message authentication code, and the first message authentication code is generated by an authentication network element.
  • the generating unit 2120 is configured to generate a second message authentication code based on the first key generation algorithm and the first parameter.
  • the generating unit 2120 is further configured to, when the authentication network element is successfully authenticated, generate a response parameter by the first device.
  • the sending unit 2140 is configured to send a first authentication response to the proxy node, where the first authentication response includes the response parameter, and the response parameter is used to authenticate the first device.
  • the response parameter includes a first response parameter
  • the first response parameter is used for the home domain network element to authenticate the first device
  • the generating unit is used to generate the first response parameter based on the first key generation algorithm and a second parameter.
  • the response parameter includes a first response parameter
  • the first response parameter is used for the home domain network element to authenticate the first device
  • the generating unit is used to generate the first response parameter based on a second key generation algorithm and the first parameter.
  • the response parameters include a second response parameter
  • the second response parameter is used for the service domain network element to authenticate the first device
  • the generating unit is used to generate the second response parameter based on the first response parameter and a third parameter.
  • the response parameters include a third response parameter
  • the third response parameter is used by the access network device to authenticate the first device.
  • the generating unit is used to generate the third response parameter based on the first response parameter and a fourth parameter.
  • the generating unit is further used to: before receiving a first authentication request from a proxy node, perform an XOR operation on the identity of the first device and a first key to generate a hidden identity of the first device; the sending unit is further used to: send a second authentication request to the proxy node, wherein the second authentication request includes the hidden identity.
  • the generating unit is further used to: before receiving a first authentication request from a proxy node, generate a hidden identity of the first device based on the identity of the first device, a first key, and a third key generation algorithm, wherein the third key generation algorithm is the first key generation algorithm or the second key generation algorithm; the sending unit is further used to: send a second authentication request to the proxy node, wherein the second authentication request includes the hidden identity.
  • the first key is a shared key between the first device and the authentication network element, or the first key is a physical layer key between the first device and the proxy node.
  • the generating unit is further used to: generate a second key when the authentication network element is successfully authenticated; and generate an application layer authentication and key management key based on the second key and a fourth key generation algorithm.
  • the sending unit is also used to: send an application session establishment request message to the proxy node; the receiving unit is also used to: receive an application session establishment response message from the proxy node; the generating unit is also used to: in response to receiving the application session establishment response message, generate an application key based on the authentication and key management key of the application layer; and generate a third key based on the application key, a first key and a fifth key generation algorithm, wherein the first key is a physical layer key between the first device and the proxy node, and the fifth key generation algorithm is the first key generation algorithm or the second key generation algorithm; the device also includes a communication unit for securely communicating with the proxy node based on the third key.
  • FIG22 is a schematic block diagram of a proxy node provided in an embodiment of the present application.
  • the proxy node 2200 shown in FIG22 may be any of the proxy nodes described above.
  • the proxy node 2200 may include a sending unit 2210 and a receiving unit 2220. These units are described in detail below.
  • the sending unit 2210 is configured to send a first authentication request to a first device, wherein the first authentication request includes a first message authentication code.
  • the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, and the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter.
  • the receiving unit 2220 is used to receive a first authentication response from the first device, where the first authentication response includes a response parameter, and the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication network element successfully authenticates.
  • the response parameters include a first response parameter
  • the first response parameter is used for the home domain network element to authenticate the first device
  • the first response parameter is generated based on the first key generation algorithm and a second parameter.
  • the response parameters include a first response parameter
  • the first response parameter is used for the home domain network element to authenticate the first device
  • the first response parameter is generated based on a second key generation algorithm and the first parameter
  • the response parameters include a second response parameter
  • the second response parameter is used for the service domain network element to authenticate the first device
  • the second response parameter is generated based on the first response parameter and a third parameter.
  • the response parameters include a third response parameter
  • the third response parameter is used by the access network device to authenticate the first device
  • the third response parameter is generated based on the first response parameter and a fourth parameter.
  • the first key is a physical layer key between the first device and the proxy node
  • the proxy node also includes a determination unit for determining the identity of the first device based on the first key and the hidden identity; the sending unit is also used to: send the second authentication request to the authentication network element, and the second authentication request includes one or more of the following information: the first key, the identity of the first device, and the identity of the proxy node.
  • the first key is a shared key between the first device and the authentication network element
  • the sending unit is further used to: send the second authentication request to the authentication network element, and the second authentication request includes one or more of the following information: the hidden identity identifier and the identifier of the proxy node.
  • the receiving unit is also used to: receive an application key from an application function network element;
  • the proxy node also includes: a generation unit, used to generate a third key based on the application key, a first key and a fifth key generation algorithm, wherein the first key is a physical layer key between the first device and the proxy node, and the fifth key generation algorithm is the first key generation algorithm or the second key generation algorithm; a communication unit, used to communicate securely with the first device based on the third key.
  • FIG23 is a schematic block diagram of an authentication network element provided in an embodiment of the present application.
  • the authentication network element 2300 shown in FIG23 may be any authentication network element described above.
  • the authentication network element 2300 may include a generating unit 2310 and a sending unit 2320. These units are described in detail below.
  • the generating unit 2310 is configured to generate a first message authentication code and an expected response, where the expected response is used to authenticate the first device, and the first message authentication code is generated based on a first key generation algorithm and a first parameter.
  • the sending unit 2320 is used to send a first authentication request to the proxy node, where the first authentication request includes the first message authentication code, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, and the second message authentication code is generated by the first device.
  • the expected response includes a first expected response
  • the first expected response is used for the home domain network element to authenticate the first device
  • the generating unit is used to generate the first expected response based on the first key generation algorithm and a second parameter.
  • the expected response includes a first expected response
  • the first expected response is used for a home domain network element to authenticate the first device
  • the generating unit is used to generate the first expected response based on a second key generation algorithm and the first parameter.
  • the expected response includes a second expected response, where the second expected response is used for serving a domain network element to authenticate the first device, and the generating unit is used to generate the second expected response based on the first expected response and a third parameter.
  • the expected response includes a third expected response
  • the third expected response is used by the access network device to authenticate the first device
  • the generating unit is used to generate the third expected response based on the first expected response and a fourth parameter.
  • the authentication network element further includes: a receiving unit, used to: receive a second authentication request from the proxy node before the authentication network element generates a first message authentication code and an expected response, the second authentication request including a hidden identity of the first device, and a determination unit, used to determine the identity of the first device based on the hidden identity and a first key.
  • the first key is a shared key between the first device and the authentication network element, or the first key is a physical layer key between the first device and the proxy node.
  • the generating unit is used to: generate a second key when the first device is authenticated successfully; and generate an application layer authentication and key management key based on the second key and a fourth key generation algorithm.
  • the first parameter includes a first random number, which is selected by the authentication network element, or the first random number is pre-shared by the authentication network element and the first device.
  • FIG24 is a schematic block diagram of an access network device provided in an embodiment of the present application.
  • the access network device 2400 shown in FIG24 may be any of the access network devices described above.
  • the access network device 2400 may include a sending unit 2410 and a receiving unit 2420. These units are described in detail below.
  • the sending unit 2410 is used to send a first authentication request to a first device, wherein the first authentication request includes a first message authentication code, the first message authentication code is generated by an authentication network element, the first message authentication code and the second message authentication code are used to authenticate the authentication network element, the second message authentication code is generated by the first device, and the first message authentication code and the second message authentication code are generated based on a first key generation algorithm and a first parameter.
  • the receiving unit 2420 is used to receive a first authentication response from the first device, where the first authentication response includes a response parameter, and the response parameter is used to authenticate the first device, and the response parameter is generated when the authentication network element successfully authenticates.
  • the response parameters include a first response parameter
  • the first response parameter is used for the home domain network element to authenticate the first device
  • the first response parameter is generated based on the first key generation algorithm and a second parameter.
  • the response parameters include a first response parameter
  • the first response parameter is used for the home domain network element to authenticate the first device
  • the first response parameter is generated based on a second key generation algorithm and the first parameter
  • the response parameters include a second response parameter
  • the second response parameter is used for the service domain network element to authenticate the first device
  • the second response parameter is generated based on the first response parameter and a third parameter.
  • the response parameters include a third response parameter
  • the third response parameter is used by the access network device to authenticate the first device
  • the third response parameter is generated based on the first response parameter and a fourth parameter.
  • the receiving unit is further used to: before the access network device sends a first authentication request to the first device, receive a second authentication request from the first device, the second authentication request including a hidden identity of the first device, and the hidden identity is generated by an exclusive OR operation of the identity of the first device and a first key.
  • the receiving unit is further used to: before the access network device sends a first authentication request to the first device, receive a second authentication request from the first device, the second authentication request including a hidden identity of the first device, the hidden identity being generated by the hidden identity of the first device, a first key, and a third key generation algorithm, the third key generation algorithm being the first key generation algorithm or the second key generation algorithm.
  • the first key is a physical layer key between the first device and the access network device
  • the access network device also includes a determination unit for determining the identity of the first device based on the first key and the hidden identity; the sending unit is also used to: send the second authentication request to the authentication network element, and the second authentication request includes one or more of the following information: the first key and the identity of the first device.
  • the first key is a shared key between the first device and the authentication network element
  • the sending unit is further used to: send the second authentication request to the authentication network element, where the second authentication request includes the hidden identity.
  • the first authentication response includes a third response parameter
  • the receiving unit is further used to: receive a second authentication response from the authentication network element, the second authentication response including a third expected response;
  • the access network device also includes: a comparison unit, used to compare the third response parameter and the third authentication response to authenticate the first device.
  • FIG25 is a schematic structural diagram of a communication device according to an embodiment of the present application.
  • the dotted line in FIG25 indicates that the unit or module is optional.
  • the device 2500 may be used to implement the method described in the above method embodiment.
  • the device 2500 may be a chip, a first device, a proxy node, an authentication network element, an access network device, or an application function network element.
  • the device 2500 may include one or more processors 2510.
  • the processor 2510 may support the device 2500 to implement the method described in the method embodiment above.
  • the processor 2510 may be a general-purpose processor or a special-purpose processor.
  • the processor may be a central processing unit (CPU).
  • the processor may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
  • DSP digital signal processor
  • ASIC application specific integrated circuits
  • FPGA field programmable gate arrays
  • a general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
  • the apparatus 2500 may further include one or more memories 2520.
  • the memory 2520 stores a program, which can be executed by the processor 2510, so that the processor 2510 executes the method described in the above method embodiment.
  • the memory 2520 may be independent of the processor 2510 or integrated in the processor 2510.
  • the apparatus 2500 may further include a transceiver 2530.
  • the processor 2510 may communicate with other devices or chips through the transceiver 2530.
  • the processor 2510 may transmit and receive data with other devices or chips through the transceiver 2530.
  • the present application also provides a computer-readable storage medium for storing a program.
  • the computer-readable storage medium can be applied to the present application.
  • the first device, proxy node, authentication network element, access network device or application function network element provided in the application embodiment, and the program enables the computer to execute the methods performed by the first device, proxy node, authentication network element, access network device or application function network element in each embodiment of the present application.
  • the embodiment of the present application also provides a computer program product.
  • the computer program product includes a program.
  • the computer program product can be applied to the first device, proxy node, authentication network element, access network device or application function network element provided in the embodiment of the present application, and the program enables the computer to execute the method performed by the first device, proxy node, authentication network element, access network device or application function network element in each embodiment of the present application.
  • the embodiment of the present application also provides a computer program.
  • the computer program can be applied to the first device, proxy node, authentication network element, access network device or application function network element provided in the embodiment of the present application, and the computer program enables the computer to execute the method performed by the first device, proxy node, authentication network element, access network device or application function network element in each embodiment of the present application.
  • the "include” mentioned may refer to direct inclusion or indirect inclusion.
  • the “include” mentioned in the embodiments of the present application may be replaced with “indicate” or “used to determine”.
  • a includes B which may be replaced with A indicates B, or A is used to determine B.
  • the term "corresponding" may indicate that there is a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship of indication and being indicated, configuration and being configured, etc.
  • the term "and/or" is only a description of the association relationship of the associated objects, indicating that there can be three relationships.
  • a and/or B can represent: A exists alone, A and B exist at the same time, and B exists alone.
  • the character "/" in this article generally indicates that the associated objects before and after are in an "or" relationship.
  • the size of the serial numbers of the above-mentioned processes does not mean the order of execution.
  • the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Small-Scale Networks (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

本申请提供了一种认证方法及装置。该方法包括:第一设备接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;所述第一设备基于第一密钥生成算法和第一参数生成第二消息认证码;所述第一设备基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;在所述认证网元认证成功的情况下,所述第一设备生成响应参数;所述第一设备向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。

