Authentication method within wireless communication network, related apparatus and system
Abstract
Provided are an authentication method within a wireless communication network, a related apparatus and a system. A core network device saving an unused authentication vector for a user equipment may send a first authentication data request message to an authentication device, the first authentication data request message being used for requesting the authentication device to generate an authentication vector for the user equipment, a first authentication data response message of the authentication device is received, the first authentication data response message carrying a first authentication vector generated by the authentication device for the user equipment, and the first authentication vector is used to initiate an authentication process for the user equipment. The present invention ensures that each time CS domain / PS domain authentication is performed, a sequence included in the authentication vector is newly generated by the authentication device. Successful synchronisation is ensured even if PS domain authentication is inserted before CS domain authentication or CS domain authentication is inserted before PS domain authentication, solving the problem in the prior art of authentication failure caused by synchronisation failure.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
27 claims: 13 independent, 14 dependent
- 1一种无线通信网络中的鉴权方法,其特征在于,所述方法包括: 为用户设备保存有未使用的鉴权向量的核心网设备向鉴权设备发送第一鉴权数据请求消息,所述第一鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量; 所述核心网设备接收所述鉴权设备根据所述第一鉴权数据请求消息返回的第一鉴权数据响应消息,所述第一鉴权数据响应消息携带第一鉴权向量; 所述核心网设备向所述用户设备发送第一鉴权请求消息,所述第一鉴权请求消息包含所述第一鉴权向量中的随机数和鉴权令牌。
- 2根据权利要求1所述的方法,其特征在于,所述为用户设备保存有未使用的鉴权向量的核心网设备向鉴权设备发送第一鉴权数据请求消息之前,所述方法还包括: 所述用户设备接入所述核心网设备所位于的第一网络之后,所述核心网设备确定所述用户设备是从第二网络接入到所述第一网络的用户设备;其中,所述第一网络的网络制式与所述第二网络的网络制式不同。
- 3根据权利要求2所述的方法,其特征在于,所述第一网络为3G网络,所述第二网络为长期演进LTE网络; 则所述核心网设备确定所述用户设备是从第二网络接入到所述第一网络的用户设备包括:所述核心网设备确定所述用户设备是从LTE网络接入到3G网络的用户设备。
- 4根据权利要求3所述的方法,其特征在于,所述3G网络的所述核心网设备确定所述用户设备是从LTE网络接入到3G网络的用户设备包括: 所述核心网设备根据所述用户设备发送的分组交换域非接入层消息,确定所述用户设备为从LTE网络接入到3G网络的用户设备;或者 所述核心网设备根据所述用户设备发送的寻呼响应消息或者电路交换域非接入层消息,确定所述用户设备是从LTE网络接入到3G网络的用户设备;或者, 所述核心网设备通过确定自身与移动管理实体MME之间对应所述用户设备存在SG S 接口关联,确定所述用户设备是从LTE网络接入到3G网络的用户设备;或者, 所述核心网设备根据基站发送的通知消息,确定所述用户设备是从LTE网络接入到3G网络的用户设备,所述通知消息为所述基站在确定所述用户设备为电路交换回落CSFB用户之后向所述核心网设备发送的消息。
- 5根据权利要求1-4任一项所述的方法,其特征在于,所述为用户设备保存有未使用的鉴权向量的核心网设备向鉴权设备发送第一鉴权数据请求消息之前,所述方法还包括: 所述核心网设备向所述鉴权设备发送第二鉴权数据请求消息,所述第二鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量; 所述核心网设备接收所述鉴权设备根据所述第二鉴权数据请求消息返回的第二鉴权数据响应消息,所述第二鉴权数据响应消息携带第二鉴权向量和所述未使用的鉴权向量; 所述核心网设备向所述用户设备发送第二鉴权请求消息,所述第二鉴权请求消息包含所述第二鉴权向量中的随机数和鉴权令牌。
- 6根据权利要求1-5任一项所述的方法,其特征在于,所述核心网设备为移动交换中心MSC或者通用分组无线系统GPRS业务支持节点SGSN。
- 7一种无线通信网络中的鉴权方法,其特征在于,所述方法包括: 鉴权设备接收为用户设备保存有未使用的鉴权向量的核心网设备发送的第一鉴权数据请求消息,所述第一鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量; 所述鉴权设备根据所述第一鉴权数据请求消息,生成第一鉴权数据响应消息,所述第一鉴权数据响应消息包含所述鉴权设备为所述用户设备生成的第一鉴权向量; 所述鉴权设备向所述核心网设备返回所述第一鉴权数据响应消息。
- 8根据权利要求6所述的方法,其特征在于,在所述鉴权设备接收为用户设备保存有未使用的鉴权向量的核心网设备发送的第一鉴权数据请求消息之前,所述方法还包括: 所述鉴权设备接收所述核心网设备发送的第二鉴权数据请求消息,所述第二鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量; 所述鉴权设备根据所述第二鉴权数据请求消息,生成第二鉴权数据响应消息,所述鉴权数据响应消息包含所述鉴权设备为所述用户设备生成的第二鉴权向量和所述未使用的鉴权向量; 所述鉴权设备向所述核心网设备返回所述第二鉴权数据响应消息。
- 9根据权利要求7或8所述的方法,其特征在于,所述鉴权设备为归属环境HE、归属位置寄存器HLR、归属用户服务器HSS或者鉴权中心AUC。
- 10一种核心网设备,其特征在于,包括: 存储单元,用于为用户设备保存未使用的鉴权向量; 获取单元,用于在所述存储单元为所述用户设备保存有所述未使用的鉴权向量的情况下,向所述鉴权设备发送第一鉴权数据请求消息,所述第一鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量,接收所述鉴权设备根据所述鉴权数据请求消息返回的第一鉴权数据响应消息,所述第一鉴权数据响应消息包含第一鉴权向量; 发送单元,用于向所述用户设备发送第一鉴权请求消息,所述第一鉴权请求消息包含所述第一鉴权向量中的随机数和鉴权令牌。
- 11根据权利要求10所述的核心网设备,其特征在于,所述核心网设备还包括: 确定单元,用于在所述用户设备接入所述核心网设备所位于的第一网络之后,确定所述用户设备是从第二网络接入到所述第一网络的用户设备;其中,所述第一网络的网络制式与所述第二网络的网络制式不同; 则所述获取单元具体用于在所述确定单元确定所述用户设备是从第二网络接入到所述第一网络的用户设备之后,向所述鉴权设备发送所述第一鉴权数据请求消息。
- 12根据权利要求11所述的核心网设备,其特征在于,所述第一网络为3G网络,所述第二网络为长期演进LTE网络; 则所述确定单元具体用于确定所述用户设备是从LTE网络接入到3G网络的用户设备。
- 13根据权利要求12所述的核心网设备,其特征在于,所述确定单元具体用于根据所述用户设备发送的分组交换域非接入层消息,确定所述用户设备为从LTE网络接入到3G网络的用户设备;或者 根据所述用户设备发送的寻呼响应消息或者电路交换域非接入层消息,确定所述用户设备是从LTE网络接入到3G网络的用户设备;或者, 通过确定自身与移动管理实体MME之间对应所述用户设备存在SG S 接口关联,确定所述用户设备是从LTE网络接入到3G网络的用户设备;或者, 根据基站发送的通知消息,确定所述用户设备是从LTE网络接入到3G网络的用户设备,所述通知消息为所述基站在确定所述用户设备为电路交换回落CSFB用户之后向所述核心网设备发送的消息。
- 14根据权利要求10-13任一项所述的核心网设备,其特征在于,所述获取单元还用于在向鉴权设备发送第一鉴权数据请求消息之前,向所述鉴权设备发送第二鉴权数据请求消息,所述第二鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量,接收所述鉴权设备根据所述第二鉴权数据请求消息返回的第二鉴权数据响应消息,所述第二鉴权数据响应消息携带第二鉴权向量和所述未使用的鉴权向量; 所述发送单元还用于在所述获取单元向鉴权设备发送第一鉴权数据请求消息之前,向所述用户设备发送第二鉴权请求消息,所述第二鉴权请求消息包含所述第二鉴权向量中的随机数和鉴权令牌。
- 15根据权利要求10-14任一项所述的核心网设备,其特征在于,所述核心网设备为移动交换中心MSC或者通用分组无线系统GPRS业务支持节点SGSN。
- 16一种鉴权设备,其特征在于,包括: 接收单元,用于接收为用户设备保存有未使用的鉴权向量的核心网设备发送的第一鉴权数据请求消息,所述第一鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量; 处理单元,用于根据所述第一鉴权数据请求消息,生成第一鉴权数据响应消息,所述第一鉴权数据响应消息包含为所述用户设备生成的第一鉴权向量; 发送单元,用于向所述核心网设备返回所述第一鉴权数据响应消息。
- 17根据权利要求16所述的鉴权设备,其特征在于,所述接收单元还用于在接收所述第一鉴权数据请求消息之前,接收所述核心网设备发送的第二鉴权数据请求消息; 所述处理单元还用于根据所述第二鉴权数据请求消息,所述第二鉴权数据请求消息用于请求所述鉴权设备为所述用户设备生成鉴权向量,生成第二鉴权数据响应消息,所述鉴权数据响应消息包含为所述用户设备生成的第二鉴权向量和所述未使用的鉴权向量; 所述发送单元还用于向所述核心网设备返回所述第二鉴权数据响应消息。
- 18根据权利要求16或17所述的方法,其特征在于,所述鉴权设备为归属环境HE、归属位置寄存器HLR、归属用户服务器HSS或者鉴权中心AUC。
- 19一种鉴权系统,其特征在于,包括如权利要求10-15任一项所述的核心网设备和如权利要求16-18任一项所述的鉴权设备。
- 20根据权利要求19所述的系统,其特征在于,还包括用户设备; 所述用户设备用于接收所述核心网设备发送的第一鉴权请求消息,利用所述第一鉴权请求消息包含的第一鉴权向量中的随机数和鉴权令牌进行鉴权。
- 21一种无线通信网络中的鉴权方法,其特征在于,所述方法包括 在用户设备从3G网络接入到长期演进LTE网络之后,所述LTE网络的移动管理实体MME获取所述3G网络的通用分组无线系统GPRS业务支撑节点SGSN为所述用户设备保存的未使用的鉴权向量; 所述MME删除或丢弃所述未使用的鉴权向量,以便在所述用户设备从所述LTE网络重新接入到所述3G网络之后,所述MME无法将所述未使用的鉴权向量发送给所述SGSN。
- 22根据权利要求21所述的方法,其特征在于,所述LTE网络的移动管理实体MME获取所述3G网络的通用分组无线系统GPRS业务支持节点SGSN为所述用户设备保存的未使用的鉴权向量包括: 所述LTE网络的移动管理实体MME向所述3G网络的SGSN发送的上下文请求消息,接收所述SGSN返回的第一上下文响应消息,所述第一上下文响应消息包含所述未使用的鉴权向量;或者, 所述LTE网络的移动管理实体MME接收所述3G网络的第一SGSN发送第一前转重定位请求消息,所述第一前转重定位请求消息包含所述未使用的鉴权向量。
- 23根据权利要求21或22所述的方法,其特征在于,在所述MME删除或丢弃所述未使用的鉴权向量之后,所述方法还包括: 在所述用户设备从所述LTE网络重新接入到所述3G网络之后,所述MME接收所述SGSN发送第二上下文请求消息,并向所述SGSN返回第二上下文响应消息,所述第二上下文响应消息不包含所述未使用的鉴权向量; 或者,在所述用户设备从所述LTE网络重新接入到所述3G网络之后,所述MME向所述SGSN发送第二前转重定位请求消息,所述第二前转重定位请求消息不包含所述未使用的鉴权向量。
- 24一种核心网设备,其特征在于,包括处理器、存储器、总线和通信接口; 所述存储器用于存储计算机执行指令,所述处理器与所述存储器通过所述总线连接,当所述核心网设备运行时,所述处理器执行所述存储器存储的所述计算机执行指令,以使所述核心网设备执行如权利要求1-6中任一项所述的无线通信网络中的鉴权方法。
- 25一种鉴权设备,其特征在于,所述包括处理器、存储器、总线和通信接口; 所述存储器用于存储计算机执行指令,所述处理器与所述存储器通过所述总线连接,当所述鉴权设备运行时,所述处理器执行所述存储器存储的所述计算机执行指令,以使所述鉴权设备执行如权利要求7-9中任一项所述的无线通信网络中的鉴权方法。
- 26一种计算机可读介质,其特征在于,包括计算机执行指令,以供计算机的处理器执行所述计算机执行指令时,所述计算机执行如权利要求1-6中任一项所述的无线通信网络中的鉴权方法。
- 27一种计算机可读介质,其特征在于,包括计算机执行指令,以供计算机的处理器执行所述计算机执行指令时,所述计算机执行如权利要求7-9中任一项所述的无线通信网络中的鉴权方法。
Independent claims27
209 paragraphs in 2 sections, as filed
A wireless communication network authentication method, apparatus and system related
TECHNICAL FIELD
0001The present invention relates to communications technologies, and particularly relates to a wireless communication network authentication method, system and related devices.
Background technique
0002Authentication is part of the mobile network security management for mobile network security, data integrity. In the current mobile communication network, only a valid user equipment (User Equipment, UE) are entitled to services, and to verify whether the UE effectively, through an authentication process to complete. UE initiating a registration request to the network, service request or a handover request, and this will trigger an authentication process. In the second generation (Second Generation, 2G) network system, a one-way authentication process, the network needs to verify the validity of the UE; and in the third generation (Third Generation, 3G) network or a long term evolution (Long Term Evolution, LTE) network in addition to the need to verify the legitimacy of the network outside the UE, UE also needs to verify the legality of the network, namely, network authentication.
0003Note that, an authentication process is divided domain, i.e. packet-switched (Packet Switched, PS) and circuit switched domain (Circuit Switched, CS) domain authentication process, respectively, PS domain authentication by the mobility management entity ( Mobility Management Entity, MME) or a General packet radio system (General packet radio service, GPRS) support node (Serving GPRSSupport node, SGSN) to initiate, CS domain authentication by a mobile switching center (mobile switching Center, MSC) initiates, UE needs respectively PS and CS domains for network authentication. In 3G authentication procedure for example, MSC / SGSN from the home location register (home location register, HLR) or authentication center (authentication center, AUC) after obtaining authentication vector transmitted authentication vector carrying the authentication request to the UE news. UE according to an authentication request message, first determine the legality of the network, if the network legally, and then verify that synchronizes itself with the network, if the synchronization, then the UE to the network authentication is successful, UE reply response message to the network, MSC / SGSN then according to UE the response message sent to verify the legitimacy of the UE; if that is synchronized synchronization fails, the UE will to MSC / SGSN replies carrying value of the reason authentication failure message, MSC / SGSN to the UE will send an authentication request message again.
