WO2006047960A1 - Method and system for guaranteeing the privacy of the user identification - Google Patents

Method and system for guaranteeing the privacy of the user identification Download PDF

Info

Publication number
WO2006047960A1
WO2006047960A1 PCT/CN2005/001862 CN2005001862W WO2006047960A1 WO 2006047960 A1 WO2006047960 A1 WO 2006047960A1 CN 2005001862 W CN2005001862 W CN 2005001862W WO 2006047960 A1 WO2006047960 A1 WO 2006047960A1
Authority
WO
WIPO (PCT)
Prior art keywords
tid
authentication
user
bsf
identity
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2005/001862
Other languages
French (fr)
Chinese (zh)
Inventor
Yingxin Huang
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Publication of WO2006047960A1 publication Critical patent/WO2006047960A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response

Definitions

  • the present invention relates to the field of wireless communication technologies, and in particular to a method and system for ensuring the privacy of a user identity in the process of applying a universal authentication framework. Background of the invention
  • the universal authentication framework is a general structure used by various application service entities to complete the verification of the user identity, and the universal authentication framework can be used to check and verify the identity of the user of the application service.
  • the foregoing multiple application services may be a multicast/broadcast service, a user certificate service, an information immediate service, or a proxy service.
  • FIG. 1 shows the structure of the general authentication framework.
  • the universal authentication framework is generally composed of a user terminal (UE) 101, an entity performing a user identity initial check (BSF) 102, a home home network server (HSS, Home Suscriber Server) 103, and a network application entity (NAF, Network). Application Function ) 104 composition.
  • the BSF 102 is configured to perform mutual authentication with the UE 101, and simultaneously generate a shared key of the BSF 102 and the user 101.
  • the HSS 103 stores a profile file for describing user information, where the profile includes all user identifiers and the like. The related description information, while the HSS 103 also has the function of generating authentication vector information.
  • the user When the user needs to use a certain service, if it knows that it needs to first go to the BSF for mutual authentication, contact the BSF for mutual authentication. Otherwise, the user will first contact the NAF corresponding to the service, if the NAF uses universal authentication.
  • the framework finds that the requesting user has not yet authenticated to the BSF, and notifies the requesting user to the BSF for mutual authentication to verify the identity.
  • the process of the user verifying the identity to the BSF is:
  • the UE sends an authentication request to the BSF, the authentication The request message includes the user identity of the UE, and after receiving the authentication request from the user, the BSF requests the HSS for the authentication information of the user, and the request message that the BSF requests the HSS for the authentication information of the user also includes the
  • the user identity of the UE the HSS searches for the profile file of the user according to the user identity of the UE, and generates an authentication vector to return to the BSF.
  • the user identity identifier is a permanent identity of the user, and the permanent identity identifier may be an IP Multimedia Private User Identity (IMPI), or may be an IMPI converted by an International Mobile Subscriber Identity (IMSI).
  • IMPI IP Multimedia Private User Identity
  • IMSI International Mobile Subscriber Identity
  • the BSF performs an authentication and key agreement protocol (AKA) with the UE according to the obtained authentication information to perform mutual authentication. After the authentication succeeds, the UE and the BSF authenticate each other and simultaneously generate a shared key Ks.
  • the BSF defines an effective period for the shared key Ks so that the shared key Ks is updated.
  • the BSF assigns a session transaction identifier (B-TID) to the UE, the B-TID is associated with Ks, and the B-TID, the user's permanent identity, the shared key Ks, and the Ks are valid for the BSF locally.
  • B-TID session transaction identifier
  • the information is stored in association, and then the B-TID is sent to the UE, and the message sent to the UE also includes the expiration date information of the Ks.
  • the shared key Ks is used as the root key and does not leave the UE and BSF of the user. When the UE communicates with the NAF, the derived key derived from Ks will be used
  • the UE After receiving the B-TID, the UE re-issues a connection request to the NAF, and the B-TID is carried in the connection request, and the UE calculates the derived key Ks_NAF according to Ks.
  • the NAF After receiving the request, the NAF confirms that the UE is legal and obtains the derived key Ks_NAF, performs normal communication with the UE, and performs communication protection by the derived key Ks-NAF in the subsequent communication process.
  • the UE When the user finds that the shared key Ks is about to expire, or the NAF requires the UE to re-authenticate to the BSF, the UE will re-authenticate to the BSF to obtain a new Ks and B-TID.
  • the UE in the process of requesting authentication from the UE to the BSF, whether the first request authentication or the update of the shared key Ks and the B-TID is performed, the UE sends the request.
  • the authentication message contains its own permanent identity.
  • the connection between the UE and the BSF is accomplished through a wireless connection over the air interface.
  • the wireless connection is characterized by poor security and is extremely vulnerable to attack. Therefore, it is very dangerous for the UE's permanent identity to be frequently used in the air interface, which is very easy to be tracked and stolen by the attacker, and the user's permanent identity is difficult to ensure privacy. ' Invention content
  • an object of the present invention is to provide a method for ensuring the privacy of a user identity, which prevents the user identity from being frequently used and improves the privacy of the user identity.
  • Another aspect of the present invention is a system for assuring privacy of a user identity for use in implementing the above method.
  • a method for ensuring the privacy of a user identity is applicable to a process in which a UE applies a universal authentication frame for authentication, and the method includes the following steps:
  • the BSF After receiving the authentication request from the UE, the BSF determines whether the request includes the session transaction identifier B-TID or the user identity. If the B-TID is included, step b is performed, and if the user identity is included, The user identity obtains the authentication information from the HSS, and then applies the authentication information for authentication processing.
  • the BSF determines whether the B-TID exists locally. If yes, the user identity corresponding to the B-TID is extracted, and the authentication information is obtained from the home network server HSS according to the user identity, and then the authentication is applied. The information is authenticated. If not, the BSF requests the UE to send an authentication request containing the user identity.
  • the method further comprises:
  • step 02 The UE determines whether there is a B-TID in the local area, if yes, step 02), otherwise step 03); 02) sending an authentication request containing the B-TID to the BSF, and then performing step a;
  • the method further includes: determining whether the B-TID is within the validity period, and if yes, performing step 02), otherwise, performing step 03).
  • the determining of step a is performed according to the identified domain name.
  • the user identity is a user's permanent identity IMPI or a user permanent identity IMPI converted by an international mobile subscriber identity.
  • a system for ensuring privacy of a user identity comprising a UE, a BSF, and an HSS, the system further comprising an identifier selection module and an identifier recognition module;
  • the identifier selection module is configured to determine whether a B-TID is included in the UE, and notify the UE of the determined information;
  • the UE is configured to send an authentication request including a B-TID according to the received notification from the identifier selection module, or send an authentication request including the user identity identifier;
  • the identifier identifying module is configured to determine whether the identifier in the authentication request received by the BSF from the UE is a B-TID or a user identity, and notify the BSF of the determined information; if the BSF determines that the received If the B-TID is included in the authentication request, and the B-TID exists locally, the user identity corresponding to the B-TID is extracted, and the authentication information of the UE is requested from the HSS according to the user identity, and then the application is applied. The authentication information is subjected to an authentication process. If it is determined that the B-TID does not exist locally, the UE is notified to send an authentication request including the user identity.