Description

认证方法及装置 技术领域
本申请涉及通信技术领域,并且更为具体地,涉及一种认证方法及装置。
背景技术
为了提高通信安全性,终端设备在与网络侧进行通信之前,可以先与网络侧进行认证与密钥协商。在引入第一设备(如零功耗终端)后,由于第一设备的计算能力较低,第一设备该如何与网络侧进行认证与密钥协商流程,目前还没有明确的规定。
发明内容
本申请提供一种认证方法及装置。下面对本申请涉及的各个方面进行详细介绍。
第一方面,提供了一种认证方法,包括:第一设备接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;所述第一设备基于第一密钥生成算法和第一参数生成第二消息认证码;所述第一设备基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;在所述认证网元认证成功的情况下,所述第一设备生成响应参数;所述第一设备向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
第二方面,提供了一种认证方法,包括:代理节点向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;所述代理节点接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
第三方面,提供了一种认证方法,包括:认证网元生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成;所述认证网元向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
第四方面,提供了一种认证方法,包括:接入网设备向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;所述接入网设备接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
第五方面,提供一种设备,所述设备为第一设备,所述第一设备包括:接收单元,用于接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;生成单元,用于基于第一密钥生成算法和第一参数生成第二消息认证码;认证单元,用于基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;所述生成单元,还用于在所述认证网元认证成功的情况下,所述第一设备生成响应参数;发送单元,用于向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
第六方面,提供一种代理节点,包括:发送单元,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;接收单元,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
第七方面,提供一种认证网元,包括:生成单元,用于生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成;发送单元,用于向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
第八方面,提供一种接入网设备,包括:发送单元,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消 息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;接收单元,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
第九方面,提供一种设备,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以执行如第一方面所述的方法。
第十方面,提供一种代理节点,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以执行第二方面所述的方法。
第十一方面,提供一种认证网元,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以执行如第三方面所述的方法。
第十二方面,提供一种接入网设备,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以执行第四方面所述的方法。
第十三方面,提供一种装置,包括处理器,用于从存储器中调用程序,以执行如第一方面至第四方面中任一方面所述的方法。
第十四方面,提供一种芯片,包括处理器,用于从存储器调用程序,使得安装有所述芯片的设备执行如第一方面至第四方面中任一方面所述的方法。
第十五方面,提供一种计算机可读存储介质,其上存储有程序,所述程序使得计算机执行如第一方面至第四方面中任一方面所述的方法。
第十六方面,提供一种计算机程序产品,包括程序,所述程序使得计算机执行如第一方面至第四方面中任一方面所述的方法。
第十七方面,提供一种计算机程序,所述计算机程序使得计算机执行如第一方面至第四方面中任一方面所述的方法。
第一设备接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;所述第一设备基于第一密钥生成算法和第一参数生成第二消息认证码;所述第一设备基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;在所述认证网元认证成功的情况下,所述第一设备生成响应参数;所述第一设备向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
本申请通过基于第一密钥生成算法和第一参数生成消息认证码(如第二消息认证码),以认证认证网元,从而为第一设备与网络侧间的认证提供了一种明确的方案。
附图说明
图1是本申请实施例应用的无线通信系统100。
图2是一种初始认证的流程示意图。
图3是一种生成AKMA密钥的流程示意图。
图4是一种生成应用密钥的流程示意图。
图5是本申请实施例涉及的各种密钥的衍生过程的示意图。
图6是本申请实施例涉及的各个参数的生成方式的示意图。
图7是本申请实施例提供的一种混合通信系统的示意图。
图8是本申请实施例提供的一种基于3GPP安全凭证的通信系统。
图9是本申请实施例提供的一种基于非3GPP安全凭证的通信系统。
图10是本申请实施例提供的一种认证方法的流程示意图。
图11是本申请实施例提供的一种基于代理节点和3GPP安全凭证的认证方法的流程示意图。
图12是基于图11的生成AKMA密钥的流程示意图。
图13是基于图12的生成应用密钥的流程示意图。
图14是本申请实施例提供的另一种认证方法的流程示意图。
图15是本申请实施例提供的一种基于3GPP安全凭证的认证方法的流程示意图。
图16是基于图15的生成应用密钥的流程示意图。
图17是本申请实施例提供的另一种认证方法的流程示意图。
图18是本申请实施例提供的一种基于代理节点和非3GPP安全凭证的认证方法的流程示意图。
图19是本申请实施例提供的另一种认证方法的流程示意图。
图20是本申请实施例提供的一种基于非3GPP安全凭证的认证方法的流程示意图。
图21是本申请实施例提供的一种第一设备的示意性框图。
图22是本申请实施例提供的一种代理节点的示意性框图。
图23是本申请实施例提供的一种认证网元的示意性框图。
图24是本申请实施例提供的一种接入网设备的示意性框图。
图25是是本申请实施例提供的一种通信装置的结构示意图。
具体实施方式
下面将结合附图,对本申请中的技术方案进行描述。
图1是本申请实施例应用的无线通信系统100。该无线通信系统100可以包括网络设备110和终端设备120。网络设备110可以是与终端设备120通信的设备。网络设备110可以为特定的地理区域提供通信覆盖,并且可以与位于该覆盖区域内的终端设备120进行通信。
图1示例性地示出了一个网络设备和两个终端设备,可选地,该无线通信系统100可以包括多个网络设备并且每个网络设备的覆盖范围内可以包括其它数量的终端设备,本申请实施例对此不做限定。
可选地,该无线通信系统100还可以包括网络控制器、移动管理实体等其他网络实体,本申请实施例对此不作限定。
应理解,本申请实施例的技术方案可以应用于各种通信系统,例如:第五代(5th generation,5G)系统或新无线(new radio,NR)、长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)等。本申请提供的技术方案还可以应用于未来的通信系统,如第六代移动通信系统,又如卫星通信系统,等等。
本申请实施例中的终端设备也可以称为用户设备(user equipment,UE)、接入终端、用户单元、用户站、移动站、移动台(mobile station,MS)、移动终端(mobile terminal,MT)、远方站、远程终端、移动设备、用户终端、终端、无线通信设备、用户代理或用户装置。本申请实施例中的终端设备可以是指向用户提供语音和/或数据连通性的设备,可以用于连接人、物和机,例如具有无线连接功能的手持式设备、车载设备等。本申请的实施例中的终端设备可以是手机(mobile phone)、平板电脑(Pad)、笔记本电脑、掌上电脑、移动互联网设备(mobile internet device,MID)、可穿戴设备,虚拟现实(virtual reality,VR)设备、增强现实(augmented reality,AR)设备、工业控制(industrial control)中的无线终端、无人驾驶(self driving)中的无线终端、远程手术(remote medical surgery)中的无线终端、智能电网(smart grid)中的无线终端、运输安全(transportation safety)中的无线终端、智慧城市(smart city)中的无线终端、智慧家庭(smart home)中的无线终端等。可选地,UE可以用于充当基站。例如,UE可以充当调度实体,其在V2X或D2D等中的UE之间提供侧行链路信号。比如,蜂窝电话和汽车利用侧行链路信号彼此通信。蜂窝电话和智能家居设备之间通信,而无需通过基站中继通信信号。
本申请实施例中的网络设备可以是用于与终端设备通信的设备,该网络设备也可以称为接入网设备或无线接入网设备,如网络设备可以是基站。本申请实施例中的网络设备可以是指将终端设备接入到无线网络的无线接入网(radio access network,RAN)节点(或设备)。基站可以广义的覆盖如下中的各种名称,或与如下名称进行替换,比如:节点B(NodeB)、演进型基站(evolved NodeB,eNB)、下一代基站(next generation NodeB,gNB)、中继站、传输点(transmitting and receiving point,TRP)、发射点(transmitting point,TP)、主站MeNB、辅站SeNB、多制式无线(MSR)节点、家庭基站、网络控制器、接入节点、无线节点、接入点(access point,AP)、传输节点、收发节点、基带单元(base band unit,BBU)、射频拉远单元(Remote Radio Unit,RRU)、有源天线单元(active antenna unit,AAU)、射频头(remote radio head,RRH)、中心单元(central unit,CU)、分布式单元(distributed unit,DU)、定位节点等。基站可以是宏基站、微基站、中继节点、施主节点或类似物,或其组合。基站还可以指用于设置于前述设备或装置内的通信模块、调制解调器或芯片。基站还可以是移动交换中心以及设备到设备D2D、车辆外联(vehicle-to-everything,V2X)、机器到机器(machine-to-machine,M2M)通信中承担基站功能的设备、6G网络中的网络侧设备、未来的通信系统中承担基站功能的设备等。基站可以支持相同或不同接入技术的网络。本申请的实施例对网络设备所采用的具体技术和具体设备形态不做限定。
基站可以是固定的,也可以是移动的。例如,直升机或无人机可以被配置成充当移动基站,一个或多个小区可以根据该移动基站的位置移动。在其他示例中,直升机或无人机可以被配置成用作与另一基站通信的设备。
在一些部署中,本申请实施例中的网络设备可以是指CU或者DU,或者,网络设备包括CU和DU。gNB还可以包括AAU。
网络设备和终端设备可以部署在陆地上,包括室内或室外、手持或车载;也可以部署在水面上;还可以部署在空中的飞机、气球或卫星上。本申请实施例中对网络设备和终端设备所处的场景不做限定。
应理解,本申请中的通信设备的全部或部分功能也可以通过在硬件上运行的软件功能来实现,或者通过平台(例如云平台)上实例化的虚拟化功能来实现。
应用层的认证与密钥管理(authentication and key management for applications,AKMA)架构
UE与应用功能(application function,AF)之间可以使用应用密钥(KAF)进行通信,KAF可用于对通信进行安全保护。KAF的生成过程涉及到多个功能网元,如接入和移动性管理功能(access and mobility management function,AMF)、身份验证服务器功能(authentication server function,AUSF)、统一数据管理(unified data management,UDM)、AKMA锚点功能(AKMA anchor function,AAnF)、AF等,下面对这些功能网元进行介绍。
AMF主要用于移动性管理和接入管理等,可以用于实现移动性管理实体(mobility management entity,MME)功能中除会话管理之外的其他功能,例如,合法监听以及接入授权/鉴权等功能。
AUSF用于鉴权服务、产生密钥、实现对UE的双向鉴权,支持统一的鉴权框架。在本申请实施例中,AUSF主要用于在UE和网络之间进行相互认证,并生成安全密钥以便在后续的流程中使用。
UDM可用于处理UE标识、接入鉴权、注册以及移动性管理等。
AF用于进行应用层的数据路由,接入网络开放功能,与策略框架交互进行策略控制等。
AAnF用于生成AKMA锚定密钥(KAKMA),以及应用密钥(KAF)。AAnF和UE可以采用相同的方式生成KAF。在生成KAF后,AAnF可以将生成的KAF发送至AF。由此,AF和UE可以基于相同的密钥KAF进行通信,以保证通信的安全性。
为了生成KAF,UE可以先与网络侧进行初始认证,在初始认证完成后获得密钥(如KAUSF),该密钥可用于生成KAF
下面结合图2,对初始认证过程进行介绍。
参见图2,在步骤S202,UDM/认证凭证存储库和处理功能(authentication credential repository and processing function,ARPF)生成认证向量(authentication vector,AV)。
UDM/ARPF可以对每个认证获取请求消息(如Nudm Authenticate Get Request)创建一个5G HE AV。UDM/ARPF可以先生成一个AMF“separation bit”为1的认证向量,然后计算得到KAUSF和XRES*。最后,UDM/ARPF可以创建一个包含RAND、AUTN、XRES*和KAUSF的5G HE AV。
在步骤S204,UDM向AUSF发送UE认证获取响应消息(如Nudm_ueauthentication_Get Response)。该UE认证获取响应消息中包括5G HE AV以及指示信息,该指示信息用于指示该5G HE AV用于5G认证与密钥协商(authentication and key agreement,AKA)。如果认证获取请求消息中包含订阅隐藏标识符(subscription concealed identifier,SUCI),则UE认证获取响应消息中可以包含订阅永久标识符(subscription permanent identifier,SUPI)。
在步骤S206,AUSF接收到UE认证获取响应消息后,可以临时保存XRES*以及接收到的SUCI或SUPI。AUSF还可以保存KAUSF
AUSF可以基于从UDM/ARPF接收到的5G HE AV生成一个5G AV。另外,AUSF可以基于XRES*计算HXRES*,基于KAUSF计算KSEAF,然后使用HXRES*和KSEAF分别替换5G HE AV中的XRES*和KAUSF
在步骤S210,AUSF向安全锚点功能(security anchor function,SEAF)发送UE认证响应(如Nausf_UEAuthentication_Authenticate Response)。该UE认证响应中包括5G SE AV,该5G SE AV可以包括RAND、AUTN和HXRES*,而不包括KSEAF
在步骤S212,SEAF向UE发送认证请求。该认证请求可以通过非接入层(non-access stratum,NAS)消息(如Auth-Reg)发送。该认证请求中可以包括RANT和认证令牌(authtoken,AUTN)。该消息中还可以包括ngKSI,该ngKSI可用于UE和AMF标识KAMF和部分原生安全上下文。UE可以包括移动设备(mobile equipment,ME)和全球用户识别模块(universal subscriber identity module,USIM)。UE接收到RANT和AUTN后,ME可以向USIM转发该RANT和AUTN。
在步骤S214,USIM接收到RANT和AUTN后,可以检查AUTN是否被接受,以此来验证认证向量是否为最新,以抵抗重放攻击。如果验证通过,则USIM可以计算响应RES,并向ME返回RES、加密密钥(encrypt key,CK)和完整性密钥(integrity key,IK)。USIM还可以计算Kc(即GPRS Kc),并向ME发送该GPRS Kc。如果GPRS Kc基于CK、IK和第三代合作伙伴计划(the third generation partnership project,3GPP)TS 33.102中描述的转换函数c3计算得到,则ME可以忽略该GPRS Kc,且该GPRS Kc不应存储在USIM或ME上。
ME可以基于RES计算RES*,以及基于CK||IK计算KAUSF。另外,ME还可以基于KAUSF计算KSEAF。如果ME接入5G,则ME还可以在认证期间检查AUTN的AMF字段“separation bit”是否设为1,其中,“separation bit”是AUTN的AMF字段的第0位。需要说明的是,AUTN的AMF字段中的 “separation bit”不能再用于运营商特定目的。
在步骤S216,UE向SEAF发送认证响应,该认证响应中可以包括RES*。该认证响应可以通过NAS消息发送。
在步骤S218,SEAF基于RES*计算HRES*。SEAF可以比较HRES*和HXRES*,确定这两个值是否一致。如果两个值一致,则SEAF从服务网络的角度认为认证成功,如果两个值不一致,则SEAF可以按照协议6.1.3.2.1的规定执行。如果UE不可达,且SEAF从未接收到RES*,SEAF可以认为认证失败,并向AUSF指示认证失败。
在步骤S220,SEAF向AUSF发送UE认证请求(如Nausf_UE Authentication_Authenticate Request)消息,该UE认证请求消息中可以包括SUCI或SUPI。
在步骤S222,AUSF接收UE认证请求消息,该UE认证请求消息中可以包含RES*。AUSF可以验证AV是否已经到期,如果AV已经到期,则AUSF可以从归属域网络的角度认为认证不成功。AUSF可以通过比较接收到的RES*与存储的XRES*,确定认证是否成功。如果RES*和XRES*一致,则AUSF从归属域网络的角度认为认证成功;如果RES*和XRES*不一致,则AUSF从归属域网络的角度认为认证不成功。
在步骤S224,AUSF通过UE认证响应(如Nausf_UE Authentication_Authenticate Response)消息向SEAF指示认证是否成功。如果认证成功,则AUSF可以通过UE认证响应消息将KSEAF发送至SEAF。如果认证成功,且AUSF在启动认证时从SEAF接收到SUCI,则UE认证响应消息还可以包括SUPI。
如果认证成功,SEAF可以将从UE认证响应消息中接收到的密钥KSEAF作为锚密钥。另外,SEAF可以基于KSEAF、ABBA参数以及SUPI,计算KAMF。SEAF可以向AMF提供KSEAF和ngKSI。
如果SUCI用于认证,则SEAF可以仅在接收到包含SUPI的UE认证响应消息后,才向AMF提供ngKSI和KAMF。在获知SUPI之前,服务网不会向UE提供通信服务。
在初始认证完成后,AUSF和UE获得KAUSF,该KAUSF可用于生成KAF。KAF的协商流程可以由UE向AF发送AKMA密钥标识(AKMA key identifier,A-KID)来触发。下面结合图3和图4,对KAF的生成过程进行介绍。
在步骤S302,在初始认证完成之后,UE和AUSF可以基于KAUSF生成KAKMA以及A-KID。
在步骤S304,AUSF可以向AAnF发送AKMA锚定密钥注册请求(如Naanf_AKMA_AnchorKey_Register Request),该AKMA锚定密钥注册请求中可以包括SUPI、A-KID以及KAKMA
在步骤S306,AAnF可以向AUSF返回AKMA锚定密钥注册响应(如Naanf_AKMA_AnchorKey_Register Response)。
参见图4,在步骤S402,在完成初始认证以及生成KAKMA后,UE可以向AF发送应用程序会话建立请求。该应用程序会话建立请求中可以包括A-KID。
在步骤S404,AF向AAnF发送AKMA应用密钥获取请求(如Naanf_AKMA_ApplicationKey_Get Request)。该AKMA应用密钥获取请求中可以包括A-KID以及AF的标识(AF identity,AF-ID)。该A-KID为应用程序会话建立请求中的A-KID。在一些实施例中,AKMA应用密钥获取请求中还可以包括对UE的标识(UE identity,UE-ID)的请求。UE-ID包括SUPI、SUCI、通用公共订阅标识符(generic public subscription identifier,GPSI)中的一种或多种。
在步骤S406,AAnF接收到AKMA应用密钥获取请求后,可以基于A-KID确定对应的KAKMA,并基于KAKMA生成密钥KAF
在步骤S408,AAnF向AF发送AKMA应用密钥获取响应。该应用密钥获取响应中可以包括KAF、KAF的有效期(KAF expTime)、UE-ID等。
在步骤S410,AF向UE发送应用程序会话建立响应。
可以理解的是,UE也可以采用与AAnF相同的方式生成KAF,即,UE基于KAKMA生成KAF的方式与AAnF基于KAKMA生成KAF的方式相同。由此,UE和AF可以使用相同的密钥KAF进行通信。
本申请实施例对上述密钥(如KAKMA、A-KID、KAF等)的生成方式不做具体限定。例如,可以使用密钥派生函数(key derivation function,KDF)来生成上述密钥。KDF可以为任意一种能够满足计算安全的密钥派生函数,例如KDF可以为HMAC-SHA-256或HMAC-SM3。下面以KDF为例,对密钥的生成方式进行举例说明。
例如,从KAUSF生成KAKMA时,可以使用以下参数作为KDF的输入S:
-FC=0xXX(如0x80);
-P0=“AKMA”;
-L0=AKMA的长度(如0x00 0x04);
-P1=SUPI;
-L1=SUPI的长度;
输入的密钥(key)为KAUSF
又例如,从KAKMA生成KAF时,可以使用以下参数作为KDF的输入S,下文将该方式称为方式一:
-FC=0xXX(如0x82);
-P0=AF_ID;
-L0=AF_ID的长度;
输入的密钥为KAKMA
其中,AF_ID=AF的FQDN||Ua*安全协议标识符。
再例如,A-KID可以包括漫游标识(routing indicator,RID)和AKMA临时UE标识(AKMA temporary ue identifier,A-TID)两部分。其中,RID包含在SUPI中,A-TID可以基于KAUSF生成。当从KAUSF生成A-TID时,可以使用以下参数作为KDF的输入S:
-FC=0xXX(如0x81);
-P0=“A-TID”;
-L0=“A-TID”的长度(如0x00 0x05);
-P1=SUPI;
-L1=SUPI的长度;
输入的密钥为KAUSF
图5是本申请实施例涉及的各种密钥的衍生过程的示意图。
本申请实施例中的NAS安全上下文可以包括KAMF、下级衍生密钥KNASint和KNASenc,以及各个密钥对应的密钥标识。
本申请实施例中的接入层(access stratum,AS)安全上下文可以包括KgNB,下级衍生密钥KRRCint、KRRCenc、KUPint和KUPenc,以及各个密钥对应的密钥标识。
本申请实施例涉及的密钥还可以包括机密性保护密钥(或称为加密密钥)和完整性保护密钥。从图5可以看出,机密性保护密钥和完整性保护密钥可以由KAMF生成,也可以由KgNB生成。其中,KAMF为AMF和UE之间的共享密钥,为gNB和UE之间的共享密钥。
在生成机密性保护密钥和完整性保护密钥时,输入的参数可以如下:
-FC=0xXX(如00x69);
-P0=算法类型标识符(algorithm type distinguisher);
-L0=算法类型标识符的长度(length of algorithm type distinguisher)(如0x00 0x01);
-P1=算法标识(algorithm identity);
-L1=算法标识的长度(length of algorithm identity)(如0x00 0x01)。
根据生成密钥的不同,输入的算法类型标识符的值也不同,如表1所示。
表1
根据使用的算法的不同,输入的算法标识的值也可以不同。本申请实施例使用的加密算法可以包括以下中的一种或多种:NIA1,NIA2,NIA3,完整性保护算法可以包括以下中的一种或多种:EIA1,EIA2,EIA3。
图6示出了本申请实施例涉及的各个参数的生成方式。
UE可以存储一个长期密钥K以及归属域网络的公钥,该公钥可用于加密SUPI。在USIM中计算的5个重要参数可以包括消息认证码(message authentication code,MAC)、响应(response,RES)、CK、IK和AK,这些参数的计算方式可以如下:
MAC=f1K(SQN||RAND||AMF);
RES=f2K(RAND);
CK=f3K(RAND);
IK=f4K(RAND);
AK=f5K(RAND)。