0004In the prior art, MSC / SGSN / MME to obtain the authentication vector HLR / AUC, in general We will obtain a plurality of authentication vector to save network expenses to reduce the burden HLR / AUC's. Moreover, since most of the UE Universal Mobile Telecommunications System Subscriber Identity Module (Universal Mobile Telecommunications System Subscriber Identity Module, USIM) does not support the sub-domain synchronous detection, thereby UE synchronization detection PS domain and CS domain network and does not completely separate. Once before the CS domain authentication insert a PS domain authentication, and the authentication process initiated by the CS domain of the MSC in the preservation of the authentication vector is not used, it may cause network authentication UE the CS domain failed; or before PS domain authentication insert a CS domain authentication, and the authentication process initiated by the PS domain of MME / SGSN has stored the authentication vector is not used, it may cause network authentication UE the CS domain failed.
0005In addition, if the MSC / SGSN / MME receives two consecutive authentication failure message sent by the UE, the authentication process is terminated to the UE sends an authentication reject message. UE event of an authentication reject message will not function properly until the restart initiates a service, giving users a serious impact.
0006<u>SUMMARY</u>
0007For the above-mentioned problems of the prior art, embodiments of the present invention, there is provided a wireless communication network authentication method, system and related devices, can solve the prior art problems authentication fails.
0008A first aspect, the present invention provides a method of authentication in a wireless communication network, the method comprising:
0009User equipment has stored unused authentication vector core network equipment to the authentication device transmits the first authentication data request message, the first authentication data request message for requesting the user authentication apparatus to the apparatus generated authentication vector;
0010The core network device receives a first authentication request to the authentication device returns the data message based on the first authentication data response message, the first authentication response message carrying the first authentication data vector;
0011The core network apparatus transmits to the user equipment a first authentication request message, the first authentication request message contains the authentication vector in the first random number and the authentication token; wherein the user equipment is stored unused authentication vector indicates that there is an unused authentication vector associated with the user equipment or the unused authentication vector is generated by the user device.
0012With the first aspect, in a first possible implementation, the user equipment has stored previously unused authentication vector request data core network apparatus transmits a first message to the authentication device authentication, the The method further comprising: the first user device to access the network devices located in the core network after the core network apparatus determines that the user device is an access from the second network to the first network user equipment; among them, the network standard network standard, the first network and the second network is different.
0013Combining a first possible implementation of the first aspect, in a second possible implementation, the first network is a 3G network, the second network is an LTE network, 2G network, 5G 4.5G network or network ; Alternatively, the first network is an LTE network, the second network is a network 5G or 4.5G networks.
0014With the first aspect, or the first or second possible implementation of the first aspect, in a third possible implementation, the user equipment is not used for the preservation of the authentication vector to the core network equipment before transmitting a first authentication device authentication data request message, the method further comprising:
0015The core network apparatus transmits to the second device authentication data request message authentication, the second authentication data request message for requesting the user authentication apparatus to the authentication vector generating device; the core receiving said network authentication device requests the second device authentication data response message returned by the authentication message based on said second data, said second authentication data response message carrying the authentication vector and a second discriminator of the unused weight vector; the core network apparatus transmits an authentication request message to the second user device, said second authentication request to the authentication vector including said second random number and the authentication token.
0016A second aspect, the present invention provides a method of authentication in a wireless communication network, the method comprising:
0017Receiving a user authentication device to a first device authentication data stored unused authentication vector core network device sends a request message, the first authentication data request message for requesting the user authentication apparatus to the authentication vector generating apparatus; said authentication apparatus according to the first authentication data request message, generating a first authentication data response message, the first response message comprising the authentication data to the user authentication device authentication device generates a first vector; the authentication device returns the first authentication data response message to the core network equipment.
0018With the second aspect, in a first possible implementation, the authentication device prior to receiving a first user authentication device holds an unused authentication vector core network device sends a data request message, the the method further comprising:
0019The authentication device receives the second authentication data with the core network device sends a request message, the second authentication data request message for requesting the user authentication apparatus to the authentication vector generating device; the authentication request message according to the second device authentication data, the authentication data is generated in response to the second message, the Said message comprising the response authentication data to the authentication device and the second user authentication vector generation device of unused authentication vector; the second authentication device returns the device to the core network authentication data response message.
0020Third aspect, embodiments of the present invention there is provided a core network equipment, the core network equipment comprising:
0021A storage unit for a user equipment to save the unused authentication vector;
0022When acquiring unit in the storage unit to the user device authentication vector preserved the unused, to the authentication device transmits the first authentication data request message, the first authentication data request message for requesting the user authentication apparatus to the authentication vector generation device, the authentication device receiving a first authentication data request message returns a response message based on the authentication data, the first discriminator a first right data response message contains the authentication vector;
0023Transmitting means for transmitting to the user equipment a first authentication request message, the first authentication request message contains the authentication vector in the first random number and the authentication token.