  • the authentication information of the UE is requested from the HSS according to the user identity, and then the authentication information is applied for authentication processing.
  • the user identity is a permanent identity of the user, IMH, or a permanent identity of the user, translated by the international mobile subscriber identity code.
  • the present invention mainly sends an authentication request including a B-TID to the BSF after the UE determines that it has a B-TID, and the BSF according to the B-TID and the information that has been saved by itself.
  • the user identity corresponding to the B-TID is extracted, and the authentication information is obtained from the home network server HSS according to the user identity, and then the authentication information is applied to perform authentication processing.
  • FIG. 1 is a schematic structural diagram of an existing universal authentication framework
  • Figure 2 is a flow chart showing the application of the present invention for authentication using a universal authentication framework. Mode for carrying out the invention
  • the idea of the present invention is: after receiving the authentication request from the UE, the BSF determines whether the request includes the B-TID or the user identity, and if the user identity is included, continues the subsequent processing according to the existing processing manner; B-TID, further determining whether the B-TID exists locally, if yes, extracting the user identity corresponding to the B-TID, and obtaining authentication information from the user home network server HSS according to the user identity, and then according to the user identity
  • the existing processing mode continues the subsequent processing. Otherwise, the BSF requests the UE to send an authentication/requesting request including the user identity, and then continues the subsequent processing according to the existing processing mode.
  • FIG. 2 is a flow chart showing the application of the present invention for authentication using a universal authentication framework.
  • Step 201 Before the UE needs to go to the BSF for authentication, first check whether a B-TID exists in the local area. If not, send an authentication request message (not shown) containing the user identity to the BSF; if present, Then, it is further checked whether the Ks associated with the B-TID expires, that is, whether the B-TID is valid, and if valid, sends an authentication request message including the B-TID to the BSF, otherwise, the user identity is still sent to the BSF. Authentication request message.
  • the BSF After the BSF and the UE complete the authentication, and assign the B-TID to the UE, and set the expiration date of the key Ks associated with the B-TID, the BSF saves the B-TID before the expiration date is reached. However, when the expiration date is reached, the BSF will delete the B-TID and related information. Therefore, if the UE detects that the locally saved B-TID has expired, it still sends an authentication request message containing the user identity to the BSF.
  • the above user identity is the user's permanent identity IMPI or the user permanent identity IMPI converted by IMSI.
  • Step 202 After receiving the authentication request from the UE, the BSF determines whether the request includes the session transaction identifier B-TID or IMPI, and if it is an IMPI, sends the authentication request information including the IMPI to the HSS (not shown). If it is a B-TID, the BSF continues to determine whether the B-TID exists. If yes, step 205 is performed; otherwise, step 203 is performed.
  • the BSF can know the identity of the B-TID or IMPL after receiving the identity sent by the user.
  • the format of the B-TID and IMPI identifiers is as follows:
  • B-TID base64encode(RAND)@B SF—servers— domain— name
  • Step 203 The BSF requests the user to send an authentication request including the IMPI.
  • Step 204 The UE sends an authentication request message including an IMPI to the BSF.
  • Step 206 The HSS returns the authentication information to the BSF.
  • Step 207 The BSF applies the authentication information acquired by the HSS to the mutual authentication right of the UE that initiates the authentication request. After the authentication succeeds, the UE and the BSF mutually authenticate the identity and simultaneously generate the shared key Ks, and the BSF is this.
  • the shared key Ks defines an expiration date so that the key Ks is updated.
  • Step 208 The BSF allocates a B-TID to the UE, and the B-TID is associated with the Ks, and locally saves information about the B-TID, the user's IMPI, the shared key Ks, and the validity period of the Ks, and then Sending the B-TID to the UE, the message also includes the expiration date information of the Ks.
  • the shared key Ks is used as the root key and does not leave the user's U and BSF. When the user communicates with the NAF, the key derived from Ks will be used.
  • Step 209 After receiving the B-TID, the UE sends a connection request to the NAF, where the B-TID is carried in the request message, and the UE calculates the derived key Ks_NAF according to the Ks.
  • Step 210 After receiving the requested NAF, confirm that the UE is legal and obtain the derived key Ks_NAF, perform normal communication with the user, and perform communication protection by using the derived key Ks-NAF in the subsequent communication process.
  • the user can initiate the authentication process again before the UE expires, so as to obtain a new B-TID and Ks. If the user does not re-authenticate within the validity period of the local B-TID because it is shut down or not in the service area, in the re-authentication process, the authentication request including the IMPI can only be sent to the BSF, because the BSF is likely to have already Delete the expired B-TID. If the NAF notifies the user for re-authentication for security reasons, at this time, if the B-TID in the UE is still within the validity period, the UE can still send an authentication request including the B-TID to the BSF.
  • the BSF receives the authentication request including the B-TID, extracts the IMPI corresponding to the B-TID, and sends the authentication request information including the ⁇ to the HSS;
  • the BSF may also receive the error message from the HSS, or the BSF may also receive the authentication information from the HSS, but for some reason it cannot be successfully mutually authenticated with the UE, and it is possible that it exists.
  • the subsequent specific processing methods are the same as the existing processing methods, and are not described here.
  • the present invention further provides a system for ensuring privacy of a user identity, the system includes not only a UE, a BSF, and an HSS, but also an identifier selection module and an identifier identification module.
  • the identifier selection module is configured to determine whether the UE is included in the UE. ⁇ - ⁇ ), and notify the UE of the determined information;
  • the foregoing UE is configured to send, according to the received notification from the identifier selection module, an authentication request including a B-TID, or send an authentication request including a user identity identifier;
  • the identifier identifying module is configured to determine whether the identifier in the authentication request received by the BSF from the UE is a B-TID or a user identity, and notify the BSF of the determined information; if the BSF determines the received authentication If the B-TID is included in the request, and the B-TID exists locally, the user identity corresponding to the B-TID is extracted, and the authentication information of the UE is requested from the HSS according to the user identity, and then the authentication is applied. The information is subjected to an authentication process. If it is determined that the B-TID does not exist locally, the UE is notified to send an authentication request including the user identity.
  • the BSF if it is determined that the received authentication request includes the user identity, requests the authentication information of the UE from the HSS according to the user identity, and then applies the authentication information to perform authentication processing.
  • the user identity identifier is the user's permanent identity IMPI or the user permanent identity IMPL converted by the international mobile subscriber identity code.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

A method and system for guaranteeing the privacy of user identification, the key is, after judging that it has its own B-TID, the UE sends the authentication request containing the B-TID to BSF. BSF extracts the user identification corresponding to the B-TID according to the B-TID and the information stored in itself, obtains the authentication information from the user home network server HSS according to the user identification, and performs the authentication process with the authentication information. With the method and system of the invention, it could reduce the times of using user identification and avoid the probability of tracking user identification, while increasing the security of the user identification at the air interfaces, thus guaranteeing the privacy of the user identification.