零功耗通信
随着无线通信技术的发展,人们希望将无线通信系统与物流、制造、运输、能源等各个垂直行业进行融合,例如,可以将无线通信系统与工业无线传感器网络(industrial wireless sensor network,IWSN)进行融合。又例如,可以将无线通信系统与智慧物流和智慧仓储进行融合。又例如,可以将无线通信系统与智能家庭网络进行融合。
然而,在这些行业中,终端设备通常需要具备较低的成本、较小的尺寸(如超薄)、免维护、长寿命等特点。因此,为了满足上述条件,网络设备和终端设备之间可以采用零功耗通信技术进行通信,在这种情况下,终端设备又可以称为“零功耗通信终端”、零功耗终端”或标签(Tag)。
在引入零功耗终端后,零功耗终端目前有两种通信方式。下面分别对这两种通信方式进行介绍。
通信方式一是零功耗终端与基站直接进行通信。基站可以向零功耗终端提供无线供能信号和触发信号。无线供能信号可用于向零功耗终端提供能量。触发信号可以携带发送给零功耗终端的控制信息。零功耗终端可以通过反向散射的方式将信息传输给基站。
通信方式二是混合通信方式,即该通信方式中包括蜂窝通信和侧行通信。在零功耗系统的实际部署中,基于蜂窝通信和侧行通信的零功耗通信系统可灵活共存或组合使用,从而匹配更多的潜在应用场景。
图7示出的是一种混合通信系统。图7示出的通信方式包括四种,下面分别对这四种通信方式进行介绍。
方式一,零功耗终端由终端设备提供供能信号和触发信号,零功耗终端的反向散射信号由基站接收。
方式二,基站向零功耗终端提供无线供能信号和发送触发信令,零功耗终端的反向散射信号由终端设备接收,从而完成侧行通信。另外,终端设备可以向基站发送空口数据。
方式三,终端设备为零功耗终端提供供能信号,基站向零功耗终端发送触发信息,并接收零功耗终端的反向散射信号。
方式四,终端设备接收网络设备发送的空口信令和数据。终端设备为零功耗终端提供供能信号和触发信号,并接收零功耗终端发送的反向散射信号,以完成侧行通信。
针对零功耗终端,如何实现零功耗终端与网络侧之间的安全认证,目前还没有明确的方案。
目前面向物联网的低吞吐量机器类型通信设备设计的电池高效安全(battery efficient security for very low throughput machine type communication devices,BEST)、机器类型通信(machine type communication,MTC)、新无线物联网(new radio-internet of things,NB-IoT)的安全标准基于AKA、通用引导架构(generic bootstrapping architecture,GBA)、AKMA等认证与密钥协商机制,存在密钥架构、交互流程和安全计算复杂度高的问题。如上文中描述的认证方式,在生成认证向量的过程中,需要终端设备同时支持f1-f5中的各种函数。MAC使用的f1函数,RES使用的是f2函数,CK使用的是f3函数,IK使用的是f4函数,AK使用的是f5函数。由于零功耗终端的计算能力较低,因此,这种方式不适合零功耗终端。
针对蜂窝与侧行通信混合的应用场景,目前的用户设备到网络中继(user equipment-to-network relay)安全存在基于近场的服务通信(proximity-based service communication,PC)5安全、U2N中继安全密钥架构、交互流程、安全计算复杂度高的问题,使得这种安全方式也不适用于零功耗终端。
另外,目前的国际标准化组织(international organization for standardization,ISO)射频识别(radio frequency identification,RFID)安全标准和标签与读写器空中接口安全(tag and reader air interface security,TRAIS)安全标准仅支持Tag和读写器(Reader)之间的认证和密钥协商,不支持Tag与网络侧之间的认证和密钥协商,也就是说,这些安全标准无法实现Tag与网络侧之间的认证与密钥协商。
针对上述问题,本申请实施例提供一种认证方法和装置,能够以一种简化的方式实现认证与密钥协商流程,从而能够适用于第一设备(如零功耗终端)与网络侧之间的安全认证。本申请实施例的认证方法只需要第一设备支持一种或两种密钥生成算法,即可实现第一设备与网络侧之间的认证与密钥协商流程,从而可以降低第一设备的复杂度。
本申请实施例中的第一设备可以为零功耗终端。该第一设备例如可以为Tag或环境使能的物联网设备(ambient power-enabled internet of things,A-IoT)设备。
在介绍本申请提供的认证方法之前,先对第一设备的通信模式和本申请涉及的安全凭证进行介绍。
本申请实施例根据第一设备的协议栈设计的不同,可以将第一设备的通信模式分为两类。第一类为非直接模式(indirect mode),第二类为直接模式(direct mode)。
对于非直接模式,第一设备不支持应用层协议,第一设备可以通过代理节点连接到服务域网元和/或AF。
本申请实施例中的服务域网元例如可以包括以下中的一种或多种:AMF、服务管理功能(service  management function,SMF)、SEAF、特定于A-IoT服务的核心网功能(ambient network function,A-NF)等。代理节点例如可以包括终端设备和/或集成接入和回程(integrated access and backhaul,IAB)节点等。终端设备例如可以为UE。
在一些实现方式中,代理节点可以转发第一设备与网络侧(如认证网元)之间的认证信息。在另一些实现方式中,代理节点也可以对认证信息进行一些处理。例如,代理节点可以通过NAS消息(如NAS安全上下文)或AS消息(如AS安全上下文)传输认证信息。又例如,代理节点可以对认证过程中的一些加密信息(如第一设备的隐藏身份标识)进行解密。下文将会结合具体的实施例对代理节点的具体处理方式进行详细描述。
对于直接模式,第一设备可以支持应用层协议(如超文本传输协议(hyper text transfer protocol,HTTP))。或者,第一设备的媒体接入控制(media access control,MAC)层或物理(physical,PHY)层具有支持上层协议(如应用层)的功能,从而使得第一设备支持应用层协议功能。在一些实现方式中,第一设备可以通过应用层协议连接到AF。
本申请实施例可以在第一设备与第三方服务器(如AF)之间建立安全的通信链路。第三方服务器可以依赖核心网对第一设备进行认证与密钥协商。根据安全凭证提供方的不同,本申请实施例中的安全凭证可以分为两类。一类安全凭证为3GPP安全凭证,另一类安全凭证为非3GPP安全凭证。
3GPP安全凭证可以理解为第一设备与认证网元之间共享的根密钥(简称K)。如果安全凭证为3GPP安全凭证,则网络侧(如UDM)可以进行授权管理,如存储认证结果。该管理授权可以为基于订阅凭证的授权管理。该认证结果例如可以包括以下中的一种或多种:第一设备认证的时间戳、第一设备的ID、第一设备的认证方式和第一设备安全上下文的标识。
图8示出的是一种基于3GPP安全凭证的通信架构。第一设备可以与核心网执行认证与密钥协商流程。在一些实现方式中,第一设备可以和第三方服务器进行通信,第三方服务器可以和核心网进行通信。
非3GPP安全凭证可以为第三方应用服务器提供的安全凭证,如第一设备与AF或网络应用功能(network application function,NAF)之间共享的根密钥(简称K)。第三方应用服务器(如AF或NAF)可以进行授权管理。该授权管理可以为基于应用层的授权管理。在涉及代理节点的场景中,第三方应用服务器可以管理代理节点与第一设备之间的映射,以及向认证网元提供安全凭证K,或向认证网元提供由安全凭证K衍生出的下级密钥。
图9示出的是一种基于3GPP安全凭证的通信架构。与图8不同的是,第三方服务器可以与核心网进行通信,以向核心网提供安全凭证K或由安全凭证K衍生出的下级密钥。
需要说明的是,本申请实施例中的安全凭证可以理解为根密钥。
下面结合图10-图20,对本申请实施例的认证方式进行详细介绍。需要说明的是,以下四个示例和不同附图中的方案在不存在冲突的情况下,都可以相互结合使用。
示例一
示例一的方案中,安全凭证为3GPP安全凭证,第一设备通过代理节点与网络侧进行通信。
图10是本申请实施例提供的一种认证方法的流程示意图。参见图10,在步骤S1010,认证网元生成第一消息认证码和/或期望响应。第一消息认证码可用于认证认证网元。期望响应可用于认证第一设备。在一些实施例中,第一消息认证码可以使用第一MAC表示,期望响应可以使用XRES表示。
本申请实施例对第一消息认证码的生成方式不做具体限定。例如,该第一消息认证码可以基于第一密钥生成算法和第一参数生成。第一密钥生成算法可以为任意一种函数。该函数可以为以下中的任意一种:f函数、KDF或其他轻量级函数。f函数例如可以为3GPP定义的f1函数、f2函数、f3函数、f4函数、f5函数中的任意一个。KDF例如可以为HMAC-SHA-256或HMAC-SM3。轻量级函数例如可以为ASCON。
第一参数可以包括以下中的一种或多种:安全凭证、第一随机数、第二随机数和第一密钥。例如,第一参数可以包括安全凭证和第二随机数。又例如,第一参数可以包括安全凭证、第二随机数和第一密钥。又例如,第一参数可以包括安全凭证、第二随机数和第一随机数。又例如,第一参数可以包括安全凭证、第二随机数、第一随机数和第一密钥。
安全凭证可以是上文描述的3GPP安全凭证或非3GPP安全凭证。第一随机数(记为N2)可以是认证网元选择的随机数或者也可以是认证网元与第一设备之间的共享密钥。该第一随机数可用于抵御重放攻击。第二随机数(记为RAND)可以是认证网元选择的随机数。第一密钥(记为N1)可以为以下中的一种或多种:第一设备与网络侧设备(如认证网元)预先共享的随机数,第一设备与代理节点之间的共享密钥,第一设备与基站之间的共享密钥。该共享密钥可以为物理层密钥。
在一些实施例中,第一消息认证码和期望响应可以基于相同的密钥生成算法和不同的参数生成,或者,第一消息认证码和期望响应可以基于不同的密钥生成算法和相同的参数生成,这样可以降低生成第 一消息认证码和期望响应的复杂度。
作为一个示例,生成期望响应所使用的密钥生成算法与生成第一消息认证码所使用的密钥生成算法相同。例如,第一消息认证码可以基于第一密钥生成算法和第一参数生成,期望响应可以基于第一密钥生成算法和第二参数生成。
第二参数可以包括以下中的一种或多种:安全凭证、第一随机数、第二随机数和第一密钥。第一参数与第二参数不同,以保证生成的期望响应与第一消息认证码不同。例如,第一参数包括安全凭证和第一随机数。第二参数包括安全凭证、第一随机数和第二随机数。又例如,第二参数包括安全凭证、第一随机数和第二随机数,第二参数包括第二参数包括安全凭证、第一随机数、第二随机数和第一密钥。又例如,第一参数包括安全凭证、第一随机数和第二随机数,第二参数包括安全凭证和第一随机数。
作为另一个示例,生成期望响应所使用的参数与生成第一消息认证码所使用的参数相同。例如,第一消息认证码可以基于第一密钥生成算法和第一参数生成,期望响应可以基于第二密钥生成算法和第一参数生成。
第一密钥生成算法与第二密钥生成算法不同,以保证生成的期望响应与第一消息认证码不同。第二密钥生成算法可以为任意一种函数。例如,第二密钥生成算法可以为以下中的任意一种:f函数、KDF或其他轻量级函数。f函数例如可以为3GPP定义的f1函数、f2函数、f3函数、f4函数、f5函数中的任意一个。KDF例如可以为HMAC-SHA-256或HMAC-SM3。轻量级函数例如可以为ASCON。
类似地,第一设备可以生成第二消息认证码和/或响应参数。第二消息认证码可用于认证认证网元,响应参数可用于认证第一设备。在一些实施例中,第二消息认证码可以使用第二MAC表示,响应参数可以使用RES表示。
在一些实施例中,第二消息认证码的生成方式与第一消息认证码的生成方式一致。例如,第二消息认证码可以基于第一密钥生成算法和第一参数生成。第一密钥生成算法与第一参数可以参见前文的描述,为了简洁,此处不再赘述。
举例说明,消息认证码可以基于以下公式中的一种或多种确定:MAC=fK(RAND,N1,N2)、MAC=fK(RAND)、MAC=fK(RAND,N1)、MAC=fK(RAND,N2)。
期望响应可以基于以下公式中的一种或多种确定:XRES=fK(RAND,N1,N2)、XRES=fK(RAND)、XRES=fK(RAND,N1)、XRES=fK(RAND,N2)。
其中,MAC表示第一消息认证码或第二消息认证码,f表示第一密钥生成算法或第二密钥生成算法,RAND表示第二随机数,N1表示第一密钥,N2表示第二随机数,K表示安全凭证。
在一些实施例中,响应参数的生成方式与期望响应的生成方式一致。例如,响应参数可以基于第二密钥生成算法和第一参数生成,或者,响应参数可以基于第一密钥生成算法和第二参数生成。响应参数的具体生成方式可以参见前文期望响应的生成方式,为了简洁,此处不再赘述。
在一些实施例中,第一设备可以接收来自认证网元的第一消息认证码。第一设备可以通过代理节点接收来自认证网元的第一消息认证码。第一设备可以比较第一消息认证码和第二消息认证码,以认证认证网元。如果第一消息认证码和第二消息认证码一致,则表示认证网元认证成功;如果第一消息认证码和第二消息认证码不一致,则表示认证网元认证失败。
在一些实施例中,认证网元可以接收来自第一设备的响应参数。认证网元可以通过代理节点接收来自第一设备的响应参数。认证网元可以比较响应参数与期望响应,以认证第一设备。如果响应参数与期望响应一致,则表示第一设备认证成功;如果响应参数与期望响应不一致,则表示第一设备认证失败。
在一些实现方式中,图10所示的方法还可以包括步骤S1020~步骤S1070。
在步骤S1020,认证网元向代理节点发送第一认证请求。该第一认证请求中包括第一消息认证码。
认证网元向代理节点发送第一认证请求可以指认证网元直接向代理节点发送第一认证请求,或者,可以指认证网元通过其他设备向代理节点发送第一认证请求。其他设备例如可以包括基站和/或服务域网元。该服务域网元可以包括AMF和/或SMF。
在步骤S1030,代理节点向第一设备发送第一认证请求。
在步骤S1040,第一设备基于第一密钥生成算法和第一参数生成第二消息认证码。具体的生成方式可以参见前文的描述。在一些实施例中,第一设备可以在接收到第一认证请求之前,生成第二消息认证码,或者,第一设备也可以在接收到第一认证请求之后,再生成第二消息认证码。
在步骤S1050,第一设备基于第一消息认证码和第二消息认证码认证认证网元。如果第一消息认证码与第二消息认证码一致,则第一设备可以确定认证网元认证成功;如果第一消息认证码和第二消息认证码不一致,则第一设备可以确定认证网元认证失败。
在步骤S1060,在认证网元认证成功的情况下,第一设备生成响应参数。如果认证网元认证失败,则第一设备可以不生成响应参数,以降低第一设备的计算量。当然,在一些实施例中,不论认证网元是 否认证成功,第一设备都可以生成响应参数。例如,第一设备可以在接收到第一认证请求之前,生成响应参数。
在步骤S1070,第一设备向代理节点发送第一认证响应。该第一认证响应中可以包括响应参数。
在步骤S1080,代理节点向认证网元发送第一认证响应。该第一认证响应中可以包括响应参数。
在一些实施例中,代理节点可以向认证网元发送响应参数。认证网元接收到响应参数后,可以比较响应参数和期望响应,以认证第一设备。
为了提高认证的安全性,本申请实施例可以从归属域网络、服务域网络和接入网络的角度对第一设备进行认证。例如,响应参数可以包括以下中的一种或多种:第一响应参数、第二响应参数和第三响应参数。第一响应参数可用于归属域网络(或归属域网元)认证第一设备,第二响应参数可用于服务域网络(或服务域网元)认证第一设备,第三响应参数可用于接入网络(或接入网设备)认证第一设备。第一响应参数可以记为RES1,第二响应参数可以记为RES2,第三响应参数可以记为RES3。
又例如,期望响应可以包括以下中的一种或多种:第一期望响应、第二期望响应和第三期望响应。第一期望响应可用于归属域网络(或归属域网元)认证第一设备,第二期望响应可用于服务域网络(或服务域网元)认证第一设备,第三期望响应可用于接入网络(或接入网设备)认证第一设备。第一期望响应可以记为XRES1,第二期望响应可以记为XRES2,第三期望响应可以记为XRES3。
在一些实施例中,期望响应可以包括第一期望响应和第二期望响应,以从归属域网络和服务域网络的角度认证第一设备。在一些实施例中,期望响应可以包括第一期望响应和第三期望响应,以从归属域网络和接入网络的角度认证第一设备。在一些实施例中,期望响应可以包括第二期望响应和第三期望响应,以从服务域网络和接入网络的角度认证第一设备。在一些实施例中,期望响应可以包括第一期望响应、第二期望响应和第三期望响应,以从归属域网络、服务域网络和接入网络的角度认证第一设备。
下面对各个网络认证第一设备的认证方式进行介绍。
归属域网元可以比较第一响应参数和第一期望响应,以认证第一设备。第一期望响应可以由归属域网元生成,第一响应参数可以由第一设备生成。第一设备可以将第一响应参数发送至归属域网元。如果第一响应参数与第一期望响应一致,则归属域网元可以从归属域网络的角度认为认证成功。如果第一响应参数和第一期望响应不一致,则归属域网元可以从归属域网络的角度认为认证失败。归属域网元可以包括AUSF和/或UDM。
服务域网元可以比较第二响应参数和第二期望响应,以认证第一设备。第二期望响应可以由归属域网元生成,归属域网元可以将第二期望响应发送至服务域网元。第二响应参数可以由第一设备生成,第一设备可以将第二响应参数发送至服务域网元。如果第二响应参数和第二期望响应一致,则服务域网元可以从服务域网络的角度认为认证成功。如果第二响应参数和第二期望响应不一致,则服务域网元可以从服务域网络的角度认为认证失败。服务域网元可以包括AMF和/或SMF。
接入网设备可以比较第三响应参数和第三期望响应,以认证第一设备。如果第三响应参数和第三期望响应一致,则接入网设备可以从接入网络的角度认为认证成功。如果第三响应参数和第三期望响应不一致,则接入网设备可以从接入网络的角度认为认证失败。接入网设备可以为基站。
在一些实施例中,第三期望响应可以由归属域网元生成,归属域网元可以将第三期望响应发送至接入网设备。或者,第三期望响应可以由接入网设备生成。认证网元可以向接入网设备发送第一期望响应,接入网设备基于接收到的第一期望响应,生成第三期望响应。例如,对于第一密钥为第一设备与接入网设备之间的共享密钥的情况,接入网设备可以基于第一期望响应和第一密钥生成第三期望响应。
在一些实施例中,第三响应参数可以由第一设备生成,第一设备可以将第三响应参数发送至接入网设备。
下面对各个响应参数和各个期望响应的生成方式进行介绍。
在一些实施例中,第一响应参数和第二消息认证码(或第一消息认证码)所基于的密钥生成算法相同,以降低第一设备的计算复杂度。例如,第一响应参数可以基于第一密钥生成算法和第二参数生成,换句话说,第一设备可以基于第一密钥生成算法和第二参数生成第一响应参数。
在一些实施例中,第一响应参数和第二消息认证码(或第一消息认证码)所基于的参数相同,以降低第一设备的计算复杂度。例如,第一响应参数可以基于第二密钥生成算法和第一参数生成,换句话说,第一设备可以基于第二密钥生成算法和第一参数生成第一响应参数。第一响应参数的生成方式可以与上文中的期望响应的生成方式一致。
举例说明,第一响应参数可以基于以下公式确定:
RES1=fK(RAND,N1,N2)
其中,RES1表示第一响应参数,f表示第一密钥生成算法或第二密钥生成算法,RAND表示第二随机数,N1表示第一密钥,N2表示第二随机数,K表示安全凭证。
在一些实施例中,第二响应参数可以基于第一响应参数和第三参数生成,换句话说,第一设备可以基于第一响应参数和第三参数生成第二响应参数。第三参数可以包括以下中的一种或多种:安全凭证、服务域网络名称(SN name)(或服务域网络标识)。在一些实现方式中,第二响应参数和第一响应参数可以基于相同的密钥生成算法生成,或者,第二响应参数和第二消息认证码(或第一消息认证码)可以基于相同的密钥生成算法生成。例如,第二响应参数可以基于第一密钥生成算法、第一响应参数和第三参数生成。又例如,第二响应参数可以基于第二密钥生成算法、第一响应参数和第三参数生成。
举例说明,第二响应参数可以基于以下公式确定:
RES2=fK(RES1,SN name)
其中,RES2表示第二响应参数,f表示第一密钥生成算法或第二密钥生成算法,RES1表示第一响应参数,SN name表示服务域网络名称或标识,K表示安全凭证。
在一些实施例中,第三响应参数可以基于第一响应参数和第四参数生成,换句话说,第一设备可以基于第一响应参数和第四参数生成第三响应参数。第四参数可以包括第一密钥。在一些实现方式中,第三响应参数和第一响应参数可以基于相同的密钥生成算法生成,或者,第三响应参数和第二消息认证码(或第一消息认证码)可以基于相同的密钥生成算法生成。例如,第三响应参数可以基于第一密钥生成算法、第一响应参数和第四参数生成。又例如,第三响应参数可以基于第二密钥生成算法、第一响应参数和第四参数生成。
举例说明,第三响应参数可以基于以下公式确定:
RES3=fN1(XRES1)
其中,RES3表示第三响应参数,f表示第一密钥生成算法或第二密钥生成算法,RES1表示第一响应参数,N1表示第一密钥。
上述各个响应参数的生成方式仅是一种示例,本申请实施例对此不做具体限定。例如,第二响应参数可以基于第三响应参数生成。又例如,第三响应参数可以基于第二响应参数生成。
第一期望响应与第一响应参数的生成方式类似,第二期望响应与第二响应参数的生成方式类似,第三期望响应与第三响应参数的生成方式类似,为了简洁,此处不再赘述。
在一些实施例中,认证网元可以生成第一匿名密钥。第一匿名密钥可用于第一设备与网络侧之间的安全传输。
在一些实施例中,为了降低生成第一匿名密钥的计算复杂度,第一匿名密钥可以基于第一密钥生成算法或第二密钥生成算法生成。例如,第一匿名密钥可以基于第一密钥生成算法和第九参数生成。又例如,第一匿名密钥可以基于第二密钥生成算法和第九参数生成。第九参数可以包括以下参数中的一种或多种:安全凭证、第一随机数、第二随机数和第一密钥。
以第九参数包括安全凭证和第二随机数为例,第一匿名密钥可以基于如下公式确定:
AK=fK(RAND)
其中,AK表示第一匿名密钥,K表示安全凭证,RAND表示第二随机数,f表示第一密钥生成算法或第二密钥生成算法。
公式AK=fK(RAND)适用于第一密钥是第一设备与认证网元之间的共享密钥的情况,也适用于第一密钥是代理节点发送给认证网元的情况。
在一些实施例中,为了降低生成第一匿名密钥的计算复杂度,第一匿名密钥可以通过异或的运算方式生成。例如,第一匿名密钥可以由安全凭证和第一密钥通过异或的方式生成。也就是说,第一匿名密钥可以基于如下公式确定:
AK=K⊕N1
其中,AK表示第一匿名密钥,K表示安全凭证,N1表示第一密钥,⊕表示异或运算。
上述公式AK=K⊕N1适用于第一密钥是第一设备与认证网元之间的共享密钥的情况。认证网元可以基于共享密钥N1生成AK。
类似地,第一设备也可以生成第二匿名密钥。第二匿名密钥的生成方式与第一匿名密钥的生成方式相同,为了简洁,此处不再赘述。
在接收来自代理节点的第一认证请求之前,第一设备可以向代理节点发送第二认证请求。换句话说,第一设备可以通过发送第二认证请求,以触发第一设备与网络侧之间的认证流程。
在一些实施例中,第二认证请求中可以包括第一设备的隐藏身份标识。为了保证信息的安全性,第一设备可以对第一设备的身份标识进行匿名处理,得到隐藏身份标识。
隐藏身份标识的生成方式有多种。例如,隐藏身份标识可以基于第一设备的身份标识和第一密钥生成。又例如,隐藏身份标识可以基于第一设备的身份标识、第一密钥和安全凭证生成。第一设备的身份标识可以理解为第一设备的真实身份标识。
下文以隐藏身份标识基于第一设备的身份标识和第一密钥生成为例,对隐藏身份标识的生成方式进行详细描述。
在一些实施例中,隐藏身份标识可以通过异或的运算方式生成,以降低第一设备的计算复杂度。例如,隐藏身份标识可以由第一设备的身份标识和第一密钥通过异或的运算方式生成。换句话说,第一设备可以对第一设备的身份标识以及第一密钥进行异或运算,生成隐藏身份标识。
举例说明,隐藏身份标识可以基于以下公式确定:
DIDi=IDi⊕N1
其中,DIDi表示隐藏身份标识,IDi表示第一设备的身份标识,N1表示第一密钥,⊕表示异或运算。
在一些实施例中,隐藏身份标识可以基于第一设备的身份标识、第一密钥以及第三密钥生成算法生成。换句话数,第一设备可以基于第一设备的身份标识、第一密钥以及第三密钥生成算法生成隐藏身份标识。其中,第三密钥生成算法可以为第一密钥生成算法或第二密钥生成算法,以降低第一设备的计算复杂度。
举例说明,隐藏身份标识可以基于以下公式确定:
DIDi=fN1(IDi)
其中,DIDi表示隐藏身份标识,IDi表示第一设备的身份标识,N1表示第一密钥,f表示第三密钥生成算法。
第一密钥可以为第一设备与网络侧(如认证网元)之间的共享密钥(或随机数),或者也可以是第一设备与代理节点之间的共享密钥,或者也可以是第一设备与基站之间的共享密钥。该共享密钥可以为物理层密钥。如果第一密钥为物理层密钥,则第一设备可以不用预先存储第一密钥,而是通过提取物理层信道特征得到第一密钥。
如果第一密钥可以为第一设备与网络侧(如认证网元)之间的共享密钥,则认证网元可以向第一设备发送新的第一密钥,以更新隐藏身份标识。
根据第一密钥的不同,第一设备生成隐藏身份标识的方式可以不同。例如,如果第一密钥为第一设备与网络侧之间的共享密钥,则隐藏身份标识可以通过公式DIDi=IDi⊕N1生成。又例如,如果第一密钥为第一设备与代理节点之间的共享密钥,则隐藏身份标识可以通过公式DIDi=IDi⊕N1或公式DIDi=fN1(IDi)生成。
代理节点接收到第二认证请求后,可以向认证网元发送该第二认证请求。代理节点发送的第二认证请求中可以包括以下信息中的一种或多种:第一密钥、第一设备的身份标识、隐藏身份标识和代理节点的标识。代理节点的标识可以包括以下中的一种或多种:GPSI、SUCI、全球唯一临时标识(globally unique temporary identifier,GUTI)、SUPI。
在一些实施例中,代理节点可以根据第一密钥的不同,采取不同的处理策略。作为一个示例,如果第一密钥为第一设备与网络侧之间的共享密钥,则代理节点发送的第二认证请求中可以包括以下中的一种或多种:隐藏身份标识和代理节点的标识。
作为另一个示例,如果第一密钥为第一设备与代理节点之间的共享密钥,则代理节点可以对隐藏身份标识进行解匿名,得到第一设备的身份标识。例如,代理节点可以基于第一密钥与隐藏身份标识,确定第一设备的身份标识。
如果隐藏身份标识由第一密钥和第一设备的身份标识通过异或的方式生成,则代理节点可以通过如下公式确定第一设备的身份标识:
IDi=DIDi⊕N1