0024Combined with a third aspect, in a first possible implementation, the core network device further comprises:
0025Determination means for, after said first network user device to access the core network apparatus is located, the user equipment is determined from the second network access network to the first user equipment; wherein, the said first network and network standard network standard of the second network is different; it is the obtaining unit for the determination unit determines that the user device is an access from the second network to the first network after the user equipment to the authentication apparatus transmits the first authentication data request message.
0026Combining the first and third aspects of one possible implementation of the third aspect, in a second possible implementation, the first network is a 3G network, the second network is an LTE network, 2G network, 5G network or 4.5G network; Alternatively, the first network is an LTE network, the second network is a network 5G or 4.5G networks.
0027Combining the first and third or second aspect of the possible implementation of the third aspect, in the third possible implementation, the obtaining unit is further used for sending a first authentication device authentication data request before the message to a second authentication device sends the authentication data request message, the second authentication data request message for requesting the user authentication apparatus to the authentication vector generation device, receiving said authentication according to the second apparatus requesting the authentication data of the second data message authentication response message returned, the second authentication data response message carrying the authentication vector and a second of said unused authentication vector; the transmitting means prior to the acquisition unit is further configured to send a first device authentication data to the authentication request message to the user The second device sends an authentication request message, the second authentication request message containing the authentication vector in the second random number and the authentication token.
0028A fourth aspect, the present invention provides a further embodiment of the authentication device, the authentication device comprises a receiving means for receiving a first authentication data for the user equipment has stored unused authentication vector is transmitted by the core network device request message, the first authentication data request message for requesting the user authentication apparatus to the authentication vector generating device; processing unit, according to the first message for requesting authentication data, generating a first discriminator right data response message, the first response message comprising authentication data of the first user authentication vector generating device; transmitting means for returning said first authentication data response message to the core network device.
0029Combined with a fourth aspect, in a first possible implementation, the receiving unit is further configured prior to receiving the first authentication data request message, the core network apparatus transmits the received second authentication data request message ; the processing unit is further configured to request authentication message based on said second data, said second authentication data request message for requesting the user authentication apparatus to the authentication vector generation device, generating a second discriminator right data response message, said response message containing authentication data for said second user device generates the authentication vector and the unused authentication vector; the sending unit is further configured to return the device to the core network said second authentication data response message.
0030Fifth aspect, the present invention provides a further embodiment of the authentication system including a core network apparatus of the third aspect or the third aspect of any of the possible implementation of the fourth aspect or the fourth aspect and any possible network authentication device implementations described.
0031A sixth aspect, embodiments of the present invention further provides a method of authentication in a wireless communication network, the method comprising: after a user network access device from a 3G network to the LTE Long Term Evolution, LTE the MME mobility management entity of the network Get the 3G network of General packet radio system GPRS support node SGSN to the service user equipment stored unused authentication vector;
0032The MME remove and discard the unused authentication vector, said authentication vector so that after the user equipment re-entry from the LTE network to the 3G network, the MME can not be transmitted in the unused to the SGSN.
0033Conjunction with the sixth aspect, in a first possible implementation, the mobility management entity MME of the LTE network to obtain the 3G network GPRS general packet radio system support node SGSN to the service user apparatus stored discriminator unused weight vector comprising:
0034Moving said context management entity MME LTE network to the 3G SGSN sends a request network message, the first message SGSN context response returned by the receiver, the first context response message comprising the authentication vector of the unused ;or,
0035Mobility management entity MME of the LTE network first receiving the 3G SGSN sends a first network forwarding relocation request message, the first message forwards the Relocation Request comprising the unused authentication vector.
0036After combining the sixth aspect, or a first possible implementation of the sixth aspect, in a second possible implementation, the MME remove and discard the unused authentication vector, the method further comprising :
0037After the re-entry from the user equipment to the network 3G LTE network, the MME receives the second SGSN context request message transmitting, to the second SGSN Context Response return message, the second context response message does not include the unused authentication vector;
0038Alternatively, after the user equipment re-entry from the LTE network to the 3G network, the MME sends a second request message forwarded to the relocation the SGSN, forwarding the second request message is not relocated the authentication vector contains unused.
0039A seventh aspect, embodiments of the present invention, there is provided a mobility management entity the MME, comprising:
0040Acquisition means for, after UE from the LTE network to access the 3G network, obtaining the 3G network SGSN for the UE stored unused authentication vector. In particular, the acquisition unit may transmit to the 3G SGSN context request message to the network, the first SGSN Context Response message returned by the receiver, the first response message comprising the context of unused authentication vector; Alternatively, the acquisition unit may receive a first network of the 3G SGSN sends a first forwarding relocation request message, the first message forwards the relocation request comprising the unused authentication vector;
0041After authentication vector processing unit to remove and discard the unused authentication vector so that the UE re-entry from the LTE network to the 3G network, the MME can not be the unused sent to the SGSN.
0042Combined with a seventh aspect, in a first possible implementation, the acquisition unit is further configured to re-access after the user equipment from the 3G network to the LTE network, the SGSN sends the received second context request message, to the second SGSN context response return message, in response to said second context of the message does not include unused authentication vector; or from the user equipment in the LTE After the network re-entry to the 3G network, sending a second forwarding the relocation request message to the SGSN, forwarding said second relocation request message does not contain the unused authentication vector.
0043Eighth aspect, embodiments of the present invention there is provided a core network equipment, including processors, memory, and communication bus interfaces;
0044The memory for storing a computer to execute instructions, the processor and the memory via the bus, when the core network equipment is running, the processor executes the memory stores the computer to execute instructions to so that the core network apparatus of the first aspect of the first aspect or any one of the possible implementation of a wireless communication network authentication method is executed.
0045A ninth aspect, embodiments of the present invention, there is provided a device authentication, characterized in that, including the processor, memory, and communications interface bus;
0046A memory for storing a computer to execute the instructions, the processor and the memory via the bus connection, when the authentication device is running, the computer processor the instruction to the execution memory to store for making the authentication device to perform a wireless communication network of the second aspect or the second aspect of any of the possible implementation of the authentication method.
0047Embodiment of the invention provides a radio communication network authentication method, the core network device before sending an authentication request message to the UE, the core network apparatus even if the UE is in the preservation of an unused authentication vector, also obtaining a first vector to the authentication device authentication, and the authentication vector using the first random number and the authentication token to the UE sends an authentication request message, to initiate the UE and the core network network authentication process between devices. The above-described method ensures that each time the CS domain / PS domain network authentication, are going to get a first authentication device authentication vector for authentication instead of using the core network equipment to save authentication vectors are unused authentication, even before the CS domain network authentication inserted PS domain network authentication or PS domain network before the insertion of the CS domain network authentication authentication, verification can ensure synchronization successfully solved by the prior art appears authentication failed synchronization problems caused by failure.
BRIEF DESCRIPTION
0048In order to more clearly illustrate examples of technical implementation of the program of the present invention, it will implement the following figures for the cases described in the need to use a simple introduction. Apparently, the following description of the drawings are only some embodiments of the present invention, for this skill in the art, without creative efforts of the premise, you can also obtain other drawings based on these drawings.
0049Figure 1 is a wireless communication network provided in the case of authentication method of the present invention;
0050Figure 2 is a wireless communication network, another embodiment of the present invention to provide a method of authentication;
0051Figure 3 is a wireless communication network according to another embodiment of the invention provides a method of authentication;
0052Figure 4 is a wireless communication network according to another embodiment of the invention provides a method of authentication;
0053Figure 5 is yet another embodiment a wireless communication network authentication method provided in the embodiment of the present invention;
00546 is a schematic embodiment of the present invention is one of the core network device provided for;
00557 is a schematic embodiment of the present invention, one kind of the authentication device provided;
00568 is a schematic implement an authentication system provided by the present invention;
0057Figure 9 is a structural embodiment of a wireless communications network in the case of providing the authentication device of the present invention is composed of a schematic diagram.
detailed description
0058Method provided a wireless communication network authentication embodiment of the present invention, apparatus and associated system can be solved by the prior art authentication synchronization failure caused failure.
0059A clearer description of the embodiments of the present invention, the first embodiment of the present invention is related to the knowledge to do some introduction.
0060Under normal circumstances, the network authentication process to verify that the UE needs to be synchronized with the network itself, if not synchronized, the authentication process fails. To detect itself is synchronized with the network, UE needs to obtain the serial number (sequence number, SQN) authentication vector from the core network equipment (MME / MSC / SGSN) sent, and detecting the serial number meets a series of testing conditions, wherein including authentication sequence (sequence, SEQ) contains the serial number meets SEQ<sub>MS</sub>-SEQ <L, where, L is typically conducted by the operator, L may be 32, SEQ<sub>MS</sub>UE is currently stored by the maximum sequence number of the sequence. If the SQN meet all the test conditions, the synchronization verification is successful, and when the SEQ> SEQ<sub>MS</sub>When the UE stored in SEQ<sub>MS</sub>It will be updated as SEQ. SQN obtained from the above-mentioned authentication vector is actually generated by the authentication device (HLR / AUC) and are included in the authentication vector.
