CN101203030B - An authentication device and method using a mobile terminal multi-mode protocol stack - Google Patents
An authentication device and method using a mobile terminal multi-mode protocol stack Download PDFInfo
- Publication number
- CN101203030B CN101203030B CN2006101651293A CN200610165129A CN101203030B CN 101203030 B CN101203030 B CN 101203030B CN 2006101651293 A CN2006101651293 A CN 2006101651293A CN 200610165129 A CN200610165129 A CN 200610165129A CN 101203030 B CN101203030 B CN 101203030B
- Authority
- CN
- China
- Prior art keywords
- authentication
- mobile terminal
- network
- module
- umts
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Landscapes
- Mobile Radio Communication Systems (AREA)
Abstract
Description
技术领域technical field
本发明涉及移动通信领域的鉴权技术,具体指一种利用移动终端多模协议栈进行鉴权的装置和方法。The invention relates to authentication technology in the field of mobile communication, and specifically refers to a device and method for authentication by using a multi-mode protocol stack of a mobile terminal.
背景技术Background technique
近几年移动用户数量快速增长,用户在使用语音服务的同时,对移动数据服务也提出了更高的要求,高速无线接入势在必行,异构网络的融合成为未来网络发展的明确方向,其中WiMAX网络和第三代移动通信网络(3G,3rdGeneration Mobile Telecommunication Network)的融合就是一个代表,但WiMAX网络和3G网络各自具有自己的鉴权机制。In recent years, the number of mobile users has grown rapidly. While using voice services, users have also put forward higher requirements for mobile data services. High-speed wireless access is imperative. The integration of heterogeneous networks has become a clear direction for future network development. , where the integration of WiMAX network and third generation mobile communication network (3G, 3rd Generation Mobile Telecommunication Network) is a representative, but WiMAX network and 3G network each have their own authentication mechanism.
WiMAX安全架构中的鉴权机制支持IEEE 802.16e中定义的移动终端和WiMAX网络间的双向设备鉴权,而3G网络的鉴权在移动终端是由移动性管理子层(MM/GMM,Mobilty Manage/GPRS Mobilty Manage)执行的,当3G网络的通用移动通信系统(UMTS,Universal Mobile Telecommunication System)的鉴权流程被执行后,在移动终端和网络之间就建立了UMTS的安全性上下文;对于一个成功的UMTS鉴权,UMTS加密密钥、UMTS完整性密钥就存储在网络和移动终端中。The authentication mechanism in the WiMAX security architecture supports bidirectional device authentication between the mobile terminal and the WiMAX network defined in IEEE 802.16e, while the authentication of the 3G network is performed by the Mobility Management sublayer (MM/GMM, Mobilty Manage /GPRS Mobilty Manage), when the UMTS (Universal Mobile Telecommunications System) authentication process of the 3G network is executed, a UMTS security context is established between the mobile terminal and the network; for a For successful UMTS authentication, the UMTS encryption key and UMTS integrity key are stored in the network and in the mobile terminal.
802.16e协议的网络工作组发布了WiMAX网络和3G网络的联合组网结构,因此3G/WIMAX多模终端协议栈的联合鉴权技术是其关键技术之一。The network working group of the 802.16e protocol released the joint networking structure of the WiMAX network and the 3G network, so the joint authentication technology of the 3G/WIMAX multi-mode terminal protocol stack is one of its key technologies.
WiMAX与3G网络的联合组网结构,主要有两种形式:The joint networking structure of WiMAX and 3G network mainly has two forms:
1.核心网融合:此方案主要考虑在无线接口侧,WiMAX和3GPP不进行互操作,只是把WiMAX接入网接入到3GPP的分组交换域(PS,PacketSequencing)核心网中,利用3GPP的PS核心网提供的业务和功能实现WiMAX网络的移动通信业务。1. Core network integration: This solution mainly considers that on the wireless interface side, WiMAX and 3GPP do not interoperate, but only connects the WiMAX access network to the 3GPP packet switching domain (PS, PacketSequencing) core network, and uses 3GPP PS The services and functions provided by the core network realize the mobile communication services of the WiMAX network.
2.接入网融合:在核心网融合的基础上,将考虑两种接入技术在空中接口上的切换,以保证用户从WiMAX覆盖的网络移动到3GPP覆盖的网络时业务的连续性。这种融合对现有3GPP和WiMAX的空中接口协议影响都比较大,因此可期望于3G中的WCDMA在R7以后阶段引入和WiMAX同样的OFDM和MIMO技术后,再考虑融合,则成为水到渠成的事情。2. Access network integration: On the basis of core network integration, the switching of two access technologies on the air interface will be considered to ensure service continuity when users move from a WiMAX-covered network to a 3GPP-covered network. This kind of integration has a relatively large impact on the existing air interface protocols of 3GPP and WiMAX. Therefore, it is expected that WCDMA in 3G will introduce the same OFDM and MIMO technology as WiMAX in the later stage of R7, and then consider the integration, which will become a matter of course. .
对于3G网络和WiMAX网络的联合组网,无论是核心网融合还是未来的接入网融合,WiMAX/3G双模终端协议栈都需要解决两个接入网络的鉴权问题;而目前WiMAX网络还处于发展的初期,提到的鉴权方案均集中在网络侧,对于移动终端协议栈的解决方案还没有人提出相关技术方案的专利。For the joint networking of 3G network and WiMAX network, whether it is core network integration or future access network integration, the WiMAX/3G dual-mode terminal protocol stack needs to solve the authentication problem of the two access networks; In the initial stage of development, the mentioned authentication schemes are all concentrated on the network side, and no one has proposed a patent for a related technical scheme for the solution of the mobile terminal protocol stack.
发明内容Contents of the invention
有鉴于此,本发明提出了一种利用移动终端多模协议栈进行鉴权的方法和装置,解决如何在一个移动终端完成UMTS模式,WiMAX模式和UMTS &WiMAX双模式这三种工作模式下的鉴权功能。In view of this, the present invention proposes a method and device for authenticating by using a mobile terminal multimode protocol stack to solve how to complete UMTS mode, WiMAX mode and UMTS&WiMAX dual mode authentication under these three working modes in a mobile terminal. power function.
