IP Library › Granted Patent US 12,513,142
Granted Patent B2
US 12,513,142 · App. 17/532,757 · Granted Dec 30, 2025

Secondary authentication method and apparatus

Inventors: Zhongding Lei (Singapore, SG); Haiguang Wang (Singapore, SG); Xin Kang (Singapore, SG)
Assignee: Huawei Technologies Co., LTD.
H04L63/0869H04L63/0876H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,142
App. No.
17/532,757
Granted
Dec 30, 2025
Kind
B2
Abstract

The present disclosure relates to secondary authentication methods and apparatus. In one example method, a core network function entity obtains an identity of a first terminal device, where the identity of the first terminal device is an identity in a first network. The core network function entity sends the identity of the first terminal device to an authentication device in a second network, where the identity of the first terminal device is used to determine an identity used by the second network to perform secondary authentication on a first user, and the identity of the first user is different from the identity of the first terminal device.

Claims (53)

1 . A secondary authentication method, comprising:

obtaining, by a core network function entity, an identity of a first terminal device, wherein the identity of the first terminal device has an association with a second identity of the first terminal device, and the second identity is used in a first network to perform primary authentication for the first terminal device;

sending, by the core network function entity, the identity of the first terminal device to an authentication device in a second network, wherein the identity of the first terminal device is used to determine an identity of a first user using the first terminal device, wherein the identity of the first user is used by the second network to perform secondary authentication on the first user, wherein the identity of the first user is different from the identity of the first terminal device, and wherein sending, by the core network function entity, the identity of the first terminal device to the authentication device in the second network comprises:

sending, by the core network function entity, a secondary authentication request to the authentication device in the second network, wherein the secondary authentication request comprises the identity of the first terminal device but does not comprise the identity of the first user; and

receiving, by the core network function entity, a secondary authentication response message from the authentication device in the second network, wherein the secondary authentication response message is used to indicate the first terminal device and the second network to perform the secondary authentication on the first user.

2 . The method according to claim 1 , further comprising:

sending, by the core network function entity, a first message to the first terminal device, wherein the first message is used to request the identity of the first user;

receiving, by the core network function entity, a second message from the first terminal device; and

when the second message does not comprise the identity of the first user, performing, by the core network function entity, the secondary authentication on the first user based on the identity of the first terminal device.

3 . The method according to claim 1 , further comprising:

before performing the secondary authentication on the first user, obtaining, by the core network function entity, capability information of the first terminal device, wherein the capability information of the first terminal device is used to indicate that the core network function entity can perform the secondary authentication on the first user based on the identity of the first terminal device.

4 . The method according to claim 3 , wherein the capability information of the first terminal device is carried in a registration request message in a process of primary authentication performed by the first terminal device and the first network.

5 . The method according to claim 1 , wherein the identity of the first terminal device corresponds to identities used by the second network to perform the secondary authentication on a plurality of users, wherein the identities of the plurality of users comprise the identity of the first user, and wherein the method further comprises:

obtaining, by the core network function entity, a first indication, wherein the first indication is used to determine the identity of the first user in the identities of the plurality of users.

6 . The method according to claim 1 , further comprising:

selecting, by the core network function entity, a first authentication method used for the secondary authentication, wherein the first authentication method is an authentication method supported by both the first terminal device and the authentication device in the second network.

7 . The method according to claim 6 , wherein the selecting, by the core network function entity, a first authentication method used for the secondary authentication comprises:

obtaining, by the core network function entity, a first authentication method set and a second authentication method set, wherein the first authentication method set comprises an authentication method preferred by the first terminal device, and wherein the second authentication method set comprises an authentication method preferred by the authentication device in the second network;

determining, by the core network function entity, the first authentication method based on the first authentication method set and the second authentication method set, wherein the first authentication method is an authentication method preferred by both the first terminal device and the authentication device in the second network; and

sending, by the core network function entity, the first authentication method to the authentication device in the second network.

8 . The method according to claim 1 , further comprising:

obtaining, by the core network function entity, a first authentication method set and a second authentication method set, wherein the first authentication method set comprises an authentication method preferred by the first terminal device, and wherein the second authentication method set comprises an authentication method preferred by the authentication device in the second network; and

when there is no intersection set of the first authentication method set and the second authentication method set, sending, by the core network function entity, the first authentication method set or a second indication to the authentication device in the second network, wherein the second indication is used to indicate the authentication device in the second network to negotiate an authentication method with the first terminal device.