0061Authentication device generated SQN usually represented in binary by SEQ and IND two parts. In the time-based mechanism for generating SQN in the authentication device in its own database for each user device stores a difference (difference, DIF) values, different value for each user equipment DIF, DIF value of the user equipment, said equipment for the user-generated SEQ value of the global counter (Golbal counter) GLC's The difference value, and therefore for the same UE generated SEQ only the value of the global counter GLC related. Under normal circumstances, the authentication device receives an authentication data request message, if the message refers to authentication data request does not carry synchronization failure indication from the query DIF value of the UE's own database and obtain the value of the current global counter GLC and then generates SEQ, this time SEQ = GLC + DIF, namely authentication device is the same difference between the two SEQ UE generated only with the value of the global counter GLC, whereas the value of the global counter GLC is typically taken from a time point (time stamp), for example, the value of the global counter GLC for every 0.1 seconds plus 1, then for the same five seconds UE generated SEQ difference is 1 * (5s / 0.1s) = 50.
0062The inventors found, the prior art since the UE synchronous detection of PS and CS domains is not completely separated, if the CS domain authentication before inserting a PS domain authentication, and authentication procedure initiated by the MSC in the CS domain in preservation of unused authentication vector, can cause network authentication UE the CS domain failed; or before the PS domain authentication insert a CS domain authentication, and the authentication process initiated by the PS domain of MME / SGSN the preservation of the authentication vector is not used, it may cause network authentication UE the PS domain failed. For example, for the UE between the CS domain network authentication twice to insert a PS domain network authentication scenario, if the core network equipment before initiating the first CS domain authentication, MSC possible to obtain a plurality of authentication device authentication vector AV<sub>C11</sub>And AV<sub>C12</sub>, After performing the first CS domain authentication, MSC still has stored unused authentication vector AV<sub>C12</sub>; Then, due to the UE radio access type changes and other reasons, may need to be initiated by the UE PS domain authentication and second authentication CS domain and PS domain authentication possible before the second CS domain authentication, if PS domain authentication is successful, the UE stored in the sequence SEQ largest serial number<sub>MS</sub>It may be updated from the PS domain authentication authentication vector AV<sub>P</sub>SEQ obtained<sub>P</sub>; The second time during the CS domain authentication, MSC will use its stored unused authentication vector AV<sub>C12</sub>Initiates an authentication process, then the UE obtained from SEQ equal to AV<sub>C12</sub>SEQ obtained<sub>C12</sub>, The SEQ<sub>MS</sub>-SEQ = SEQ<sub>P</sub>-SEQ<sub>C12</sub>That SEQ<sub>MS</sub>-SEQ Value and generate AV<sub>P</sub>(SEQ<sub>P</sub>) And AV<sub>C12</sub>(SEQ<sub>C12</sub>) Related to the time difference. However, since during the second domain authentication CS, core network device makes use of unused authentication vector AV saved by itself when the first acquired CS domain network authentication<sub>C12</sub>If the authentication device generates AV<sub>P</sub>And AV<sub>C12</sub>The time difference is large, so SEQ<sub>MS</sub>-SEQ Not less than L, can not meet the test conditions, causing synchronization to fail, causing authentication to fail.
0063In addition, in the prior art, when authentication fails due to the synchronization failure cause, the core network equipment usually carry the cause value received authentication failure message sent by the UE, the reason is synchronization fails, the core network equipment by carrying synchronization failure indication data authentication request message to the authentication device to trigger the same weight Step process, in which the portable data synchronization failure indication message also contains the authentication request failed synchronization sequence SEQ UE stored largest sequence number<sub>MS1</sub>Information. Unlike synchronization failure indication received do not carry data authentication authentication device according to DIF value identification UE UE acquired to generate a sequence of SEQ request message flow in the re-synchronization process authentication device you first need to get SEQ<sub>MS1</sub>The DIF value is reset to SEQ UE<sub>MS1</sub>-GLC1, And then reset the value generated based on the value of DIF and the current global counter GLC resynchronization sequence SEQ<sub>sy</sub>In this case resynchronization sequence SEQ<sub>sy</sub>= SEQ<sub>MS1</sub>-GLC1 + GLC2, which is connected to SEQ GLC1<sub>MS1</sub>Time, GLC2 resynchronization sequence to generate a time; and then re-synchronization sequence according to a preset algorithm SEQ<sub>sy</sub>Send information contained in the authentication vectors to the core network equipment for re-authentication. However, since GLC1 and GLC2 usually small difference, resulting in resynchronization sequence SEQ<sub>sy</sub>Almost equal to the SEQ<sub>MS1</sub>. At this time, if the core network equipment comprising the sequence of SEQ resynchronization<sub>sy</sub>Before the authentication vector again initiate the CS domain authentication, insert a PS domain authentication, the UE when the CS domain network authentication again, the largest number of UE synchronization parameters are stored in SEQ<sub>MS2</sub>It may have been updated from the PS domain authentication as the authentication vector AV<sub>P2</sub>SEQ obtained<sub>P2</sub>At a time when the SEQ is equal resynchronization sequence SEQ<sub>sy</sub>, The SEQ<sub>MS2</sub>-SEQ = SEQ<sub>P2</sub>-SEQ<sub>sy</sub>≈SEQ<sub>P2</sub>-SEQ<sub>MS1</sub>, And often SEQ<sub>P2</sub>And SEQ<sub>MS1</sub>May vary greatly, and SEQ<sub>P2</sub>Greater than SEQ<sub>MS1</sub>So SEQ<sub>MS2</sub>-SEQ<sub>sy</sub><L can not be established, causing authentication to fail again. Similarly, prior to use of the device at a core network comprising resynchronization authentication vector sequence PS domain authentication initiated again, insert a CS domain authentication method according to the prior art, it may lead to re-authentication fails, such Kam the right to suspend the process, resulting in not properly UE initiates a service until it is restarted.
0064To solve the above problems, embodiments of the present invention proposes a wireless communication network authentication method, enables the core network apparatus (MSC / SGSN / MME) before initiating an authentication request to the UE, from the authentication device picks authentication vector (authorization vector, AV), even if the core network equipment to save unused authentication vector, and take advantage of new authentication vectors obtained for authentication to ensure that every time the CS domain / PS domain network authentication , SEQ authentication device authentication vectors are included in the new generation, even before the CS domain network authentication insert the PS domain network authentication or before the PS domain network authentication inserted CS domain network authentication, are able to ensure synchronization successfully solve the authentication synchronization failure caused by the prior art appear to fail, to avoid authentication failure may cause the UE off-grid.
0065Also proposed a wireless communication network authentication method embodiment of the present invention enables the authentication device when the core network equipment failure since the synchronization trigger resynchronization process, instead of using the sequence SEQ UE stored largest sequence number<sub>MS</sub>Generating resynchronization sequence SEQ<sub>sy</sub>But do not carry as receive synchronization failure means Authentication data request message, as shown, to obtain the UE DIF values directly from the identity of the UE (ie generate resynchronization SEQ time) according to DIF values UE and the value of the current global counter GLC generating resynchronization sequence SEQ<sub>sy</sub>So that resynchronization sequence SEQ<sub>sy</sub>Not equal (or approximately equal) SEQ<sub>MS1</sub>To ensure that the core network equipment in use including the re-synchronization sequence SEQ<sub>sy</sub>Authentication vector for authentication success when authentication, thus avoiding UE again after authentication fails due to not properly initiate service until it is restarted problems.
0066The present invention will now be combined with the embodiment of the drawings, for example in the technical implementation of the program of the present invention will be clear and complete description. It should be noted that the various embodiments of the present invention, the core network device may be a MSC, SGSN or MME, the authentication device may be a HLR, home subscriber server (Home Subscriber Server, HSS), AUC or home environment (Home Environment, HE ).
00671, the embodiment of the present invention provides a method of authentication in a wireless communication network, the method comprising:
0068S101: the UE has stored unused authentication vector to the core network apparatus transmits a first authentication device authentication data request message (authentication data request), the first authentication data request message for requesting the authentication device for the UE authentication vector generation.
0069When the UE has a radio access type (Radio Access Type, RAT) change, access from one network to another network, core network equipment UE will target network initiates an authentication process, the authentication process may be a PS domain network authentication process, the CS domain may be a network authentication process. For example, since the circuit switched down (Circuit Switched Fallback, CSFB) or network re-election and other reasons to switch to 2G or 3G network UE in the LTE network, the 2G or 3G core network equipment network may send to the UE authentication request message to initiate a CS domain or PS domain network authentication procedure.
0070Before initiating the CS domain or PS domain network authentication process, the core network apparatus can transmit the first authentication data request message to the authentication device, a request to obtain the authentication vector. In the embodiment of the invention, the core network device before sending the first authentication request message to the UE, that UE regardless of whether their own preservation unused authentication vector, can request authentication device generates authentication for the UE vector, and using the generated authentication vector initiate CS domain or PS domain network authentication, to avoid the prior art core network equipment using its own stored unused authentication vector initiate network authentication, it may cause synchronization failures the problem caused by the failure of the authentication, as much as possible to protect the successful network authentication.
0071Accordingly, the authentication device may have received for the UE stored unused authentication vector by Said core network apparatus transmits data of a first authentication request message, the request message according to the first authentication data, generating first authentication data response message, the first response message comprising authentication data to the authentication device the UE first authentication vector generation, authentication data returned in response to the first message to the core network device.
0072It notes that, various embodiments of the present invention, the UE has stored unused authentication vector, i.e. the unused authentication vector is generated for the UE, or the unused authentication vector with the UE related. S102: The core network device receives a first authentication request to the authentication device returns the data message is a response message (authentication data response) based on the first authentication data, the first response message carrying the first authentication data authentication vector.
0073S103: The core network apparatus transmits a first authentication request message (authentication request) to the UE, the first authentication request message contains the authentication vector in the first random number and the authentication token.