Description

一种保证用户身份标识私密性的方法和系统  Method and system for guaranteeing privacy of user identity

技术领域 Technical field

本发明涉及无线通信技术领域, 特别是指在应用通用鉴权框架过程 中, 一种保证用户身份标识私密性的方法和系统。 发明背景  The present invention relates to the field of wireless communication technologies, and in particular to a method and system for ensuring the privacy of a user identity in the process of applying a universal authentication framework. Background of the invention

在无线通信标准中, 通用鉴权框架是多种应用业务实体使用的一个 用于完成对用户身份进行验证的通用结构, 应用通用鉴权框架可实现对 应用业务的用户进行检查和验证身份。 上述多种应用业务可以是多播 / 广播业务、 用户证书业务、 信息即时提供业务等, 也可以是代理业务。  In the wireless communication standard, the universal authentication framework is a general structure used by various application service entities to complete the verification of the user identity, and the universal authentication framework can be used to check and verify the identity of the user of the application service. The foregoing multiple application services may be a multicast/broadcast service, a user certificate service, an information immediate service, or a proxy service.

图 1所示为通用鉴权框架的结构示意图。 通用鉴权框架通常由用户 终端( UE ) 101、执行用户身份初始检查验证的实体( BSF, Bootstrapping Server Function ) 102、用户归属网络服务器( HSS , Home Suscriber Server ) 103和网络应用实体 ( NAF, Network Application Function ) 104组成。 BSF 102用于与 UE101进行互验证身份, 同时生成 BSF 102与用户 101 的共享密钥; HSS 103 中存储有用于描述用户信息的描述(Profile )文 件, 该 Profile中包括用户身份标识等所有与用户有关的描述信息, 同时 HSS 103还兼有产生鉴权矢量信息的功能。  Figure 1 shows the structure of the general authentication framework. The universal authentication framework is generally composed of a user terminal (UE) 101, an entity performing a user identity initial check (BSF) 102, a home home network server (HSS, Home Suscriber Server) 103, and a network application entity (NAF, Network). Application Function ) 104 composition. The BSF 102 is configured to perform mutual authentication with the UE 101, and simultaneously generate a shared key of the BSF 102 and the user 101. The HSS 103 stores a profile file for describing user information, where the profile includes all user identifiers and the like. The related description information, while the HSS 103 also has the function of generating authentication vector information.

用户需要使用某种业务时,如果其知道需要首先到 BSF进行互鉴权 过程, 则与 BSF联系进行互鉴权, 否则, 用户会首先和该业务对应的 NAF联系, 如果该 NAF使用通用鉴权框架, 并且发现发出请求的用户 还未到 BSF进行互鉴权, 则通知发出请求的用户到 BSF进行互鉴权以 验证身份。  When the user needs to use a certain service, if it knows that it needs to first go to the BSF for mutual authentication, contact the BSF for mutual authentication. Otherwise, the user will first contact the NAF corresponding to the service, if the NAF uses universal authentication. The framework, and finds that the requesting user has not yet authenticated to the BSF, and notifies the requesting user to the BSF for mutual authentication to verify the identity.

用户到 BSF验证身份的过程是: UE向 BSF发出鉴权请求, 该鉴权 请求消息中包括 UE的用户身份标识, BSF接到来自用户的鉴权请求后, 向 HSS请求该用户的鉴权信息, 该 BSF向 HSS请求该用户的鉴权信息 的请求消息中也包含了该 UE的用户身份标识, HSS根据该 UE的用户 身份标识查找到该用户的 profile文件并且生成鉴权矢量返回给 BSF。上 述用户身份标识是用户的永久身份标识,该永久身份标识可以是 IP多媒 体私有用户标识(IMPI ), 也可以是由国际移动用户识别码 (IMSI )转 换得到的 IMPI。 The process of the user verifying the identity to the BSF is: The UE sends an authentication request to the BSF, the authentication The request message includes the user identity of the UE, and after receiving the authentication request from the user, the BSF requests the HSS for the authentication information of the user, and the request message that the BSF requests the HSS for the authentication information of the user also includes the The user identity of the UE, the HSS searches for the profile file of the user according to the user identity of the UE, and generates an authentication vector to return to the BSF. The user identity identifier is a permanent identity of the user, and the permanent identity identifier may be an IP Multimedia Private User Identity (IMPI), or may be an IMPI converted by an International Mobile Subscriber Identity (IMSI).

BSF根据所获取的鉴权信息与 UE之间执行鉴权和密钥协商协议 ( AKA ), 以进行互鉴权。 鉴权成功后, UE和 BSF之间互相认证了身 份并且同时生成了共享密钥 Ks, BSF为这个共享密钥 Ks定义了一个有 效期限, 以便共享密钥 Ks进行更新。 之后, BSF分配一个会话事务标 识( B-TID )给 UE,该 B-TID与 Ks相关联, 并在 BSF本地对该 B-TID、 用户的永久身份标识、共享密钥 Ks及 Ks的有效期限等信息进行关联保 存, 然后再将该 B-TID发送给 UE, 该发送给 UE的消息中同时包含了 Ks的有效期限信息。 共享密钥 Ks是作为根密钥来使用的, 不会离开用 户的 UE和 BSF, 当 UE和 NAF通信时, 将使用由 Ks衍生出的衍生密 钥。  The BSF performs an authentication and key agreement protocol (AKA) with the UE according to the obtained authentication information to perform mutual authentication. After the authentication succeeds, the UE and the BSF authenticate each other and simultaneously generate a shared key Ks. The BSF defines an effective period for the shared key Ks so that the shared key Ks is updated. Thereafter, the BSF assigns a session transaction identifier (B-TID) to the UE, the B-TID is associated with Ks, and the B-TID, the user's permanent identity, the shared key Ks, and the Ks are valid for the BSF locally. The information is stored in association, and then the B-TID is sent to the UE, and the message sent to the UE also includes the expiration date information of the Ks. The shared key Ks is used as the root key and does not leave the UE and BSF of the user. When the UE communicates with the NAF, the derived key derived from Ks will be used.