9 . The method according to claim 1 , wherein the identity of the first terminal device includes a generic public subscription identifier (GPSI), and the second identity of the first terminal device includes a subscriber permanent identifier (SUPI).

10 . The method according to claim 1 , wherein the second network includes a third-party network.

11 . A secondary authentication method, comprising:

receiving an identity of a first terminal device from a core network function entity, wherein the identity of the first terminal device has an association with a second identity of the first terminal device, and the second identity is used in a first network to perform primary authentication for the first terminal device;

determining an identity of a first user using the first terminal device based on the identity of the first terminal device and a mapping relationship between the identity of the first terminal device and the identity used by a second network to perform secondary authentication on the first user, wherein the identity of the first user is different from the identity of the first terminal device; and

performing the secondary authentication on the first user based on the identity of the first user;

wherein the receiving an identity of a first terminal device from a core network function entity comprises:

receiving a secondary authentication request from the core network function entity, wherein the secondary authentication request comprises the identity of the first terminal device but does not comprise the identity of the first user; and

wherein the performing the secondary authentication on the first user based on the identity of the first user comprises:

sending a secondary authentication response message to the core network function entity, wherein the secondary authentication response message is used to indicate the first terminal device and the second network to perform the secondary authentication on the first user.

12 . The method according to claim 11 , wherein the identity of the first terminal device corresponds to identities used by the second network to perform the secondary authentication on a plurality of users, wherein the identities of the plurality of users comprise the identity of the first user, and wherein the method further comprises:

receiving a first indication from the core network function entity, wherein the first indication is used to determine the identity of the first user in the identities of the plurality of users.

13 . The method according to claim 11 , further comprising:

receiving a first authentication method from the core network function entity, wherein the first authentication method is an authentication method supported by both the first terminal device and an authentication device in the second network; and

performing the secondary authentication on the first user according to the first authentication method.

14 . The method according to claim 11 , further comprising:

receiving a first authentication method set from the core network function entity, wherein the first authentication method set comprises an authentication method preferred by the first terminal device;

selecting a second authentication method from the first authentication method set, wherein the second authentication method is an authentication method supported by an authentication device in the second network; and

performing the secondary authentication on the first user according to the second authentication method.

15 . The method according to claim 11 , further comprising:

receiving a second indication from the core network function entity, wherein the second indication is used to indicate an authentication device in the second network to negotiate an authentication method with the first terminal device.

16 . The method according to claim 11 , wherein the identity of the first terminal device includes a generic public subscription identifier (GPSI), and the second identity of the first terminal device includes a subscriber permanent identifier (SUPI).

17 . The method according to claim 11 , wherein the second network includes a third-party network.

18 . A secondary authentication method, comprising:

establishing a mapping relationship between an identity of a first terminal device and an identity of a first user using the first terminal device, wherein the identity of the first user is used by a second network to perform secondary authentication on the first user, wherein the identity of the first terminal device has an association with a second identity of the first terminal device, and the second identity is used in a first network to perform primary authentication for the first terminal device;

sending the identity of the first terminal device to a core network function entity, or sending the identity of the first terminal device and a first indication to a core network function entity, wherein the first indication is used to determine the identity of the first user in identities used by the second network to perform secondary authentication on a plurality of users; and

before performing the secondary authentication on the first user, sending capability information of the first terminal device to the core network function entity, wherein the capability information of the first terminal device is used to indicate that the core network function entity can perform the secondary authentication on the first user based on the identity of the first terminal device.

19 . The method according to claim 18 , further comprising:

sending a first authentication method set to the core network function entity, wherein the first authentication method set comprises an authentication method preferred by the first terminal device.