0074The first authentication vector may contain a random number (random number, RAND), an authentication token (authentication token, AUTN), the expected response (expected response, XRES), integrity key (integrity key, IK) and encryption key (cipher key, CK). After acquiring the authentication vector to the first, the core network apparatus can be used in the authentication vector of the first random number and the authentication token sending a first authentication request message, to the UE and the start said authentication process between the core network equipment. The UE may be determined based on the random number and the authentication token SQN, ie determine SEQ (SQN contains SEQ), to take advantage of SQN (SEQ) can be synchronized between the detection of the UE and the network or other authentication process.
0075Furthermore, the first authentication vector of the core network equipment to obtain authentication device may be one or more, when the first authentication vector into a plurality of said plurality of first authentication vectors constitute the KAM weight vector group (authorization vectors), then the first authentication request message may comprise a plurality of first authentication vector in a vector authentication token authentication and the random number.
0076Alternatively, since the core network equipment if before each initiates an authentication process went authentication device acquires authentication vector, may bring a big burden to the authentication device. In practice, authentication failures since the synchronization failure caused basically it occurs after the UE handover from the LTE network to the 3G network to perform authentication process, or occurs after the UE handover from 2G network to the 3G network the authentication process, the scene can be used for the above method of the invention only, then step 101 may specifically be: After the 3G UE access network, the core network apparatus transmits the first 3G network authentication data request message to the authentication device, this time, the core network apparatus has stored unused authentication vector for the UE . Accordingly, steps 102 and 103 in the core network equipment is intended to mean the 3G core network equipment network.
0077Alternatively, the network may be performed only after the authentication of UE handover from a first network to a second network for a scene, prior to the step S101, the method may further comprise the step S100:
0078S100: UE accessing the first network devices are located in the core network after the core network access device determines whether the UE is a UE from a second network to the first network.
0079Accordingly, steps S101 to step S103 means that the core network devices are located in the core network apparatus of the first network. In the embodiment of the invention, the network standard network standard, the first network with the second network different from the first network may be a 3G network, the second network may be an LTE network or 2G network; or the first network may be an LTE network, the second network may be a 5G / 4.5G networks.
0080For example, when the first network is a 3G network, the second network is an LTE network, SlOO as follows: After the 3G UE access network, the core network apparatus of the 3G network determines that the UE is received from the LTE network 3G network into the UE, i.e. the UE for the UE determines from the LTE network. This method ensures that only when the UE from the LTE network to the 3G network access authentication procedure caused, even if the core network device has stored unused authentication vector, but also to the core network apparatus to acquire the first authentication device authentication vector, authentication vector using the first network to initiate an authentication process.
0081The core network equipment in the UE when determining access from the LTE network to the 3G network for the UE, can also have a variety of ways. The core network device can (Stratum, CS domain NAS CS domain Non-Access) or the UE paging message at the scene called a response message is determined according to the CS domain of the non-access layer is sent by the UE whether the UE CSFB to users, if it is determined CSFB user, i.e. the UE is determined from the LTE access network to the 3G network the UE, the CS domain NAS message may be a connection management service request message or a location update request message, etc., this when the core network equipment for MSC; or,
0082The PS core network apparatus according to a non-access layer (PS domain Non-Access Stratum, PS domain NAS) message sent by the UE, the UE determines whether the UE from the LTE network to the 3G access network, for example, according to the route update request message (routing Area update, RAU), the UE determines from the LTE access network is the 3G network to the UE, in which case the core Network equipment for the SGSN; or,
0083The base station can also be enhanced, so that the RRC (Radio Resource Control, RRC) of the UE by analyzing the base station may transmit a connection request message includes CSFB indication information, the UE determines whether CSFB user, in determining the CSFB said UE when a user, to the core network equipment sends a notification message, the core network equipment according to the notification message, determining that the UE from the access network to the LTE UE of the 3G network, this time the core network equipment for MSC or SGSN; or
0084For a UE, the core network apparatus can determine whether the user's own interfaces and SGS MME association, the UE determines from the LTE access network is the 3G network to the UE, if the interface associated SGS exists, is determined UE is the UE access to the 3G network from LTE network, then the core network equipment for MSC.
0085In the above-described embodiment, the authentication vector stored in the core network apparatus may be unused time prior to the core network initiates an authentication process on the obtained device, shown in Figure 2, at step S101 before the method may further comprise:
0086S201: The core network apparatus transmits the second device authentication data to the authentication request message, the second request message for requesting authentication data of said generated authentication vector is an authentication device of the UE.
0087Accordingly, the authentication device may receive the second core network apparatus transmits an authentication data request message, the request message according to the second authentication data, the authentication data is generated in response to the second message, said authentication data a second response message contains the authentication vector and the unused authentication vector, and to return to the core network apparatus of the second authentication data response message.
0088S202: The core network apparatus receives the apparatus authentication request message according to said second authentication data returned second authentication data response message, the second message comprising the response authentication data to the authentication device said UE and said second authentication vector generated by the authentication vector unused.
0089S203: The core network apparatus transmits an authentication request message to the second UE, the second authentication request message contains the authentication vector in the second random number and the authentication token.
0090In the present embodiment of the invention, the core network device before sending a second authentication request message, to the UE acquired authentication vector, and generating a second unused authentication vector from the authentication device, in the the UE transmits a second authentication request message, using the second authentication vector, then the core network device also stores the unused authentication vector. Follow-up of the core network equipment to send the first authentication When the request message, instead of using the unused authentication vector, but the use of the authentication device to re-acquire the UE is first generated authentication vector, the prior art to avoid the use of the core network device stored in itself is not used when initiating authentication vector network authentication, synchronization failure may cause problems due to the failure of the authentication, as much as possible to protect the successful network authentication.
0091As shown in Figure 3, the present invention provides an embodiment of a network authentication method, it may be applied to the CS domain authentication inserted between the two first PS domain authentication scenario. The scene may be specifically located in the UE LTE network launch joint attachment process, registered in the MME on MSC LTE networks and 3G networks. In the joint registration process / post, the MSC will the UE initiates an authentication process that initiated the first CS domain authentication process. After completion of the joint attachment process, the UE is camping on the LTE network. Follow the UE may be other reasons because the CSFB from the 3G network to the LTE access network, and may provide the original MSC of the CS domain registration service, the SGSN of the 3G network and the MSC may be respectively the said UE initiates a PS domain authentication process and the second CS domain authentication process, the above method can ensure successful authentication the authentication procedure, the method may include:
0092S301: the UE is located in the LTE network launch joint attachment process, registered in the MSC of the network MME LTE and 3G networks.
0093In the attachment process, the correspondence between the MME and the MSC of the UE associated SGs interface. Specifically, the UE sends an attach request message to the MME, the attachment request message contains the type of cell adhesion, the type of cell attachment to inform the MME for the UE requests the United Evolved Packet System (evolved packet system, EPS) attachment or international mobile subscriber identity (international mobile Subscriber Identity, IMSI) attachment. Attaching the MME after receiving the request message, execution EPS attachment process, then the MME selects a MSC based on the configuration information and / or budget algorithm, to the MSC sends a location update request message so that the UE registers to the MSC on. Upon completion of the UE's IMSI attached after the MSC, the MME SGs mouth and into the association between the MSC status, that is associated corresponding to the UE SGs interface between the two.
0094S302: In the course of the joint is attached, the MSC sends a second device authentication data to the authentication request message, the second authentication data request message contains UE's identity, the authentication data request message for the second said authentication request to the authentication vector generation device UE.
0095Combined attachment process, the MME or MSC may trigger initiates an authentication process. The MSC initiates an authentication process before, can acquire the authentication vector request message through the second authentication data.
0096Wherein the UE identity may be an IMSI. Typically, when the authentication device to the authentication data transmission request message may specify the number of the acquired authentication vector request. To conserve network resources expenditure, each may obtain a plurality of authentication vector, that is reserved for subsequent authentication required authentication vector. For example, the second authentication data request message may contain information indicating said indication information is used to indicate the number of requests for the acquisition of the authentication vector 3.
0097S303: The authentication device returns the second authentication data response message to the MSC, the second response message containing authentication data for the UE-generated authentication vector AV21, AV22 and AV23.
0098The authentication vector returned by the authentication device, each authentication vector may comprise a random number RAND, the authentication token of AUTN, the expected response The XRES, the integrity key IK and an encryption key CK. When generating an authentication vector, the authentication device may SQN and the use of a random number RAND obtained anonymity key (anonymity key, AK) contained in the authentication token AUTN, where, SQN may comprise SEQ and IND two parts (such as SQN = SEQ || IND). For example SQN authentication vector AV21, AV22 and AV23 contains contained in SEQ can be respectively: SEQ21 = 756EA3, SEQ22 = 756EA4, SEQ23 = 756EA5.
0099If you need to get follow-UE SQN from the authentication token AUTN can be obtained from the first random number RAND in anonymity key AK, use an anonymity key AK and the correlation algorithm to obtain synchronous detection SQN from the authentication token AUTN, but also That verification SQN is in the correct range.
0100S304: The MSC sends an authentication request message to the second UE, the second authentication request message contains the authentication vector AV21 RAND21 and AUTN21.
0101S305: the UE based on the second authentication request message to the 3G network CS domain authentication, after successful authentication, the MSC returns to the second authentication response message (authentication response).
0102The UE may first use RAND21 and AUTN21 verify the legality of the network, if the network legitimate, reuse AK21 and correlation algorithm obtained from RAND21, get the synchronization sequence number SQN21 from AUTN21, where SQN21 contain parameters SEQ21. UE can be compared with the maximum number of own SEQ21 stored synchronization parameter SEQ<sub>MS</sub>If satisfied SEQ<sub>MS</sub>-SEQ21 <L (L = 32), and the other test conditions are met (eg: SEQ21-SEQ<sub>MS</sub>≤ △ and SEQ21> SEQ<sub>MS</sub>(I), where △ can be set to a very large number, such as 2<sup>28</sup>, I IND with the same value), the UE determines SQN is in the correct range, this synchronization experience Certificate successfully.