其中,DIDi表示隐藏身份标识,IDi表示第一设备的身份标识,N1表示第一密钥,⊕表示异或运算。
如果隐藏身份标识基于第一密钥、第一设备的身份标识和第三密钥生成算法生成,则代理节点可以通过如下公式确定第一设备的身份标识:
IDi=fN1(DIDi)
其中,DIDi表示隐藏身份标识,IDi表示第一设备的身份标识,N1表示第一密钥,f表示第三密钥生成算法。
在得到第一设备的身份标识后,第一设备发送的第二认证请求中可以包括以下中的一种或多种:第一密钥、第一设备的身份标识和代理节点的标识。
如果第二认证请求中包括第一设备的身份标识,为了保证信息的安全性,代理节点可以通过NAS消息或AS消息发送第二认证请求消息。例如,代理节点可以通过NAS安全上下文或AS安全上下文发送第二认证请求消息。
认证网元接收到第二认证请求后,如果第二认证请求中包括隐藏身份标识,则认证网元可以通过对隐藏身份标识进行解匿名,得到第一设备的身份标识。例如,如果第一密钥为第一设备与认证网元之间的共享密钥,则认证网元可以基于第一密钥,对隐藏身份标识进行解匿名。例如,认证网元可以通过公式IDi=DIDi⊕N1得到第一设备的身份标识。
认证网元在得到第一设备的身份标识后,可以利用第一设备的身份标识生成后文中的第四密钥。
在第一设备和认证网元认证成功的情况下,第一设备和认证网元可以生成第二密钥(记为Ks)。第二密钥也可以理解为第一设备与认证网元之间的共享密钥。第二密钥可以基于第六密钥生成算法和第六参数生成。第六密钥生成算法可以为第一密钥生成算法或第二密钥生成算法,以降低第一设备的计算复杂度。第六参数可以包括以下参数中的一种或多种:第一匿名密钥、第一密钥、第一随机数、代理节点的标识、第一设备的标识、服务域网络的名称和归属域网络标识。
举例说明,第二密钥可以基于以下公式确定:
Ks=fAK(N1,N2,UE ID,IDi,SN name)
其中,Ks表示第二密钥,AK表示第一匿名密钥,N1表示第一密钥,N2表示第一随机数,UE ID表示代理节点的标识,IDi表示第一设备的身份标识,SN name表示服务域网络的名称,f表示第六密钥生成算法。
生成AKMA密钥
上述第二密钥可用于AKMA密钥的生成。也就是说,第一设备可以基于第二密钥,生成AKMA密钥。或者,认证网元可以基于第二密钥,生成AKMA密钥。
可以理解的是,第一设备生成AKMA密钥的方式与认证网元生成AKMA密钥的方式相同。下面以第一设备为例,对AKMA密钥的生成方式进行介绍。认证网元生成AKMA密钥的方式可以参考第一设备生成AKMA密钥的方式,为了简洁,不再重复描述。
第一设备可以基于第二密钥和第四密钥生成算法,生成AKMA密钥。第四密钥生成算法可以为第一密钥生成算法或第二密钥生成算法,以降低第一设备的计算复杂度。在一些实施例中,第一设备可以基于第二密钥、第四密钥生成算法以及第五参数生成。第五参数可以包括以下中的一种或多种:AKMA、第一设备的身份标识。
举例说明,AKMA密钥可以基于以下公式确定:
KAKMA=fKs(“AKMA”,“IDi”)
其中,KAKMA表示AKMA密钥,Ks表示第一匿名密钥,IDi表示第一设备的身份标识。
在一些实施例中,第二密钥可用于生成密钥标识。或者说,第一设备可以基于第二密钥生成密钥标识。该密钥标识例如可以包括A-TID和/或A-KID。例如,A-TID可以基于第一设备的身份标识、第一匿名密钥和第七密钥生成算法生成。该第七密钥生成算法可以为第一密钥生成算法或第二密钥生成算法。
举例说明,A-TID可以基于以下公式确定:
A-TID=fKs(IDi)
其中,f表示第七密钥生成算法,Ks表示第一匿名密钥,IDi表示第一设备的身份标识。
在一些实施例中,A-KID可以基于A-TID生成。例如,A-KID可以基于A-TID以及第七参数生成。第七参数可以包括以下参数中的一种或多种:RID和归属域网络标识(home network identifier,HNI)。为了降低第一设备的计算复杂度,A-KID可以由A-TID、RID和第七参数通过级联的方式得到。
例如,A-KID可以基于以下公式确定:
A-KID=A-TID||RID||HNI
在一些实施例中,认证网元可以向AAnF和/或密钥管理服务(key management server,KMS)发送密钥参数,该密钥参数可以包括以下中的一种或多种:AKMA密钥、A-KID和第一设备的标识。
在一些实施例中,AAnF和/或AMF接收到AKMA密钥后,可以基于AKMA密钥生成应用密钥(记为KAF)。应用密钥可以基于第八密钥生成算法和第八参数生成。第八参数可以包括以下参数中的一种或多种:AF ID、IDi、代理节点的标识、A-KID。第八密钥生成算法可以为第一密钥生成算法或第二密钥生成算法,以降低第一设备的计算复杂度。
例如,应用密钥可以基于以下公式确定:
KAF=fKs(AF ID,IDi,UE ID,A-KID)
其中,KAF表示应用密钥,f表示第八密钥生成算法,AF ID表示AF的标识,IDi表示第一设备的身份标识,UE ID表示代理节点的标识。
在一些实施例中,AAnF可以在接收到来自AF的应用密钥请求消息后,生成应用密钥。
可以理解的是,第一设备生成应用密钥的方式与AAnF生成应用密钥的方式相同,为了简洁,此处不再赘述。在一些实施例中,第一设备可以在向AF发送应用会话建立请求消息后,生成应用密钥。
在一些实施例中,应用密钥可用于生成第三密钥,该第三密钥可用于第一设备与代理节点之间的安全通信。也就是说,第一设备与代理节点可以基于第三密钥,进行安全通信。
在一些实现方式中,第三密钥可以包括完整性保护密钥和/或加密密钥。也就是说,以设备和代理节点可以基于应用密钥生成完整性保护密钥和/或加密密钥。基于应用密钥生成完整性保护密钥和/或加密密钥的方式可以为相关技术中的方式,本申请实施例对此不做具体限定。
在一些实现方式中,第三密钥可以基于应用密钥和第一密钥生成。第一密钥为第一设备与代理节点之间的共享密钥。为了降低第一设备的计算复杂度,第三密钥可以由应用密钥和第一密钥通过异或的方式生成。
例如,第三密钥可以基于以下公式确定:
Ku1=KAF⊕N1
其中,Ku1表示第三密钥,KAF表示应用密钥,N1表示第一密钥,⊕表示异或运算。
在一些实施例中,第三密钥(如Ku1)可用于进一步生成完整性保护密钥和/或加密密钥。本申请实施例通过先生成第三密钥,再生成完整性保护密钥和/或加密密钥,能够为第一设备的移动性管理提供一种简化的方式。例如,如果第一设备由于移动,导致连接的代理节点发生了变化,第一设备可以直接基于与代理节点之间的共享密钥生成第三密钥,并进一步生成完整性保护密钥和/或加密密钥,从而可以不用再进行第一设备与网络侧之间的认证与密钥协商流程。
举例说明,如果与第一设备连接的代理节点从第一代理节点变为第二代理节点,第一设备与第一代理节点之间的共享密钥为N1,第一设备与第二代理节点之间的共享密钥为N3,在第一设备与第一代理节点处于连接状态时,第一设备可以基于应用密钥以及N1,生成第三密钥,并进一步生成与第一代理节点进行安全通信的完整性保护密钥和/或加密密钥。在第一设备与第二代理节点处于连接状态时,第一设备可以基于应用密钥以及N3,生成第三密钥,并进一步生成与第二代理节点进行安全通信的完整性保护密钥和/或加密密钥。由上可知,在连接的代理节点发生变化时,第一设备可以跳过认证与密钥协商流程,来生成不同的完整性保护密钥和/或加密密钥,而是可以基于不同的第一密钥,生成不同的完整性保护密钥和/或加密密钥,以与不同的代理节点进行安全通信。
对于第一消息认证码需要基于第一随机数生成的情况,如果第一随机数由认证网元选择,则认证网元还可以将第一随机数发送至第一设备,以使第一设备可以基于第一随机数生成第二消息认证码。
在一些实施例中,为了保证第一随机数的安全性,认证网元可以使用第一匿名密钥保护第一随机数的传输安全。为了降低计算复杂度,认证网元可以将第一匿名密钥与第一随机数进行异或运算,得到第十参数,即第十参数可以为N2⊕AK。认证网元可以向第一设备发送第十参数,或者认证网元可以向第一设备发送第十一参数,第十一参数可以为N2⊕AK||MAC。其中,MAC为第一消息认证码,N2为第一随机数,AK为第一匿名密钥,||表示级联。
第一设备接收到认证网元发送的第十参数或者第十一参数后,可以基于第一匿名密钥,确定第一随机数。然后基于第一随机数,生成第二消息认证码。进一步地,第一设备可以基于第一消息认证码和第二消息认证码,认证认证网元。
在一些实施例中,对于第一消息认证码基于第二随机数生成的情况,认证网元还可以将第二随机数发送至第一设备,以使第一设备基于第二随机数,生成第二消息认证码。
下面结合图11-图13,对有代理节点参与的认证与密钥协商流程进行详细介绍。
图11示出的是第一设备与认证网元之间进行认证的流程。第一设备可以与认证网元共享密钥K,该密钥K即为上文描述的安全凭证。第一设备可以与基站和/或代理节点共享密钥N1,该密钥N1即为上文描述的第一密钥。该密钥N1可以为物理层密钥。
参见图11,在步骤S1102,第一设备向代理节点发送认证请求。该认证请求中可以包括第一设备的隐藏身份标识DIDi。隐藏身份标识DIDi可以基于第一设备的身份标识IDi生成。
隐藏身份标识DIDi的生成方式有两种。如果N1是第一设备与AUSF之间预先共享的密钥(或随机数),则DIDi可以基于以下公式确定:DIDi=IDi⊕N1。在建立第一设备的安全上下文之后,AUSF可以向第一设备发送新的第一密钥以更新DIDi。
如果N1是第一设备与代理节点之间的共享密钥(如物理层密钥),则DIDi可以基于公式DIDi=IDi⊕N1或DIDi=fN1(IDi)确定。
在步骤S1104,代理节点向服务域网元发送认证请求。在一些实现方式中,代理节点可以通过基站向服务域网元发送认证请求。服务域网元可以包括AMF、SEAF、SMF、A-NF中的一个或多个。
在一些实施例中,该认证请求中可以包括DIDi和代理节点的标识。例如,如果N1为第一设备与认证网元之间的共享密钥,则认证请求中可以包括DIDi和代理节点的标识。
在一些实施例中,如果N1是第一设备与代理节点之间的共享密钥,则代理节点可以基于N1对 DIDi解匿名,得到第一设备的身份标识IDi。代理节点发送的认证请求中可以包括以下中的一种或多种:IDi、代理节点的标识和N1。
代理节点的标识可以包括GPSI、SUCI、GUTI中的一种或多种。
为了保证信息的安全性,代理节点可以通过NAS消息发送认证请求,例如,代理节点可以通过NAS安全上下文发送认证请求。
在步骤S1106,服务域网元向认证网元发送认证请求,该认证请求中可以包括服务域网络的名称(SN name)。该认证请求中还可以包括DIDi和代理节点的标识。或者,该认证请求中可以包括IDi、N1和代理节点的标识。
在一些实施例中,该认证请求中可以包括可指示认证类型的标识。认证类型的标识可以通过以下中的一种或多种指示:BSF ID、A-NF的标识类型、IDi的类型、认证类型标识(Auth_type_ID)。
在步骤S1108,认证网元可以进行认证类型的确认。
认证网元可以通过核心网网元(如UDM)查询第一设备与代理节点的订阅凭证。核心网网元可以基于IDi和代理节点的标识检查第一设备与代理节点的订阅凭证,以确定第一设备是否有权使用A-IoT服务。
认证网元可以基于可指示认证类型的标识判断认证类型,如判断认证类型是否为A-IoT认证。
如果认证网元接收到的认证请求中包括DIDi,则认证网元可以对DIDi进行解匿名,得到IDi。例如,如果N1是第一设备与认证网元之间的共享密钥,则认证网元可以基于N1对DIDi进行解匿名,得到IDi。举例说明,IDi可以基于公式IDi=DIDi⊕N1确定。
认证网元可以生成第一匿名密钥AK。如果N1是第一设备与认证网元之间的共享密钥,则第一匿名密钥AK可以基于公式AK=K⊕N1确定。如果N1是第一设备与代理节点之间的共享密钥(代理节点可以向认证网元发送N1),或者N1是第一设备与认证网元之间的共享密钥,则第一匿名密钥AK可以基于公式AK=fK(RAND)确定。其中,RAND是认证网元选取的随机数。
认证网元可以生成第一消息认证码(记为MAC)和第一期望响应(记为XRES1)。MAC和XRES1可以基于公式MAC/XRES1=fK(RAND,N1,N2)确定。其中,N2可以是第一设备与认证网元之间共享的密钥,或者N2是认证网元选择的随机数。
上述MAC和XRES1的生成方式中引入的参数包括RAND、N1和N2,但这仅是一种示例,本申请实施例对此不做具体限定。例如,MAC和XRES1中引入的参数可以仅包含RAND、或RAND和N1、或RAND和N2。
MAC和XRES1的生成方式不同,以使得到的MAC和XRES1的值不同。例如,如果MAC和XRES1计算时使用相同的函数f,则引入的参数可以不同。又例如,如果MAC和XRES1计算时引入的参数相同,则可以使用不同的函数f。
函数f可以有多种。例如,函数f可以是3GPP定义的f1-f5中的任意一种函数。又例如,函数f可以为KDF(如HMAC-SHA256)。又例如,函数f可以为其他轻量级函数(如ASCON)。
如果N2是认证网元选择的随机数,则AK可用于保护N2,如可以通过AK对N2进行加密处理。
认证网元可以生成第二期望响应XRES2,XRES2为服务域网络认证第一设备的材料。XRES2可以基于公式XRES2=fK(XRES1,SN name)确定。
认证网元可以生成第三期望响应XRES3,XRES3为基站认证第一设备的材料。XRES3可以基于公式XRES3=fN1(XRES1)确定。
认证网元可以生成认证向量。该认证向量可以包括认证网元生成和/或选择的多个参数。如该认证向量中可以包括以下中的一种或多种:RAND、N2、AK、MAC、XRES1、XRES2和XRES3。如果N2由认证网元选择,则认证向量中可以包括N2;如果N2是第一设备与认证网元之间共享的,则认证向量中可以不包括N2。
在一些实施例中,认证向量可以为AV=RAND||N2⊕AK||MAC||XRES1||XRES2||XRES3。在另一些实施例中,认证向量可以为AV=RAND||AK||MAC||XRES1||XRES2||XRES3。
在一些实施例中,认证向量中还可以包括以下参数中的一种或多种:IDi,UE ID,SN name。
在步骤S1110,认证网元向服务域网元发送认证响应。该认证响应中包括认证向量AV。在一些实施例中,该认证响应中还可以包括IDi。
在步骤S1112,服务域网元接收到认证向量后,可以存储认证向量中的XRES2。
在步骤S1114,服务域网元向基站发送认证请求(或认证响应)。该认证请求中包括认证向量。在一些实施例中,该认证向量可以不包括XRES2。在一些实施例中,该认证响应中还可以包括IDi。
在步骤S1116,如果认证向量中包括XRES3,则基站存储XRES3;如果认证向量中不包括XRES3,则基站可以基于XRES1生成XRES3。
在步骤S1118,基站通过代理节点向第一设备发送认证请求。该认证请求中可以包括RAND和MAC。或者,该认证请求中可以包括RAND和N2⊕AK||MAC。其中,如果N2是认证网元选择的随机数,该AK可用于保护N2的安全。
在步骤S1120,第一设备接收到认证请求后,可以检验MAC。检验成功后,第一设备可以计算第一响应参数RES1、第二响应参数RES2和第三响应参数RES3。另外,第一设备还可以生成密钥Ks。密钥Ks可以基于如下公式Ks=fAK(N1,N2,UE ID,IDi,SN name)确定。
在步骤S1122,第一设备通过代理节点向基站发送认证响应。该认证响应中包括RES1、RES2和RES3。
在步骤S1124,基站比较RES3和XRES3,以认证第一设备。如果RES3和XRES3一致,则第一设备认证成功。基站从接入网络的角度认为第一设备认证成功。
在步骤S1126,在第一设备认证成功后,基站向服务域网元发送认证响应。该认证响应中包括RES2和RES1。
在步骤S1128,服务域网元接收到认证响应后,可以从认证响应中获取RES2。服务域网元比较RES2和XRES2,以认证第一设备。认证成功后,服务域网元从服务域网络的角度认为第一设备认证成功。
在步骤S1130,服务域网元向认证网元发送认证请求(或者认证响应),该认证请求中包括RES1。
在步骤S1132,认证网元比较RES1和XRES1,以认证第一设备。认证成功后,认证网元从归属域网络的角度认为第一设备认证成功。
认证网元还可以生成密钥Ks。密钥Ks可以基于公式Ks=fAK(N1,N2,UE ID,IDi,SN name)确定。
在步骤S1134,认证网元向代理节点发送响应消息或者认证网元向服务域网元发送响应消息。在一些实施例中,认证网元可以通过服务域网元和基站向代理节点发送响应消息。
在一些实施例中,该认证响应中可以包括密钥Ks。该密钥Ks可用于代理节点生成完整性保护密钥和/或加密密钥。
图12示出的是初始认证(或轻量级初始认证)完成后,生成AKMA密钥的流程。
参见图12,在步骤S1202,认证网元生成密钥Ks、A-KID和AKMA密钥。第一设备生成密钥Ks、A-KID和AKMA密钥。
在一些实施例中,认证网元可以基于密钥Ks生成A-TID。作为一个示例,A-TID可以基于Ks和IDi生成。例如,A-TID可以基于公式A-TID=fKs(IDi)确定。
在一些实施例中,认证网元可以基于A-TID生成A-KID。作为一个示例,A-KID可以基于A-TID、RID和HNI生成。例如,A-TID可以基于公式A-KID=A-TID||RID||HNI确定。
在一些实施例中,认证网元可以生成AKMA密钥(记为KAKMA)。AKMA密钥可以基于Ks生成,在该情况下,Ks的作用与相关技术中的KAUSF的作用相同。作为一个示例,AKMA密钥可以基于Ks、IDi和AKMA生成。例如,AKMA密钥可以基于公式Kakma=fKs(“AKMA”,“IDi”)确定。
在步骤S1204,认证网元可以向AAnF或KMS发送注册请求,该注册请求中可以包括以下信息中的一种或多种:AKMA密钥、A-KID和第一设备的标识IDi。该注册请求例如可以为AKMA锚点密钥注册请求(如Naanf_AKMA_AnchorKey_Register Request)。
类似地,在步骤S1202,第一设备可以生成密钥Ks、A-KID和AKMA密钥。第一设备生成A-KID的方式与认证网元生成A-KID的方式类似,第一设备生成AKMA密钥的方式与认证网元生成AKMA密钥的方式类似,为了简洁,此处不再赘述。
图13示出的是生成应用密钥的流程。
参见图13,在步骤S1302,第一设备向AF发送应用会话建立请求。该应用会话建立请求中可以包括A-KID。该应用会话建立请求也可以为其他的通信请求。
在一些实施例中,该应用会话建立请求中可以包括UE ID和DIDi。UE ID例如可以为GPSI。UE ID为代理节点的标识。
在步骤S1304,AF接收到应用会话建立请求后,向AAnF或KMS发送应用密钥请求。该应用密钥请求中可以包括A-KID。在一些实施例中,该应用密钥请求中还可以包括UE ID和DIDi。
在步骤S1306,AAnF或KMS接收到应用密钥请求后,可以基于A-KID生成应用密钥。
在一些实施例中,该应用密钥KAF可以基于Ks、AF ID、IDi、UE ID以及A-KID生成。例如,应用密钥KAF可以基于公式KAF=fKs(AF ID,IDi,UE ID,A-KID)确定。
在步骤S1308,AAnF或KMS向AF发送应用密钥响应。该应用密钥响应中包括KAF和KAF的有效期。
AAnF或KMS可以存储KAF和KAF的有效期,以便于第一设备的移动性管理。
在步骤S1310,AF向代理节点发送应用密钥响应。该应用密钥响应中包括KAF和KAF的有效期。
在步骤S1312,代理节点生成密钥Ku1。密钥Ku1可以基于KAF生成。作为一个示例,Ku1可以基于KAF和N1生成。例如,Ku1可以基于公式Ku1=KAF⊕N1确定。其中,N1为第一设备与代理节点之间的共享密钥。
在步骤S1314,代理节点向第一设备发送应用会话建立响应。
在步骤S1316,第一设备生成应用密钥KAF和密钥Ku1。第一设备生成KAF的方式与AAnF或KMS生成KAF的方式类似,第一设备生成密钥Ku1和代理节点生成密钥Ku1的方式类似,为了简洁,此处不再赘述。
在步骤S1318,第一设备可以向代理节点发送响应消息。
上述密钥Ku1可用于生成完整性保护密钥和/或加密密钥,该完整性保护密钥和/或加密密钥可用于保证第一设备与代理节点之间的安全通信。之后,如果第一设备使用其他的设备(如UEx)作为代理节点时,可以使用第一设备与UEx之间的共享密钥Nx,以及KAF,生成下级密钥Kux。该Kux可用于进一步生成完整性保护密钥和/或加密密钥。这样,在代理节点发生变化时,第一设备不一定需要进行第一设备的认证与密钥协商流程,从而可以降低第一设备的复杂度。
示例二
示例二的方案中,安全凭证为3GPP安全凭证,第一设备不需要通过代理节点与网络侧进行通信,即第一设备可以直接与网络侧进行通信。
示例二与示例一的区别在于:1、没有代理节点参与,2、认证信息中不包括代理节点的信息(如代理节点的标识或UE ID)。
示例二的方案与示例一的方案基本类似,示例二中未详细描述的内容可以参见示例一的描述。
图14是本申请实施例提供的一种认证方法的流程示意图。参见图14,在步骤S1410,认证网元生成第一消息认证码和/或期望响应。第一消息认证码和期望响应的生成方式可以参见示例一的描述。
在步骤S1420,认证网元向接入网设备发送第一认证请求。该第一认证请求中可以包括第一消息认证码。
认证网元向接入网设备发送第一认证请求,可以指认证网元直接向接入网设备发送第一认证请求,或者,也可以指认证网元通过其他设备向接入网设备发送第一认证请求。其他设备例如可以包括服务域网元。服务域网元例如可以包括AMF和/或SMF。
在步骤S1430,接入网设备向第一设备发送第一认证请求。
在步骤S1440,第一设备基于第一密钥生成算法和第二参数生成第二消息认证码。
在步骤S1450,第一设备基于第一消息认证码和第二消息认证码认证认证网元。
在步骤S1460,在认证网元认证成功的情况下,第一设备生成响应参数。
在步骤S1470,第一设备向接入网设备发送第一认证响应。该第一认证响应中包括响应参数。
在步骤S1480,接入网设备向认证网元发送第一认证响应。该第一认证响应中包括响应参数。
在一些实施例中,接入网设备可以向认证网元发送响应参数。认证网元接收到响应参数后,可以比较响应参数和期望响应,以认证第一设备。
在一些实施例中,在接收来自接入网设备的第一认证请求之前,第一设备可以向接入网设备发送第二认证请求。换句话说,第一设备可以通过发送第二认证请求,以触发第一设备与网络侧之间的认证流程。
在一些实施例中,第二认证请求中可以包括第一设备的隐藏身份标识。为了保证信息的安全性,第一设备可以对第一设备的身份标识进行匿名处理,得到隐藏身份标识。
接入网设备接收到第二认证请求后,可以向认证网元发送该第二认证请求。接入网设备发送的第二认证请求中可以包括以下信息中的一种或多种:第一密钥、第一设备的身份标识、隐藏身份标识。
在一些实施例中,接入网设备可以根据第一密钥的不同,采取不同的处理策略。作为一个示例,如果第一密钥为第一设备与网络侧之间的共享密钥,则接入网设备发送的第二认证请求中可以包括隐藏身份标识。
作为另一个示例,如果第一密钥为第一设备与接入网设备之间的共享密钥,则接入网设备可以对隐藏身份标识进行解匿名,得到第一设备的身份标识。例如,接入网设备可以基于第一密钥与隐藏身份标识,确定第一设备的身份标识。
如果隐藏身份标识由第一密钥和第一设备的身份标识通过异或的方式生成,则接入网设备可以通过如下公式确定第一设备的身份标识:
IDi=DIDi⊕N1
其中,DIDi表示隐藏身份标识,IDi表示第一设备的身份标识,N1表示第一密钥,⊕表示异或运算。
如果隐藏身份标识基于第一密钥、第一设备的身份标识和第三密钥生成算法生成,则接入网设备可以通过如下公式确定第一设备的身份标识:
IDi=fN1(DIDi)
其中,DIDi表示隐藏身份标识,IDi表示第一设备的身份标识,N1表示第一密钥,f表示第三密钥生成算法。
在得到第一设备的身份标识后,第一设备发送的第二认证请求中可以包括以下中的一种或多种:第一密钥、第一设备的身份标识。
第一设备与认证网元认证完成后,可以生成第二密钥Ks。第二密钥也可以理解为第一设备与认证网元之间的共享密钥。第二密钥可以基于第六密钥生成算法和第六参数生成。第六密钥生成算法可以为第一密钥生成算法或第二密钥生成算法,以降低第一设备的计算复杂度。第六参数可以包括以下参数中的一种或多种:第一匿名密钥、第一密钥、第一随机数、第一设备的标识和服务域网络的名称。
举例说明,第二密钥可以基于以下公式确定:
Ks=fAK(N1,N2,IDi,SN name)
其中,Ks表示第二密钥,AK表示第一匿名密钥,N1表示第一密钥,N2表示第一随机数,IDi表示第一设备的身份标识,SN name表示服务域网络的名称,f表示第六密钥生成算法。
下面结合图15和16,对没有代理节点参与的认证与密钥协商流程进行详细介绍。
图15示出的是第一设备与认证网元之间进行认证的流程。第一设备可以与认证网元共享密钥K,该密钥K即为上文描述的安全凭证。第一设备可以与基站共享密钥N1,该密钥N1即为上文描述的第一密钥。该密钥N1可以为物理层密钥。
图15所示的方法与图11所示的方案基本类似,图15中未详细描述的内容可以参见图11中的描述。
参见图15,在步骤S1502,第一设备向基站发送认证请求。该认证请求中可以包括第一设备的隐藏身份标识DIDi。隐藏身份标识DIDi可以基于第一设备的身份标识IDi生成。
在步骤S1504,基站向服务域网元发送认证请求。
在一些实施例中,该认证请求中可以包括DIDi。例如,如果N1为第一设备与认证网元之间的共享密钥,则认证请求中可以包括DIDi。
在一些实施例中,如果N1为第一设备与基站之间的共享密钥,则基站可以基于N1对DIDi解匿名,得到第一设备的身份标识IDi。基站发送的认证请求中可以包括以下中的一种或多种:IDi和N1。
在步骤S1506,服务域网元向认证网元发送认证请求,该认证请求中可以包括服务域网络的名称(SN name)。在一些实施例中,该认证请求中还可以包括DIDi,或者,该认证请求中可以包括IDi和N1。
在步骤S1508,认证网元可以进行认证类型的确认。
在一些实施例中,如果认证网元接收到的认证请求中包括DIDi,则认证网元可以对DIDi进行解匿名,得到IDi。
在一些实施例中,认证网元可以生成第一匿名密钥AK、第一消息认证码、第一期望响应、第二期望响应和第三期望响应。
在一些实施例中,认证网元可以生成认证向量。该认证向量可以包括认证网元生成和/或选择的多个参数。如该认证向量中可以包括以下中的一种或多种:RAND、N2、AK、MAC、XRES1、XRES2和XRES3。如果N2由认证网元选择,则认证向量中可以包括N2;如果N2是第一设备与认证网元之间共享的,则认证向量中可以不包括N2。