一种利用移动终端多模协议栈进行鉴权的装置,应用于移动终端,该装置至少包括:A device for authentication using a mobile terminal multi-mode protocol stack, applied to a mobile terminal, the device at least includes:
模式选择模块(101),用于根据接收到的指令完成移动终端的工作模式选择;A mode selection module (101), configured to complete the selection of the working mode of the mobile terminal according to the received instruction;
用户识别模组SIM卡管理模块(103),用于管理不同类型的SIM卡驱动程序,识别插入的不同的SIM卡类型;并根据识别结果通过所述SIM卡驱动程序管理SIM卡中用户信息的数据结构和用户信息的存储空间;Subscriber identification module SIM card management module (103), is used for managing different types of SIM card drivers, identifies different SIM card types inserted; and manages user information in the SIM card by the SIM card driver according to the identification result Data structure and storage space for user information;
接口管理模块(104),用于通过SIM卡管理模块(103)与不同类型的SIM卡进行用户信息的读取和存储;通过不同协议栈接收网络侧的鉴权请求信息,并把鉴权响应消息通过对应的协议栈发送给不同的网络侧;The interface management module (104) is used for reading and storing user information through the SIM card management module (103) and different types of SIM cards; receiving the authentication request information of the network side through different protocol stacks, and sending the authentication response The message is sent to different network sides through the corresponding protocol stack;
鉴权执行模块(102),用于通过接口管理模块(104)获取用户信息和接收网络侧发送来的鉴权请求信息,使用相应鉴权算法根据所述用户信息和所述鉴权请求信息进行鉴权操作生成鉴权响应消息,发送给接口管理模块(104)。An authentication execution module (102), configured to obtain user information through an interface management module (104) and receive authentication request information sent from the network side, and use a corresponding authentication algorithm to perform user information and authentication request information according to the user information and the authentication request information. The authentication operation generates an authentication response message and sends it to the interface management module (104).
该装置所述工作模式分为UMTS模式,WiMAX模式和UMTS & WiMAX双模式;The working mode of the device is divided into UMTS mode, WiMAX mode and UMTS & WiMAX dual mode;
鉴权执行模块(102)执行的鉴权操作为执行UMTS网络、WiMAX网络的鉴权算法。The authentication operation performed by the authentication execution module (102) is to execute the authentication algorithm of the UMTS network and the WiMAX network.
该装置鉴权执行模块(102)至少包括执行UMTS网络鉴权所需的f1、f2、f3、f4、f5算法模块;The device authentication execution module (102) at least includes f1, f2, f3, f4, f5 algorithm modules required for performing UMTS network authentication;
鉴权执行模块(102)至少包括执行WiMAX网络鉴权所需的EAP方法模块(1022)和EAP模块(1023)。The authentication execution module (102) at least includes an EAP method module (1022) and an EAP module (1023) required for WiMAX network authentication.
该装置鉴权执行模块(102)中的EAP方法模块(1022)执行不同EAP认证的算法,所述EAP认证至少包括EAP-MD5、EAP-SIM、EAP-PEAP、EAP-TTLS、EAP-TLS和EAP-AKA,并根据系统选择的认证执行该认证对应的算法。The EAP method module (1022) in the device authentication execution module (102) executes different EAP authentication algorithms, and the EAP authentication includes at least EAP-MD5, EAP-SIM, EAP-PEAP, EAP-TTLS, EAP-TLS and EAP-AKA, and execute the algorithm corresponding to the authentication according to the authentication selected by the system.
该装置所述接口管理模块(104)中至少包括:The interface management module (104) of the device at least includes:
SIM卡接口模块(1042),用于管理不同类型SIM卡的驱动程序;SIM card interface module (1042), used to manage the drivers of different types of SIM cards;
消息缓存模块(1043),对于发送到UMTS协议栈/WiMAX协议栈的鉴权信息在该协议栈接收到以前进行缓存,接收后删除该鉴权信息;在鉴权执行模块(102)对接收到的鉴权信息进行操作之前进行缓存,接收后删除该鉴权信息;对于接收到的消息在鉴权执行模块(102)处理之前,也须缓存;The message cache module (1043), buffers the authentication information sent to the UMTS protocol stack/WiMAX protocol stack before the protocol stack receives it, and deletes the authentication information after receiving it; The authentication information is cached before the operation, and the authentication information is deleted after receiving; the received message must also be cached before the authentication execution module (102) processes;
消息路由模块(1041),所述接口管理模块(104)中的消息路由模块(1041),将从协议栈接收到的网络侧发出的鉴权请求消息发送给鉴权执行模块(102);把接收到的鉴权执行模块(102)发来的鉴权响应消息,根据鉴权响应消息的类型,发送给对应协议栈中的相应模块,并在路由鉴权消息时调用消息缓存模块(1043)对该鉴权消息进行缓存。The message routing module (1041), the message routing module (1041) in the interface management module (104), sends the authentication request message sent from the network side received from the protocol stack to the authentication execution module (102); The received authentication response message sent by the authentication execution module (102) is sent to the corresponding module in the corresponding protocol stack according to the type of the authentication response message, and the message cache module (1043) is called when routing the authentication message The authentication message is cached.
该装置所述接口管理模块(104)中的SIM卡接口模块(1042)为SIM卡管理模块(103)所管理的不同SIM卡驱动程序提供统一的对外部的接口。The SIM card interface module (1042) in the interface management module (104) of the device provides a unified external interface for different SIM card drivers managed by the SIM card management module (103).
该装置所述利用移动终端多模协议栈进行鉴权的装置在移动终端独立存在,或者作为一个插件成为UMTS终端协议栈单元的一个组成部分,或者作为一个插件成为WiMAX终端协议栈单元的一个组成部分。The device described in the device uses the mobile terminal multimode protocol stack for authentication to exist independently in the mobile terminal, or as a plug-in to become a component of the UMTS terminal protocol stack unit, or as a plug-in to become a component of the WiMAX terminal protocol stack unit part.