0103After the UE and the legality of the network synchronization verification is successful, that is, after successful authentication, the UE to the MSC returns the second authentication response message, and if SEQ21> SEQ<sub>MS</sub>The UE adds its own storage SEQ<sub>MS</sub>Update SEQ21, namely SEQ<sub>MS</sub>= 756EA3.
0104S306: the UE access from the LTE network to the 3G network.
0105For some reason, the UE may access the network from the 3G LTE network, and the MSC may provide the original register CS domain services. For example, it may be due to the LTE network does not support voice traffic when the UE needs to make voice calls via CSFB down to the 3G network originating CS voice service; another example, the LTE network may be due to an abnormality occurs, the UE via switch or network reselection way and access the 3G network.
0106S307: The UE sends a RAU request message to the 3G SGSN network.
0107Due to changes in the type of radio access RATs, the UE may 3G network to the SGSN a RAU request message, for requesting to register the PS domain of the 3G network, PS domain to enable service.
0108S308: the SGSN sending a third device to authenticate the authentication data request message, the third authentication data request message comprises UE identity, the third authentication data request message for requesting the said authentication device authentication vector generated for the UE.
0109After receiving the RAU request message sent by the UE, the SGSN initiates an authentication process may be required, i.e. PS domain authentication thus eliminated before the authentication, possibly through the third authentication data request message, acquire the authentication vector.
0110S309: the third authentication device returns an authentication data response message to the SGSN, the third message comprising the response authentication data to the authentication vector generated UE AV31, AV32 and AV33.
0111For example, suppose that the third authentication data request message after transmitting the second authentication data 5s request message, the authentication device generating the AV31 / AV32 / AV33 and generate AV21 / AV22 / AV23 time difference as 5s, then the authentication vector AV31, SQN AV32 and AV33 included in SEQ be included are: SEQ31 = 756ED5, SEQ32 = 756ED6, SEQ33 = 756ED7.
0112S310: The SGSN sends an authentication request message to the third UE, the third authentication request message contains the authentication vector AV31 RAND31 and AUTN32.
0113S311: the UE according to the third authentication request message, to the 3G network PS domain authentication, After successful authentication, to the third SGSN returns an authentication response message.
0114After the UE to verify the legality of the network, you can use RAND31 and AUTN31 get SQN31 (which contains SEQ31 = 756ED4), and then use SQN31 synchronize verification that verify SQN31 is within the correct range. Suppose the UE to the network and synchronization legality verification is successful, the authentication is successful, the UE adds its own storage SEQ<sub>MS</sub>From SEQ21 updated SEQ31, namely SEQ<sub>MS</sub>= 756ED5.
0115Alternatively, in step S306- step S311, the authentication vector and obtaining the SGSN initiates an authentication process for the PS domain process may be performed by the MME, then in this case, the UE is still located in LTE network, the MME obtain authentication vectors and initiates an authentication process for the PS domain, after the end of the authentication process, the UE may switch from the LTE network to the 3G network, performed by the MSC 3G network the following steps to obtain the authentication vector and initiate CS domain authentication process.
0116S312: The UE sends a service access request message or a request message to the MSC, in order to obtain the 3G network CS domain services.
0117The UE from the LTE network migration to 3G network, you can send an access request message to the MSC or service request message, such as a location update request message and the connection management service request message, etc., in order to obtain the 3G network CS domain services .
0118S313: The MSC service request message or according to the access request message, determines whether the UE from the LTE access network to the 3G network UE.
0119S314: the UE is then determined from the access network to the LTE UE 3G network, the MSC sends the first authentication data request message to the authentication device, said first authentication data request message contains the UE identity, the first first authentication data request message for requesting the authentication of the authentication vector generation device UE.
0120The present invention, although the MSC in the preservation of unused authentication vector AV22 and AV23, but the MSC will still go to the authentication device acquires the newly generated authentication vector AV11, in order to ensure successful authentication. Otherwise, the process according to the present technology, the MSC will use AV22 / AV23 sends an authentication request message, if the UE use AV22 / AV23 authenticated, since the UE saved SEQ<sub>MS</sub>= 756ED5 than SEQ22 = 756EA4 / SEQ23 = 756EA5 large, and greater than 32, does not meet the detection rule in SEQ<sub>MS</sub>-SEQ <L, will cause synchronization detection failures caused by authentication fails.
0121S315: the first authentication data with the authentication device returns the response message to the MSC, the first Authentication data response message contains the authentication vector generated by the UE AV11.
0122Suppose after the first authentication data request message is a request message in the third authentication data transmission 0.5s sent, said authentication apparatus generates AV31 / AV32 / AV33 and AV11 of the generated time difference of about 0.5s, SEQ authentication vector information is included AV11 can: SEQ31 = 756EDA.
0123Alternatively, the MSC may also acquire a plurality of the authentication vector to the authentication device, said first authentication data response message may also include a plurality of authentication vectors.
0124S316: The MSC sends a first authentication request message to the UE, the first authentication request message contains the authentication vector AV11 RAND11 and AUTN11.
0125S317: the UE based on the first authentication request message to the 3G network CS domain authentication, after successful authentication, the MSC returns to the first authentication response message.
0126The UE AV11 use of the network AUTN11 RAND11 and legality verification, and use obtained from AUTN in SQN11 synchronous detection. Since the UE saved SEQ<sub>MS</sub>= 756ED5 than SQN31 in SEQ31 = 756EDA small, meet SEQ<sub>MS</sub>-SEQ <0 <L, so that synchronous detection is successful, avoiding the use of existing technology for authentication when the authentication failed due to a problem and avoid the UE off-grid.
0127Since in the prior art, when the UE from a 3G network to access the LTE network, the SGSN might authentication vector 3G network passed the MME LTE network when the UE from the LTE network again after re-access to the 3G network, the MME may well authentication vector will be sent to the SGSN of the 3G network, so that the authentication procedure, the SGSN may send an authentication using the authentication vector request message, rather than to acquire authentication device newly generated authentication vector, resulting in authentication failure.
0128In view of this, the present embodiment provides a wireless communication network, the authentication method, after the UE moves from the 3G network to the LTE access network, the first SGSN itself does not save the 3G network of the UE unused authentication vector transmitted to the MME LTE network, so when the UE from the LTE network re-entry to the 3G network again, the MME can not be saved in the authentication vector transmitted to second SGSN the 3G network, the first SGSN may be the same or different, the method provided by the embodiment of the present invention, can be avoided to save unused authentication vector in the SGSN, SGSN in order to ensure each launch KAM the right to go before the process authentication device acquires authentication vector to solve the problems of the prior art. Specifically, in FIG. 4, the method may comprise:
0129S400: After the UE from a 3G network to access the LTE network, the first 3G network SGSN receives the LTE network MME sends a context request message (context request).
0130The context request message for requesting the UE to obtain information.
0131S401: the preservation of the unused authentication vector transmitting a first first SGSN Context Response message (context response) to the MME, the first context response message does not include the unused authentication vector.
0132The authentication vector may be unused authentication vector 3G (3G AV).
0133Unlike the prior art, in the present invention, even if the first SGSN has stored unused authentication vector, nor will the unused authentication vector is transmitted to the MME, make follow-up when the UE after the network re-entry from the LTE to the 3G network, the authentication vector MME can not be transmitted to the unused 3G SGSN in the network, to avoid unused authentication vector stored in the SGSN, in order to ensure before each SGSN initiates an authentication process to obtain new authentication vectors are to solve the prior art authentication failure.
0134Alternatively, if the UE is due to the implementation of PS domain handover from 3G access network LTE network, step S400-S401 can be replaced:
0135S401 ': After the UE from the access network to the 3G LTE network, the SGSN sends a first forwarding a first relocation request message to the 3G network (forward relocation request) to the MME of the LTE network; wherein the first SGSN sends the first time before the transfer relocation request message, the UE for the preservation of an unused authentication vector, the first forwarding relocation request message does not contain the unused authentication vector.
0136Wherein said first forwarding relocation request message for the UE information, such as the UE identity and context, etc., to inform the MME. The Forward Relocation Request message does not include the 3G authentication vector unused.
0137Optionally, the method may further comprise:
0138S402: After the UE from the LTE network to re-access the 3G network, the 3G network sending a second SGSN Context Request message to the second MME.
0139The first SGSN and the second SGSN may be the same or may be different. Through steps S400-S401 or steps S401 ', so that the authentication vector and not the MME unused.
0140S403: receiving a second of said second SGSN Context Response message returned by the MME, the first Two Context Response message does not include the unused authentication vector.
0141If the UE is due to the implementation of PS domain handover re-access the 3G network from the LTE network, the steps S402-S403 can be replaced:
0142S403 ': re-access after the UE from the LTE network to the 3G network, a second forwarding the relocation of the 3G SGSN receives a second network request message sent by the MME, the second front transfer relocation request message does not contain the unused authentication vector.
0143Forwarding the second request message for the relocation of the UE information, such as the UE identity and context, etc., to inform the second SGSN.
0144S404: The SGSN to a second authentication device sends an authentication data request message.
0145After the UE from the LTE network to the 3G network re-entry, the second SGSN initiates an authentication process may be due to the second SGSN unsaved unused authentication vector, then initiates an authentication before the process, the second SGSN will request to obtain the authentication device authentication vector.
0146S405: the second authentication data SGSN receives the response message returned by the authentication device, the authentication data response message contains the authentication vector.
0147The authentication vector contains a random number and the authentication token, or may also contain a desired response, integrity and encryption keys.
0148S406: the second SGSN sends an authentication request message to the UE, the authentication request message containing the authentication data response message contains the authentication vector of the random number and the authentication token.