在一些实施例中,认证向量可以为AV=RAND||N2⊕AK||MAC||XRES1||XRES2||XRES3。在另一些实施例中,认证向量可以为AV=RAND||AK||MAC||XRES1||XRES2||XRES3。
在一些实施例中,认证向量中还可以包括以下参数中的一种或多种:IDi,UE ID,SN name。
在步骤S1510,认证网元向服务域网元发送认证响应。该认证响应中包括认证向量AV。
在步骤S1512,服务域网元接收到认证向量后,可以存储认证向量中的XRES2。
在步骤S1514,服务域网元向基站发送认证请求(或认证响应)。该认证请求中包括认证向量。在一些实施例中,该认证向量可以不包括XRES2。
在步骤S1516,如果认证向量中包括XRES3,则基站存储XRES3;如果认证向量中不包括XRES3,则基站可以基于XRES1生成XRES3。
在步骤S1518,基站向第一设备发送认证请求。该认证请求中可以包括RAND和MAC。或者,该认证请求中可以包括RAND和N2⊕AK||MAC。其中,如果N2是认证网元选择的随机数,该AK可用于保护N2的安全。
在步骤S1520,第一设备接收到认证请求后,可以检验MAC。检验成功后,第一设备可以计算第一响应参数RES1、第二响应参数RES2和第三响应参数RES3。另外,第一设备还可以生成密钥Ks。密钥Ks可以基于如下公式Ks=fAK(N1,N2,IDi,SN name)确定。
在步骤S1522,第一设备向基站发送认证响应。该认证响应中包括RES1、RES2和RES3。
在步骤S1524,基站比较RES3和XRES3,以认证第一设备。如果RES3和XRES3一致,则第一设备认证成功。基站从接入网络的角度认为第一设备认证成功。
在步骤S1526,在第一设备认证成功后,基站向服务域网元发送认证响应。该认证响应中包括RES2和RES1。
在步骤S1528,服务域网元接收到认证响应后,可以从认证响应中获取RES2。服务域网元比较RES2和XRES2,以认证第一设备。认证成功后,服务域网元从服务域网络的角度认为第一设备认证成功。
在步骤S1530,服务域网元向认证网元发送认证请求(或者认证响应),该认证请求中包括RES1。
在步骤S1532,认证网元比较RES1和XRES1,以认证第一设备。认证成功后,认证网元从归属域网络的角度认为第一设备认证成功。
认证网元还可以生成密钥Ks。密钥Ks可以基于公式Ks=fAK(N1,N2,IDi,SN name)确定。
在步骤S1534,认证网元可以向服务域网元发送响应消息。
在得到密钥Ks后,认证网元和第一设备可以按照图12所示的方法生成AKMA密钥。另外,认证网元可以向AAnF或KMS发送注册请求,该注册请求中可以包括以下信息中的一种或多种:AKMA密钥、A-KID和第一设备的标识IDi。
图16示出的是生成应用密钥的流程。
参见图16,在步骤S1602,第一设备向AF发送应用会话建立请求。该应用会话建立请求中可以包括A-KID。该应用会话建立请求也可以为其他的通信请求。在一些实施例中,该应用会话建立请求中可以包括DIDi。
在步骤S1604,AF接收到应用会话建立请求后,向AAnF或KMS发送应用密钥请求。该应用密钥请求中可以包括A-KID。在一些实施例中,该应用密钥请求中还可以包括DIDi。
在步骤S1606,AAnF或KMS接收到应用密钥请求后,可以基于A-KID生成应用密钥。
在一些实施例中,该应用密钥KAF可以基于Ks、AF ID、IDi以及A-KID生成。例如,应用密钥KAF可以基于公式KAF=fKs(AF ID,IDi,A-KID)确定。
在步骤S1608,AAnF或KMS向AF发送应用密钥响应。该应用密钥响应中包括KAF和KAF的有效期。
AAnF或KMS可以存储KAF和KAF的有效期,以便于第一设备的移动性管理。
在步骤S1610,AF向第一设备发送应用会话建立响应。
之后,第一设备和AF可以基于KAF建立安全连接(如TLS连接)。
示例三
示例三的方案中,安全凭证为非3GPP安全凭证,如安全凭证为第一设备与应用功能网元之间的共享密钥,第一设备通过代理节点与网络侧进行通信。
图17是本申请实施例提供的一种认证方法的流程示意图。参见图17,在步骤S1710,第一设备向应用功能网元发送认证请求。在一些实施例中,第一设备可以通过代理节点向应用功能网元发送认证请求。
该认证请求中可以包括以下信息中的一种或多种:第一设备的隐藏身份标识、第一设备的身份标识、代理节点的标识和第一密钥。在一些实施例中,认证请求中可以包括第一设备的隐藏身份标识和代理节点的标识。在另一些实施例中,认证请求中可以包括第一设备的身份标识、代理节点的标识和第一密钥。
在步骤S1720,应用功能网元对第一设备和/或代理节点进行授权检查。例如,应用功能网元可以检查第一设备是否被授权使用某种服务(如A-IoT服务)。又例如,应用功能网元可以检查代理节点是否被授权作为代理为第一设备提供服务(如A-IoT服务)。
在一些实施例中,应用功能网元可以管理第一设备的白名单与代理节点之间的映射。
应用功能网元在对第一设备进行授权检查时,可以基于第一设备的身份标识IDi对第一设备进行授权检查。应用功能网元在对代理节点进行授权检查时,可以基于代理节点的标识(如UE ID)对代理节点进行授权检查。
第一设备的身份标识和代理节点的标识可由代理节点发送至应用功能网元。
在一些实施例中,第一设备可以向代理节点发送认证请求,该认证请求中可以包括第一设备的隐藏身份标识DIDi。代理节点可以对隐藏身份标识DIDi进行解匿名,得到第一设备的身份标识。
代理节点可以向应用功能网元发送认证请求,该认证请求中可以包括第一设备的身份标识IDi和代 理节点的标识。为了保证信息的安全性,代理节点可以通过NAS安全上下文或AS安全上下文发送认证请求。
在步骤S1730,在第一设备和/或代理节点授权检查成功的情况下,应用功能网元向认证网元发送认证请求。
如果第一设备和/或代理节点授权检查失败,则应用功能网元可以不向认证网元发送认证请求,即不进行后续的认证与密钥协商流程。
本申请实施例可以由应用功能网元先对第一设备和代理节点进行授权检查,在授权检查成功的情况下,才进行后续的认证与密钥协商流程,有利于降低第一设备的计算复杂度。例如,如果在认证与密钥协商流程完成后,才进行授权检查,会出现授权检查失败的情况,这就会使得第一设备的认证与密钥协商流程无效,从而造成资源的浪费,不利于降低第一设备的计算复杂度。
在一些实施例中,隐藏身份标识可以基于第一密钥N1生成。第一密钥可以为第一设备与应用功能网元之间的共享密钥,或者,第一密钥可以为第一设备与代理节点之间的共享密钥(如物理层密钥)。
如果第一密钥为第一设备与代理节点之间的共享密钥,则代理节点可以基于第一密钥,对隐藏身份标识进行解匿名,得到第一设备的身份标识。如果第一密钥为第一设备与应用功能网元之间的共享密钥,则应用功能网元可以对隐藏身份标识进行解匿名,得到第一设备的身份标识。
举例说明,第一设备的身份标识IDi可以通过公式IDi=DIDi⊕N1或公式IDi=fN1(DIDi)确定。
如果第一密钥为第一设备与代理节点之间的共享密钥,则代理节点向应用功能网元发送的认证请求中可以包括第一设备的身份标识、代理节点的标识和第一密钥。如果第一密钥为第一设备与应用功能网元之间的共享密钥,则代理节点向应用功能网元发送的认证请求中可以包括第一设备的隐藏身份标识和代理节点的标识。
在一些实施例中,应用功能网元可以向认证网元发送安全凭证K,或者应用功能网元可以向认证网元发送安全凭证K的下级密钥(记为Kb)。该下级密钥为基于安全凭证K生成的密钥。认证网元可以基于下级密钥,确定出安全凭证K。
下级密钥例如可以基于安全凭证K、第一密钥(记为N1)和第一随机数(记为N2)中的一个或多个生成。例如,下级密钥Kb可以基于公式Kb=K⊕N1或公式Kb=K⊕N2生成。其中,N2可以是第一设备与AF之间的共享密钥,或者,N2可以是AF选择的随机数。
如果认证网元接收的是安全凭证K,则认证网元可以基于安全凭证K生成认证过程中所需要的参数。该参数例如可以为认证向量中包含的参数。该参数例如可以包括以下中的一种或多种:第一匿名密钥、第一消息认证码、期望响应、密钥Ks等。密钥Ks为第一设备与认证网元认证成功后,生成的共享密钥。
在一些实施例中,第一匿名密钥可以基于安全凭证K和目标参数生成。该目标参数可以包括RAND和/或N1。例如,第一匿名密钥AK可以基于公式AK=fK(RAND)或公式AK=K⊕N1确定。
在一些实施例中,第一消息认证码可以基于安全凭证K和目标参数生成。该目标参数可以包括以下中的一种或多种:RAND、N1和N2。例如,目标参数包括RAND。又例如,目标参数包括RAND和N1。又例如,目标参数包括RAND和N2。又例如,目标参数包括RAND、N1和N2。
举例说明,第一消息认证码可以基于以下公式中的一种或多种确定:MAC=fK(RAND,N1,N2),MAC=fK(RAND,N1),MAC=fK(RAND,N2),MAC=fK(RAND)。
在一些实施例中,期望响应可以基于安全凭证K和目标参数生成。该目标参数可以包括以下中的一种或多种:RAND、N1和N2。例如,目标参数包括RAND。又例如,目标参数包括RAND和N1。又例如,目标参数包括RAND和N2。又例如,目标参数包括RAND、N1和N2。
举例说明,期望响应可以基于以下公式中的一种或多种确定:XRES=fK(RAND,N1,N2),XRES=fK(RAND,N1),XRES=fK(RAND,N2),XRES=fK(RAND)。
密钥Ks可以基于安全凭证K和目标参数生成。目标参数可以包括以下中的一种或多种:AK、N1、N2、IDi、UE ID、AF ID、HNI、SN name。例如,目标参数可以包括AK、N1、N2、IDi、UE ID、AF ID、HNI。又例如,目标参数可以包括AK、N1、N2、IDi、UE ID、AF ID、SN name。
举例说明,密钥Ks可以基于公式Ks=fAK(N1,N2,IDi,UE ID,AF ID,HNI)或公式Ks=fAK(N1,N2,IDi,UE ID,AF ID,SN name)确定。
如果认证网元接收的是密钥Kb,则认证网元可以基于密钥Kb生成认证过程中所需要的参数。该参数例如可以为认证向量中包含的参数。该参数例如可以包括以下中的一种或多种:第一消息认证码、期望响应、密钥Ks等。
第一消息认证码可以基于密钥Kb以及目标参数生成。该目标参数可以包括以下中的一种或多种:RAND、N1和N2。例如,目标参数包括RAND。又例如,目标参数包括RAND和N1。又例如,目标 参数包括RAND和N2。又例如,目标参数包括RAND、N1和N2。
举例说明,第一消息认证码可以基于以下公式中的一种或多种确定:MAC=fKb(RAND,N1,N2),MAC=fKb(RAND,N1),MAC=fKb(RAND,N2),MAC=fKb(RAND)。
在一些实施例中,期望响应可以基于安全凭证K和目标参数生成。该目标参数可以包括以下中的一种或多种:RAND、N1和N2。例如,目标参数包括RAND。又例如,目标参数包括RAND和N1。又例如,目标参数包括RAND和N2。又例如,目标参数包括RAND、N1和N2。
举例说明,期望响应可以基于以下公式中的一种或多种确定:XRES=fKb(RAND,N1,N2),XRES=fKb(RAND,N1),XRES=fKb(RAND,N2),XRES=fKb(RAND)。
密钥Ks可以基于安全凭证K和目标参数生成。目标参数可以包括以下中的一种或多种:AK、N1、N2、IDi、UE ID、AF ID、HNI、SN name。例如,目标参数可以包括AK、N1、N2、IDi、UE ID、AF ID、HNI。又例如,目标参数可以包括AK、N1、N2、IDi、UE ID、AF ID、SN name。
举例说明,密钥Ks可以基于公式Ks=fKb(N1,N2,IDi,UE ID,AF ID,HNI)或公式Ks=fKb(N1,N2,IDi,UE ID,AF ID,SN name)确定。
在一些实施例中,第一设备可以采用与认证网元相同的方式,生成以下参数中的一种或多种:第一匿名密钥、第二消息认证码、响应参数、密钥Ks等。例如,第二消息认证码的生成方式与第一消息认证码的生成方式相同。又例如,响应参数的生成方式与期望响应的生成方式相同。
在一些实施例中,上述期望响应可以包括第一期望响应、第二期望响应和第三期望响应。第一期望响应的生成方式可以为上文中的期望响应的生成方式。第二期望响应和第三期望响应可以基于第一期望响应生成,具体的生成方式可以参见其他示例中的描述。
在一些实施例中,上述响应参数可以包括第一响应参数、第二响应参数和第三响应参数。第一响应参数的生成方式可以为上文中的响应参数的生成方式。第二响应参数和第三响应参数可以基于第一响应参数生成,具体的生成方式可以参见其他示例中的描述。
上述公式中的f可以为相同的密钥生成算法,或者上述公式中的f可以包括第一密钥生成算法和第二密钥生成算法。例如,第一密钥生成算法用于生成第一消息认证码或第二消息认证码,第二密钥生成算法用于生成期望响应或响应参数。
在得到Ks后,第一设备和认证网元可以基于Ks生成A-TID、A-KID以及AKMA密钥中的一种或多种。具体的生成方式可以参见前文中其他示例的描述。
由于应用功能网元参与了认证与密钥协商流程,则应用功能网元可以直接接收AAnF发送的应用密钥。例如,AAnF可以在生成应用密钥后,直接向AF发送应用密钥,而不需要AF发送应用密钥请求来触发。
AF接收到应用密钥后,可以向代理节点发送应用密钥。该应用密钥可用于代理节点生成第三密钥(如Ku1)。
AAnF生成应用密钥的方式、以及代理节点生成第三密钥的方式可以参见前文的描述,此处不再赘述。
图17所示的方案中涉及的第一设备与网络侧之间的认证与密钥协商流程可以与前文中的方案类似,未详细描述的内容可以参见前文的描述,为了简洁,此处不再赘述。
下面结合图18,对有代理节点参与的认证与密钥协商流程进行详细介绍。在图18所示的方案中,第一设备可以与AF共享密钥K。
参见图18,在步骤S1802,第一设备向代理节点发送认证请求。该认证请求中包括第一设备的隐藏身份标识DIDi。隐藏身份标识DIDi可以基于第一设备的身份标识IDi生成。
隐藏身份标识DIDi的生成方式有两种。如果N1是第一设备与AF之间预先共享的密钥(或随机数),则DIDi可以基于以下公式确定:DIDi=IDi⊕N1。在建立第一设备的安全上下文之后,AF可以向第一设备发送新的第一密钥以更新DIDi。
如果N1是第一设备与代理节点之间的共享密钥(如物理层密钥),则DIDi可以基于公式DIDi=IDi⊕N1或DIDi=fN1(IDi)确定。
在步骤S1804,代理节点向AF发送认证请求。
在一些实施例中,该认证请求中可以包括DIDi和代理节点的标识。例如,如果N1为第一设备与AF之间的共享密钥,则认证请求中可以包括DIDi和代理节点的标识。
在一些实施例中,如果N1是第一设备与代理节点之间的共享密钥,则代理节点可以基于N1对DIDi解匿名,得到第一设备的身份标识IDi。代理节点发送的认证请求中可以包括以下中的一种或多种:IDi、代理节点的标识和N1。
代理节点的标识可以包括GPSI、SUCI、GUTI中的一种或多种。
为了保证信息的安全性,代理节点可以通过NAS消息发送认证请求,例如,代理节点可以通过NAS安全上下文发送认证请求。
在步骤S1806,AF可以进行授权管理。
在一些实施例中,如果N1为第一设备与AF之间的共享密钥,则AF可以根据N1解匿名得到第一设备的身份标识IDi。例如,IDi可以通过公式IDi=DIDi⊕N1或公式IDi=fN1(DIDi)确定。
在一些实施例中,AF可以检查第一设备是否被授权。在一些实施例中,AF可以检查代理节点是否被授权为第一设备提供服务(如A-IoT服务)。在一些实施例中,AF还可以检查第一设备与代理节点之间的映射关系。AF可以管理第一设备的白名单与代理节点名单间的映射。
在一些实施例中,如果AF接收到的认证请求中包括IDi、代理节点的标识和N1,则AF可以直接进行授权检查,以及管理第一设备与代理节点之间的映射。
在步骤S1808,AF向认证网元发送认证请求。该认证请求中可以包括安全凭证K或由安全凭证K衍生的下级密钥Kb。在一些实施例中,该认证请求中还可以包括以下信息中的一种或多种:IDi,UE ID,AF ID。
在一些实施例中,该认证请求中可以包括以下中的一种或多种:K、K||N1、K||N1||N2和K||N2。其中,N1可以是第一设备与代理节点之间的共享密钥,或者N1可以是第一设备与AF之间的共享密钥。N2可以是第一设备与AF之间的共享密钥,或者N2可以是AF选择的随机数。
在一些实施例中,该认证请求中可以包括以下中的一种或多种:Kb、Kb||N2、Kb||N1。
如果Kb基于K和N1生成,则认证请求中可以包括Kb||N2;如果Kb基于K和N2生成,则认证请求中可以包括Kb||N1。
在一些实施例中,该认证请求中可以包括可指示认证类型的标识。认证类型的标识可以通过以下中的一种或多种指示:AF ID、IDi的类型、认证类型标识(Auth_type_ID)。
在步骤S1810,第一设备与认证网元之间进行认证(如AKA认证)。该认证方式可以参见前文的描述,如参见前文图11的描述。
代理节点可以转发第一设备与认证网元之间的认证消息。
认证网元可以通过核心网网元(如UDM)查询第一设备与代理节点的订阅凭证。核心网网元可以基于IDi和代理节点的标识检查第一设备与代理节点的订阅凭证,以确定第一设备是否有权使用A-IoT服务。
认证网元可以基于可指示认证类型的标识判断认证类型,如判断认证类型是否为A-IoT认证。
认证网元生成认证向量。认证网元可以选择随机数RAND,该随机数RAND可用于生成认证向量。
如果认证网元接收到的认证请求中包括K、K||N1、K||N1||N2、K||N2中的一个或多个,则认证网元可以基于K和RAND生成认证参数。该认证参数包括以下中的一种或多种:第一匿名密钥AK、第一消息认证码MAC、期望响应XRES和认证向量AV。
第一匿名密钥AK可以通过公式AK=fK(RAND)或公式AK=K⊕N1确定。
第一消息认证码MAC可以基于公式MAC=fK(RAND,N1,N2)确定。
期望响应XRES可以基于公式XRES=fK(RAND,N1,N2)确定。
认证向量可以为AV=RAND||AK||MAC||XRES。
MAC与XRES计算时可以使用相同的函数f和不同的参数。或者,MAC和XRES计算时可以使用相同的参数和不同的函数f。
如果认证网元接收到的认证请求中包括Kb、Kb||N1、Kb||N2中的一个或多个,则认证网元可以基于Kb和RAND生成认证参数。该认证参数包括以下中的一种或多种:第一消息认证码MAC、期望响应XRES和认证向量AV。
第一消息认证码MAC可以基于以下公式中一种或多种确定:MAC=fKb(RAND,N1,N2)、MAC=fKb(RAND)、MAC=fKb(RAND,N1)、MAC=fKb(RAND,N2)。
期望响应XRES可以基于以下公式中一种或多种确定:XRES=fKb(RAND,N1,N2)、XRES=fKb(RAND)、XRES=fKb(RAND,N1)、XRES=fKb(RAND,N2)。
认证向量可以为AV=RAND||MAC||XRES。
MAC与XRES计算时可以使用相同的函数f和不同的参数。或者,MAC和XRES计算时可以使用相同的参数和不同的函数f。
在一些实施例中,认证网元可以通过代理节点向第一设备发送认证响应。该认证响应中可以包括RAND和第一消息认证码。在一些实施例中,如果N2是AF选择的随机数,则认证响应中还可以包括AK⊕N2或者Kb⊕N2,其中,AK和Kb用于保护N2,以保证N2安全地传输。在一些实施例中,认证响应中可以包括AF ID和IDi。
第一设备可以计算第二消息认证码,并比较第一消息认证码和第二消息认证码,以认证认证网元。认证成功后,第一设备可以生成密钥Ks。密钥Ks可以基于以下公式中的一种或多种确定:Ks=fAK(N1,N2,IDi,UE ID,AF ID,SN name),Ks=fAK(N1,N2,IDi,UE ID,AF ID,HNI),Ks=fKb(N1,N2,IDi,UE ID,AF ID,SN name),Ks=fKb(N1,N2,IDi,UE ID,AF ID,HNI)。
在一些实施例中,第一设备可以生成A-TID。A-TID可以基于公式A-TID=fKs(IDi)确定。在一些实施例中,第一设备可以生成A-KID,A-KID可以基于公式A-KID=A-TID||RID||HNI确定。在一些实施例中,第一设备可以生成AKMA密钥,AKMA密钥可以基于公式KAKMA=fKs(“AKMA”,“IDi”)确定。
在一些实施例中,第一设备可以生成响应参数RES,RES的计算方式与XRES的计算方式相同。
第一设备可以通过代理节点向认证网元发送认证响应,该认证响应可以包括响应参数RES。认证网元可以比较RES和XRES,以认证第一设备。如果RES和XRES一致,则第一设备认证成功;如果RES和XRES不一致,则第一设备认证失败。在第一设备认证成功后,认证网元可以生成以下参数中的一种或多种:Ks、A-TID、A-KID以及AKMA密钥。认证网元生成这些参数的方式与第一设备生成对应参数的方式相同。
在步骤S1812,认证网元向AAnF提供密钥材料,该密钥材料可以包括AKMA密钥和A-KID。
在步骤S1814,AAnF基于AKMA密钥生成应用密钥KAF。应用密钥KAF可以基于公式KAF=fKAKMA(AF ID,IDi,UE ID)确定。
在步骤S1816,AAnF向AF和/或代理节点发送响应消息。该消息可以为成功响应消息。该响应消息中可以包括应用密钥和/或应用密钥的有效期。在一些实施例中,响应消息中还可以包括新选取的第一密钥(或随机数),新的第一密钥可用于更新隐藏身份标识。
在步骤S1818,代理节点生成密钥Ku1。
在步骤S1820,第一设备生成密钥Ku1。
密钥Ku1可以基于应用密钥生成。具体的生成方式可以参见前文的描述。
在一些实施例中,代理节点可以向第一设备发送响应消息。该响应消息中包括以下信息中的一种或多种:A-KID、应用密钥的有效期、新选取的第一密钥、消息完整性校验码(message integrity check,MIC)。该响应消息可以通过密钥进行保护,如完整性保护和/或加密保护。该密钥可以包括以下中的一种或多种:KAF、Ku1、由KAF衍生出的下级密钥、由Ku1衍生出的下级密钥。
第一设备与代理节点之间的共享密钥N1可用于移动性管理。例如,第一设备和代理节点可以基于N1和KAF生成密钥Ku1,然后基于Ku1生成完整性保护密钥和/或加密密钥。之后,如果第一设备使用其他的设备(如UEx)作为代理节点时,可以使用第一设备与UEx之间的共享密钥Nx,以及KAF,生成下级密钥Kux。该Kux可用于进一步生成完整性保护密钥和/或加密密钥。这样,在代理节点发生变化时,第一设备不一定需要进行第一设备的认证与密钥协商流程,从而可以降低第一设备的复杂度。
当然,在一些实施例中,认证网元也可以按照前文描述的方式生成XRES1、XRES2和XRES3,第一设备可以按照前文描述的方式生成RES1、RES2和RES3。
示例四
示例四的方案中,安全凭证为非3GPP安全凭证,如安全凭证为第一设备与应用功能网元之间的共享密钥,第一设备直接与网络侧进行通信。
图19是本申请实施例提供的一种认证方法的流程示意图。参见图19,在步骤S1910,第一设备向应用功能网元发送认证请求。
该认证请求中可以包括以下信息中的一种或多种:第一设备的隐藏身份标识、第一设备的身份标识和第一密钥。在一些实施例中,认证请求中可以包括第一设备的隐藏身份标识。在另一些实施例中,认证请求中可以包括第一设备的身份标识和第一密钥。
在一些实施例中,隐藏身份标识可以基于第一密钥N1生成。第一密钥可以为第一设备与应用功能网元之间的共享密钥。
在步骤S1920,应用功能网元对第一设备进行授权检查。例如,应用功能网元可以检查第一设备是否被授权使用某种服务(如A-IoT服务)。
在一些实施例中,应用功能网元可以管理第一设备的白名单。
应用功能网元在对第一设备进行授权检查时,可以基于第一设备的身份标识IDi对第一设备进行授权检查。在一些实施例中,认证请求中可以包括第一设备的隐藏身份标识DIDi。应用功能网元可以对隐藏身份标识DIDi进行解匿名,得到第一设备的身份标识。例如,应用功能网元可以利用第一密钥N1对隐藏身份标识DIDi进行解匿名,得到第一设备的身份标识。举例说明,第一设备的身份标识IDi可以通过公式IDi=DIDi⊕N1或公式IDi=fN1(DIDi)确定。
在步骤S1930,在第一设备授权检查成功的情况下,应用功能网元向认证网元发送认证请求。
如果第一设备授权检查失败,则应用功能网元可以不向认证网元发送认证请求,即不进行后续的认证与密钥协商流程。
本申请实施例可以由应用功能网元先对第一设备进行授权检查,在授权检查成功的情况下,才进行后续的认证与密钥协商流程,有利于降低第一设备的计算复杂度。例如,如果在认证与密钥协商流程完成后,才进行授权检查,会出现授权检查失败的情况,这就会使得第一设备的认证与密钥协商流程无效,从而造成资源的浪费,不利于降低第一设备的计算复杂度。
在一些实施例中,应用功能网元可以向认证网元发送安全凭证K,或者应用功能网元可以向认证网元发送安全凭证K的下级密钥(记为Kb)。该下级密钥为基于安全凭证K生成的密钥。认证网元可以基于下级密钥,确定出安全凭证K。
下级密钥例如可以基于安全凭证K、第一密钥(记为N1)和第一随机数(记为N2)中的一个或多个生成。例如,下级密钥Kb可以基于公式Kb=K⊕N1或公式Kb=K⊕N2生成。其中,N2可以是第一设备与AF之间的共享密钥,或者,N2可以是AF选择的随机数。
如果认证网元接收的是安全凭证K,则认证网元可以基于安全凭证K生成认证过程中所需要的参数。该参数例如可以为认证向量中包含的参数。该参数例如可以包括以下中的一种或多种:第一匿名密钥、第一消息认证码、期望响应、密钥Ks等。密钥Ks为第一设备与认证网元认证成功后,生成的共享密钥。这些参数的具体生成方式可以参见示例三的描述,为了简洁,此处不再赘述。
如果认证网元接收的是密钥Kb,则认证网元可以基于密钥Kb生成认证过程中所需要的参数。该参数例如可以为认证向量中包含的参数。该参数例如可以包括以下中的一种或多种:第一消息认证码、期望响应、密钥Ks等。这些参数的具体生成方式可以参见示例三的描述,为了简洁,此处不再赘述。
在一些实施例中,第一设备可以采用与认证网元相同的方式,生成以下参数中的一种或多种:第一匿名密钥、第二消息认证码、响应参数、密钥Ks等。例如,第二消息认证码的生成方式与第一消息认证码的生成方式相同。又例如,响应参数的生成方式与期望响应的生成方式相同。
在一些实施例中,上述期望响应可以包括第一期望响应、第二期望响应和第三期望响应。第一期望响应的生成方式可以为上文中的期望响应的生成方式。第二期望响应和第三期望响应可以基于第一期望响应生成,具体的生成方式可以参见其他示例中的描述。