UE收到这个 B-TID后, 重新向 NAF发出连接请求, 该连接请求中携 带了该 B-TID, 同时 UE根据 Ks计算出衍生密钥 Ks— NAF。接收到请求的 NAF确认该 UE合法且获得了衍生密钥 Ks— NAF后, 与该 UE进行正常的 通信, 且在后面的通信过程中通过衍生密钥 Ks— NAF进行通信保护。  After receiving the B-TID, the UE re-issues a connection request to the NAF, and the B-TID is carried in the connection request, and the UE calculates the derived key Ks_NAF according to Ks. After receiving the request, the NAF confirms that the UE is legal and obtains the derived key Ks_NAF, performs normal communication with the UE, and performs communication protection by the derived key Ks-NAF in the subsequent communication process.

当用户发现共享密钥 Ks即将过期, 或 NAF要求 UE重新到 BSF进 行鉴权时, UE就会重新到 BSF进行鉴权, 以得到新的 Ks及 B-TID。  When the user finds that the shared key Ks is about to expire, or the NAF requires the UE to re-authenticate to the BSF, the UE will re-authenticate to the BSF to obtain a new Ks and B-TID.

由上述过程可知, 在 UE向 BSF请求鉴权的过程中, 不论是首次请 求鉴权还是为了更新共享密钥 Ks及 B-TID进行鉴权, 在 UE发送的请 求鉴权的消息中都包含了自己永久身份标识。 而 UE和 BSF之间的连接 是通过空中接口的无线连接来完成的, 无线连接的特点就是安全性很差 极容易被攻击。 因此 UE的永久身份标识在空中接口被频繁的使用是很 危险的, 极容易被攻击者跟踪、 窃取, 用户的永久身份标识很难保证私. 密性。 ' 发明内容 According to the above process, in the process of requesting authentication from the UE to the BSF, whether the first request authentication or the update of the shared key Ks and the B-TID is performed, the UE sends the request. The authentication message contains its own permanent identity. The connection between the UE and the BSF is accomplished through a wireless connection over the air interface. The wireless connection is characterized by poor security and is extremely vulnerable to attack. Therefore, it is very dangerous for the UE's permanent identity to be frequently used in the air interface, which is very easy to be tracked and stolen by the attacker, and the user's permanent identity is difficult to ensure privacy. ' Invention content

有鉴于此, 本发明的一个目的在于提供一种保证用户身份标识私密 性的方法,避免用户身份标识被频繁使用,提高用户身份标识的私密性。  In view of this, an object of the present invention is to provide a method for ensuring the privacy of a user identity, which prevents the user identity from being frequently used and improves the privacy of the user identity.

本发明的另一个 ϋ的在于一种用于保证用户身份标识私密性的系 统, 以用于实现上述方法。  Another aspect of the present invention is a system for assuring privacy of a user identity for use in implementing the above method.

为达到上述目的, 本发明的技术方案是这样实现的:  In order to achieve the above object, the technical solution of the present invention is achieved as follows:

一种保证用户身份标识私密性的方法, 适用于 UE应用通用鉴权框 架进行鉴权的过程, 该方法包括以下步驟:  A method for ensuring the privacy of a user identity is applicable to a process in which a UE applies a universal authentication frame for authentication, and the method includes the following steps:

a、 BSF接收到来自 UE的鉴权请求后, 判断该请求中是包含会话事 务标识 B-TID还是用户身份标识, 如果包含 B-TID, 则执行步骤 b, 如 果包含用户身份标识, 则根据该用户身份标识从 HSS中获取鉴权信息, 然后应用该鉴权信息进行鉴权处理。  After receiving the authentication request from the UE, the BSF determines whether the request includes the session transaction identifier B-TID or the user identity. If the B-TID is included, step b is performed, and if the user identity is included, The user identity obtains the authentication information from the HSS, and then applies the authentication information for authentication processing.

b、 BSF 判断本地是否存在该 B-TID, 如果存在, 则提取该 B-TID 对应的用户身份标识, 并根据该用户身份标识从用户归属网络服务器 HSS中获取鉴权信息,然后应用该鉴权信息进行鉴权处理,如果不存在, 则 BSF要求 UE发送包含用户身份标识的鉴权请求。  b. The BSF determines whether the B-TID exists locally. If yes, the user identity corresponding to the B-TID is extracted, and the authentication information is obtained from the home network server HSS according to the user identity, and then the authentication is applied. The information is authenticated. If not, the BSF requests the UE to send an authentication request containing the user identity.

较佳地, 该方法进一步包括:  Preferably, the method further comprises:

01 ) UE判断本地是否存在 B-TID, 如果存在, 则执行步骤 02 ), 否 则执行步骤 03 ); 02 ) 向 BSF发送包含 B-TID的鉴权请求, 然后执行步骤 a; 01) The UE determines whether there is a B-TID in the local area, if yes, step 02), otherwise step 03); 02) sending an authentication request containing the B-TID to the BSF, and then performing step a;

03 ) 向 BSF发送包含用户身份标识的鉴权请求, 然后执行步骤 a。 较佳地 , UE判断出本地存在 B-TID后,进一步包括: 判断该 B-TID 是否处于有效期之内, 如果是, 再执行步骤 02 ), 否则, 执行步骤 03 )。  03) Send an authentication request containing the user identity to the BSF, and then perform step a. Preferably, after the UE determines that the B-TID exists locally, the method further includes: determining whether the B-TID is within the validity period, and if yes, performing step 02), otherwise, performing step 03).

较佳地, 步骤 a所述判断是根据标识的域名进行识别的。  Preferably, the determining of step a is performed according to the identified domain name.

较佳地, 所述用户身份标识是用户的永久身份标识 IMPI或由国际 移动用户识別码转换得到的用户永久身份标识 IMPI。  Preferably, the user identity is a user's permanent identity IMPI or a user permanent identity IMPI converted by an international mobile subscriber identity.

一种用于保证用户身份标识私密性的系统, 该系统包括 UE、 BSF 和 HSS, 该系统还包括标识选择模块和标识识别模块;  A system for ensuring privacy of a user identity, the system comprising a UE, a BSF, and an HSS, the system further comprising an identifier selection module and an identifier recognition module;

所述标识选择模块, 用于确定 UE内是否包含 B-TID, 并将所确定 的信息通知给 UE;  The identifier selection module is configured to determine whether a B-TID is included in the UE, and notify the UE of the determined information;

所述 UE, 用于根据接收到的来自标识选择模块的通知, 发送包含 B-TID的鉴权请求, 或者, 发送包含用户身份标识的鉴权请求;  The UE is configured to send an authentication request including a B-TID according to the received notification from the identifier selection module, or send an authentication request including the user identity identifier;

所述标识识别模块, 用于确定 BSF接收到的来自 UE的鉴权请求中 的标识是 B-TID还是用户身份标识, 并将所确定的信息通知给 BSF; 所述 BSF, 如果确定接收到的鉴权请求中包含 B-TID, 且确定本地 存在该 B-TID, 则提取该 B-TID对应的用户身份标识, 并根据该用户身 份标识向 HSS中请求该 UE的鉴权信息, 然后应用该鉴权信息进行鉴权 处理, 如果确定本地不存在该 B-TID, 通知 UE发送包含用户身份标识 的鉴权请求;  The identifier identifying module is configured to determine whether the identifier in the authentication request received by the BSF from the UE is a B-TID or a user identity, and notify the BSF of the determined information; if the BSF determines that the received If the B-TID is included in the authentication request, and the B-TID exists locally, the user identity corresponding to the B-TID is extracted, and the authentication information of the UE is requested from the HSS according to the user identity, and then the application is applied. The authentication information is subjected to an authentication process. If it is determined that the B-TID does not exist locally, the UE is notified to send an authentication request including the user identity.