0149In the present embodiment of the invention, after the UE from the access network to the 3G LTE network, the SGSN the first 3G network does not itself stored unused authentication vector transmitted to the MME of the LTE network, so that the after the UE from the LTE network to the 3G network re-entry, the MME authentication vector can not be transmitted to the unused 3G network in the second SGSN, the SGSN stored in the second to avoid the unused the authentication vector, whereby the second SGSN before sending an authentication request message to the UE, to obtain new authentication vector generated from the authentication device, in the prior art to solve the problem of failure of the authentication.
0150SGSN embodiment provides a wireless communication network authentication method of the present invention, after the UE moves from the 3G network to the LTE access network, the mobility management entity MME of the LTE access network to the 3G network to save UE unused authentication vector, the MME remove and discard the unused Authentication vector in order to re-access the UE from the LTE network to the 3G network after authentication vector can not be said of the MME unused transmitted to the SGSN. Method provided by the embodiment of the present invention, can be avoided to save unused authentication vector in the SGSN to ensure before each SGSN initiates an authentication process to obtain new authentication vectors are to solve the problems of the prior art. Specifically, in FIG. 5, the method may include:
0151S500: After the UE moves from the 3G network to the LTE access network, the LTE network MME context of the SGSN sends to the 3G network a first request message.
0152S501: The MME receives the first SGSN context response returned by the first message, the first response message comprising the context of the first SGSN for the UE stored unused authentication vector.
0153The unused authentication vector for 3G authentication vector.
0154Alternatively, if the UE is due to the implementation of PS domain handover from 3G access network LTE network, step S500-S501 can be replaced:
0155S501 ': After the UE in the access network from a 3G network to the LTE, MME of the LTE network first receiving the 3G network SGSN forwards the relocation request message sent by a first (forward relocation request), the first when the SGSN sending the prequel relocation request message to the UE preservation unused authentication vector is the first forwarding relocation request message containing the first SGSN stored unused authentication vector. Step S501 'can refer to the specific implementation of step S401'.
0156S502: After the UE from the LTE network to the 3G network re-entry, the MME receives the second SGSN context request message sent by the second.
0157S503: second context in response to the MME returns to the second SGSN message, the message does not contain a second context in response to the unused authentication vector.
0158Since steps S500-S501, so that the MME has stored the authentication vector of the unused, unlike the prior art, there are stored a second Context Response message sent by the MME the unused authentication vector, no the authentication vector contains unused.
0159Unlike the prior art, in the present invention, after the UE from the LTE network to the 3G network re-entry, even if the MME has stored the authentication vector is not used, nor will the unused authentication vector is transmitted to the second SGSN 3G network, avoid saving the unused authentication vector in the second SGSN in order to ensure as shown in the second SGSN initiates an authentication process before each went KAM Get the right equipment authentication vector to solve the prior art authentication failure.
0160If the UE is due to the implementation of PS domain handover re-access the 3G network from the LTE network, the steps S502-S503 can be replaced:
0161S503 ': re-access after the UE from the LTE network to the 3G network, the MME sends a Forward Relocation second request message to the 3G SGSN second network, the second forwarding relocation request message does not contain the unused authentication vector.
0162Since the step S501 ', so that the MME has stored the authentication vector of the unused, unlike the prior art, the preservation of the second Forwarding Relocation of unused authentication vector request message sent by the MME , does not include the unused authentication vector.
0163It should be noted that the MME after receiving the authentication vector of the first SGSN sends unused, you can remove and discard the unused authentication vector, thereby transmitting to the second SGSN transmitting said second relocation request message forwarding or said second context response message does not have the authentication vector of the unused. Alternatively, the MME may not remove the unused authentication vector, but not said authentication vector only unused transmitted to the second SGSN.
0164Optionally, the method may further comprise:
0165S504: The SGSN to a second authentication device sends an authentication data request message.
0166After the UE from the LTE network re-entry to the 3G network, the second SGSN may initiate an authentication process, since the second SGSN unsaved have unused authentication vector, then launched KAM right before the process, the second SGSN can request the authentication device to get a new generation of authentication vectors.
0167S505: the second authentication data SGSN receives a response message returned by the authentication device, the authentication data response message contains the authentication vector.
0168S506: the second SGSN sends an authentication request message to the UE, the authentication request message containing the authentication data response message contains the authentication vector of the random number and the authentication token.
0169In the embodiment of the invention, after the UE from the LTE network re-entry to the 3G network, even if the MME LTE network in the preservation of unused authentication vector, nor will the unused Kam right before sending vectors to the second SGSN 3G network, avoid saving the unused authentication vector in the second SGSN, so that the second SGSN sending an authentication request message to the UE, need Get new authentication vectors generated from the authentication device solves the prior art authentication failure.
0170Corresponds to the above-described embodiment of the method embodiment, embodiments of the present invention there is provided a core network device 60, shown in Figure 6, the core network device may be a mobile switching center MSC or SGSN of the core network or network device 5G, the core network device 601 may include a storage unit, an acquisition unit 602 and the transmitting unit 603;
0171The storage unit 601 is used for the authentication vector of the UE stored unused.
0172The acquiring unit 602, for transmitting a first authentication data to the authentication request message ,, the first device authentication data request message for requesting the authentication apparatus for the UE authentication vector generation, receiving a first authentication request to the authentication device returns the data message based on the message authentication response data, the first response message comprising the authentication data to the authentication device generating a first UE authentication vector . For example, the acquisition unit 602 may transmit to the UE a first authentication unit 603 before transmitting the request message, the storage unit 601 for the case where the UE has stored the unused authentication vector to the said authentication apparatus sends the first authentication data request message, the first authentication data request message may further comprise the UE identity, the core network apparatus according to the UE identity, to the said UE generates a first authentication vector.
0173The transmitting unit 603 for transmitting a first authentication request message to the UEUE, the first authentication request message contains the authentication vector in the first random number and the authentication token.
0174Since the core network equipment if before each initiates an authentication process went authentication device acquires authentication vector, may bring a big burden to the authentication device. In practice, it can refer to protection against certain scenes. Then the core network device may further comprise:
0175Determination unit 604, after the first network for the UE to access the core network apparatus is located, the UE determines the access is to a UE from a second network of the first network; if the acquisition unit the determination unit 602 may determine that the UE 604 after the access network to the second UE from the first network, before transmitting said first authentication data request message to the authentication device.
0176For example, the first network may be a 3G network, the second network may be an LTE LTE network, the determining means 604 for determining a specific UE is the LTE access network to the 3G network from the UE. This method ensures that only when the UE from the LTE network to the 3G network access authentication procedure caused, even if the core network device has stored unused authentication vector, but also to the core network apparatus to acquire the first authentication device authentication vector, authentication vector using the first network to initiate an authentication process.
0177Specifically, the determination unit 604 determines the UE from the LTE access network to the 3G network When the UE, can also have a variety of ways. The determination unit 604 may judge based on the response message of the CS domain NAS message sent by the UE or the UE in a paging the called UE scene whether CSFB user, if it is determined CSFB user, i.e. the UE is determined access to the UE from the LTE network to the 3G network, the CS domain NAS message may be a connection management service request message or a location update request message, etc., when the core network device may be the MSC; Alternatively, the determining PS domain NAS message unit 604 may transmit according to the UE, the UE determines whether the access of the UE from the LTE network to the 3G network, for example according to the RAU request message, the UE is determined from the LTE access network 3G network to the UE, the core network device at this time may be the SGSN; Alternatively, the determination unit 604 according to the notification message sent by the base station, the UE is determined from the LTE access network to the 3G network the UE, the notification message to the base station after determining circuit switched fall CSFB users to send messages to the core network equipment of the UE, the core network device at this time may be a MSC or SGSN; or, for a UE, the said determination unit 604 may SGS is associated with the interface exists between the MME, the UE determines by identifying a UE from the core network is the LTE network access to the 3G network, if the interface associated with the presence of SGS, is determined by said UE is UE access to the 3G network from LTE network, then the core network equipment for MSC.
0178Alternatively, the authentication vector stored in the storage unit 601 may be unused before on the core network equipment to initiate a process to obtain authorization, then: the acquisition unit 602 is also used to KAM right before the first device authentication data transmission request message to the authentication device transmits the second authentication data request message, the second authentication data request message for requesting the authentication apparatus for the UE generates KAM the second weight vector authentication data, the authentication device receiving the request message returns the authentication data based on the second response message, said second message carrying the authentication data in response to the authentication device UE generated the second authentication vector and the unused authentication vector; the transmitting unit 603 is also used for the acquisition unit 602 transmits the first authentication data to the authentication device prior to the request, the UE sends the second authentication request message, the second authentication request message containing the authentication vector in the second random number and the authentication token.
0179In the embodiment of the present invention, the acquisition unit 602 may be a UE stored in the storage unit 601 under the unused authentication vector, the transmitting apparatus to the authentication of the first authentication data request message, receiving a first authentication request to the authentication device returns the data message based on the message authentication response data, the first response message comprising the authentication data to the authentication device generating a first authentication of UE Vector, the transmitting unit 603 may transmit to the UE a first authentication request message, the first authentication request message contains the authentication vector in the first random number and the authentication token, so that the core network equipment there even when stored unused authentication vector, also used for authentication of the first authentication vector, the prior art to avoid the use of the core network device stored in itself an unused authentication vector to initiate authentication for the network, the synchronization may cause authentication problems caused by the failure of the failure, as much as possible to protect the successful network authentication.
0180Corresponds to the above-described embodiment of the method in accordance with Embodiment of the present invention further provides an authentication device shown in Figure 7, the authentication device may be a home environment by HE, the HLR home location register, the home subscriber server HSS or Authentication Center the AUC, the authentication apparatus comprises a receiving unit 701, a processing unit 702 and transmission unit 703;
0181The receiving unit 701 for receiving a first authentication data stored unused authentication vector has a core network device sends a request message, the first authentication data request message for requesting the authentication of the apparatus said UE generated authentication vector;
0182The processing unit 702, a request message according to said first authentication data to generate first authentication data response message, the first response message comprising authentication data to the authentication vector generated first UE;
0183The transmitting unit 703, the first authentication data for returning a response message to the core network device.