一种利用移动终端多模协议栈进行鉴权的方法,包括:A method for authenticating by using a mobile terminal multimode protocol stack, comprising:
A.根据接收到的指令判断当前移动终端需要进入的工作模式,如果是单模,则执行单模鉴权流程,如果是多模转步骤B;A. Judging the working mode that the current mobile terminal needs to enter according to the received instruction, if it is single-mode, execute the single-mode authentication process, if it is multi-mode, go to step B;
B.收到第一网络侧发来的鉴权请求消息后,移动终端通过与第一网络侧的交互执行第一网络的原有鉴权流程;B. After receiving the authentication request message sent by the first network side, the mobile terminal executes the original authentication process of the first network through interaction with the first network side;
C.第一网络的鉴权完成后,第一网络侧查询当前的移动终端是否签约同一个运营商提供的第二网络的网络业务,如果是,转步骤D,否则鉴权结束;C. After the authentication of the first network is completed, the first network side inquires whether the current mobile terminal has subscribed to the network service of the second network provided by the same operator, if yes, go to step D, otherwise the authentication ends;
D.第一网络侧向移动终端发送第二网络的鉴权请求消息,移动终端根据用户信息和相应鉴权算法通过与第一网络侧进行鉴权消息的交互,移动终端和第一网络侧的鉴权服务器分别生成主会话密钥,该鉴权服务器把该主会话密钥发送给第二网络的基站;D. The first network side sends an authentication request message of the second network to the mobile terminal. The mobile terminal interacts with the first network side through the authentication message according to the user information and the corresponding authentication algorithm. The mobile terminal and the first network side The authentication server generates a master session key respectively, and the authentication server sends the master session key to the base station of the second network;
E.第二网络的基站根据接收到的所述主会话密钥生成授权密钥,并且移动终端根据自身生成的主会话密钥产生授权密钥,利用授权密钥移动终端与第二网络侧进行后续的鉴权操作。E. The base station of the second network generates an authorization key according to the received master session key, and the mobile terminal generates an authorization key according to the master session key generated by itself, and uses the authorization key to communicate between the mobile terminal and the second network side Subsequent authentication operations.
该方法所述第一网络是UMTS网络,第二网络是WiMAX网络;The first network described in the method is a UMTS network, and the second network is a WiMAX network;
所述步骤B包括:按照现有UMTS鉴权流程执行UMTS网络的鉴权;The step B includes: performing the authentication of the UMTS network according to the existing UMTS authentication process;
所述步骤C包括:完成UMTS网络的鉴权后,如果确认用户签约了同一运营商提供的WiMAX网络业务,则UMTS网络侧MSC/VLR向AAA鉴权服务器发送用户标示信息,否则鉴权结束;The step C includes: after completing the authentication of the UMTS network, if it is confirmed that the user has signed the WiMAX network service provided by the same operator, the UMTS network side MSC/VLR sends the user identification information to the AAA authentication server, otherwise the authentication ends;
所述步骤D包括:移动终端与UMTS网络侧的MSC/VLR和AAA鉴权服务器经过鉴权消息的发送和转发,在移动终端和AAA鉴权服务器上产生主会话密钥MSK;Said step D comprises: the mobile terminal and the MSC/VLR and AAA authentication server on the UMTS network side send and forward the authentication message, and generate the master session key MSK on the mobile terminal and the AAA authentication server;
AAA鉴权服务器根据MSK产生共享主密钥PMK发送给位于UMTS网络的基站最近的WiMAX基站;The AAA authentication server generates the shared master key PMK according to the MSK and sends it to the nearest WiMAX base station located in the base station of the UMTS network;
所述步骤E包括:在基站和移动终端产生授权密钥AK,利用授权密钥AK移动终端与第二网络侧进行后续的鉴权操作。The step E includes: generating an authorization key AK at the base station and the mobile terminal, and using the authorization key AK to perform subsequent authentication operations between the mobile terminal and the second network side.
该方法步骤C所述查询过程为UMTS网络侧查询该移动终端的用户签约信息判断是否签约同一个运营商提供的WiMAX的网络业务。The query process described in step C of the method is that the UMTS network side queries the user subscription information of the mobile terminal to determine whether to subscribe to the WiMAX network service provided by the same operator.
该方法步骤D所述鉴权消息包括符合扩展鉴权协议的EAP-REQUEST/TLS start和EAP-RESPONSE/TLS start。The authentication message described in step D of the method includes EAP-REQUEST/TLS start and EAP-RESPONSE/TLS start conforming to the extended authentication protocol.
在本发明技术方案中,通过在移动终端新增加一个利用移动终端多模协议栈进行鉴权的装置,执行3G网络的UMTS鉴权功能和WiMAX网络支持的扩展鉴权协议(EAP,Extensible Authentication Protocol)鉴权功能,解决了在一个移动终端完成UMTS模式,WiMAX模式和UMTS & WiMAX双模式三种模式下的鉴权功能。In the technical scheme of the present invention, by newly adding a device that utilizes the multimode protocol stack of the mobile terminal to perform authentication on the mobile terminal, the UMTS authentication function of the 3G network and the Extensible Authentication Protocol (EAP, Extensible Authentication Protocol) supported by the WiMAX network are executed. ) authentication function, which solves the authentication function in three modes of UMTS mode, WiMAX mode and UMTS & WiMAX dual mode in one mobile terminal.
附图说明Description of drawings
图1为本发明利用移动终端多模协议栈进行鉴权的装置示意图;FIG. 1 is a schematic diagram of a device for authentication using a mobile terminal multimode protocol stack in the present invention;
图2为本发明接口管理模块的各子模块示意图;Fig. 2 is a schematic diagram of each sub-module of the interface management module of the present invention;
图3为本发明鉴权执行模块的信息交互示意图;Fig. 3 is a schematic diagram of information interaction of the authentication execution module of the present invention;
图4为本发明移动终端鉴权工作流程示意图;FIG. 4 is a schematic diagram of a mobile terminal authentication workflow in the present invention;
图5为本发明UMTS模式鉴权流程示意图;FIG. 5 is a schematic diagram of the UMTS mode authentication flow chart of the present invention;
图6为本发明UMTS鉴权模式下的鉴权执行模块102执行f1~f5算法示意图;FIG. 6 is a schematic diagram of algorithms f1-f5 executed by the
图7为本发明WiMAX模式鉴权流程示意图;FIG. 7 is a schematic diagram of a WiMAX mode authentication flow in the present invention;
图8为本发明通过UMTS接入网络完成WiMAX鉴权的流程示意图。FIG. 8 is a schematic flow chart of completing WiMAX authentication through UMTS access network in the present invention.
具体实施方式Detailed ways
本发明是在WiMAX与3G网络采用核心网融合的联合组网方式上提出的。在移动终端新增加一个利用移动终端多模协议栈进行鉴权的装置,执行3G网络的UMTS的鉴权功能和WiMAX网络支持的EAP鉴权功能;所述的利用移动终端多模协议栈进行鉴权的装置位于支持3G/WiMAX双工作模式的移动终端上。The present invention is proposed on the joint networking mode of WiMAX and 3G network adopting core network fusion. Newly increase a device that utilizes the mobile terminal multimode protocol stack to authenticate at the mobile terminal, execute the authentication function of the UMTS of the 3G network and the EAP authentication function supported by the WiMAX network; described utilize the mobile terminal multimode protocol stack to authenticate The authorized device is located on a mobile terminal supporting 3G/WiMAX dual working mode.