如果确定接收到的鉴权请求中包含用户身份标识, 根据该用户身份 标识向 HSS中请求该 UE的鉴权信息, 然后应用该鉴权信息进行鉴权处 理。  If it is determined that the received authentication request includes the user identity, the authentication information of the UE is requested from the HSS according to the user identity, and then the authentication information is applied for authentication processing.

较佳地 , 所述用户身份标识是用户的永久身份标识 IMH或由国际 移动用户识别码转换得到的用户永久身份标识 IMPL 与现有技术相比,由于本发明主要是在 UE判断出自身有 B-TID后, 将包含 B-TID的鉴权请求发送给 BSF, 而 BSF则根据该 B-TID以及自 身已保存的信息提取该 B-TID对应的用户身份标识, 并根据该用户身份 标识从用户归属网络服务器 HSS中获取鉴权信息,然后应用该鉴权信息 进行鉴权处理。 应用本发明所述方法和系统, 减少了用户身份标识的使 用次数, 避免了用户身份标识被追踪的可能, 提高了用户身份标识在空 中接口的安全性, 从而保证了用户身份标识的私密性。 附图简要说明 Preferably, the user identity is a permanent identity of the user, IMH, or a permanent identity of the user, translated by the international mobile subscriber identity code. Compared with the prior art, the present invention mainly sends an authentication request including a B-TID to the BSF after the UE determines that it has a B-TID, and the BSF according to the B-TID and the information that has been saved by itself. The user identity corresponding to the B-TID is extracted, and the authentication information is obtained from the home network server HSS according to the user identity, and then the authentication information is applied to perform authentication processing. By applying the method and system of the invention, the number of times of using the user identity is reduced, the possibility that the user identity is tracked is avoided, the security of the user identity on the air interface is improved, and the privacy of the user identity is ensured. BRIEF DESCRIPTION OF THE DRAWINGS

图 1所示为现有通用鉴权框架的结构示意图;  FIG. 1 is a schematic structural diagram of an existing universal authentication framework;

图 2 所示为应用本发明的使用通用鉴权框架进行鉴权的流程示意 图。 实施本发明的方式  Figure 2 is a flow chart showing the application of the present invention for authentication using a universal authentication framework. Mode for carrying out the invention

为使本发明的目的、 技术方案及有益效果更加清楚, 下面结合具体 实施方式与附图对发明做进一步地详细描述。  In order to make the objects, technical solutions and advantageous effects of the present invention more clear, the invention will be further described in detail below with reference to the specific embodiments and drawings.

本发明的思路是: BSF接收到来自 UE的鉴权请求后, 判断该请求 中是包含 B-TID还是用户身份标识, 如果包含用户身份标识, 则按照现 有的处理方式继续后续处理; 如果包含 B-TID, 则进一步判断本地是否 存在该 B-TID, 如果存在, 则提取该 B-TID对应的用户身份标识, 并根 据该用户身份标识从用户归属网络服务器 HSS中获取鉴权信息,然后按 照现有的处理方式继续后续处理, 否则, BSF要求 UE发送包含用户身 份标识的鉴权 ·清求, 然后按照现有的处理方式继续后续处理。  The idea of the present invention is: after receiving the authentication request from the UE, the BSF determines whether the request includes the B-TID or the user identity, and if the user identity is included, continues the subsequent processing according to the existing processing manner; B-TID, further determining whether the B-TID exists locally, if yes, extracting the user identity corresponding to the B-TID, and obtaining authentication information from the user home network server HSS according to the user identity, and then according to the user identity The existing processing mode continues the subsequent processing. Otherwise, the BSF requests the UE to send an authentication/requesting request including the user identity, and then continues the subsequent processing according to the existing processing mode.

图 2 所示为应用本发明的使用通用鉴权框架进行鉴权的流程示意 图。 步骤 201 , 当 UE需要到 BSF进行鉴权前, 首先检查本地是否已经 存在一个 B-TID, 如果不存在, 则给 BSF发送包含用户身份标识的鉴权 请求消息(图未示); 如果存在, 则进一步检查该 B-TID相关联的 Ks是 否到期, 即该 B-TID是否有效, 如果有效, 则给 BSF发送包含 B-TID 的鉴权请求消息, 否则, 仍旧给 BSF发送包含用户身份标识的鉴权请求 消息。 Figure 2 is a flow chart showing the application of the present invention for authentication using a universal authentication framework. Step 201: Before the UE needs to go to the BSF for authentication, first check whether a B-TID exists in the local area. If not, send an authentication request message (not shown) containing the user identity to the BSF; if present, Then, it is further checked whether the Ks associated with the B-TID expires, that is, whether the B-TID is valid, and if valid, sends an authentication request message including the B-TID to the BSF, otherwise, the user identity is still sent to the BSF. Authentication request message.

在 BSF和 UE完成鉴权, 并给 UE分配了 B-TID, 同时设置了与该 B-TID相关联的密钥 Ks的有效期限后, 在该有效期限达到之前 BSF都 会保存该 B-TID, 但当有效期限到达后, BSF将删除该 B-TID及相关信 息, 因此, 如果 UE检测出本地保存的 B-TID已失效, 仍要给 BSF发送 包含用户身份标识的鉴权请求消息。  After the BSF and the UE complete the authentication, and assign the B-TID to the UE, and set the expiration date of the key Ks associated with the B-TID, the BSF saves the B-TID before the expiration date is reached. However, when the expiration date is reached, the BSF will delete the B-TID and related information. Therefore, if the UE detects that the locally saved B-TID has expired, it still sends an authentication request message containing the user identity to the BSF.

上述用户身份标识是用户的永久身份标识 IMPI或由 IMSI转换得到 的用户永久身份标识 IMPI。  The above user identity is the user's permanent identity IMPI or the user permanent identity IMPI converted by IMSI.