0184Alternatively, the receiving unit 701 is further configured prior to receiving the first authentication data request message, the core network apparatus transmits the received second authentication data request message, said second message authentication data request for requesting the authentication of the UE device to generate a warning weight vector; the processing unit 702 according to the second message for requesting the authentication data, the authentication data is generated in response to the second message, the second discriminator a second right data response message contains the authentication vector for the UE and the authentication vector generated by unused; the sending unit 703 is further configured to return data to the second authentication response message to the core network device .
0185In the present embodiment of the invention, the UE device may receive authentication with a first authentication data stored unused authentication vector core network device sends a request message, and saved to the unused authentication vector has a core a first network device returns an authentication data response message, the first response message comprising authentication data to the authentication vector generated first UE, the core network apparatus even when stored such that there is an unused authentication vector, but also using the said first authentication vector for authentication, to avoid the prior art core network equipment using its own preservation When unused authentication vector initiated network authentication, synchronization failure may cause problems due to the failure of the authentication, as much as possible to protect the successful network authentication.
0186As shown in Figure 8, the embodiment of the present invention further provides an authentication system 80 comprises a core network device 60 and authentication device 70. 70 describes each action performed by the core network device 60 and the authentication device and the interactions between them, can be found in Figures 1 to 3 the corresponding method embodiment can also refer to Figures 6 and 7 correspond to the description of embodiments of the apparatus not repeat them here.
0187Alternatively, the system may also include a user authentication device 801;
0188For example, the core network apparatus can be used, the user equipment is in the preservation of unused authentication vector to the authentication device in the case of first authentication data transmission request message, the first message authentication data request for requesting the user authentication apparatus to the authentication vector generating device;
0189The authentication device may be used for receiving the first authentication data request message, the request message according to the first authentication data, generating first authentication data response message, the first response message comprising the authentication data said first authentication device authentication vector generated by the user equipment, core network equipment to the return of the first authentication data response message.
0190The core network apparatus can also be used for receiving the first authentication data response message, to the user device sends a first authentication request message, the first authentication request message including the first random authentication vector number and the authentication token;
0191The first user device may receive the authentication request message, using the first authentication request to the authentication vector in the first random number and the authentication token contained in the authentication message.
01929, the embodiment of the present invention as shown embodiment is also provided a wireless communication system, an authentication apparatus, the authentication means may comprise:
0193Processor 901, memory 902, bus 904, and a communication interface 905. Processor 901, and complete the connection between the communication between the memory 902 and communication interface 905 via a bus 904.
0194Processor 901 may be a single or multi-core central processing unit, or for a specific integrated circuit, or the embodiment of the present invention is configured to be one case of integrated circuits or more embodiments.
0195RAM memory 902 may be high speed memory may be a non-volatile memory (non-volatile memory), such as at least one disk storage.
0196A computer memory 902 for executing instructions 903. Specifically, the computer 903 may execute instructions comprising program code.
0197The wireless communication system process flow when the method of operation of the authentication device, the processor 901 runs a computer to execute instructions 903 may be performed at any one of three corresponding to Figures 1 to the embodiment of the authentication method of FIG. 4, or the method of the wireless communication system to any process of FIG. 5 corresponds to the method according to the embodiment of the authentication method. The authentication device may be a core network device or authentication device.
0198Example embodiments of the present invention further provides a computer-readable medium comprising computer instruction execution, when the execution of the computer for the computer processor to execute instructions, the computer 3 execute any one of Figures 1 to a corresponding method of Example process 5 the method of any one of the radio communication system 4 to the wireless communication system according to the authentication method or process flow diagram of a method corresponding to the embodiment of the authentication method.
0199The present invention is mentioned LTE network, the A network including LTE, LTE release and subsequent possible. Embodiment of the first, second, third present invention, fourth, fifth, etc. used only to distinguish the different instructions, messages or other objects, the order does not mean the relationship.
0200Those skilled in the art can appreciate that any of the various units and algorithm steps described in the exemplary embodiments disclosed herein, it is possible in electronic hardware, computer software, or a combination of the two to achieve, in order to clearly illustrate the hardware and software interchangeability, in accordance with the above description has been generally described functional composition and procedures of the examples. These functions actually to be performed by hardware or software depends upon the particular application and design constraints technical solutions. Professional and technical personnel can use different methods for each particular application to implement the functions described herein, but such implementation should not be beyond the scope of the present invention.
0201Those skilled in the art can clearly understand that, for convenience and brevity of description, specific work process described above systems, devices and units, refer to the aforementioned method according to the corresponding implementation process, not repeat them here.
0202In this application several examples provided, it should be understood that the disclosed system, apparatus and method can through other ways. , E.g., cell division, for example the apparatus described above is merely illustrative embodiment functions only as a logical functional division, the actual implementation may have another Division manner outside, such as a plurality of elements or components may be combined or integrated in another system or certain features may be omitted, or not implemented. Further, the display coupled or directly coupled or communicating with each other, or the connection between the discussion may be through some interface, device, or indirect coupling or communication connection unit may be electrical, mechanical, or other form of connection.
0203Unit said as a separate component description may or may not be physically separated as part display unit may or may not be a physical unit, which can be located in one place, or it can be distributed to multiple network elements. You can select some or all of the cells to achieve the object of the embodiment of the present invention implemented in accordance with actual needs.
0204Further, in the embodiment of the present invention, the functional units in each embodiment may be integrated in a processing unit, each unit may be a separate physical existence, it may be two or more units integrated in one unit. The integrated unit described above can be used both implemented in the form of hardware, the software can also be used in the form of functional units realized.
0205The integrated unit if implemented as software functional unit and as a standalone product sold or used, can be stored in a computer readable storage medium. Based on this understanding, the technical nature of the invention or the part contributing to the prior art, or all or part may be embodied in the form of a software product that aspect of it, the computer software product is stored in a storage medium , including a number of instructions to instruct a computer device (may be a personal computer, server, or network equipment) to perform all or part of the steps of the present invention embodiment of the method with various embodiments. The aforementioned storage media include: U disk, removable hard disk, read only memory (ROM, Read-Only Memory), a random access memory, etc. (RAM, Random Access Memory), floppy disk or CD-ROM can store a variety of program codes medium .
0206The above is only a specific embodiment of the present invention, but the scope of the present invention is not limited thereto, and any skilled in the art in the art within the technical scope of the present invention disclosed, may easily occur to equivalent modify or replace, modify or replace these should fall within the scope of the present invention. Accordingly, the scope of the present invention shall be subject to the scope of the claims.
Contents2
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN112867001A | Cited by | China | – | Search report | – |
| US11595817B2 | Cited by | United States of America | – | Search report | – |
| CN114338073A | Cited by | China | – | Search report | – |
| CN110536296A | Cited by | China | – | Search report | – |
| US2023048689A1 | Cited by | United States of America | – | Search report | – |
| US2020228982A1 | Cited by | United States of America | – | Search report | – |
| CN103281693A | Cites | China | A | International search | 1-27 |
| CN103905400A | Cites | China | A | International search | 1-27 |
| US7574599B1 | Cites | United States of America | A | International search | 1-27 |
3 members in 2 offices; this record represents the family
Members3
| Document | Office | Kind | |
|---|---|---|---|
| WO2016086355A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| CN107005842A | China | A | |
| CN107005842B | China | B |
Numbers
- Publication
- 2016/086355
- Application
- 92787
Titles5
- English
- AUTHENTICATION METHOD WITHIN WIRELESS COMMUNICATION NETWORK, RELATED APPARATUS AND SYSTEM
- French
- PROCÉDÉ D'AUTHENTIFICATION DANS UN RÉSEAU DE COMMUNICATION SANS FIL, APPAREIL ET SYSTÈME ASSOCIÉS
- Chinese
- 一种无线通信网络中的鉴权方法、相关装置及系统
- Unlabeled
- 一种无线通信网络中的鉴权方法、相关装置及系统
- Chinese
- A wireless communication network authentication method, apparatus and system related
Classification
- CPC, 1
- H04W12/06
- IPC, 1
- H04W12 06
Designated states147
- Regional, 80
- Botswana
- Ghana
- Gambia
- Kenya
- Liberia
- Lesotho
- Malawi
- Mozambique
- Namibia
- Rwanda
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Russian Federation
- Tajikistan
and 56 moreShow fewer
- Turkmenistan
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Lithuania
- Luxembourg
- Latvia
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Comoros
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- Sao Tome and Principe
- National, 67
- United Arab Emirates
- Antigua and Barbuda
- Angola
- Australia
- Bosnia and Herzegovina
- Barbados
- Bahrain
- Brunei Darussalam
- Brazil
- Belize
- Canada
- Chile
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Dominican Republic
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Guatemala
and 43 moreShow fewer
- Honduras
- Indonesia
- Israel
- India
- Iran (Islamic Republic of)
- Japan
- Saint Kitts and Nevis
- Democratic People’s Republic of Korea
- Republic of Korea
- Lao People’s Democratic Republic
- Saint Lucia
- Sri Lanka
- Libya
- Morocco
- Republic of Moldova
- Montenegro
- Madagascar
- Mongolia
- Mexico
- Malaysia
- Nigeria
- Nicaragua
- New Zealand
- Oman
- Panama
- Peru
- Papua New Guinea
- Philippines
- Qatar
- Saudi Arabia
- Seychelles
- Singapore
- El Salvador
- Syrian Arab Republic
- Thailand
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- South Africa