如图1所示,利用移动终端多模协议栈进行鉴权的装置包括模式选择模块101、鉴权执行模块102、用户识别模组(SIM)卡管理模块103、接口管理模块104四个功能模块;四个功能模块各自的功能如下:As shown in Figure 1, the device utilizing the mobile terminal multimode protocol stack for authentication includes four functional modules: a
模式选择模块101完成3G/WiMAX移动终端的工作模式设定,所述工作模式分为UMTS模式,WiMAX模式和UMTS/WiMAX双模式三种。其中,在UMTS & WiMAX双模式的工作环境下,模式选择包括确定网络接入优先级,也就是确定优先接入WiMAX网络进行鉴权还是优先接入UMTS网络进行鉴权。模式选择可以由用户手动设置,也可以是系统默认,如果是系统默认,则可以是UMTS优先接入网络进行鉴权。The
鉴权执行模块102完成接入UMTS网络和接入WiMAX网络的鉴权算法的具体执行工作,包括:接入UMTS网络鉴权所执行的f1、f2、f3、f4、f5算法模块1021;接入WiMAX网络的EAP方法模块1022和EAP模块1023。对接入UMTS网络进行鉴权时:从位于移动终端的UMTS协议栈的MM层接收来自网络侧的鉴权请求(user authentication request),调用接口管理模块104,并在接口管理模块104中调用SIM卡管理模块103从SIM卡中读取主密钥K,在算法模块1021中运行f1~f5算法,然后向MM层发送鉴权响应(user authentication response)。对接入WiMAX网络进行鉴权时,执行EAP鉴权协议,具体的EAP认证方法有多种,例如EAP-MD5、EAP-SIM、EAP-PEAP、EAP-TTLS、EAP-TLS和EAP-AKA,上述EAP认证的算法执行程序是通用的,本发明中则是存放在EAP方法模块1022中,因为到底采用哪种EAP方法是由运营商选择,因此本发明EAP方法模块1022必须支持多种EAP算法。The
SIM卡管理模块103的功能主要是根据SIM卡厂商提供的驱动接口读取、保存进行鉴权所需的相关数据;识别用户插入的SIM卡类型;统一管理UMTSSIM卡和WiMAX SIM卡的数据存储空间。该模块及其功能在现有技术中是放在UMTS协议栈中实现的,由于SIM管理主要实现从SIM卡中读取、存储数据等功能,本发明将SIM卡管理模块103提取出来,作为利用移动终端多模协议栈进行鉴权的装置中的一个功能模块。The function of the SIM
接口管理模块104,负责UMTS消息和WiMAX消息的分发,与UMTS协议栈和WiMAX协议栈均有密切的交互;如图2所示,接口管理模块104包括:消息路由模块1041,SIM卡接口模块1042,消息缓存模块1043。
其中,消息路由模块1041主要完成消息的接收与发送,例如将接收到的网络侧发出的鉴权消息发送给鉴权执行模块102;对鉴权执行模块102发送的鉴权响应消息,根据消息的类型,发送给UMTS协议栈的MM层或WiMAX协议栈的EAP封装模块。Among them, the
SIM卡接口模块1042主要负责调用SIM卡的驱动程序,WiMAX使用的SIM卡与UMTS的UMTS SIM卡的驱动程序有可能一样,也可能不一样,因此本发明SIM卡管理模块103支持多种类型的SIM卡驱动程序,而SIM卡接口模块1042屏蔽了SIM卡管理模块103的这种差异性,负责调用SIM卡供应商提供的不同类型的SIM卡的驱动程序对SIM卡中的数据进行读取和存储。The SIM
对于SIM卡中数据结构、数据内容的安排由SIM卡管理模块103完成,SIM卡接口模块1042对上述内容不作处理。The arrangement of the data structure and data content in the SIM card is completed by the SIM
消息缓存模块1043对于发送到UMTS协议栈和WiMAX协议栈的消息在对方接收到以前,不能删除,必须缓存;对于接收到的消息在鉴权执行模块102处理之前,也必须缓存,因此,消息缓存模块1043负责管理这些缓存中临时存放的数据,并对外提供接口,由消息路由模块1041调用消息缓存模块1043的对外接口来处理这些缓存中的数据。The
图3描述了鉴权执行模块102和其他模块以及与UMTS协议栈和WiMAX协议栈之间的消息交互:鉴权执行模块102包括接入UMTS网络鉴权所执行的f1、f2、f3、f4、f5算法模块,以及接入WiMAX网络的EAP方法模块1022和EAP模块1023;鉴权执行模块102和WiMAX SIM卡以及UMTS SIM卡的信息和数据交互通过接口管理模块104和SIM卡管理模块103实现,鉴权执行模块102调用接口管理模块104中的SIM卡接口模块1042,SIM卡接口模块1042直接调用SIM卡管理模块103中相应的驱动程序完成信息和数据的传输;与UMTS协议栈,主要是MM层,以及WiMAX协议栈,主要是EAP封装模块,的交互则是通过消息路由模块1041完成。Fig. 3 describes the message interaction between the
本发明涉及3种工作模式下的鉴权过程,下面结合具体情况描述移动终端如何在3种工作模式中进行工作模式的选择,以及在选定工作模式后的鉴权过程的简要步骤;然后对每一种工作模式下的鉴权过程进行详细的描述。The present invention relates to the authentication process under 3 kinds of working modes, how mobile terminal is described how to carry out the selection of working mode in 3 kinds of working modes in conjunction with specific situation below, and the brief steps of the authentication process after the selected working mode; Then to The authentication process in each working mode is described in detail.
首先描述移动终端如何在3种工作模式中进行工作模式的选择的流程,如图4所示。Firstly, the flow of how the mobile terminal selects the working mode among the three working modes is described, as shown in FIG. 4 .