在一些实施例中,上述响应参数可以包括第一响应参数、第二响应参数和第三响应参数。第一响应参数的生成方式可以为上文中的响应参数的生成方式。第二响应参数和第三响应参数可以基于第一响应参数生成,具体的生成方式可以参见其他示例中的描述。
上述公式中的f可以为相同的密钥生成算法,或者上述公式中的f可以包括第一密钥生成算法和第二密钥生成算法。例如,第一密钥生成算法用于生成第一消息认证码或第二消息认证码,第二密钥生成算法用于生成期望响应或响应参数。
在得到Ks后,第一设备和认证网元可以基于Ks生成A-TID、A-KID以及AKMA密钥中的一种或多种。具体的生成方式可以参见前文中其他示例的描述。
由于应用功能网元参与了认证与密钥协商流程,则应用功能网元可以直接接收AAnF发送的应用密钥。例如,AAnF可以在生成应用密钥后,直接向AF发送应用密钥,而不需要AF发送应用密钥请求来触发。
AF接收到应用密钥后,可以向代理节点发送应用密钥。该应用密钥可用于代理节点生成第三密钥(如Ku1)。
AAnF生成应用密钥的方式、以及代理节点生成第三密钥的方式可以参见前文的描述,此处不再赘述。
图19所示的方案中涉及的第一设备与网络侧之间的认证与密钥协商流程可以与前文中的方案类似,未详细描述的内容可以参见前文的描述,为了简洁,此处不再赘述。
下面结合图20,对没有代理节点参与的认证与密钥协商流程进行详细介绍。在图20所示的方案中,第一设备可以与AF共享密钥K。
参见图20,在步骤S2002,第一设备向AF发送认证请求。该认证请求中包括第一设备的隐藏身份标识DIDi。隐藏身份标识DIDi可以基于第一设备的身份标识IDi生成。
如果N1是第一设备与AF之间预先共享的密钥(或随机数),则DIDi可以基于以下公式确定:DIDi=IDi⊕N1。在建立第一设备的安全上下文之后,AF可以向第一设备发送新的第一密钥以更新DIDi。
在步骤S2004,AF可以进行授权管理。
在一些实施例中,如果N1为第一设备与AF之间的共享密钥,则AF可以根据N1解匿名得到第一设备的身份标识IDi。例如,IDi可以通过公式IDi=DIDi⊕N1或公式IDi=fN1(DIDi)确定。
在一些实施例中,AF可以检查第一设备是否被授权。在一些实施例中,AF还可以管理第一设备的 白名单。
在步骤S2006,AF向认证网元发送认证请求。该认证请求中可以包括安全凭证K或由安全凭证K衍生的下级密钥Kb。在一些实施例中,该认证请求中还可以包括AF ID和IDi。
在一些实施例中,该认证请求中可以包括以下中的一种或多种:K、K||N1、K||N1||N2和K||N2。其中,N1可以是第一设备与代理节点之间的共享密钥,或者N1可以是第一设备与AF之间的共享密钥。N2可以是第一设备与AF之间的共享密钥,或者N2可以是AF选择的随机数。
在一些实施例中,该认证请求中可以包括以下中的一种或多种:Kb、Kb||N2、Kb||N1。
如果Kb基于K和N1生成,则认证请求中可以包括Kb||N2;如果Kb基于K和N2生成,则认证请求中可以包括Kb||N1。
在一些实施例中,该认证请求中可以包括可指示认证类型的标识。认证类型的标识可以通过以下中的一种或多种指示:AF ID、IDi的类型、认证类型标识(Auth_type_ID)。
在步骤S2008,第一设备与认证网元之间进行认证(如AKA认证)。该认证方式可以参见前文的描述,如参见前文图11的描述。
认证网元可以通过核心网网元(如UDM)查询第一设备与代理节点的订阅凭证。核心网网元可以基于IDi和代理节点的标识检查第一设备与代理节点的订阅凭证,以确定第一设备是否有权使用A-IoT服务。
认证网元可以基于可指示认证类型的标识判断认证类型,如判断认证类型是否为A-IoT认证。
认证网元生成认证向量。认证网元可以选择随机数RAND,该随机数RAND可用于生成认证向量。
如果认证网元接收到的认证请求中包括K、K||N1、K||N1||N2、K||N2中的一个或多个,则认证网元可以基于K和RAND生成认证参数。该认证参数包括以下中的一种或多种:第一匿名密钥AK、第一消息认证码MAC、期望响应XRES和认证向量AV。
第一匿名密钥AK可以通过公式AK=fK(RAND)或公式AK=K⊕N1确定。
第一消息认证码MAC可以基于公式MAC=fK(RAND,N1,N2)确定。
期望响应XRES可以基于公式XRES=fK(RAND,N1,N2)确定。
认证向量可以为AV=RAND||AK||MAC||XRES。
MAC与XRES计算时可以使用相同的函数f和不同的参数。或者,MAC和XRES计算时可以使用相同的参数和不同的函数f。
如果认证网元接收到的认证请求中包括Kb、Kb||N1、Kb||N2中的一个或多个,则认证网元可以基于Kb和RAND生成认证参数。该认证参数包括以下中的一种或多种:第一消息认证码MAC、期望响应XRES和认证向量AV。
第一消息认证码MAC可以基于以下公式中一种或多种确定:MAC=fKb(RAND,N1,N2)、MAC=fKb(RAND)、MAC=fKb(RAND,N1)、MAC=fKb(RAND,N2)。
期望响应XRES可以基于以下公式中一种或多种确定:XRES=fKb(RAND,N1,N2)、XRES=fKb(RAND)、XRES=fKb(RAND,N1)、XRES=fKb(RAND,N2)。
认证向量可以为AV=RAND||MAC||XRES。
MAC与XRES计算时可以使用相同的函数f和不同的参数。或者,MAC和XRES计算时可以使用相同的参数和不同的函数f。
在一些实施例中,认证网元可以通过代理节点向第一设备发送认证响应。该认证响应中可以包括RAND和第一消息认证码。在一些实施例中,如果N2是AF选择的随机数,则认证响应中还可以包括AK⊕N2或者Kb⊕N2,其中,AK和Kb用于保护N2,以保证N2安全地传输。在一些实施例中,认证响应中可以包括AF ID和IDi。
第一设备可以计算第二消息认证码,并比较第一消息认证码和第二消息认证码,以认证认证网元。认证成功后,第一设备可以生成密钥Ks。密钥Ks可以基于以下公式中的一种或多种确定:Ks=fAK(N1,N2,IDi,UE ID,AF ID,SN name),Ks=fAK(N1,N2,IDi,UE ID,AF ID,HNI),Ks=fKb(N1,N2,IDi,UE ID,AF ID,SN name),Ks=fKb(N1,N2,IDi,UE ID,AF ID,HNI)。
在一些实施例中,第一设备可以生成A-TID。A-TID可以基于公式A-TID=fKs(IDi)确定。在一些实施例中,第一设备可以生成A-KID,A-KID可以基于公式A-KID=A-TID||RID||HNI确定。在一些实施例中,第一设备可以生成AKMA密钥,AKMA密钥可以基于公式KAKMA=fKs(“AKMA”,“IDi”)确定。
在一些实施例中,第一设备可以生成响应参数RES,RES的计算方式与XRES的计算方式相同。
第一设备可以通过代理节点向认证网元发送认证响应,该认证响应可以包括响应参数RES。认证网元可以比较RES和XRES,以认证第一设备。如果RES和XRES一致,则第一设备认证成功;如果RES和XRES不一致,则第一设备认证失败。在第一设备认证成功后,认证网元可以生成以下参数中的一种 或多种:Ks、A-TID、A-KID以及AKMA密钥。认证网元生成这些参数的方式与第一设备生成对应参数的方式相同。
在步骤S2010,认证网元向AAnF提供密钥材料,该密钥材料可以包括AKMA密钥和A-KID。
在步骤S2012,AAnF基于AKMA密钥生成应用密钥KAF。应用密钥KAF可以基于公式KAF=fKAKMA(AF ID,IDi,UE ID)确定。类似地,第一设备基于AKMA密钥生成应用密钥KAF
在步骤S2014,AAnF向AF发送响应消息。该响应消息可以为成功响应消息。该响应消息中包括应用密钥和/或应用密钥的有效期。在一些实施例中,响应消息中还可以包括新选取的第一密钥(或随机数),新的第一密钥可用于更新隐藏身份标识。
在步骤S2016,AF向第一设备发送响应消息。该响应消息中包括以下信息中的一种或多种:A-KID、应用密钥的有效期、新选取的第一密钥、消息完整性校验码(message integrity check,MIC)。该响应消息可以通过密钥进行保护,如完整性保护和/或加密保护。该密钥可以包括以下中的一种或多种:KAF、Ku1、由KAF衍生出的下级密钥、由Ku1衍生出的下级密钥。
下文描述的方案对以上四个示例均适用。
在一些实施例中,为了减少密钥的衍生次数,认证网元可以将Ks发送至代理节点,以使代理节点基于Ks保护传输在空口中的信息。例如,代理节点可以基于Ks生成完整性保护密钥和/或加密密钥,该完整性保护密钥和/或加密密钥用于第一设备与代理节点之间的安全通信。
在一些实施例中,为了减少密钥的衍生次数,认证网元可以将Ks发送至AF,AF与第一设备可以基于Ks建立安全连接(如安全传输层(transport layer security,TLS)连接),以保护传输在空口中的信息。
在一些实施例中,对于有代理节点参与的方案,在触发第一设备与网络侧之间的认证与密钥协商之前,第一设备可以与代理节点之间进行相互认证,以避免恶意的第一设备利用代理节点对网络发起分布式拒绝服务(distributed denial of service,DDOS)攻击,影响网络质量,或恶意的代理节点发起中间人攻击,窃取第一设备与网络、第三方应用间的通信数据,或者第一设备的认证信令搭载在恶意的代理节点上,导致无法成功认证与密钥协商。
第一设备与代理节点之间的认证方式可以包括以下中的一种或多种:配对、代理节点激活第一设备、物理不可克隆函数(physical unclonable function,PUF)和物理层认证。
在认证成功后,代理节点可以使用自身的安全上下文,保护第一设备的认证消息。例如,代理节点在接收到第一设备的认证请求或响应消息后,可以将第一设备的认证容器(如Tag_authentication_container)使用第一设备的NAS安全上下文或AS安全上下文进行传输,以与网络侧进行交互。
上文中的AF与认证网元之间的信息传输可以通过网络开放功能(network exposure function,NEF)来实现。例如,NEF可以转发AF与认证网元之间的传输消息。
上文中的安全凭证也可以称为密钥或根密钥等。
上文描述的方案是基于应用密钥保护第一设备与代理节点之间的安全传输。在一些实施例中,为了减少密钥的衍生次数,可以直接使用密钥Ks保护第一设备与代理节点之间的安全传输。也就是说,密钥Ks相当于密钥KAF的功能。例如,认证网元可以将密钥Ks发送至代理节点,代理节点可以基于密钥Ks生成完整性保护密钥和/或加密密钥。类似地,第一设备也可以基于密钥Ks生成完整性保护密钥和/或加密密钥。
在一些实施例中,密钥Ks可用于生成NAS安全上下文和/或AS安全上下文。例如,认证网元可以基于Ks生成KAMF,并向AMF提供KAMF。在该情况下,Ks相当于KAUSF的功能。AMF可以基于KAMF生成NAS安全上下文。又例如,认证网元可以向AMF提供Ks,在该情况下,Ks相当于KAMF的功能。AMF可以基于Ks生成NAS安全上下文。NAS安全上下文例如可以包括Knas-int和Knas-enc。
又例如,认证网元可以基于Ks生成Kgnb,并向基站提供Kgnb。在该情况下,Ks相当于KAUSF的功能。基站可以基于Kgnb生成AS安全上下文。又例如,认证网元可以向基站提供Ks,在该情况下,Ks相当于Kgnb的功能。基站可以基于Ks生成AS安全上下文。
在一些实施例中,代理节点的中继方式可以包括L2中继和L3中继。即代理节点在用于中继通信时,中继使用的协议栈可以属于L2层,也可以属于L3层。对于L2中继,第一设备与核心网之间有单独的上下文。第一设备与网络间存在逐跳(hop by hop)和端到端(end-to-end)的安全连接。对于L3中继,第一设备只需要实现与代理节点之间的安全连接即可。
对于L3中继,安全上下文可以包括第一设备与代理节点之间的安全上下文。对于L2中继,安全上下文包括第一设备与代理节点之间的安全上下文、NAS安全上下文和AS安全上下文。
上述公式中的函数f可以是3GPP定义的f1-f5中的任意一种函数。或者,函数f可以为KDF(如 HMAC-SHA256)。或者,函数f可以为其他轻量级函数(如ASCON)。
上文中的归属域网元或认证网元可以包括以下网元中的一种或多种:UDM、AUSF、KMS、ARPF。上文中的服务域网元可以包括以下中的一种或多种:AMF、SMF、SEAF、特定于A-IoT服务的核心网网元A-NF。
上文中的代理节点如果为终端设备,则代理节点的标识可以使用UE ID来表示。
上文中的第一密钥N1有三种用途:一是可用于保护第一设备的身份标识;二是可用于计算认证向量和哦共享密钥Ks;三是可用于移动性管理,即生成Ku1。
需要说明的是,本申请实施例对产生的密钥的产生不做限定,可以为任意长度。密钥生成过程中可能引入编号FC、参数长度等值,本申请实施例对这些值的大小也不做具体限定。
上文结合图1至图20,详细描述了本申请的方法实施例,下面结合图21至图25,详细描述本申请的装置实施例。应理解,方法实施例的描述与装置实施例的描述相互对应,因此,未详细描述的部分可以参见前面方法实施例。
图21是本申请实施例提供的一种第一设备的示意性框图。图21所示的第一设备2100可以为上文描述的任意一种第一设备。该第一设备2100可以包括接收单元2110、生成单元2120、认证单元2130和发送单元2140。下面对这些单元进行详细介绍。
接收单元2110,用于接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成。
生成单元2120,用于基于第一密钥生成算法和第一参数生成第二消息认证码。
认证单元2130,用于基于所述第一消息认证码和所述第二消息认证码认证所述认证网元。
生成单元2120,还用于在所述认证网元认证成功的情况下,所述第一设备生成响应参数。
发送单元2140,用于向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
在一些实现方式中,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述生成单元用于:基于所述第一密钥生成算法和第二参数生成所述第一响应参数。
在一些实现方式中,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述生成单元用于:基于第二密钥生成算法和所述第一参数生成所述第一响应参数。
在一些实现方式中,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述生成单元用于:基于所述第一响应参数和第三参数,生成所述第二响应参数。
在一些实现方式中,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述生成单元用于:基于所述第一响应参数和第四参数,生成所述第三响应参数。
在一些实现方式中,所述生成单元还用于:在接收来自代理节点的第一认证请求之前,对所述第一设备的身份标识以及第一密钥进行异或运算,生成所述第一设备的隐藏身份标识;所述发送单元还用于:向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
在一些实现方式中,所述生成单元还用于:在接收来自代理节点的第一认证请求之前,基于所述第一设备的身份标识、第一密钥以及第三密钥生成算法,生成所述第一设备的隐藏身份标识,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述发送单元还用于:向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
在一些实现方式中,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
在一些实现方式中,所述生成单元还用于:在所述认证网元认证成功的情况下,生成第二密钥;基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
在一些实现方式中,所述发送单元还用于:向所述代理节点发送应用会话建立请求消息;所述接收单元还用于:接收来自所述代理节点的应用会话建立响应消息;所述生成单元还用于:响应于接收到所述应用会话建立响应消息,基于所述应用层的认证和密钥管理密钥,生成应用密钥;以及基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;所述设备还包括通信单元,用于基于所述第三密钥,与所述代理节点进行安全通信。
图22是本申请实施例提供的一种代理节点的示意性框图。图22所示的代理节点2200可以为上文描述的任意一种代理节点。该代理节点2200可以包括发送单元2210和接收单元2220。下面对这些单元进行详细介绍。
发送单元2210,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码, 所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成。
接收单元2220,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
在一些实现方式中,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
在一些实现方式中,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
在一些实现方式中,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
在一些实现方式中,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
在一些实现方式中,所述接收单元还用于:在向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
在一些实现方式中,所述接收单元还用于:在向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
在一些实现方式中,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述代理节点还包括确定单元,用于基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥、所述第一设备的身份标识和所述代理节点的标识。
在一些实现方式中,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述隐藏身份标识和所述代理节点的标识。
在一些实现方式中,所述接收单元还用于:接收来自应用功能网元的应用密钥;所述代理节点还包括:生成单元,用于基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;通信单元,用于基于所述第三密钥,与所述第一设备进行安全通信。
图23是本申请实施例提供的一种认证网元的示意性框图。图23所示的认证网元2300可以为上文描述的任意一种认证网元。该认证网元2300可以包括生成单元2310和发送单元2320。下面对这些单元进行详细介绍。
生成单元2310,用于生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成。
发送单元2320,用于向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
在一些实现方式中,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述生成单元用于:基于所述第一密钥生成算法和第二参数生成所述第一期望响应。
在一些实现方式中,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述生成单元用于:基于第二密钥生成算法和所述第一参数生成所述第一期望响应。
在一些实现方式中,所述期望响应包括第二期望响应,所述第二期望响应用于服务域网元认证所述第一设备,所述生成单元用于:基于所述第一期望响应和第三参数,生成所述第二期望响应。
在一些实现方式中,所述期望响应包括第三期望响应,所述第三期望响应用于接入网设备认证所述第一设备,所述生成单元用于:基于所述第一期望响应和第四参数,生成所述第三期望响应。
在一些实现方式中,所述认证网元还包括:接收单元,用于:在所述认证网元生成第一消息认证码和期望响应之前,接收来自所述代理节点的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,确定单元,用于基于所述隐藏身份标识与第一密钥,确定所述第一设备的身份标识。
在一些实现方式中,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
在一些实现方式中,所述生成单元用于:在所述第一设备认证成功的情况下,生成第二密钥;基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
在一些实现方式中,所述第一参数包括第一随机数,所述第一随机数由所述认证网元选择,或所述第一随机数由所述认证网元与所述第一设备预共享。
图24是本申请实施例提供的一种接入网设备的示意性框图。图24所示的接入网设备2400可以为上文描述的任意一种接入网设备。该接入网设备2400可以包括发送单元2410和接收单元2420。下面对这些单元进行详细介绍。
发送单元2410,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成。
接收单元2420,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
在一些实现方式中,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
在一些实现方式中,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
在一些实现方式中,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
在一些实现方式中,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
在一些实现方式中,所述接收单元还用于:在所述接入网设备向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
在一些实现方式中,所述接收单元还用于:在所述接入网设备向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
在一些实现方式中,所述第一密钥为所述第一设备与所述接入网设备之间的物理层密钥,所述接入网设备还包括确定单元,用于基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥和所述第一设备的身份标识。
在一些实现方式中,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
在一些实现方式中,所述第一认证响应中包括第三响应参数,所述接收单元还用于:接收来自所述认证网元的第二认证响应,所述第二认证响应中包括第三期望响应;所述接入网设备还包括:比较单元,用于比较所述第三响应参数和所述第三认证响应,以认证所述第一设备。
图25是本申请实施例的通信装置的示意性结构图。图25中的虚线表示该单元或模块为可选的。该装置2500可用于实现上述方法实施例中描述的方法。装置2500可以是芯片、第一设备、代理节点、认证网元、接入网设备或应用功能网元。
装置2500可以包括一个或多个处理器2510。该处理器2510可支持装置2500实现前文方法实施例所描述的方法。该处理器2510可以是通用处理器或者专用处理器。例如,该处理器可以为中央处理单元(central processing unit,CPU)。或者,该处理器还可以是其他通用处理器、数字信号处理器(digital signal processor,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现成可编程门阵列(field programmable gate array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。
装置2500还可以包括一个或多个存储器2520。存储器2520上存储有程序,该程序可以被处理器2510执行,使得处理器2510执行前文方法实施例所描述的方法。存储器2520可以独立于处理器2510也可以集成在处理器2510中。
装置2500还可以包括收发器2530。处理器2510可以通过收发器2530与其他设备或芯片进行通信。例如,处理器2510可以通过收发器2530与其他设备或芯片进行数据收发。
本申请实施例还提供一种计算机可读存储介质,用于存储程序。该计算机可读存储介质可应用于本 申请实施例提供的第一设备、代理节点、认证网元、接入网设备或应用功能网元中,并且该程序使得计算机执行本申请各个实施例中的由第一设备、代理节点、认证网元、接入网设备或应用功能网元执行的方法。
本申请实施例还提供一种计算机程序产品。该计算机程序产品包括程序。该计算机程序产品可应用于本申请实施例提供的第一设备、代理节点、认证网元、接入网设备或应用功能网元中,并且该程序使得计算机执行本申请各个实施例中的由第一设备、代理节点、认证网元、接入网设备或应用功能网元执行的方法。
本申请实施例还提供一种计算机程序。该计算机程序可应用于本申请实施例提供的第一设备、代理节点、认证网元、接入网设备或应用功能网元中,并且该计算机程序使得计算机执行本申请各个实施例中的由第一设备、代理节点、认证网元、接入网设备或应用功能网元执行的方法。
应理解,本申请使用的术语仅用于对本申请的具体实施例进行解释,而非旨在限定本申请。本申请的说明书和权利要求书及所述附图中的术语“第一”、“第二”、“第三”和“第四”等是用于区别不同对象,而不是用于描述特定顺序。
在本申请的实施例中,提到的“包括”可以指直接包括,也可以指间接包括。可选地,可以将本申请实施例中提到的“包括”替换为“指示”或“用于确定”。例如,A包括B,可以替换为A指示B,或A用于确定B。
在本申请实施例中,术语“对应”可表示两者之间具有直接对应或间接对应的关系,也可以表示两者之间具有关联关系,也可以是指示与被指示、配置与被配置等关系。
本申请实施例中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本文中字符“/”,一般表示前后关联对象是一种“或”的关系。
在本申请的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。