步驟 202, BSF接收到来自 UE的鉴权请求后, 判断该请求中是包 含会话事务标识 B-TID还是 IMPI, 如果是 IMPI, 则向 HSS发送包含该 IMPI的鉴权请求信息(图未示); 如果是 B-TID, 则 BSF继续判断自身 是否存在该 B-TID, 如果存在, 则执行步骤 205 , 否则, 执行步骤 203。  Step 202: After receiving the authentication request from the UE, the BSF determines whether the request includes the session transaction identifier B-TID or IMPI, and if it is an IMPI, sends the authentication request information including the IMPI to the HSS (not shown). If it is a B-TID, the BSF continues to determine whether the B-TID exists. If yes, step 205 is performed; otherwise, step 203 is performed.

由于 B-TID与用户身份标识的域名不同,所以 BSF在收到用户发送 的标识后就能够知道该标识 B-TID还是 IMPL 通常, B-TID和 IMPI的 标识的格式如下:  Since the B-TID is different from the domain name of the user identity, the BSF can know the identity of the B-TID or IMPL after receiving the identity sent by the user. Generally, the format of the B-TID and IMPI identifiers is as follows:

B-TID: base64encode(RAND)@B SF—servers— domain— name  B-TID: base64encode(RAND)@B SF—servers— domain— name

IMPI : 用 户 @MNC.MCC.IMSI.3gppnetwork.org 或 者 用 户 @MNC .MCC .3 gppnetwork. org  IMPI : User @MNC.MCC.IMSI.3gppnetwork.org or User @MNC .MCC .3 gppnetwork. org

步骤 203 , BSF要求用户发送包含 IMPI的鉴权请求。  Step 203: The BSF requests the user to send an authentication request including the IMPI.

步骤 204 , UE给 BSF发送包含 IMPI的鉴权请求消息。 步骤 205,如果 BSF接收到包含 B-TID的鉴权请求, 则 BSF根据本 地管理保存的 B-TID、 用户的 IMPI、 密钥 Ks及密钥 Ks的有效期限的 信息对应关系, 提取该 B-TID对应的 IMPI, 并向 HSS发送包含 IMPI 的鉴权请求信息; 如果 BSF接收到包含 IMPI的鉴权请求, 则向 HSS发 送包含 IMPI的鉴权请求信息。 Step 204: The UE sends an authentication request message including an IMPI to the BSF. Step 205: If the BSF receives the authentication request including the B-TID, the BSF extracts the B- according to the information correspondence between the B-TID saved by the local management, the IMPI of the user, the key Ks, and the expiration date of the key Ks. The IMPI corresponding to the TID, and sending the authentication request information including the IMPI to the HSS; if the BSF receives the authentication request including the IMPI, sending the authentication request information including the IMPI to the HSS.

步骤 206, HSS给 BSF返回鉴权信息。  Step 206: The HSS returns the authentication information to the BSF.

步骤 207, BSF应用从 HSS获取的鉴权信息与发起鉴权请求的 UE 进行互鉴权, 鉴权成功后, UE和 BSF之间互相认证了身份并且同时生 成了共享密钥 Ks, BSF为这个共享密钥 Ks定义了一个有效期限, 以便 密钥 Ks进行更新。  Step 207: The BSF applies the authentication information acquired by the HSS to the mutual authentication right of the UE that initiates the authentication request. After the authentication succeeds, the UE and the BSF mutually authenticate the identity and simultaneously generate the shared key Ks, and the BSF is this. The shared key Ks defines an expiration date so that the key Ks is updated.

步骤 208, BSF分配一个 B-TID给 UE, 该 B-TID与 Ks相关联, 并 在本地对该 B-TID、 用户的 IMPI、 共享密钥 Ks及 Ks的有效期限等信 息进行关联保存, 之后, 将该 B-TID发送给 UE, 该消息中同时包含了 Ks的有效期限信息。 共享密钥 Ks是作为根密钥来使用的, 不会离开用 户的 U 和 BSF, 当用户和 NAF通信时, 将使用由 Ks衍生出的密钥。  Step 208: The BSF allocates a B-TID to the UE, and the B-TID is associated with the Ks, and locally saves information about the B-TID, the user's IMPI, the shared key Ks, and the validity period of the Ks, and then Sending the B-TID to the UE, the message also includes the expiration date information of the Ks. The shared key Ks is used as the root key and does not leave the user's U and BSF. When the user communicates with the NAF, the key derived from Ks will be used.

步骤 209, UE收到这个 B-TID后, 重新向 NAF发出连接请求, 该 请求消息中携带了该 B-TID,同时 UE根据 Ks计算出衍生密钥 Ks— NAF。  Step 209: After receiving the B-TID, the UE sends a connection request to the NAF, where the B-TID is carried in the request message, and the UE calculates the derived key Ks_NAF according to the Ks.

步骤 210, 接收到请求的 NAF确认该 UE合法且获得了衍生密钥 Ks— NAF后, 与该用户进行正常的通信, 且在后面的通信过程中通过衍 生密钥 Ks— NAF进行通信保护。  Step 210: After receiving the requested NAF, confirm that the UE is legal and obtain the derived key Ks_NAF, perform normal communication with the user, and perform communication protection by using the derived key Ks-NAF in the subsequent communication process.

为了不影响用户正常使用业务,用户可以通过 UE在 Ks的有效期到 达之前再次发起鉴权过程, 以便得到新的 B-TID及 Ks。 如果用户因为 关机或不在服务区而没有在本地 B-TID的有效期内及时进行重鉴权, 则 在再次鉴权过程中,只能向 BSF发送包含 IMPI的鉴权请求, 因为, BSF 很可能已经将到期的 B-TID删除。 如果 NAF出于安全的原因通知用户进行重鉴权, 此时, 如果该 UE 内的 B-TID仍在有效期内,则该 UE仍然可以向 BSF发送包含 B-TID的 鉴权请求。 In order not to affect the normal use of the service by the user, the user can initiate the authentication process again before the UE expires, so as to obtain a new B-TID and Ks. If the user does not re-authenticate within the validity period of the local B-TID because it is shut down or not in the service area, in the re-authentication process, the authentication request including the IMPI can only be sent to the BSF, because the BSF is likely to have already Delete the expired B-TID. If the NAF notifies the user for re-authentication for security reasons, at this time, if the B-TID in the UE is still within the validity period, the UE can still send an authentication request including the B-TID to the BSF.