步骤201,用户开启移动终端后,根据用户设置或系统默认设置,分别选择only UMTS mode,only WiMAX mode或者UMTS & WiMAX mode,并进入相应的鉴权流程。
进入only UMTS mode,开始鉴权:Enter only UMTS mode and start authentication:
步骤202,MM层发给鉴权执行模块102来自网络侧的鉴权请求参数。In
步骤203,SIM卡管理模块103读取移动终端的SIM卡中的主密钥K,并发给鉴权执行模块102。
步骤204,鉴权执行模块102执行f1~f5算法,得到鉴权响应参数。In
步骤205,鉴权执行模块102把鉴权响应参数通过SIM卡管理模块103返回给MM层。
步骤206,结束鉴权流程。
进入only WiMAX mode,开始鉴权:Enter only WiMAX mode and start authentication:
步骤207,位于移动终端的EAP模块1023接收到来自基站(BS,BaseStation)的鉴权请求(EAP-Request),发送给鉴权执行模块102。
步骤208,鉴权执行模块102调用EAP方法模块1022(EAP-Method)执行鉴权算法,得到EAP-Response,并发送给EAP模块1023。
步骤209,EAP模块1023向BS发送EAP-Response。
步骤210,BS判断鉴权是否成功,如果成功则发送给移动终端的EAP模块1023EAP-success,EAP完全激活链路。In
步骤211,EAP方法模块1022计算出AAA-Key。In
步骤212,鉴权结束。
进入UMTS & WiMAX mode,开始鉴权。Enter UMTS & WiMAX mode and start authentication.
步骤213,UMTS接入网执行UMTS鉴权。
步骤214,UMTS网络侧查询用户签约信息,确认用户签约WiMAX网络业务。In
步骤215,经过UMTS接入网执行WiMAX鉴权。
步骤216,鉴权结束。
其中,鉴权流程202~206,207~212以及213~216是移动终端在三种不同的鉴权模式下的鉴权流程,其执行顺序不分先后。情况1:Among them, the authentication procedures 202-206, 207-212 and 213-216 are the authentication procedures of the mobile terminal in three different authentication modes, and the execution order is not in particular order. Case 1:
如图5所示,移动终端选择only UMTS mode后,开始具体的鉴权流程。鉴权流程涉及到若干设备,包括位于网络侧的用户归属环境/用户归属位置寄存器(HE/HLR,Home Environment/Home Location Registor),访问位置寄存器/支持GPRS服务节点(VLR/SGSN,Visit Location Registor/Serving GatewaySupport Nodes),以及移动终端。As shown in Figure 5, after the mobile terminal selects only UMTS mode, the specific authentication process starts. The authentication process involves several devices, including the user home environment/user home location register (HE/HLR, Home Environment/Home Location Registor) on the network side, the visitor location register/supporting GPRS service node (VLR/SGSN, Visit Location Registor) /Serving GatewaySupport Nodes), and mobile terminals.
步骤301,网络侧产生用户鉴权请求(user authentication request),上述用户鉴权请求由VLR/SGSN发送到UMTS协议栈的MM层,利用移动终端多模协议栈进行鉴权的装置中的鉴权执行模块102通过接口管理模块104接收到MM层的用户鉴权请求;鉴权执行模块102调用SIM卡管理模块103,SIM卡管理模块103以透传方式读取SIM卡中的主密钥K,发送给鉴权执行模块102用于执行f1~f5算法,开始鉴权。
步骤302,在UMTS鉴权过程中,首先VLR/SGSN向HE/HLR申请认证向量(AV,Authentication Vector)对移动终端进行鉴权,HE/HLR生成n组AV。
所述认证向量AV=(RAND||XRES||CK||IK||AUTN);上述5个参数分别为随机数RAND、期望响应值XRES、加密密钥CK、完整性密钥IK和认证令牌AUTN;分别由以下方法在网络侧产生:The authentication vector AV=(RAND||XRES||CK||IK||AUTN); the above five parameters are respectively the random number RAND, the expected response value XRES, the encryption key CK, the integrity key IK and the authentication order Card AUTN; respectively generated on the network side by the following methods:
RAND由f0产生;RAND is generated by f0;
XRES=f2K(RAND);XRES = f2K(RAND);
CK=f3K(RAND);CK = f3K(RAND);
IK=f4K(RAND);IK = f4K(RAND);
在认证令牌AUTN中,SQN是序列号;AK是匿名密钥,用于隐藏SQN;AMF是认证管理域;MAC是消息认证码。上述算法模块f1~f5在网络侧的HE/HLR中和移动终端的鉴权执行模块102中均存在,且算法完全相同,f0算法模块仅在网络侧HE/HLR中存在。In the authentication token AUTN, SQN is the serial number; AK is the anonymous key used to hide the SQN; AMF is the authentication management domain; MAC is the message authentication code. The above-mentioned algorithm modules f1-f5 both exist in the HE/HLR on the network side and in the
步骤303,HE/HLR把生成的n组AV发送给VLR/SGSN,VLR/SGSN接收到n组认证向量AV后,将其中的RAND和AUTN发送给移动终端UTMS协议栈的MM层,用于鉴权。
步骤304,鉴权执行模块102通过接口管理模块104取得MM层中的RAND和AUTN;如图6所示,鉴权执行模块102调用f1~f5算法模块开始执行f1~f5算法:把f5算法放在f1算法之前执行,f5算法利用RAND生成匿名密钥AK,其计算公式是AK=f5K(RAND)。AK异或AUTN中的SQN,即得到f1算法的输入数据SQN;f1算法利用RAND以及AUTN中的SQN和AMF,计算出期望消息认证码XMAC,其计算公式是XMAC=f1K(SQN||RAND||AMF)。SIM卡中存放的主密钥K是移动终端和HE/HLR之间共享的密钥。
步骤305,鉴权执行模块102比较XMAC和AUTN中的MAC是否匹配,如不匹配,则向网络侧发送拒绝认证消息,放弃该鉴权过程;如果二者相等,则判断接收的SQN是否在正确的数值范围内,若SQN不在正确的范围内,则移动终端向VLR/SGSN发送同步失败消息,并放弃该鉴权过程;若上面的两项验证都通过,鉴权执行模块102利用公式RES=f2K(RAND)计算响应值RES,并将RES作为对网络侧鉴权请求应答消息的一部分发送给VLR/SGSN,VLR/SGSN收到应答信息后,比较RES和从HE/HLR中取得的XRES,相等则鉴权认证成功,否则失败。
步骤306,在成功的完成UMTS鉴权之后,利用移动终端多模协议栈进行鉴权的装置中的鉴权执行模块102将会执行f3和f4算法,并把得到的加密密钥CK与一致性检查密钥IK通过调用SIM卡管理模块103,以透传方式存放到SIM卡中。
以上描述的情况中,步骤301,步骤302的执行无严格的时间先后顺序。In the situation described above, the execution of
当移动终端选择在only WiMAX mode进行鉴权时,其具体的鉴权流程在情况2进行详细描述。When the mobile terminal chooses to perform authentication in only WiMAX mode, its specific authentication process is described in detail in Case 2.