Claims (87)

  1. 一种认证方法,其特征在于,包括:
    第一设备接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;
    所述第一设备基于第一密钥生成算法和第一参数生成第二消息认证码;
    所述第一设备基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;
    在所述认证网元认证成功的情况下,所述第一设备生成响应参数;
    所述第一设备向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
  2. 根据权利要求1所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一设备生成响应参数,包括:
    所述第一设备基于所述第一密钥生成算法和第二参数生成所述第一响应参数。
  3. 根据权利要求1所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一设备生成响应参数,包括:
    所述第一设备基于第二密钥生成算法和所述第一参数生成所述第一响应参数。
  4. 根据权利要求2或3所述的方法,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第一设备生成响应参数,包括:
    所述第一设备基于所述第一响应参数和第三参数,生成所述第二响应参数。
  5. 根据权利要求2-4中任一项所述的方法,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第一设备生成响应参数,包括:
    所述第一设备基于所述第一响应参数和第四参数,生成所述第三响应参数。
  6. 根据权利要求1-5中任一项所述的方法,其特征在于,在所述第一设备接收来自代理节点的第一认证请求之前,所述方法还包括:
    所述第一设备对所述第一设备的身份标识以及第一密钥进行异或运算,生成所述第一设备的隐藏身份标识;
    所述第一设备向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
  7. 根据权利要求1所述的方法,其特征在于,在所述第一设备接收来自代理节点的第一认证请求之前,所述方法还包括:
    所述第一设备基于所述第一设备的身份标识、第一密钥以及第三密钥生成算法,生成所述第一设备的隐藏身份标识,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;
    所述第一设备向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
  8. 根据权利要求6或7所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
  9. 根据权利要求1-8中任一项所述的方法,其特征在于,所述方法还包括:
    在所述认证网元认证成功的情况下,所述第一设备生成第二密钥;
    所述第一设备基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
  10. 根据权利要求9所述的方法,其特征在于,所述方法还包括:
    所述第一设备向所述代理节点发送应用会话建立请求消息;
    所述第一设备接收来自所述代理节点的应用会话建立响应消息;
    响应于接收到所述应用会话建立响应消息,所述第一设备基于所述应用层的认证和密钥管理密钥,生成应用密钥;
    所述第一设备基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;
    所述第一设备基于所述第三密钥,与所述代理节点进行安全通信。
  11. 一种认证方法,其特征在于,包括:
    代理节点向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;
    所述代理节点接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
  12. 根据权利要求11所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
  13. 根据权利要求11所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
  14. 根据权利要求12或13所述的方法,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
  15. 根据权利要求12-14中任一项所述的方法,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
  16. 根据权利要求11-15中任一项所述的方法,其特征在于,在所述代理节点向第一设备发送第一认证请求之前,所述方法还包括:
    所述代理节点接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
  17. 根据权利要求11-15中任一项所述的方法,其特征在于,在所述代理节点向第一设备发送第一认证请求之前,所述方法还包括:
    所述代理节点接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
  18. 根据权利要求16或17所述的方法,其特征在于,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述方法还包括:
    所述代理节点基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;
    所述代理节点向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥、所述第一设备的身份标识和所述代理节点的标识。
  19. 根据权利要求16或17所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述方法还包括:
    所述代理节点向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述隐藏身份标识和所述代理节点的标识。
  20. 根据权利要求11-19中任一项所述的方法,其特征在于,所述方法还包括:
    所述代理节点接收来自应用功能网元的应用密钥;
    所述代理节点基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;
    所述代理节点基于所述第三密钥,与所述第一设备进行安全通信。
  21. 一种认证方法,其特征在于,包括:
    认证网元生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成;
    所述认证网元向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
  22. 根据权利要求21所述的方法,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述认证网元生成期望响应,包括:
    所述认证网元基于所述第一密钥生成算法和第二参数生成所述第一期望响应。
  23. 根据权利要求21所述的方法,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述认证网元生成期望响应,包括:
    所述认证网元基于第二密钥生成算法和所述第一参数生成所述第一期望响应。
  24. 根据权利要求22或23所述的方法,其特征在于,所述期望响应包括第二期望响应,所述第二期望响应用于服务域网元认证所述第一设备,所述方法还包括:
    所述认证网元基于所述第一期望响应和第三参数,生成所述第二期望响应。
  25. 根据权利要求22-24中任一项所述的方法,其特征在于,所述期望响应包括第三期望响应,所 述第三期望响应用于接入网设备认证所述第一设备,所述方法还包括:
    所述认证网元基于所述第一期望响应和第四参数,生成所述第三期望响应。
  26. 根据权利要求21-25中任一项所述的方法,其特征在于,在所述认证网元生成第一消息认证码和期望响应之前,所述方法还包括:
    所述认证网元接收来自所述代理节点的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,
    所述认证网元基于所述隐藏身份标识与第一密钥,确定所述第一设备的身份标识。
  27. 根据权利要求26所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
  28. 根据权利要求21-27中任一项所述的方法,其特征在于,所述方法还包括:
    在所述第一设备认证成功的情况下,所述认证网元生成第二密钥;
    所述认证网元基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
  29. 根据权利要求21-28中任一项所述的方法,其特征在于,所述第一参数包括第一随机数,所述第一随机数由所述认证网元选择,或所述第一随机数由所述认证网元与所述第一设备预共享。
  30. 一种认证方法,其特征在于,包括:
    接入网设备向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;
    所述接入网设备接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
  31. 根据权利要求30所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
  32. 根据权利要求30所述的方法,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
  33. 根据权利要求31或32所述的方法,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
  34. 根据权利要求31-33中任一项所述的方法,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
  35. 根据权利要求30-34中任一项所述的方法,其特征在于,在所述接入网设备向第一设备发送第一认证请求之前,所述方法还包括:
    所述接入网设备接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
  36. 根据权利要求30-34中任一项所述的方法,其特征在于,在所述接入网设备向第一设备发送第一认证请求之前,所述方法还包括:
    所述接入网设备接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
  37. 根据权利要求35或36所述的方法,其特征在于,所述第一密钥为所述第一设备与所述接入网设备之间的物理层密钥,所述方法还包括:
    所述接入网设备基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;
    所述接入网设备向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥和所述第一设备的身份标识。
  38. 根据权利要求35或36所述的方法,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述方法还包括:
    所述接入网设备向所述认证网元发送所述第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
  39. 根据权利要求30-38中任一项所述的方法,其特征在于,所述第一认证响应中包括第三响应参 数,所述方法还包括:
    所述接入网设备接收来自所述认证网元的第二认证响应,所述第二认证响应中包括第三期望响应;
    所述接入网设备比较所述第三响应参数和所述第三认证响应,以认证所述第一设备。
  40. 一种设备,其特征在于,所述设备为第一设备,所述第一设备包括:
    接收单元,用于接收来自代理节点的第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成;
    生成单元,用于基于第一密钥生成算法和第一参数生成第二消息认证码;
    认证单元,用于基于所述第一消息认证码和所述第二消息认证码认证所述认证网元;
    所述生成单元,还用于在所述认证网元认证成功的情况下,所述第一设备生成响应参数;
    发送单元,用于向所述代理节点发送第一认证响应,所述第一认证响应中包括所述响应参数,所述响应参数用于认证所述第一设备。
  41. 根据权利要求40所述的设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述生成单元用于:
    基于所述第一密钥生成算法和第二参数生成所述第一响应参数。
  42. 根据权利要求40所述的设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述生成单元用于:
    基于第二密钥生成算法和所述第一参数生成所述第一响应参数。
  43. 根据权利要求41或42所述的设备,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述生成单元用于:
    基于所述第一响应参数和第三参数,生成所述第二响应参数。
  44. 根据权利要求41-43中任一项所述的设备,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述生成单元用于:
    基于所述第一响应参数和第四参数,生成所述第三响应参数。
  45. 根据权利要求40-44中任一项所述的设备,其特征在于,所述生成单元还用于:在接收来自代理节点的第一认证请求之前,对所述第一设备的身份标识以及第一密钥进行异或运算,生成所述第一设备的隐藏身份标识;
    所述发送单元还用于:向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
  46. 根据权利要求40所述的设备,其特征在于,所述生成单元还用于:在接收来自代理节点的第一认证请求之前,基于所述第一设备的身份标识、第一密钥以及第三密钥生成算法,生成所述第一设备的隐藏身份标识,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;
    所述发送单元还用于:向所述代理节点发送第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
  47. 根据权利要求45或46所述的设备,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
  48. 根据权利要求40-47中任一项所述的设备,其特征在于,所述生成单元还用于:
    在所述认证网元认证成功的情况下,生成第二密钥;
    基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
  49. 根据权利要求48所述的设备,其特征在于,
    所述发送单元还用于:向所述代理节点发送应用会话建立请求消息;
    所述接收单元还用于:接收来自所述代理节点的应用会话建立响应消息;
    所述生成单元还用于:响应于接收到所述应用会话建立响应消息,基于所述应用层的认证和密钥管理密钥,生成应用密钥;以及基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;
    所述设备还包括通信单元,用于基于所述第三密钥,与所述代理节点进行安全通信。
  50. 一种代理节点,其特征在于,包括:
    发送单元,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;
    接收单元,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述 响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
  51. 根据权利要求50所述的代理节点,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
  52. 根据权利要求50所述的代理节点,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
  53. 根据权利要求51或52所述的代理节点,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
  54. 根据权利要求51-53中任一项所述的代理节点,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
  55. 根据权利要求50-54中任一项所述的代理节点,其特征在于,
    所述接收单元还用于:在向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
  56. 根据权利要求50-54中任一项所述的代理节点,其特征在于,
    所述接收单元还用于:在向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
  57. 根据权利要求55或56所述的代理节点,其特征在于,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述代理节点还包括确定单元,用于基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;
    所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥、所述第一设备的身份标识和所述代理节点的标识。
  58. 根据权利要求55或56所述的代理节点,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,
    所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述隐藏身份标识和所述代理节点的标识。
  59. 根据权利要求50-58中任一项所述的代理节点,其特征在于,所述接收单元还用于:接收来自应用功能网元的应用密钥;
    所述代理节点还包括:
    生成单元,用于基于所述应用密钥、第一密钥以及第五密钥生成算法,生成第三密钥,所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥,所述第五密钥生成算法为所述第一密钥生成算法或第二密钥生成算法;
    通信单元,用于基于所述第三密钥,与所述第一设备进行安全通信。
  60. 一种认证网元,其特征在于,包括:
    生成单元,用于生成第一消息认证码和期望响应,所述期望响应用于认证第一设备,所述第一消息认证码基于第一密钥生成算法和第一参数生成;
    发送单元,用于向所述代理节点发送第一认证请求,所述第一认证请求中包括所述第一消息认证码,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成。
  61. 根据权利要求60所述的认证网元,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述生成单元用于:
    基于所述第一密钥生成算法和第二参数生成所述第一期望响应。
  62. 根据权利要求60所述的认证网元,其特征在于,所述期望响应包括第一期望响应,所述第一期望响应用于归属域网元认证所述第一设备,所述生成单元用于:
    基于第二密钥生成算法和所述第一参数生成所述第一期望响应。
  63. 根据权利要求61或62所述的认证网元,其特征在于,所述期望响应包括第二期望响应,所述第二期望响应用于服务域网元认证所述第一设备,所述生成单元用于:
    基于所述第一期望响应和第三参数,生成所述第二期望响应。
  64. 根据权利要求61-63中任一项所述的认证网元,其特征在于,所述期望响应包括第三期望响应,所述第三期望响应用于接入网设备认证所述第一设备,所述生成单元用于:
    基于所述第一期望响应和第四参数,生成所述第三期望响应。
  65. 根据权利要求60-64中任一项所述的认证网元,其特征在于,所述认证网元还包括:
    接收单元,用于:在所述认证网元生成第一消息认证码和期望响应之前,接收来自所述代理节点的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,
    确定单元,用于基于所述隐藏身份标识与第一密钥,确定所述第一设备的身份标识。
  66. 根据权利要求65所述的认证网元,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,或所述第一密钥为所述第一设备与所述代理节点之间的物理层密钥。
  67. 根据权利要求60-66中任一项所述的认证网元,其特征在于,所述生成单元用于:
    在所述第一设备认证成功的情况下,生成第二密钥;
    基于所述第二密钥和第四密钥生成算法,生成应用层的认证和密钥管理密钥。
  68. 根据权利要求60-67中任一项所述的认证网元,其特征在于,所述第一参数包括第一随机数,所述第一随机数由所述认证网元选择,或所述第一随机数由所述认证网元与所述第一设备预共享。
  69. 一种接入网设备,其特征在于,包括:
    发送单元,用于向第一设备发送第一认证请求,所述第一认证请求中包括第一消息认证码,所述第一消息认证码由认证网元生成,所述第一消息认证码和第二消息认证码用于认证所述认证网元,所述第二消息认证码由所述第一设备生成,所述第一消息认证码和所述第二消息认证码基于第一密钥生成算法和第一参数生成;
    接收单元,用于接收来自所述第一设备的第一认证响应,所述第一认证响应中包括响应参数,所述响应参数用于认证所述第一设备,所述响应参数在所述认证网元认证成功的情况下生成。
  70. 根据权利要求69所述的接入网设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于所述第一密钥生成算法和第二参数生成。
  71. 根据权利要求69所述的接入网设备,其特征在于,所述响应参数包括第一响应参数,所述第一响应参数用于归属域网元认证所述第一设备,所述第一响应参数基于第二密钥生成算法和所述第一参数生成。
  72. 根据权利要求70或71所述的接入网设备,其特征在于,所述响应参数包括第二响应参数,所述第二响应参数用于服务域网元认证所述第一设备,所述第二响应参数基于所述第一响应参数和第三参数生成。
  73. 根据权利要求70-72中任一项所述的接入网设备,其特征在于,所述响应参数包括第三响应参数,所述第三响应参数用于接入网设备认证所述第一设备,所述第三响应参数基于所述第一响应参数和第四参数生成。
  74. 根据权利要求69-73中任一项所述的接入网设备,其特征在于,所述接收单元还用于:
    在所述接入网设备向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的身份标识与第一密钥通过异或运算生成。
  75. 根据权利要求69-73中任一项所述的接入网设备,其特征在于,所述接收单元还用于:
    在所述接入网设备向第一设备发送第一认证请求之前,接收来自所述第一设备的第二认证请求,所述第二认证请求中包括所述第一设备的隐藏身份标识,所述隐藏身份标识由所述第一设备的隐藏身份标识、第一密钥以及第三密钥生成算法生成,所述第三密钥生成算法为所述第一密钥生成算法或第二密钥生成算法。
  76. 根据权利要求74或75所述的接入网设备,其特征在于,所述第一密钥为所述第一设备与所述接入网设备之间的物理层密钥,所述接入网设备还包括确定单元,用于基于所述第一密钥和所述隐藏身份标识,确定所述第一设备的身份标识;
    所述发送单元还用于:向所述认证网元发送所述第二认证请求,所述第二认证请求中包括以下信息中的一种或多种:所述第一密钥和所述第一设备的身份标识。
  77. 根据权利要求74或75所述的接入网设备,其特征在于,所述第一密钥为所述第一设备与所述认证网元之间的共享密钥,所述发送单元还用于:
    向所述认证网元发送所述第二认证请求,所述第二认证请求中包括所述隐藏身份标识。
  78. 根据权利要求69-77中任一项所述的接入网设备,其特征在于,所述第一认证响应中包括第三 响应参数,所述接收单元还用于:接收来自所述认证网元的第二认证响应,所述第二认证响应中包括第三期望响应;
    所述接入网设备还包括:比较单元,用于比较所述第三响应参数和所述第三认证响应,以认证所述第一设备。
  79. 一种设备,其特征在于,所述设备为第一设备,所述第一设备包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述第一设备执行如权利要求1-10中任一项所述的方法。
  80. 一种代理节点,其特征在于,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述代理节点执行如权利要求11-20中任一项所述的方法。
  81. 一种认证网元,其特征在于,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述认证网元执行如权利要求21-29中任一项所述的方法。
  82. 一种接入网设备,其特征在于,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述接入网设备执行如权利要求30-39中任一项所述的方法。
  83. 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求1-10中任一项所述的方法。
  84. 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求11-20中任一项所述的方法。
  85. 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求21-29中任一项所述的方法。
  86. 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以执行如权利要求30-39中任一项所述的方法。
  87. 一种芯片,其特征在于,包括处理器,用于从存储器调用程序,使得安装有所述芯片的设备执行如权利要求1-10中任一项所述的方法。
PCT/CN2023/095769 2023-05-23 2023-05-23 认证方法及装置 Ceased WO2024239231A1 (zh)

