Mobility Management Entity, Terminal, and Identity Authentication Method
A mobility management entity (MME), a terminal and an identity authentication method are disclosed. The MME comprises: a sending unit, configured to send an identity authentication request, an encryption key and a corresponding digital certificate to a terminal when detecting that a mapping relation between a globally unique temporary terminal identity and an international mobile subscriber identity code is lost, so that the terminal is enabled to verify the mobility management entity according to the digital certificate, use the encryption key to encrypt the international mobile subscriber identity code when the verification is successful, and send the encrypted international mobile subscriber identity code to the mobility management entity; a receiving unit, configured to receive the encrypted international mobile subscriber identity code sent by the terminal; and a decrypting unit, configured to decrypt the encrypted international mobile subscriber identity code according to a stored decryption key corresponding to the encryption key.
1 . A mobility management entity, comprising:
a sending unit, configured to send an identity authentication request, an encryption key and a digital certificate corresponding to the encryption key to a terminal when detecting that a mapping relation between a globally unique temporary terminal identity and an international mobile subscriber identity code is lost, so that the terminal is enabled to verify the mobility management entity according to the digital certificate, use the encryption key to encrypt the international mobile subscriber identity code when the verification is successful, and send the encrypted international mobile subscriber identity code to the mobility management entity;
a receiving unit, configured to receive the encrypted international mobile subscriber identity code sent by the terminal; and
a decrypting unit, configured to decrypt the encrypted international mobile subscriber identity code according to a stored decryption key corresponding to the encryption key.
2 . The mobility management entity according to claim 1 , further comprising:
a key generating unit, configured to generate an encryption key and a decryption key corresponding to the encryption key upon a first network access of the mobility management entity; and
a storage unit, configured to store the encryption key and the decryption key corresponding to the encryption key.
3 . The mobility management entity according to claim 1 , wherein the sending unit is also configured to:
send the encryption key and the entity identity information of the mobility management entity to a home subscriber manager, so that the home subscriber manager is enabled to verify the identity of the mobility management entity, and generate and send a digital certificate corresponding to the encryption key to the mobility management entity when the verification is successful.
4 . The mobility management entity according to claim 1 , further comprising:
a processing unit, configured to stop the verification upon receiving a message of terminating verification sent by the terminal.
5 . (canceled)
6 . A terminal, comprising:
a receiving unit, configured to receive an identity authentication request, an encryption key and a digital certificate sent by a mobility management entity;
a verifying unit, configured to verify the digital certificate of the mobility management entity according to the identity authentication request;
an encrypting unit, configured to encrypt, upon successful verification of the digital certificate, an international mobile subscriber identity code in the terminal with the encryption key sent by the mobility management entity to obtain the encrypted international mobile subscriber identity code; and
a sending unit, configured to send the encrypted international mobile subscriber identity code to the mobility management entity.
7 . The terminal according to claim 6 , wherein the encrypting unit comprises:
an acquiring unit, configured to acquire an international mobile subscriber identity code in the terminal upon successful verification of the digital certificate; and
a computing unit, configured to compute the international mobile subscriber identity code according to the encryption key and a preset encryption function so as to obtain the encrypted international mobile subscriber identity code.
8 . The terminal according to claim 6 , further comprising:
a processing unit, configured to stop the verification upon unsuccessful verification of the digital certificate, and send a message of terminating verification to the mobility management entity.
9 . (canceled)
10 . An identity authentication method, used for an identity authentication system comprising a mobility management entity, a terminal and a home server, wherein
the mobility management entity sends an identity authentication request, an encryption key and a digital certificate corresponding to the encryption key to the terminal when detecting that a mapping relation between a globally unique temporary terminal identity and an international mobile subscriber identity code is lost;
the terminal receives the identity authentication request, the encryption key and the digital certificate sent by the mobility management entity and verifies the digital certificate of the mobility management entity according to the identity authentication request;
the terminal encrypts the international mobile subscriber identity code in the terminal with the encryption key sent by the mobility management entity upon successful verification of the digital certificate, and then sends the encrypted international mobile subscriber identity code to the mobility management entity; and
the mobility management entity decrypts the encrypted international mobile subscriber identity code according to a stored decryption key corresponding to the encryption key.
11 . The identity authentication method according to claim 10 , further comprising:
sending, by the mobility management entity, the encryption key and the entity identity information of the mobility management entity to the home subscriber manager;
receiving, by the home subscriber manager, the encryption key and the entity identity information of the mobility management entity sent by the mobility management entity, and then verifying the identity of the mobility management entity according to the encryption key and the entity identity information of the mobility management entity.
12 . The identity authentication method according to claim 10 , characterized by further comprising:
generating, by the mobility management entity upon a first network access thereof, an encryption key and a decryption key corresponding to the encryption key, and then storing the encryption key and the decryption key corresponding to the encryption key.
13 . The identity authentication method according to claim 10 , wherein the step that the terminal encrypts the international mobile subscriber identity code in the terminal with the encryption key sent by the mobility management entity upon successful verification of the digital certificate specifically comprises:
upon successful verification of the digital certificate, acquiring, by the terminal, an international mobile subscriber identity code, and computing the international mobile subscriber identity code according to the encryption key and a preset encryption function to obtain the encrypted mobile subscriber identity code.
14 . The identity authentication method according to claim 10 , further comprising:
upon unsuccessful verification of the digital certificate, stopping, by the terminal, the verification, and then sending a message of terminating verification to the mobility management entity; and
stopping, by the mobility management entity, the verification upon receiving the message of terminating verification sent by the terminal.
15 . The mobility management entity according to claim 3 , wherein
the receiving unit is also configured to:
receive the digital certificate corresponding to the encryption key sent by the home subscriber manager.
16 . The identity authentication method according to claim 11 , further comprising:
upon successful identity verification of the mobility management entity, generating, by the home subscriber manager, a digital certificate corresponding to the encryption key, and then sending the digital certificate to the mobility management entity; and
receiving, by the mobility management entity, the digital certificate corresponding to the encryption key sent by the home subscriber manager.
17 . The mobility management entity according to claim 1 , wherein
the encryption key and the decryption key correspond to a public key and a private key, wherein
the public key is used for encryption, and in the case of decryption, the private key corresponding to the public key is needed.
18 . The terminal according to claim 6 , wherein
the encryption key corresponds to a public key which is used for encryption.
19 . The identity authentication method according to claim 10 , wherein
the encryption key and the decryption key correspond to a public key and a private key, wherein
the public key is used for encryption, and in the case of decryption, the private key corresponding to the public key is needed.