Terminal authenticating method, apparatus, and system
Abstract
Embodiments of the present invention disclose a terminal authenticating method, including: receiving, by a UE-to-network relay UE-R, a first request message sent by user equipment UE; sending, by the UE-R, a second request message to a control network element according to the first request message sent by the UE; receiving, by the UE-R, an authentication request message sent by the control network element, and determining whether the authentication request message is for authenticating on the UE; if the authentication request message is for authenticating on the UE, sending, by the UE-R, an authentication request message to the UE; and receiving, by the UE-R, an authentication response message sent by the UE according to the authentication request message, and sending the authentication response message to the control network element.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A terminal authenticating method comprising:
receiving, by a UE-to-network relay (UE-R), a first request message sent by user equipment (UE); sending, by the UE-R, a second request message to a control network element according to the first request message sent by the UE; receiving, by the UE-R, an authentication request message sent by the control network element; determining whether the authentication request message is for authenticating on the UE; and sending, by the UE-R, an authentication request message to the UE when the authentication request message sent by the control network element is for authenticating on the UE.
2 . The method according to claim 1 , wherein the first request message sent by the UE comprises the identification information for authenticating on the UE; and
wherein sending, by the UE-R, the second request message to the control network element according to the first request message sent by the UE comprises:
adding, by the UE-R to the second request message, the identification information for authenticating on the UE that is carried in the first request message, and sending the second request message to the control network element.
3 . The method according to claim 1 , wherein the first request message sent by the UE does not comprise the identification information for authenticating on the UE; and
wherein sending, by the UE-R, the second request message to the control network element according to the first request message sent by the UE comprises:
adding, by the UE-R, the identification information for authenticating on the UE to the second request message, and sending the second request message to the control network element.
4 . The method according to claim 1 , wherein the authentication request message sent by the control network element comprises authentication identification information that is for authenticating on the UE and is set by a home subscriber server (HSS) according to the identification information for authenticating on the UE; and
wherein determining whether the authentication request message is for authenticating on the UE comprises:
determining whether the authentication request message comprises the authentication identification information; and
determining that the authentication request message is for authenticating on the UE when the authentication request message comprises the authentication identification information.
5 . A terminal authenticating method comprising:
receiving, by a control network element, a second request message sent by a UE-to-network relay (UE-R), and determining whether the second request message comprises identification information for authenticating on a UE; sending, by the control network element, an authentication data request message to a home subscriber server (HSS) when the second request message comprises the identification information for authenticating on the UE, wherein the authentication data request message carries the identification information for authenticating on the UE; acquiring, by the control network element, from the HSS, an authentication vector determined by the HSS according to the authentication data request message; and sending, by the control network element, an authentication request message that comprises information about the authentication vector to the UE-R, so that the UE-R determines whether the authentication request message is for authenticating on the UE.
6 . The method according to claim 5 , wherein after receiving, by the control network element, the second request message sent by the UE-R, the method further comprises:
determining whether the second request message is of a specified message type; and sending, by the control network element, the authentication data request message to the HSS in response to the second request message being of the specified message type.
7 . The method according to claim 5 , wherein before sending, by the control network element, the authentication data request message to the HSS, the method further comprises:
adding, by the control network element, an identification information for authenticating on the UE to the authentication data request message.
8 . The method according to claim 5 , wherein before sending, by the control network element, the authentication request message comprising information about the authentication vector to the UE-R, the method further comprises:
adding, by the control network element, the identification information for authenticating on the UE to the authentication request message.
9 . A terminal authentication relay device comprising:
a receiving module configured to receive a first request message sent by a UE; a sending module configured to send a second request message to a control network element according to the first request message sent by the UE; the receiving module is further configured to receive an authentication request message sent by the control network element; a determining module configured to determine, according to the authentication request message received by the receiving module, whether the authentication request message is for authenticating on the UE; and the sending module is further configured to send an authentication request message to the UE when a result of the determining by the determining module that the authentication request message is for authentication on the UE,
wherein the authentication request message sent by the sending module comprises an authentication parameter of the UE.
10 . The relay device according to claim 9 , wherein the first request message sent by the UE and received by the receiving module comprises the identification information for authenticating on the UE; and
wherein the sending module is further specifically configured to:
add, to the second request message, the identification information for authenticating on the UE carried in the first request message; and
send the second request message to the control network element.
11 . The relay device according to claim 9 , wherein the first request message sent by the UE and received by the receiving module does not comprise the identification information for authenticating on the UE; and
wherein the sending module is specifically configured to:
add the identification information for authenticating on the UE to the second request message, and send the second request message to the control network element.
12 . The relay device according to claim 9 , wherein the authentication request message sent by the control network element and received by the receiving module comprises authentication identification information for authenticating on the UE and is set by a home subscriber server (HSS) according to the identification information for authenticating on the UE; and
wherein the determining module is specifically configured to:
determine whether the authentication request message comprises the authentication identification information; and
determine that the authentication request message is for authenticating on the UE when the authentication request message comprises the authentication identification information.Join the waitlist — get patent alerts
Track US2020162913A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.