以上是以鉴权成功为例进行说明的, 当然, 如果 BSF接收到包含 B-TID的鉴权请求, 提取出该 B-TID对应的 IMPI, 并向 HSS发送包含 ΪΜΡΙ的鉴权请求信息; 之后, BSF也可能接收到来自 HSS错误信息, 或者, BSF也可能接收到来自 HSS的鉴权信息后,但因为某种原因而不 能与 UE进行成功地互鉴权, 都是有可能存在的, 其后续的具体的处理 方式均与现有的处理方式相同, 在此不再赘述。  The above is described by taking the authentication success as an example. Of course, if the BSF receives the authentication request including the B-TID, extracts the IMPI corresponding to the B-TID, and sends the authentication request information including the ΪΜΡΙ to the HSS; The BSF may also receive the error message from the HSS, or the BSF may also receive the authentication information from the HSS, but for some reason it cannot be successfully mutually authenticated with the UE, and it is possible that it exists. The subsequent specific processing methods are the same as the existing processing methods, and are not described here.

本发明还提供了一种用于保证用户身份标识私密性的系统, 该系统 不但包括 UE、 BSF和 HSS, 还包括标识选择模块和标识识别模块; 上述标识选择模块, 用于确定 UE内是否包含 Β-ΉΕ), 并将所确定 的信息通知给 UE;  The present invention further provides a system for ensuring privacy of a user identity, the system includes not only a UE, a BSF, and an HSS, but also an identifier selection module and an identifier identification module. The identifier selection module is configured to determine whether the UE is included in the UE. Β-ΉΕ), and notify the UE of the determined information;

上述 UE, 用于根据接收到的来自标识选择模块的通知, 发送包含 B-TID的鉴权请求, 或者, 发送包含用户身份标识的鉴权请求;  The foregoing UE is configured to send, according to the received notification from the identifier selection module, an authentication request including a B-TID, or send an authentication request including a user identity identifier;

上述标识识别模块, 用于确定 BSF接收到的来自 UE的鉴权请求中 的标识是 B-TID还是用户身份标识, 并将所确定的信息通知给 BSF; 上述 BSF, 如果确定接收到的鉴权请求中包含 B-TID, 且确定本地 存在该 B-TID , 则提取该 B-TID对应的用户身份标识, 并根据该用户身 份标识向 HSS中请求该 UE的鉴权信息, 然后应用该鉴权信息进行鉴权 处理, 如果确定本地不存在该 B-TID, 通知 UE发送包含用户身份标识 的鉴权请求;  The identifier identifying module is configured to determine whether the identifier in the authentication request received by the BSF from the UE is a B-TID or a user identity, and notify the BSF of the determined information; if the BSF determines the received authentication If the B-TID is included in the request, and the B-TID exists locally, the user identity corresponding to the B-TID is extracted, and the authentication information of the UE is requested from the HSS according to the user identity, and then the authentication is applied. The information is subjected to an authentication process. If it is determined that the B-TID does not exist locally, the UE is notified to send an authentication request including the user identity.

上述 BSF, 如果确定接收到的鉴权请求中包含用户身份标识, 则根 据该用户身份标识向 HSS中请求该 UE的鉴权信息, 然后应用该鉴权信 息进行鉴权处理。 上述用户身份标识是用户的永久身份标识 IMPI或由国际移动用户 识别码转换得到的用户永久身份标识 IMPL The BSF, if it is determined that the received authentication request includes the user identity, requests the authentication information of the UE from the HSS according to the user identity, and then applies the authentication information to perform authentication processing. The user identity identifier is the user's permanent identity IMPI or the user permanent identity IMPL converted by the international mobile subscriber identity code.

以上所述仅为本发明的较佳实施例而已 , 并不用以限制本发明, 凡 在本发明的精神和原则之内, 所作的任何修改、 等同替换、 改进等, 均 应包含在本发明的保护范围之内。  The above is only the preferred embodiment of the present invention, and is not intended to limit the present invention. Any modifications, equivalents, improvements, etc., which are included in the spirit and scope of the present invention, should be included in the present invention. Within the scope of protection.

