IP Library Granted Patent US 12,562,915
Granted Patent B2
US 12,562,915 · App. 18/356,420 · Granted Feb 24, 2026

Authentication method and communication apparatus

Inventor: Fei Li (Shenzhen, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L9/3239H04L9/3271H04W60/04H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,562,915
App. No.
18/356,420
Granted
Feb 24, 2026
Kind
B2
Abstract

Authentication methods and communication apparatuses are provided. In an implementation, an authentication method includes: receiving an authentication vector request message from a serving call session control function network element, calculating a first hash value of a security parameter based on a first security algorithm, calculating a second hash value of the security parameter based on a second security algorithm, and sending an authentication vector request response to the serving call session control function network element, wherein the authentication vector request response comprises the first hash value and the second hash value.

Claims (77)

1 . An authentication method, comprising:

receiving a first registration request message from a terminal device;

sending an authentication vector request message to a home subscriber server;

receiving an authentication vector request response from the home subscriber server, wherein the authentication vector request response comprises a first hash value of a security parameter and a second hash value of the security parameter, the first hash value is calculated based on a first security algorithm, and the second hash value is calculated based on a second security algorithm;

sending an authentication challenge request message to the terminal device, wherein the authentication challenge request message comprises information about the first security algorithm and information about the second security algorithm;

receiving a second registration request message from the terminal device, wherein the second registration request message comprises a first authentication response and information about a third security algorithm, the first authentication response is calculated based on the third security algorithm, and the third security algorithm is the first security algorithm or the second security algorithm;

selecting, from the first hash value and the second hash value, a hash value corresponding to the third security algorithm;

calculating a second authentication response based on the third security algorithm and the hash value corresponding to the third security algorithm; and

checking the first authentication response by using the second authentication response, to obtain an authentication result of the terminal device.

2 . The method according to claim 1 , wherein the first hash value and the second hash value are in the authentication vector request response in a preset order, and the preset order is determined based on a priority of the first security algorithm and a priority of the second security algorithm;

and wherein

selecting the hash value corresponding to the third security algorithm comprises:

selecting, based on the preset order of the first hash value and the second hash value, the hash value corresponding to the third security algorithm.

3 . The method according to claim 1 , wherein the information about the first security algorithm and the information about the second security algorithm are comprised in the authentication challenge request message in a preset order, and the preset order is determined based on a priority of the first security algorithm and a priority of the second security algorithm.

4 . The method according to claim 1 , wherein the first security algorithm is a secure hash algorithm (SHA)256 or a secure hash algorithm (SHA)512, and the second security algorithm is a message digest 5 algorithm.

5 . A communication apparatus, comprising:

at least one processor; and

one or more memories coupled to the at least one processor and storing programming instructions for execution by the at least one processor to:

receive a first registration request message from a terminal device;

send an authentication vector request message to a home subscriber server;

receive an authentication vector request response returned by the home subscriber server, wherein the authentication vector request response carries a first hash value of a security parameter and a second hash value of the security parameter, the first hash value is calculated based on a first security algorithm, and the second hash value is calculated based on a second security algorithm;

send an authentication challenge request message to the terminal device, wherein the authentication challenge request message carries information about the first security algorithm and information about the second security algorithm;

receive a second registration request message from the terminal device, wherein the second registration request message comprises a first authentication response and information about a third security algorithm, the first authentication response is calculated based on the third security algorithm, and the third security algorithm is the first security algorithm or the second security algorithm;

select, from the first hash value and the second hash value, a hash value corresponding to the third security algorithm;

calculate a second authentication response based on the third security algorithm and the hash value corresponding to the third security algorithm; and

check the first authentication response by using the second authentication response, to obtain an authentication result of the terminal device.

6 . The apparatus according to claim 5 , wherein the information about the first security algorithm and the information about the second security algorithm are comprised in the authentication challenge request message in a preset order, and the preset order is determined based on the priority of the first security algorithm and the priority of the second security algorithm.

