IP Library Granted Patent US 12,167,239
Granted Patent B2
US 12,167,239 · App. 17/680,980 · Granted Dec 10, 2024

Identity authentication method and apparatus

Inventors: Weiyu Jiang (Beijing, CN); Bingyang Liu (Beijing, CN); Junjie Wan (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04W12/06H04W12/08H04W12/75
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,167,239
App. No.
17/680,980
Granted
Dec 10, 2024
Kind
B2
Abstract

A method comprises generating, based on identity information of a user by an identity management server, a temporary privacy identity identifier of a terminal device, receiving, from the terminal device, a network access request comprising the temporary privacy identity identifier, generating an authentication key of the temporary privacy identity identifier based on the temporary privacy identity identifier and a primary identity authentication key of a domain to which the terminal device belongs, generating a first message based on the temporary privacy identity identifier and the authentication key, sending the first message to the terminal device, receiving a second message from the terminal device based on the first message, performing authentication on the second message based on the temporary privacy identity identifier and the authentication key, and allowing access to a network device by the terminal device after the authentication succeeds.

Claims (30)

1. A method comprising:

generating, by an identity management server and based on identity information of a user, a temporary privacy identity identifier of a terminal device;

receiving, from the terminal device, a network access request comprising the temporary privacy identity identifier;

generating a first authentication key of the temporary privacy identity identifier based on the temporary privacy identity identifier and a primary identity authentication key of a domain to which the terminal device belongs;

generating a first message based on the temporary privacy identity identifier and the first authentication key;

sending the first message to the terminal device;

receiving a second message from the terminal device based on the first message;

performing authentication on the second message based on the temporary privacy identity identifier and the first authentication key; and

allowing the terminal device to access a network device when the authentication succeeds.

2. The method of claim 1 , wherein the network access request further comprises a domain identifier of the domain, and wherein after receiving the network access request, the method further comprises:

extracting a second authentication key corresponding to the domain identifier to be the primary identity authentication key when the network device stores the second authentication key; and

when the network device does not store the second authentication key,

sending a primary identity authentication key request to the identity management server; and

using, in response to the primary identity authentication key request, a third authentication key from the identity management server as the primary identity authentication key.

3. The method of claim 1 , wherein generating the first authentication key comprises performing derivation calculation using a one-way function based on the primary identity authentication key and the temporary privacy identity identifier.

4. The method of claim 1 , further comprising further receiving the network access request through a secure channel.

5. The method of claim 1 , wherein the network access request further comprises a random number.

6. The method of claim 1 , wherein the one-way function comprises a hash function with a key.

7. An apparatus comprising:

a receiver configured to receive, from a terminal device, a network access request comprising a temporary privacy identity identifier of the terminal device;

a key generator configured to generate a first authentication key of the temporary privacy identity identifier based on the temporary privacy identity identifier and a primary identity authentication key of a domain to which the terminal device belongs;

a message generator configured to generate a first message based on the temporary privacy identity identifier and the first authentication key;

a transmitter configured to send the first message to the terminal device, wherein the receiver is further configured to receive a second message from the terminal device based on the first message;

an authenticator configured to perform authentication on the second message based on the temporary privacy identity identifier and the authentication key; and

an access system configured to allow the terminal device to access a network device when the authentication succeeds.

8. The apparatus of claim 7 , wherein the network access request further comprises a domain identifier of the domain, and wherein the apparatus further comprises an extracting system configured to extract a second authentication key corresponding to the domain identifier to be the primary identity authentication key when the network device stores the second authentication key, and wherein the transmitter is further configured to send a primary identity authentication key request to an identity management server when the network device does not store the second authentication key.

9. The apparatus according to claim 7 , wherein the key generator is further configured to perform derivation calculation using a one-way function based on the primary identity authentication key and the temporary privacy identity identifier to generate the first authentication key.

10. The apparatus of claim 7 , wherein the receiver is further configured to further receive the network access request through a secure channel.

11. The apparatus of claim 7 , wherein the network access request further comprises a random number.

12. The apparatus of claim 7 , wherein the one-way function comprises a hash function with a key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2022
From: JIANG, WEIYU; LIU, BINGYANG; WAN, JUNJIE
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 059253/0685 →
Priority Claims (1)
CN 201910815346.X · Aug 30, 2019 · national
Continuity (2)
Continuation PCTCN2020085610 · Apr 20, 2020
Related Publication 20220182825A1 · Jun 9, 2022