Claims

权利要求书 Claim 1、一种保证用户身份标识私密性的方法,适用于用户终端 UE应用 通用鉴权框架进行鉴权的过程, 其特征在于, 该方法包括以下步骤: a、 BSF接收到来自 UE的鉴权请求后, 判断该请求中是包含会话事 务标识 B-TID还是用户身份标识, 如果包含 B-TID, 则执行步骤 b, 如 果包含用户身份标识, 则根据该用户身份标识向用户归属网络服务器 HSS请求该 UE的鉴权信息,然后应用该鉴权信息进行鉴权处理,结束; b、 BSF判断本地是否存在该 B-TID, 如果存在, 则提取该 B-TID 对应的用户身份标识, 并根据该用户身份标识向 HSS中请求该 UE的鉴 权信息, 然后应用该鉴权信息进行鉴权处理, 如果不存在, 则 BSF要求 UE发送包含用户身份标识的鉴权请求。  A method for ensuring the privacy of a user identity, which is applicable to a process in which a user terminal UE applies a universal authentication framework for authentication, and the method includes the following steps: a. The BSF receives an authentication request from the UE. After determining whether the request includes the session transaction identifier B-TID or the user identity, if the B-TID is included, step b is performed, and if the user identity is included, requesting the user home network server HSS according to the user identity The authentication information of the UE is then applied to the authentication process and ends; b. The BSF determines whether the B-TID exists locally, and if so, extracts the user identity corresponding to the B-TID, and according to the user The identity requesting the authentication information of the UE from the HSS, and then applying the authentication information to perform authentication processing. If not, the BSF requests the UE to send an authentication request including the user identity. 2、 根据权利要求 1所述的方法, 其特征在于, 该方法进一步包括: 2. The method according to claim 1, wherein the method further comprises: 01 ) UE判断本地是否存在 B-TID, 如果存在, 则执行步骤 02 ), 否 则执行步骤 03 ); 01) The UE determines whether there is a B-TID in the local area, if yes, step 02), otherwise, step 03); 02 ) 向 BSF发送包含 B-TID的鉴权请求, 然后执行步骤 a;  02) Send an authentication request containing the B-TID to the BSF, and then perform step a; 03 ) 向 BSF发送包含用户身份标识的鉴权请求, 然后执行步骤 a。 03) Send an authentication request containing the user identity to the BSF, and then perform step a. 3、 根据权利要求 2所述的方法, 其特征在于, UE判断出本地存在 B-TID后, 进一步包括: 判断该 B-TID是否处于有效期之内, 如果是, 再执行步骤 02 ), 否则, 执行步骤 03 )。 The method according to claim 2, wherein after the UE determines that the B-TID exists locally, the method further includes: determining whether the B-TID is within a valid period, and if yes, performing step 02), otherwise, Go to step 03). 4、根据权利要求 1所述的方法, 其特征在于, 步骤 a所述判断是根 据标识的域名进行识别的。  The method according to claim 1, wherein the determining of the step a is performed based on the identified domain name. 5、 根据权利要求 1 所述的方法, 其特征在于, 所述用户身份标识是用 户的永久身份标识 IMPI或由国际移动用户识别码转换得到的用户永久身份 标识 IMPL 5. The method according to claim 1, wherein the user identity is a permanent identity of the user, IMPI, or a permanent identity of the user, translated by the international mobile subscriber identity. 6、一种用于保证用户身份标识私密性的系统,该系统包括 UE、 BSF 和 HSS, 其特征在于, 该系统还包括标识选择模块和标识识别模块; 所述标识选择 用于确定 UE内是否包含 B-TID, 并将所确定的信 息通知给 UE; . A system for ensuring privacy of a user identity, the system comprising a UE, a BSF, and an HSS, wherein the system further includes an identifier selection module and an identifier identification module; Contains the B-TID and notifies the UE of the determined information; 所述 UE,用于根据接收到的来自标识选择模块的通知,发送包含 B-TID 的鉴权请求, 或者, 发送包含用户身份标识的鉴权请求;  The UE is configured to send an authentication request including a B-TID according to the received notification from the identifier selection module, or send an authentication request including the user identity identifier; 所述标识识别模块,用于确定 BSF接收到的来自 UE的鉴权请求中的标 识是 B-TID还是用户身份标识, 并将所确定的信息通知给 BSF;  The identifier identifying module is configured to determine whether the identifier in the authentication request received by the BSF from the UE is a B-TID or a user identity, and notify the BSF of the determined information; 所述 BSF, 如果确定接收到的鉴权请求中包含 B-TID, 且确定本^ 在 该 Β-ΉΌ, 则提取该 B-TID对应的用户身份标识, 并根据该用户身份标 识向 HSS中请求该 UE的鉴权信息,然后应用该鉴权信息进行鉴权处理, 如果确定本地不存在该 B-TID, 通知 UE发送包含用户身份标识的鉴权请 求;  If the BSF determines that the received authentication request includes the B-TID, and determines that the B-TID is in the Β-ΉΌ, extracts the user identity corresponding to the B-TID, and requests the HSS according to the user identity. And authenticating the authentication information of the UE, and then applying the authentication information to perform an authentication process. If it is determined that the B-TID does not exist locally, the UE is notified to send an authentication request that includes the user identity. 如果确定接收到的鉴权请求中包含用户身份标识, 根据该用户身份标 识向 HSS中请求该 UE的鉴权信息,然后应用该鉴权信息进行鉴权处理。  If it is determined that the received authentication request includes the user identity, the authentication information of the UE is requested from the HSS according to the identity of the user, and then the authentication information is applied for authentication processing. 7、 根据权利要求 6所述的系统, 其特征在于, 所述用户身份标识是用 户的永久身份标识 IMPI或由国际移动用户识别码转换得到的用户永久身份 标识 MPL  7. The system according to claim 6, wherein the user identity is a user's permanent identity IMPI or a user permanent identity MPL converted by an international mobile subscriber identity code.
PCT/CN2005/001862 2004-11-05 2005-11-07 Method and system for guaranteeing the privacy of the user identification Ceased WO2006047960A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200410088580.0 2004-11-05
CN 200410088580 CN100563154C (en) 2004-11-05 2004-11-05 A method to ensure the privacy of user identity

Publications (1)

Publication Number Publication Date
WO2006047960A1 true WO2006047960A1 (en) 2006-05-11

Family

ID=36318895

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2005/001862 Ceased WO2006047960A1 (en) 2004-11-05 2005-11-07 Method and system for guaranteeing the privacy of the user identification

Country Status (2)

Country Link
CN (1) CN100563154C (en)
WO (1) WO2006047960A1 (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102143460B (en) * 2010-02-02 2017-07-14 中兴通讯股份有限公司 The call back on busy service cut-in method and system of identity-based identification
CN112654013B (en) * 2019-09-25 2022-06-14 华为技术有限公司 Certificate issuing method and device

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020095605A1 (en) * 2001-01-12 2002-07-18 Royer Barry Lynn System and user interface for managing user access to network compatible applications
CN1614903A (en) * 2003-11-07 2005-05-11 华为技术有限公司 Method for authenticating users
CN1617494A (en) * 2003-11-11 2005-05-18 华为技术有限公司 Method for establishing interaction between conversation business mark and network application entity

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020095605A1 (en) * 2001-01-12 2002-07-18 Royer Barry Lynn System and user interface for managing user access to network compatible applications
CN1614903A (en) * 2003-11-07 2005-05-11 华为技术有限公司 Method for authenticating users
CN1617494A (en) * 2003-11-11 2005-05-18 华为技术有限公司 Method for establishing interaction between conversation business mark and network application entity

Also Published As

Publication number Publication date
CN1770685A (en) 2006-05-10
CN100563154C (en) 2009-11-25

Similar Documents

Publication Publication Date Title
US8613058B2 (en) Systems, methods and computer program products for providing additional authentication beyond user equipment authentication in an IMS network
US8275355B2 (en) Method for roaming user to establish security association with visited network application server
CN100534028C (en) Method and communication system for controlling security association lifetime
US7941121B2 (en) Method for verifying the validity of a user
WO2008006306A1 (en) Method and device for deriving local interface key
US20110173689A1 (en) Network id based federation and single sign on authentication method
CN1299537C (en) Method for realizing management of connecting visit network using general weight discrimination frame
CN112261022A (en) Security authentication method based on API gateway
CN105681259A (en) Open authorization method and apparatus and open platform
WO2011144081A2 (en) Method, system and server for user service authentication
CN1929371B (en) Method for User and Peripheral to Negotiate a Shared Key
CN1921682B (en) Enhancing the key agreement method in the general authentication framework
WO2012000313A1 (en) Method and system for home gateway certification
CN101399665B (en) Service authentication method and system by using cipher system based on identity as fundation
CN101312395B (en) Method and system for security authentication and card exchanging process for application service
CN100525186C (en) General authentication framework and method for renewing user safety describing information in BSF
CN110891067B (en) A revocable multi-server privacy protection authentication method and system
CN100563159C (en) Universal authentication system and method for accessing network service applications in the system
CN100563154C (en) A method to ensure the privacy of user identity
US9485654B2 (en) Method and apparatus for supporting single sign-on in a mobile communication system
WO2009086769A1 (en) A negotiation method for network service and a system thereof
CN101087260B (en) Method and device for realizing push function via guiding architecture
CN100512137C (en) A method for deleting session transaction ID and related information
CN100450283C (en) Method for establishing trust relationship between access terminal and business application entity
WO2006081742A1 (en) A method for realizing the user information synchronization and authenticating the user end

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KM KN KP KR KZ LC LK LR LS LT LU LV LY MA MD MG MK MN MW MX MZ NA NG NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SM SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LT LU LV MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 05806965

Country of ref document: EP

Kind code of ref document: A1