Priority Applications (5)

Application Number Priority Date Filing Date Title
CN202380098422.4A CN121220076A (zh) 2023-05-23 2023-05-23 认证方法及装置
PCT/CN2023/095769 WO2024239231A1 (zh) 2023-05-23 2023-05-23 认证方法及装置
EP23937907.6A EP4718901A1 (en) 2023-05-23 2023-05-23 Method and apparatus for authentication
MX2025013824A MX2025013824A (es) 2023-05-23 2025-11-19 Metodo y aparato para autenticacion
US19/397,618 US20260082224A1 (en) 2023-05-23 2025-11-21 Method and apparatus for authentication

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2023/095769 WO2024239231A1 (zh) 2023-05-23 2023-05-23 认证方法及装置

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US19/397,618 Continuation US20260082224A1 (en) 2023-05-23 2025-11-21 Method and apparatus for authentication

Publications (1)

Publication Number Publication Date
WO2024239231A1 true WO2024239231A1 (zh) 2024-11-28

Family

ID=93588762

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/095769 Ceased WO2024239231A1 (zh) 2023-05-23 2023-05-23 认证方法及装置

Country Status (5)

Country Link
US (1) US20260082224A1 (zh)
EP (1) EP4718901A1 (zh)
CN (1) CN121220076A (zh)
MX (1) MX2025013824A (zh)
WO (1) WO2024239231A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170353859A1 (en) * 2016-06-07 2017-12-07 Sears Brands, L.L.C. System and method for automatically and securely registering an internet of things device
CN110012467A (zh) * 2019-04-18 2019-07-12 苏州博联科技有限公司 窄带物联网的分组认证方法
CN111669276A (zh) * 2019-03-07 2020-09-15 华为技术有限公司 一种网络验证方法、装置及系统
CN115380570A (zh) * 2020-03-29 2022-11-22 华为技术有限公司 一种通信方法、装置及系统
CN115776398A (zh) * 2022-11-18 2023-03-10 华润数字科技有限公司 一种IoT边缘设备认证方法及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170353859A1 (en) * 2016-06-07 2017-12-07 Sears Brands, L.L.C. System and method for automatically and securely registering an internet of things device
CN111669276A (zh) * 2019-03-07 2020-09-15 华为技术有限公司 一种网络验证方法、装置及系统
CN110012467A (zh) * 2019-04-18 2019-07-12 苏州博联科技有限公司 窄带物联网的分组认证方法
CN115380570A (zh) * 2020-03-29 2022-11-22 华为技术有限公司 一种通信方法、装置及系统
CN115776398A (zh) * 2022-11-18 2023-03-10 华润数字科技有限公司 一种IoT边缘设备认证方法及系统

Also Published As

Publication number Publication date
MX2025013824A (es) 2025-12-01
EP4718901A1 (en) 2026-04-01
US20260082224A1 (en) 2026-03-19
CN121220076A (zh) 2025-12-26

Similar Documents

Publication Publication Date Title
US11785510B2 (en) Communication system
US11805409B2 (en) System and method for deriving a profile for a target endpoint device
CN101500229B (zh) 建立安全关联的方法和通信网络系统
US20230379700A1 (en) Security parameter obtaining method, apparatus, and system
CN109691154B (zh) 基于密钥刷新的按需网络功能重新认证
CN117544947A (zh) 通信方法、装置及可读存储介质
WO2022253083A1 (zh) 一种公私网业务的隔离方法、装置及系统
EP4447511A1 (en) Method and apparatus for data processing in random access process
EP4718901A1 (en) Method and apparatus for authentication
WO2023213191A1 (zh) 安全保护方法及通信装置
US20260128857A1 (en) User-level homomorphic encryption management method and apparatus
EP4712529A1 (en) Communication method and device
CN114208240A (zh) 数据传输方法、装置及系统
US20240380742A1 (en) Information protection mrthod and device
WO2026073511A1 (zh) 通信方法、装置、设备以及存储介质
WO2026025341A1 (zh) 传输方法、终端设备和网络设备
CN118830225A (zh) 生成密钥的方法及装置
CN118402262A (zh) 中继通信的方法及设备
CN120390213A (zh) 信息处理方法及装置、系统
WO2023178530A1 (zh) 生成密钥的方法及装置
WO2025066757A1 (zh) 一种通信方法及装置
WO2023205978A1 (zh) 邻近通信业务的密钥生成方法、装置、设备及存储介质
WO2025025060A1 (zh) 认证方法和设备
CN119729457A (zh) Nas消息的安全保护方法、装置及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23937907

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: MX/A/2025/013824

Country of ref document: MX

WWP Wipo information: published in national office

Ref document number: MX/A/2025/013824

Country of ref document: MX

WWE Wipo information: entry into national phase

Ref document number: 2023937907

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

ENP Entry into the national phase

Ref document number: 2023937907

Country of ref document: EP

Effective date: 20251223

WWP Wipo information: published in national office

Ref document number: 2023937907

Country of ref document: EP