7 . The apparatus according to claim 5 , wherein the first security algorithm is a secure hash algorithm (SHA)256 or a secure hash algorithm (SHA)512, and the second security algorithm is a message digest 5 algorithm.

8 . An authentication method, comprising:

receiving, by a serving call session control function network element, a first registration request message from a terminal device;

sending, by the serving call session control function network element, an authentication vector request message to a home subscriber server;

receiving, by the home subscriber server, the authentication vector request message;

calculating, by the home subscriber server, a first hash value of a security parameter based on a first security algorithm;

calculating, by the home subscriber server, a second hash value of the security parameter based on a second security algorithm;

sending, by the home subscriber server, an authentication vector request response to the serving call session control function network element, wherein the authentication vector request response comprises the first hash value and the second hash value;

receiving, by the serving call session control function network element, the authentication vector request response,

sending, by the serving call session control function network element, an authentication challenge request message to the terminal device, wherein the authentication challenge request message comprises information about the first security algorithm and information about the second security algorithm;

receiving, by the serving call session control function network element, a second registration request message from the terminal device, wherein the second registration request message comprises a first authentication response and information about a third security algorithm, the first authentication response is calculated based on the third security algorithm, and the third security algorithm is the first security algorithm or the second security algorithm;

selecting, by the serving call session control function network element from the first hash value and the second hash value, a hash value corresponding to the third security algorithm;

calculating, by the serving call session control function network element, a second authentication response based on the third security algorithm and the hash value corresponding to the third security algorithm; and

checking, by the serving call session control function network element, the first authentication response by using the second authentication response, to obtain an authentication result of the terminal device.

9 . The method according to claim 8 , wherein the information about the first security algorithm and the information about the second security algorithm are comprised in the authentication challenge request message in a preset order, and the preset order is determined based on a priority of the first security algorithm and a priority of the second security algorithm.

10 . The method according to claim 8 , wherein the first security algorithm is a secure hash algorithm (SHA)256 or a secure hash algorithm (SHA)512, and the second security algorithm is a message digest 5 algorithm.

11 . The method according to claim 8 , further comprising:

sending, by the terminal device, the first registration request message to a serving call session control function network element;

receiving, by the terminal device, the authentication challenge request message from the serving call session control function network element;

determining, by the terminal device, the third security algorithm;

calculating, by the terminal device, a hash value of the security parameter based on the third security algorithm;

calculating, by the terminal device, the first authentication response based on the third security algorithm and the hash value; and

sending, by the terminal device, the second registration request message to the serving call session control function network element.

12 . The method according to claim 11 , wherein determining, by the terminal device, the third security algorithm comprises:

determining, by the terminal device, as the third security algorithm, a 1st security algorithm that is supported by the terminal device and that is in the authentication challenge request message.

13 . A system, comprising: a serving call session control function network element and a home subscriber server,

wherein the serving call session control function network element is configured to:

receive a first registration request message from a terminal device; and

send an authentication vector request message to the home subscriber server;

wherein the home subscriber server is configured to:

receive the authentication vector request message;

calculate a first hash value of a security parameter based on a first security algorithm;

calculate a second hash value of the security parameter based on a second security algorithm; and

send an authentication vector request response to the serving call session control function network element, wherein the authentication vector request response comprises the first hash value and the second hash value;

wherein the serving call session control function network element is further configured to:

receive the authentication vector request response,

send an authentication challenge request message to the terminal device, wherein the authentication challenge request message comprises information about the first security algorithm and information about the second security algorithm;

receive a second registration request message from the terminal device, wherein the second registration request message comprises a first authentication response and information about a third security algorithm, the first authentication response is calculated based on the third security algorithm, and the third security algorithm is the first security algorithm or the second security algorithm;

select, from the first hash value and the second hash value, a hash value corresponding to the third security algorithm;

calculate a second authentication response based on the third security algorithm and the hash value corresponding to the third security algorithm; and

check the first authentication response by using the second authentication response, to obtain an authentication result of the terminal device.