情况2:Case 2:
如图7所示,在选择了only WiMAX mode后,移动终端利用移动终端多模协议栈进行鉴权的装置执行移动终端接入WiMAX网络的鉴权流程。开始鉴权后:As shown in FIG. 7, after only WiMAX mode is selected, the mobile terminal uses the mobile terminal multi-mode protocol stack for authentication device to execute the authentication process for the mobile terminal to access the WiMAX network. After starting authentication:
步骤401,基站的EAP认证者(EAP authenticator)实体中的EAP层发送一条EAP-Request消息,该消息作为EAP身份(EAP-Identity)请求,被封装为MAC管理消息的PDU并被发送给移动终端的WiMAX协议栈。Step 401, the EAP layer in the EAP authenticator (EAP authenticator) entity of the base station sends an EAP-Request message, which is encapsulated as a PDU of the MAC management message as an EAP identity (EAP-Identity) request and sent to the mobile terminal WiMAX protocol stack.
步骤402,位于利用移动终端多模协议栈进行鉴权的装置中的鉴权执行模块102通过接口管理模块104从WiMAX协议栈的安全子层的EAP封装模块收到EAP-Request,并向上传递给EAP方法层进行处理。Step 402, the
步骤403,EAP-Request经过EAP方法层处理后,得到EAP-Response,鉴权执行模块102发送EAP-Response给WiMAX协议栈的安全子层的EAP封装模块。Step 403, after the EAP-Request is processed by the EAP method layer, an EAP-Response is obtained, and the
步骤404,EAP封装模块转发来自鉴权执行模块102的所有的EAP-Response给AAA鉴权服务器。所述AAA鉴权服务器是指通过AAA协议(如RADIUS)实现远程连接的鉴权服务器(Authentication Server)。Step 404, the EAP encapsulation module forwards all EAP-Response from the
步骤405,在AAA鉴权服务器和移动终端的鉴权执行模块102经过一次或多次EAP-Request/Response的交互后,AAA鉴权服务器决定鉴权是否成功,如果AAA鉴权服务器决定鉴权成功,转步骤406,否则转步骤408。Step 405, after one or more EAP-Request/Response interactions between the AAA authentication server and the
步骤406,AAA鉴权服务器发送EAP-Success消息给移动终端,移动终端的利用移动终端多模协议栈进行鉴权的装置收到EAP-Success消息以后完全激活无线链路,解除传输限制,同时鉴权执行模块102的EAP方法层生成共享主密钥AAA-key。Step 406, the AAA authentication server sends an EAP-Success message to the mobile terminal, and the device of the mobile terminal that utilizes the mobile terminal multimode protocol stack to perform authentication fully activates the wireless link after receiving the EAP-Success message, removes the transmission restriction, and authenticates at the same time The EAP method layer of the
步骤407,鉴权执行模块102的EAP层从EAP方法层获取AAA-key,传递给WiMAX协议栈的安全子层的密钥管理模块,执行后续的不涉及利用移动终端多模协议栈进行鉴权的装置的流程;同时把包括AAA-key在内的相关密钥通过SIM卡管理模块103保存在SIM卡中的鉴权部分。由利用移动终端多模协议栈进行鉴权的装置执行的,涉及到执行模块EAP层的WiMAX鉴权流程到此完成。Step 407, the EAP layer of the
步骤408,鉴权不成功,停止鉴权。Step 408, the authentication is unsuccessful, and the authentication is stopped.
当在UMTS & WiMAX mode进行鉴权时,其具体的鉴权流程在以下实施例中进行描述。When authentication is performed in UMTS & WiMAX mode, the specific authentication process is described in the following embodiments.
在对两个网络进行鉴权时,首先按照已有的网络鉴权流程完成第一网络的鉴权;然后,移动终端处理把接收到鉴权请求消息进行处理并生成鉴权响应消息,发送给已经完成鉴权的第一网络的网络侧,然后转发给AAA鉴权服务器;When performing authentication on two networks, first complete the authentication of the first network according to the existing network authentication process; then, the mobile terminal processes the received authentication request message and generates an authentication response message, and sends it to the already The network side of the first network that completes the authentication is then forwarded to the AAA authentication server;
根据该鉴权响应消息,在移动终端和AAA鉴权服务器同时产生主会话密钥MSK,发送给位于第一网络基站最近的第二网络的基站,建立底层链路,并在第二网络基站和移动终端产生授权密钥AK。According to the authentication response message, the mobile terminal and the AAA authentication server simultaneously generate the master session key MSK, send it to the base station of the second network that is closest to the base station of the first network, establish the underlying link, and communicate between the base station of the second network and the base station of the second network. The mobile terminal generates an authorization key AK.
在UMTS & WiMAX双模式下,根据用户设定或系统默认的接入网络的优先级,假设UMTS优先,那么首先要完成接入UMTS网络,利用移动终端多模协议栈进行鉴权的装置进行UMTS网络鉴权;完成UMTS网络接入以后,搜索WiMAX网络,执行WiMAX网络鉴权流程,UMTS&WiMAX双模式的鉴权具体流程如图8所示。In the UMTS & WiMAX dual mode, according to the priority of the access network set by the user or the system default, assuming that UMTS is prioritized, then the access to the UMTS network must be completed first, and the device using the mobile terminal multi-mode protocol stack for authentication to perform UMTS Network authentication; after completing the UMTS network access, search for the WiMAX network and execute the WiMAX network authentication process. The specific process of UMTS&WiMAX dual-mode authentication is shown in Figure 8.