20 . The method according to claim 18 , wherein the identity of the first terminal device includes a generic public subscription identifier (GPSI), and the second identity of the first terminal device includes a subscriber permanent identifier (SUPI).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2024
From: LEI, ZHONGDING; WANG, HAIGUANG; KANG, XIN
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 069060/0740 →
Priority Claims (1)
CN 201910522598.3 · Jun 17, 2019 · national
Continuity (2)
Continuation PCTCN2020088907 · May 7, 2020
Related Publication 20220086145A1 · Mar 17, 2022
References Cited (45)
US 20030186680A1 · Bhasin · 2003 [cited by examiner]
US 20090183246A1 · Kokologiannakis · 2009 [cited by examiner]
US 20090227226A1 · Gupta · 2009 [cited by examiner]
US 20100269153A1 · Kato · 2010 [cited by examiner]
US 20170118165A1 · Kumar · 2017 [cited by examiner]
US 20180069846A1 · Park · 2018 [cited by examiner]
US 20180317157A1 · Baek et al. · 2018 [cited by applicant]
US 20190116521A1 · Qiao et al. · 2019 [cited by applicant]
US 20190174208A1 · Speicher · 2019 [cited by examiner]
US 20190174449A1 · Shan et al. · 2019 [cited by applicant]
US 20190260741A1 · Ashok · 2019 [cited by examiner]
US 20210076209A1 · Suh · 2021 [cited by examiner]
CN 101626369A · 2010 [cited by applicant]
CN 101754219A · 2010 [cited by applicant]
CN 102143136A · 2011 [cited by applicant]
CN 107809776A · 2018 [cited by applicant]
CN 108012267A · 2018 [cited by applicant]
CN 108200007A · 2018 [cited by applicant]
CN 108347729A · 2018 [cited by applicant]
CN 108833181A · 2018 [cited by applicant]
CN 108881252A · 2018 [cited by applicant]
CN 108901018A · 2018 [cited by applicant]
CN 109104726A · 2018 [cited by applicant]
CN 109150864A · 2019 [cited by applicant]
CN 109511115A · 2019 [cited by applicant]
CN 111818516A · 2020 [cited by applicant]
3GPP TR 23.740 V16.0.0 (Dec. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Enhancement of Network Slicing(Release 16),” Dec. 2018, 70 pages. [cited by applicant]
3GPP TR 33.813 V0.4.0 (May 2019), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Aspects; Study on Security Aspects of Enhanced Network Slicing(Release 16),” May… [cited by applicant]
3GPP TS 33.501 V15.12.0 (Mar. 2021), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system(Release 15),” Mar. 2021, 192 pages. [cited by applicant]
3GPP TS 23.502 V16.1.1 (Jun. 2019), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2(Release 16),” Jun. 2019, 495 pages. [cited by applicant]
Aboba et al., “Extensible Authentication Protocol (EAP),” Network Working Group, Request for Comments: 3748, Jun. 2004, 67 pages. [cited by applicant]
Aboba et al., “The Network Access Identifier,” Network Working Group, Request for Comments: 4282, Dec. 2005, 16 pages. [cited by applicant]
Huawei, Hisilicon, “A solution to KI#1 Authentication for access to specific Network Slices,” 3GPP TSG SA WG3 (Security) Meeting #94, S3-190202, Kochi, India, Jan. 28-Feb. 1, 2019, 3 pages. [cited by applicant]
Office Action issued in Chinese Application No. 201910522598.3 on Aug. 11, 2021, 33 pages (with English translation). [cited by applicant]
PCT International Search Report and Written Opinion issued in International Application No. PCT/CN2020/088907 on Jul. 29, 2020, 13 pages (with English translation). [cited by applicant]
Simon et al., “The EAP-TLS Authentication Protocol,” Network Working Groups, Request for Comments: 5216, Mar. 2008, 34 pages. [cited by applicant]
Jun-zhi et al., “Blockchain based PKI certificate system,” Telecommunications Engineering Technology and Standardization, Nov. 2017, 5 pages (with English abstract). [cited by applicant]
Nokia et al., “Introduction of Network Slice-Specific Secondary authentication,” 3GPP TSG-SA WG2 Meeting #131, S2-1901675, Tenerife, Spain, Feb. 25- Mar. 1, 2019, 17 pages. [cited by applicant]
Office Action issued in Chinese Application No. 201910522598.3 on Jun. 6, 2022, 7 pages (with English translation). [cited by applicant]
3GPP TR 33.899 V1.3.0 (Aug. 2017), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14),” Aug. 2017, 60… [cited by applicant]
China Mobile, “Discussion on clarification of concept of slice authentication,” 3GPP TSG SA WG3 (Security) Meeting #92, S3-182449, Dalian, China, Aug. 20-24, 2018, 5 pages. [cited by applicant]
Extended European Search Report issued in European Application No. 20827832.5 on May 30, 2022, 17 pages. [cited by applicant]
Huawei, “GPSI in 5G,” 3GPP TSG CT4 Meeting #83, C4-182100, Montreal, Canada, Feb. 26-Mar. 2, 2018, 3 pages. [cited by applicant]
Samsung et al., “Clarification on ON authorization data,” 3GPP TSG SA WG2 Meeting #131, S2-1902345, Santa Cruz, Tenerife, Spain, Feb. 25-Mar. 1, 2019, 3 pages. [cited by applicant]
Office Action issued in Chinese Application No. 201910522598.3 on Feb. 7, 2022, 39 pages (with English translation). [cited by applicant]