14 . The system according to claim 13 , wherein the information about the first security algorithm and the information about the second security algorithm are comprised in the authentication challenge request message in a preset order, and the preset order is determined based on a priority of the first security algorithm and a priority of the second security algorithm.

15 . The system according to claim 13 , wherein the first security algorithm is a secure hash algorithm (SHA)256 or a secure hash algorithm (SHA)512, and the second security algorithm is a message digest 5 algorithm.

16 . The system according to claim 13 , further comprising: the terminal device configured to:

send the first registration request message to a serving call session control function network element;

receive the authentication challenge request message from the serving call session control function network element;

determine the third security algorithm;

calculate a hash value of the security parameter based on the third security algorithm;

calculate the first authentication response based on the third security algorithm and the hash value; and

send the second registration request message to the serving call session control function network element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2025
From: LI, FEI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 072150/0323 →
Priority Claims (1)
CN 202110090637.4 · Jan 22, 2021 · national
Continuity (2)
Continuation PCTCN2022071670 · Jan 12, 2022
Related Publication 20230370277A1 · Nov 16, 2023
References Cited (24)
US 10581611B1 · Osborn · 2020 [cited by examiner]
US 20170272944A1 · Link, II · 2017 [cited by examiner]
US 20170272945A1 · Link, II · 2017 [cited by examiner]
US 20170339115A1 · Cho · 2017 [cited by examiner]
US 20190245006A1 · Tsai et al. · 2019 [cited by applicant]
US 20190260730A1 · Mainali · 2019 [cited by applicant]
US 20220014918A1 · Mastenbrook · 2022 [cited by examiner]
CN 1913437A · 2007 [cited by applicant]
CN 101132279A · 2008 [cited by applicant]
CN 103905405A · 2014 [cited by applicant]
CN 110324291A · 2019 [cited by applicant]
EP 1755311A1 · 2007 [cited by applicant]
JP 2009543453A · 2009 [cited by applicant]
JP 2012531792A · 2012 [cited by applicant]
JP 2018516403A · 2018 [cited by applicant]
WO 2007022800A1 · 2007 [cited by applicant]
China Mobile et al., “Proposed text to the “Session setup efficiency” for TR 23.8bc (Feasibility Study on IMS Evolution),” 3GPP TSG SA WG2 Meeting #68, S2-086999, Qing Dao, China, Oct. 13-17, 2008, 5 pages. [cited by applicant]
3GPP TS 33.203 V16.1.0, “3rd Generation Partnership Project, Technical Specification Group Services and System Aspects; 3G security; Access securiy for IP-based services (Release 16),” Sep. 2020, 146 pages. [cited by applicant]
Huawei et al., “IMS SCAS: new test case on high-priority algorithm selection in the P-CSCF,” 3GPP TSG-SA3 Meeting #100e, e-meeting, S3-201856, Aug. 17-28, 2020, 2 pages. [cited by applicant]
Huawei et al., “user id clarification for scenario of using Web id direct registration in IMS,” 3GPP TSG-SA WG3 (Security) Meeting #75, S3-140823, Sapporo, Japan, May 12-16, 2014, 3 pages. [cited by applicant]
Ofice Action in Japanese AppIn. No. 2023-544403, mailed on Aug. 13, 2024, 9 pages (with English translation). [cited by applicant]
Office Action in Australian Appin. No. 2022210153, mailed on Oct. 25, 2024, 3 pages. [cited by applicant]
3GPP SA3, “LS on key derivation for IMS-based application services,” 3GPP TSG SA WG3 Security-S3#27, S3-030147, Feb. 25-28, 2003, Sophia Antipolis, France, 61 pages. [cited by applicant]
Extended European Search Report in European Appln No. 22742059.3, dated Jun. 25, 2024, 10 pages. [cited by applicant]