当WiMAX网络和UMTS网络属于同一个运营商的情形下,两个网络共用一个AAA鉴权服务器时,可以通过UMTS接入网完成WiMAX网络的鉴权流程,其具体鉴权流程如下:When the WiMAX network and the UMTS network belong to the same operator and the two networks share an AAA authentication server, the authentication process of the WiMAX network can be completed through the UMTS access network. The specific authentication process is as follows:
步骤501,移动终端开机以后,系统读取SIM卡中的配置文件,根据配置文件中的信息,判断运营商网络允许用户通过UMTS网络完成WiMAX用户鉴权,则需要首先在UMTS网络侧的无线网络系统(RNS,Radio Network System)和移动终端之间建立无线链路。
步骤502,执行UMTS网络鉴权开始后,网络侧发送鉴权请求消息AUTHENTICATION REQEST给移动终端,开始UMTS网络鉴权。Step 502: After the UMTS network authentication starts, the network side sends an authentication request message AUTHENTICATION REQEST to the mobile terminal to start UMTS network authentication.
步骤503,移动终端完成UMTS鉴权以后,通过鉴权响应消息AUTHENTICATION RESPONSE把参数返回给网络侧,网络侧完成UMTS鉴权。
步骤502和503与情况1描述的整个UMTS的鉴权流程一致。
步骤504,UMTS网络侧查询用户签约信息以后,确认用户同时签约WiMAX的网络业务,UMTS网络侧的MSC/VLR通过MAP信令向AAA鉴权服务器发送用户标示信息(例如IMSI,International Mobile SubscriberIdentification)。Step 504, after the UMTS network side inquires about the user's subscription information, confirming that the user has signed up for the WiMAX network service at the same time, the MSC/VLR at the UMTS network side sends user identification information (such as IMSI, International Mobile SubscriberIdentification) to the AAA authentication server through MAP signaling.
步骤505,AAA鉴权服务器收到用户标示信息后进行处理,并通过MAP信令返回EAP-RESPONSE消息给MSC/VLR,EAP-RESPONSE消息的内容为TLS start,且可以表示为EAP-RESPONSE/TLS start的形式。Step 505: After receiving the user identification information, the AAA authentication server processes it, and returns an EAP-RESPONSE message to MSC/VLR through MAP signaling. The content of the EAP-RESPONSE message is TLS start, and can be expressed as EAP-RESPONSE/TLS The form of start.
所述EAP-RESPONSE/TLS start,其包含的消息是符合扩展鉴权协议的TLS start,是位于传输层的实现EAP协议的响应消息,该消息表示鉴权服务器开始对移动终端鉴权。Described EAP-RESPONSE/TLS start, the message that it contains is the TLS start that conforms to the extended authentication agreement, is the response message that realizes EAP agreement that is positioned at the transport layer, and this message indicates that the authentication server begins to authenticate the mobile terminal.
步骤506,UMTS网络侧的MSC/VLR通过扩展鉴权请求消息EAP-REQUEST/TLS start把上述的EAP-RESPONSE/TLS start消息发送给移动终端,其内容也是符合扩展鉴权协议的消息TLS start。
步骤507,移动终端中位于鉴权执行模块102的EAP方法层对上述的EAP-RESPONSE/TLS start进行处理,并通过扩展鉴权响应消息把EAP-RESPONSE/TLS ClientHello发送给UMTS网络侧的MSC/VLR;
然后MSC/VLR再使用MAP信令把上述消息发送给AAA鉴权服务器。Then the MSC/VLR uses the MAP signaling to send the above message to the AAA authentication server.
步骤508,移动终端,UMTS网络侧的MSC/VLR和AAA鉴权服务器经过多次消息发送和转发,在移动终端的利用移动终端多模协议栈进行鉴权的装置和AAA服务器上同时产生了主会话密钥(MSK,Master Session Key)。In
步骤509,AAA鉴权服务器取MSK的最高160bit作为共享主密钥(PMK,Shared Primary Master Key)发送给位于UMTS的基站最近的WiMAX基站。Step 509, the AAA authentication server takes the highest 160 bits of the MSK as a shared master key (PMK, Shared Primary Master Key) and sends it to the nearest WiMAX base station located in the UMTS base station.
在WiMAX和UMTS同属于一个运营商的情况下,尤其在UMTS和WiMAX共站址的情况下上述过程是可行的;另外,由于WiMAX基站辐射范围大于UMTS基站覆盖的地域,所以可以由UMTS基站地址确定邻近的WiMAX基站。In the case where WiMAX and UMTS belong to the same operator, especially when UMTS and WiMAX share the site, the above process is feasible; in addition, since the radiation range of the WiMAX base station is larger than the area covered by the UMTS base station, the address of the UMTS base station can Identify nearby WiMAX base stations.
步骤510,在成功的完成ranging和基本能力协商后,WiMAX基站的底层向上层的EAP authenticator实体发送一个逻辑信号“link activation”,表明底层链路已经建立。
步骤511,WiMAX基站和移动终端的利用移动终端多模协议栈进行鉴权的装置根据IEEE802.16e中的规定产生授权密钥AK。Step 511 , the WiMAX base station and the mobile terminal's authentication device using the mobile terminal's multi-mode protocol stack generate an authorization key AK according to the regulations in IEEE802.16e.
步骤512~514,完成上述步骤以后,当完成WiMAX网络切换或者网络进入的时候,基站确定自身拥有移动终端的PMK,此时基站向移动终端的利用移动终端多模协议栈进行鉴权的装置发出EAP-Establish-Key-Request消息,消息中携带本基站的Nonce随机数,并可能携带EAP-Master-Key-Id,其中携带EAP-Master-Key-Id是可选的,EAP-Master-Key-Id是代表PMK的唯一标识;随后完成安全联合(SA,Security Association)描述符分配过程。Steps 512-514, after completing the above steps, when the WiMAX network switching is completed or the network enters, the base station determines that it owns the PMK of the mobile terminal, and at this time, the base station sends an EAP-Establish-Key-Request message, the message carries the Nonce random number of the base station, and may carry EAP-Master-Key-Id, which is optional to carry EAP-Master-Key-Id, EAP-Master-Key- The Id is the unique identifier representing the PMK; then the security association (SA, Security Association) descriptor allocation process is completed.
利用移动终端多模协议栈进行鉴权的装置可以单独独立,以上描述的是利用移动终端多模协议栈进行鉴权的装置单独作为移动终端的一个独立模块时进行鉴权的流程,但是利用移动终端多模协议栈进行鉴权的装置也可以放在3G终端协议栈或WiMAX终端协议栈之内,成为其单模协议栈的一个组成部分,成为双模协议栈的一个插件(接口部件)。同时,利用移动终端多模协议栈进行鉴权的装置也可以执行通过WCDMA或者CDMA2000等3G网络执行WiMAX的鉴权。The device for authentication by using the multi-mode protocol stack of the mobile terminal can be independent. The above description is the process of authentication when the device for authentication by the multi-mode protocol stack of the mobile terminal is used as an independent module of the mobile terminal. The authentication device for the terminal multi-mode protocol stack can also be placed in the 3G terminal protocol stack or the WiMAX terminal protocol stack, and become a component of the single-mode protocol stack and a plug-in (interface component) of the dual-mode protocol stack. At the same time, the device for performing authentication by using the multi-mode protocol stack of the mobile terminal may also perform WiMAX authentication through a 3G network such as WCDMA or CDMA2000.
