IP Library › Granted Patent US 11,405,780
Granted Patent B2
US 11,405,780 · App. 16/924,412 · Granted Aug 2, 2022

Method for performing verification by using shared key, method for performing verification by using public key and private key, and apparatus

Inventors: Chengdong He (Shenzhen, CN); Hua Li (Xi'an, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/0433H04L9/085H04L9/30H04W12/037H04W12/08H04W12/40H04W60/00H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,405,780
App. No.
16/924,412
Granted
Aug 2, 2022
Kind
B2
Abstract

A method and an apparatus for performing verification using a shared key are disclosed. The method includes: receiving, by a first network element, a registration request message from a second network element, where the registration request message includes a user identifier, first network identifier information, and second network identifier information, the second network identifier information is obtained by processing the first network identifier information by using a shared key, and the shared key is a key used between the first network element and the second network element; verifying, by the first network element, the registration request message by using the shared key; and sending, by the first network element, a registration response message to the second network element. When receiving a registration request from a visited network, a home network verifies the registration request message by using a shared key, to avoid a spoofing attack from the visited network.

Claims (44)

1. A method for performing verification using a public land mobile network identifier (PLMN ID), comprising:

receiving, by a security edge protection proxy (SEPP) in a second network, an N32 interface message from a SEPP in a first network, wherein the N32 interface message carries an N32 interface context identifier and a PLMN ID of the first network;

determining, by the SEPP in the second network, whether a remote PLMN ID comprised in an N32 interface context corresponding to the N32 interface context identifier is the same as the PLMN ID carried in the N32 interface message; and

in response to determining that the remote PLMN ID comprised in the N32 interface context is the same as the PLMN ID carried in the N32 interface message, sending, by the SEPP in the second network, a second message to a network function entity in the second network.

2. The method according to claim 1 , wherein the method further comprises:

in responding to determining that the remote PLMN ID comprised in the N32 interface context is different from the PLMN ID carried in the N32 interface message, sending, by the SEPP in the second network to the SEPP in the first network, an N32 interface response message indicating a failure.

3. The method according to claim 2 , wherein the N32 interface response message comprises an error code indicating a PLMN ID failure.

4. The method according to claim 1 , wherein the PLMN ID carried in the N32 interface message is a PLMN ID carried in a first message from a function entity in the first network to the SEPP in the first network.

5. The method according to claim 4 , wherein the PLMN ID in the first message is carried in at least one of the following:

a dedicated PLMN ID information element in the first message,

a serving network name information element that comprises the PLMN ID,

a network function entity identifier that comprises the PLMN ID, or

a terminal identifier, a user identifier, or a service identifier, wherein the terminal identifier, the user identifier, or the service identifier comprises the PLMN ID.

6. The method according to claim 1 , wherein the first network is a serving network, and the second network is a home network.

7. The method according to claim 4 , wherein the function entity in the first network is a network function entity that requires a roaming service in the first network, and the network function entity in the second network is a network function entity that provides a roaming service in the second network.

8. A communications apparatus, comprising:

at least one processor; and

a memory coupled to the at least one processor and having program instructions stored thereon which, when executed by the at least one processor, cause the apparatus to:

receive an N32 interface message from a SEPP in a first network, wherein the N32 interface message carries an N32 interface context identifier and a PLMN ID of the first network;

determine whether a remote PLMN ID comprised in an N32 interface context corresponding to the N32 interface context identifier is the same as the PLMN ID carried in the N32 interface message; and

in response to determining that the remote PLMN ID comprised in the N32 interface context is the same as the PLMN ID carried in the N32 interface message, send a second message to another network function entity in a second network.

9. The communications apparatus according to claim 8 , wherein the instructions further cause the apparatus to:

in response to determining that the remote PLMN ID comprised in the N32 interface context is different from the PLMN ID carried in the N32 interface message, send, to the SEPP in the first network, an N32 interface response message indicating a failure.

10. The communications apparatus according to claim 9 , wherein the N32 interface response message comprises an error code indicating a PLMN ID failure.

11. The communications apparatus according to claim 8 , wherein the PLMN ID carried in the N32 interface message is a PLMN ID carried in a first message from a function entity in the first network to the SEPP in the first network.

12. The communications apparatus according to claim 11 , wherein the PLMN ID in the first message is carried in a dedicated PLMN ID information element in the first message, is carried in at least one of the following:

a dedicated PLMN ID information element in the first message,

a serving network name information element that comprises the PLMN ID,

a network function entity identifier that comprises the PLMN ID, or

a terminal identifier, a user identifier, or a service identifier, wherein the terminal identifier, the user identifier, or the service identifier comprises the PLMN ID.

13. The communications apparatus according to claim 8 , wherein the first network is a serving network, and the second network is a home network.

14. The communications apparatus according to claim 11 , wherein the function entity in the first network is a network function entity that requires a roaming service in the first network, and the network function entity in the second network is a network function entity that provides a roaming service in the second network.

15. A communications system, comprising a security edge protection proxy (SEPP) in a first network and a SEPP in a second network, wherein

the SEPP in the first network is configured to: send an N32 interface message to the SEPP in the second network, wherein the N32 interface message carries an N32 interface context identifier and a PLMN ID of the first network; and

the SEPP in the second network is configured to: receive the N32 interface message from the SEPP in the first network; determine whether a remote PLMN ID comprised in an N32 interface context corresponding to the N32 interface context identifier is the same as the PLMN ID carried in the N32 interface message; and in response to determining that the remote PLMN ID comprised in the N32 interface context is the same as the PLMN ID carried in the N32 interface message, send a second message to a network function entity in the second network.

16. The communications system according to claim 15 , wherein the SEPP in the second network is further configured to: in responding to determining that the remote PLMN ID comprised in the N32 interface context is different from the PLMN ID carried in the N32 interface message, send, to the SEPP in the first network, an N32 interface response message indicating a failure.

17. The communications system according to claim 16 , wherein the N32 interface response message comprises an error code indicating a PLMN ID failure.

18. The communications system according to claim 15 , wherein the SEPP in the first network is further configured to: receive a first message sent by a function entity in the first network, wherein the first message comprises the PLMN ID carried in the N32 interface message.

19. The communications system according to claim 18 , wherein the PLMN ID in the first message is carried in at least one of the following:

a dedicated PLMN ID information element in the first message,

a serving network name information element that comprises the PLMN ID,

a network function entity identifier that comprises the PLMN ID, or

a terminal identifier, a user identifier, or a service identifier, wherein the terminal identifier, the user identifier, or the service identifier comprises the PLMN ID.

20. The communications system according to claim 18 , wherein the first network is a serving network, and the second network is a home network; wherein the function entity in the first network is a network function entity that requires a roaming service in the serving network, and the network function entity in the second network is a network function entity that provides a roaming service in the home network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2020
From: HE, CHENGDONG; LI, HUA
To: HUAWEI TECHNOLOGIES CO., LTD
Reel/Frame 053848/0435 →
Priority Claims (3)
CN 201810028282.4 · Jan 11, 2018 · national
CN 201810174626.2 · Mar 2, 2018 · national
CN 201811082476.9 · Sep 17, 2018 · national
Continuity (2)
Continuation PCTCN2019071414 · Jan 11, 2019
Related Publication 20200344604A1 · Oct 29, 2020