以上所述仅为本发明的较佳实施例而已,并不用以限制本发明;可以看出本发明通过构造一个利用移动终端多模协议栈进行鉴权的装置,实现了对UMTS模式,WiMAX模式和UMTS & WiMAX双模式这三种模式下鉴权的支持,根据使用场景自动完成两个网络的单独鉴权和联合鉴权;本发明的技术在通信领域有广泛的应用前景,因此凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。The above is only a preferred embodiment of the present invention, and is not intended to limit the present invention; it can be seen that the present invention realizes UMTS mode, WiMAX mode by constructing a device that utilizes the mobile terminal multimode protocol stack to perform authentication. and UMTS & WiMAX dual-mode authentication support in these three modes, and automatically complete the individual authentication and joint authentication of the two networks according to the usage scenario; the technology of the present invention has a wide application prospect in the communication field, so all Within the spirit and principles of the invention, any modifications, equivalent replacements, improvements, etc., shall be included in the protection scope of the present invention.
Claims (11)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN2006101651293A CN101203030B (en) | 2006-12-13 | 2006-12-13 | An authentication device and method using a mobile terminal multi-mode protocol stack |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN2006101651293A CN101203030B (en) | 2006-12-13 | 2006-12-13 | An authentication device and method using a mobile terminal multi-mode protocol stack |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN101203030A CN101203030A (en) | 2008-06-18 |
| CN101203030B true CN101203030B (en) | 2010-10-06 |
Family
ID=39517937
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN2006101651293A Active CN101203030B (en) | 2006-12-13 | 2006-12-13 | An authentication device and method using a mobile terminal multi-mode protocol stack |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN101203030B (en) |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101754443B (en) * | 2008-11-28 | 2012-09-19 | 爱思开电讯投资(中国)有限公司 | Mobile phone, intelligent card and method for using the intelligent card to control the peripheral equipment of the mobile phone |
| CN101945501A (en) * | 2010-08-05 | 2011-01-12 | 华为终端有限公司 | Method and device for realizing SIM card sharing of convergence terminal |
| CN102769850B (en) * | 2012-04-16 | 2015-10-28 | 中兴通讯股份有限公司 | Single-card multi-mode multi-operator authentication method and device |
| CN103781069B (en) * | 2012-10-19 | 2017-02-22 | 华为技术有限公司 | Bidirectional-authentication method, device and system |
| CN104184761B (en) * | 2013-05-22 | 2017-11-21 | 中国移动通信集团公司 | Mobile service confirmation method and device, service server |
| CN104182703B (en) * | 2013-05-22 | 2017-03-15 | 中国银联股份有限公司 | A kind of safety component SE steerable systems and method |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6125283A (en) * | 1998-05-18 | 2000-09-26 | Ericsson Inc. | Multi-mode mobile terminal and methods for operating the same |
| CN1549494A (en) * | 2003-05-16 | 2004-11-24 | 华为技术有限公司 | A Method for Realizing User Authentication |
| CN1561119A (en) * | 2004-03-10 | 2005-01-05 | 中国联合通信有限公司 | A network access method and device for a multi-mode mobile terminal |
| CN1874598A (en) * | 2005-12-13 | 2006-12-06 | 华为技术有限公司 | Device, system and method of authenticating when terminal to access second system network |
-
2006
- 2006-12-13 CN CN2006101651293A patent/CN101203030B/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6125283A (en) * | 1998-05-18 | 2000-09-26 | Ericsson Inc. | Multi-mode mobile terminal and methods for operating the same |
| CN1549494A (en) * | 2003-05-16 | 2004-11-24 | 华为技术有限公司 | A Method for Realizing User Authentication |
| CN1561119A (en) * | 2004-03-10 | 2005-01-05 | 中国联合通信有限公司 | A network access method and device for a multi-mode mobile terminal |
| CN1874598A (en) * | 2005-12-13 | 2006-12-06 | 华为技术有限公司 | Device, system and method of authenticating when terminal to access second system network |
Non-Patent Citations (1)
| Title |
|---|
| CN 1561119 A,全文. |
Also Published As
| Publication number | Publication date |
|---|---|
| CN101203030A (en) | 2008-06-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11895157B2 (en) | Network security management method, and apparatus | |
| JP5199405B2 (en) | Authentication in communication systems | |
| KR101068424B1 (en) | Inter-working function for a communication system | |
| US9668139B2 (en) | Secure negotiation of authentication capabilities | |
| US20200195445A1 (en) | Registration method and apparatus based on service-based architecture | |
| US20070178885A1 (en) | Two-phase SIM authentication | |
| CN1549482B (en) | A Method for Realizing High-Rate Packet Data Service Authentication | |
| CN100493247C (en) | Access authentication method in data packet network at high speed | |
| CN103402201B (en) | A kind of WiFi-WiMAX heterogeneous wireless network authentication method based on pre-authentication | |
| JP4687788B2 (en) | Wireless access system and wireless access method | |
| CN101203030B (en) | An authentication device and method using a mobile terminal multi-mode protocol stack | |
| CN101990207B (en) | Access control method, home base station (HBS) and HBS authorization server | |
| CN101877852A (en) | User access control method and system | |
| WO2006079953A1 (en) | Authentication method and device for use in wireless communication system | |
| WO2004102883A1 (en) | A kind of method to realize user authentication | |
| WO2025232244A1 (en) | Authentication method and apparatus, and communication device, storage medium and computer program product | |
| JP2024176045A (en) | COMMUNICATION SYSTEM AND AUTHENTICATION METHOD | |
| WO2024183537A1 (en) | Communication method and communication apparatus | |
| KR101068426B1 (en) | Interoperability for Communication Systems | |
| CN103874062B (en) | Access evolution HRPD eHRPD network method, system and terminal | |
| HK1072849B (en) | A method for implementing authentication of high rapidity packet data |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant |