WO2023115913A1 - 认证方法、系统、电子设备和计算机可读存储介质 - Google Patents
认证方法、系统、电子设备和计算机可读存储介质 Download PDFInfo
- Publication number
- WO2023115913A1 WO2023115913A1 PCT/CN2022/105156 CN2022105156W WO2023115913A1 WO 2023115913 A1 WO2023115913 A1 WO 2023115913A1 CN 2022105156 W CN2022105156 W CN 2022105156W WO 2023115913 A1 WO2023115913 A1 WO 2023115913A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- target
- address
- authentication server
- authentication
- network element
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
- H04W12/084—Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
Definitions
- the present disclosure relates to the technical field of communication, and in particular to an authentication method, system, electronic equipment and computer-readable storage medium.
- the network system In order to ensure that the terminal accessing the network system is normal and safe, the network system usually needs to authenticate the terminal when the terminal accesses.
- the addressing of Authentication Server Function (AUSF) and Unified Data Management (UDM) in the terminal authentication process of the relevant network is realized based on the service discovery process or static configuration, which needs to be based on the user number segment to address.
- AUSF Authentication Server Function
- UDM Unified Data Management
- the future 6G network will realize the ubiquitous connection of air-space-ground integration, mobile operator equipment and satellite operator equipment, etc.
- the future mobile network will be composed of operators' equipment. Considering the cost of base station construction, there may be only one operator's base station node in the same area. Therefore, a more flexible addressing method is required in the user identity authentication process.
- the purpose of the present disclosure is to provide an authentication method, system, electronic equipment and computer-readable storage medium.
- an authentication method including: a target access control network element receives a registration request sent by a target device; the target access control network element determines the target User identification, and the target access method for the target device to access the network system; the target access control network element requests the target block chain for the target authentication server address corresponding to the target access method and the target authentication server address corresponding to the target device
- the address of the target signing database corresponding to the user identification, at least one authentication server address and at least one signing database address are stored in the target block chain, the at least one authentication server includes the target authentication server, and the at least one signing database address includes the target signing database address Address;
- the target access control network element sends an authentication request carrying the address of the target subscription database to the target authentication server according to the address of the target authentication server, so that the target authentication server accesses the target subscription database according to the address of the target subscription database Obtain target signing data corresponding to the target device, so as to authenticate the target device according to the target signing data.
- the target access control network element requests the target blockchain for the address of the target authentication server corresponding to the target access method and the address of the target subscription database corresponding to the target user identifier, including: The target access control network element sends the target user ID of the target device, the target security token, and the target access mode to the target block chain; the target access control network element receives the target block The address of the target authentication server corresponding to the target access mode and the address of the target subscription database corresponding to the target user identifier returned by the chain.
- the sending by the target access control network element to the target blockchain of the target user ID of the target device, the target security token, and the target access method includes: the target access control The network element sends the target user identifier of the target device, the target security token, and the target access method to the target blockchain through the target blockchain network element.
- the registration request carries a target security token of the target device, and the target security token is generated by a target random number issued by the target operation platform; wherein, the target access control network element Requesting the target authentication server address corresponding to the target access method and the target subscription database address corresponding to the target user identification from the target block chain, including: the target access control network element sends the target block chain Send the target user ID of the target device, the target security token, and the target access method; the target blockchain determines the target authority credential corresponding to the target device according to the target user ID, the The target authority certificate is generated according to the target random number issued by the target operation platform to the target device; if the target blockchain determines that the target authority certificate matches the target security token, then it is determined that the The address of the target authentication server corresponding to the target access method, and the address of the target subscription database corresponding to the target user ID; The target subscription database address corresponding to the target user identifier is returned to the target access control network element.
- the target access control network element sends the target user ID of the target device, the target security token, and the target access method to the target block chain, including: the target The access control network element sends an authentication request carrying the target user ID of the target device, the target security token, and the target access mode to the target blockchain network element; The authentication request sends the target user ID of the target device, the target security token, and the target access method to the target block chain, so as to request the target block chain to match the target access method The corresponding target authentication server address and the target subscription database address corresponding to the target user identifier.
- the target access control network element requests the target blockchain for the address of the target authentication server corresponding to the target access method and the address of the target subscription database corresponding to the target user identifier, including: The target access control network element requests the target block chain for the address of the target authentication server corresponding to the target access method, the address of the target subscription database corresponding to the target user identifier, and the address corresponding to the contract data of the target device target key; wherein, the target access control network element sends an authentication request carrying the address of the target subscription database to the target authentication server according to the address of the target authentication server, so that the target authentication server
- the address accessing the target subscription database to obtain the target subscription data corresponding to the target device includes: the target access control network element sending an authentication request carrying the address of the target subscription database and the target key to the target authentication The target authentication server corresponding to the server address, so that the target authentication server accesses the target contract database according to the target contract database address to obtain the target contract data corresponding to the target device through the target key.
- the target access control network element before the target access control network element receives the registration request sent by the target device, it further includes: the target operation platform stores the target user identifier and target subscription data corresponding to the target device in the target subscription database, and The target user identification and the target contract database address are stored in the target block chain.
- the target access control network element before the target access control network element receives the registration request sent by the target device, it further includes: the target operation platform signs a card for the target device; The target signing data corresponding to the target device is encrypted to obtain the target signing ciphertext; the target operation platform sends the target user identification corresponding to the target device and the target signing ciphertext to the target signing database for storage; the The target operation platform is to receive the target subscription database address and the target user identifier returned by the target subscription database; the target operation platform sends the target user identifier, the target subscription database address and the target key to the The target block chain, so that the target block chain associates and stores the target user identifier, the target subscription database address, and the target key.
- the method further includes: the target operation platform generates a target random number for the target device; the target operation platform generates a target permission credential according to the target random number; The target authority credential is sent to the target blockchain, so that the target blockchain associates and stores the target authority credential with the target user identifier.
- the method before the target access control network element receives the registration request sent by the target device, the method includes: the target operation platform acquires multiple access modes, the multiple access modes include the target access method; the target operation platform obtains multiple authentication server addresses of multiple authentication servers, and the multiple authentication server addresses include the address of the target authentication server; To determine the corresponding authentication server address respectively.
- an authentication device which is set in a target access control network element, and includes: a receiving module configured to receive a registration request sent by a target device; a determining module configured to The registration request determines the target user identifier corresponding to the target device and the target access method for the target device to access the network system; the request module is configured to request the target block chain for the target corresponding to the target access method An authentication server address and a target subscription database address corresponding to the target user identifier; a sending module configured to send an authentication request carrying the target subscription database address to the target authentication server according to the target authentication server address, so that the target The authentication server accesses the target contract database according to the address of the target contract database to obtain target contract data corresponding to the target device, so as to authenticate the target device according to the target contract data.
- an authentication system including: a target block chain, at least one authentication server address and at least one contract database address are stored in the target block chain, and the at least one authentication server includes The target authentication server, wherein the at least one subscription database address includes the target subscription database address; the target access control network element is configured to: receive a registration request sent by the target device; determine the target user identifier of the target device according to the registration request , and the target access method for the target device to access the network system; request the target authentication server address corresponding to the target access method and the target subscription database address corresponding to the target user identification from the target block chain; The address of the target authentication server sends an authentication request carrying the address of the target subscription database to the target authentication server, so that the target authentication server accesses the target subscription database according to the address of the target subscription database to obtain the target contract data corresponding to the target device , so as to authenticate the target device according to the target signing data.
- it also includes: a target operation platform configured to store the target user identifier and target subscription data corresponding to the target device in the target subscription database, and store the target user identifier and the target subscription database address in the target blockchain.
- an electronic device includes: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the electronic The device executes the authentication method described in any one of the above electronic devices.
- a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the authentication method described in any one of the above is implemented.
- a computer program including: instructions, which when executed by a processor cause the processor to execute the aforementioned authentication method.
- Fig. 1 shows an authentication method according to related technologies.
- Fig. 2 is a flowchart of an authentication method according to some exemplary embodiments.
- Fig. 3 shows an authentication system according to some exemplary embodiments.
- Fig. 4 is a sequence diagram of an authentication method according to some exemplary embodiments.
- Fig. 5 is a sequence diagram of an authentication method according to some exemplary embodiments.
- FIG. 6 shows a schematic structural diagram of an electronic device suitable for implementing an embodiment of the present disclosure.
- Fig. 7 is a schematic structural diagram of an authentication device according to some embodiments of the present disclosure.
- Example embodiments will now be described more fully with reference to the accompanying drawings.
- Example embodiments may, however, be embodied in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of example embodiments to those skilled in the art.
- the same reference numerals denote the same or similar parts in the drawings, and thus their repeated descriptions will be omitted.
- the terms “a”, “an”, “the”, “” and “at least one” are used to indicate the presence of one or more elements/components/etc.; the terms “comprising”, “including” and “having " is used in an open, inclusive sense and means that there may be additional elements/components/etc. in addition to the listed elements/components/etc.; the terms “first”, “second” and “Third” and so on are used only as marks, not as restrictions on the number of their objects.
- the user terminal UE sends a NAS message (a 5G message) to the AMF (Authentication Management Function, authentication management function), including SUCI (Subscription Concealed Identifier, subscription hidden identifier) or 5G-GUTI (5G Globally Unique Temporary UE Identity, 5G globally unique identifier) for registration.
- AMF Authentication Management Function, authentication management function
- SUCI Subscribed Identifier, subscription hidden identifier
- 5G-GUTI 5G Globally Unique Temporary UE Identity, 5G globally unique identifier
- AMF sends an authentication request to AUSF (Authentication server function, authentication service function), including SUCI/SUPI (Subscription Permanent Identifier, user permanent identifier) and service network name.
- AUSF Authentication server function, authentication service function
- SUCI/SUPI Subscribescription Permanent Identifier, user permanent identifier
- UDM Unified Data Management, unified data management function
- the UDM analyzes the SUCI to obtain the SUPI, determines the authentication method, and performs authentication processing.
- AUSF and UDM are addressed by AMF based on user identification (that is, user's number prefix or number segment) during authentication.
- the disclosure provides an authentication method, device, electronic equipment, and computer-readable storage medium.
- a target device When a target device sends a registration request, it can dynamically match the target device according to the target device's target access method and target user ID.
- the corresponding target authentication server address and the target subscription database address so as to authenticate the target device through the target authentication server corresponding to the target authentication server address and the target subscription database address corresponding to the target subscription database address.
- different authentication servers can be dynamically adapted for devices with different access modes, and the subscription database can be adapted without relying on the user number segment.
- the target operating platform can be allowed to sign a card for the target device through the following methods.
- the target operation platform signs a card for the target device; the target operation platform encrypts the target contract data corresponding to the target device through the target key to obtain the target contract ciphertext;
- the document is sent to the target contract database for storage; the target operation platform receives the target contract database address and the target user ID returned by the target contract database; the target operation platform sends the target user ID, target contract database address and target key to the target block chain , so that the target blockchain can associate and store the target user ID, target signing database address and target key.
- the data storage is carried out through the block chain.
- the data transfer process is also traceable; at the same time, the target contract data is encrypted using the target key, which makes the data safe, reliable and reliable on the one hand.
- the authentication process it can be guaranteed that only the device corresponding to the target signing data can hold the target key to decrypt the target ciphertext, thus ensuring the security in the authentication process.
- the target operation platform will also generate a target random number for the target device, and then generate a target authority certificate according to the target random number, and finally send the target authority certificate to the target blockchain, so that the target blockchain can associate the target authority certificate with the target user ID for associative storage.
- the target operation platform will also obtain multiple access methods, the multiple access methods include the target access method; the target operation platform can obtain multiple authentication server addresses of multiple authentication servers, and the multiple authentication server addresses include the target Authentication server address; the target operation platform can determine the corresponding authentication server address for each access method according to the authentication method of each authentication server.
- the target operating platform After the target operating platform determines the corresponding authentication server address for each access method, it will store each authentication server address and its corresponding access method in the target blockchain.
- the multiple access methods may include space-based access (such as satellite), ground-based access (such as base station), and space-based access (such as airplane, drone, hot air balloon, etc.), which is not limited in the present disclosure .
- space-based access such as satellite
- ground-based access such as base station
- space-based access such as airplane, drone, hot air balloon, etc.
- each access mode has an authentication server corresponding to it.
- At least one authentication server address and at least one contract database address can be stored in the target block chain, wherein at least one authentication server includes the target authentication server, at least one contract database address includes the target contract database address, each authentication server Corresponding to at least one access method (that is, an authentication server address can be matched through the access method), each subscription database corresponds to at least one user ID (that is, a subscription database can store subscription data corresponding to multiple user IDs, A subscription database address can be matched through the user ID).
- Fig. 2 is a flowchart showing an authentication method according to an exemplary embodiment.
- the authentication method provided by the embodiment of the present disclosure may include the following steps.
- Step S202 the target access control network element receives the registration request sent by the target device.
- the target device may send a registration request to the target access control network element in the target mobile network when accessing the target mobile network for the first time.
- the target access control network element may be any device in the target mobile network system, for example, it may be an AMF network element in the 5G network, and the disclosure does not limit this.
- the target device may be any electronic device that needs to communicate, such as a mobile phone, a computer, and a notebook, and this disclosure does not limit it.
- step S204 the target access control network element determines the target user ID corresponding to the target device and the target access method for the target device to access the network system according to the registration request.
- the above-mentioned target access method may be any access method such as space-based access, ground-based access, space-based access, fixed network access, etc., which is not limited in the present disclosure.
- Step S206 the target access control network element requests the target blockchain for the target authentication server address corresponding to the target access mode and the target subscription database address corresponding to the target user ID.
- the target access control network element can request the corresponding authentication server address from the target blockchain according to the target access mode, and can request the corresponding subscription database address from the target blockchain according to the target user identifier.
- the target blockchain can determine the target authentication server address corresponding to the target access method in at least one authentication server address according to the pre-stored association between the access method and the authentication server address, and can determine the target authentication server address corresponding to the target access method according to the pre-stored user identification and the subscription database. For the address association, determine the target subscription database address corresponding to the target user identifier in at least one subscription database, and return the target authentication server address and the target subscription database address to the target access control network element.
- the registration request sent by the target device may also carry a target security token of the target device, and the target security token is generated by a target random number issued by the target operation platform.
- the target access control network element requests the target blockchain for the target authentication server address and the target subscription database address corresponding to the target access mode
- the target access control network element sends the target user identification of the target device to the target blockchain , the target security token, and the target access method
- the target blockchain determines the target authority certificate corresponding to the target device according to the target user ID, and the target authority certificate is generated according to the target random number issued by the target operation platform to the target device; if If the target blockchain determines that the target authority certificate matches the target security token, then it determines the address of the target authentication server corresponding to the target access method, and the address of the target signing database corresponding to the target user ID; the target blockchain will match the target access method
- the address of the target authentication server corresponding to the mode and the address of the target subscription database corresponding to the target user ID are returned to the target access
- the above process compares the target security token with the target authority certificate, which can ensure the security of the entire authentication process and avoid illegal data acquisition.
- the target access control network element sending the target user identification of the target device, the target security token, and the target access method to the target blockchain may include the target access control network element sending the target blockchain network element Send an authentication request carrying the target user ID, target security token, and target access mode; the target blockchain network element sends the target user ID, target security token, and target access mode to the target blockchain according to the authentication request, so as to The target block chain requests the address of the target authentication server corresponding to the target access method and the address of the target signing database corresponding to the target user identification.
- the target blockchain network element may be a certain node in the target blockchain.
- the target blockchain network element may be located in the target network, for example, it may be the target access control network element, and of course it may also be a device independent of the target access control network element, which is not limited in the present disclosure.
- Step S208 the target access control network element sends an authentication request carrying the address of the target subscription database to the target authentication server according to the address of the target authentication server, so that the target authentication server accesses the target subscription database according to the address of the target subscription database to obtain the target subscription data corresponding to the target device , so as to authenticate the target device according to the target signing data.
- the target access control network element may request the target authentication server corresponding to the target authentication server address to access the target subscription database corresponding to the target subscription database address, so as to obtain the subscription data corresponding to the target device, so as to perform authentication processing on the target device .
- the target access control network element requests the target authentication server address corresponding to the target access mode and the target subscription database address corresponding to the target user identifier from the target block chain, including: the target access control network element requests The target block chain requests the address of the target authentication server corresponding to the target access method, the address of the target subscription database corresponding to the target user ID, and the target key corresponding to the contract data of the target device;
- the target access control network element sends an authentication request carrying the target subscription database address to the target authentication server according to the target authentication server address, so that the target authentication server accesses the target subscription database according to the target subscription database address to obtain the target subscription data corresponding to the target device.
- the target access control network element sends the authentication request, the target signing database address and the target key to the target authentication server corresponding to the target authentication server address, so that the target authentication server accesses the target signing database according to the target signing database address to pass the target key
- the target signing data corresponding to the target device is obtained.
- the above process can encrypt and decrypt the target contract data through the target key, which improves the security of data transmission and avoids illegal acquisition of data.
- the technical solution provided by this embodiment introduces blockchain technology, and records the address of the authentication server and the address of the signing database on the blockchain; the terminal passes the security token to the blockchain through the network element of the blockchain, and the blockchain determines After the security token and the authority certificate are consistent, the contract database and authentication server address and key are returned; when the access control network element sends the authentication request to the blockchain, it carries the access type and user ID, and the blockchain responds according to different access types Different authentication servers return different subscription database addresses according to different user IDs. For different access methods, different operators may provide services, so there may be different authentication servers, and for different user identities, services may be provided by different subscription databases, so there may be different subscription databases. If services are provided by the same operator, different authentication servers may be used for different access technologies, and the subscription databases may be unified or different.
- This method solves the routing and addressing problem of identity authentication when providing services across operators, and supports flexible selection of independent subscription databases and authentication servers according to access types, providing a solid foundation for future (such as 6G) heterogeneous network integration.
- the authentication system corresponding to the authentication method provided by this disclosure may include network devices, authentication servers, contract databases and other devices of each operator, and these devices can interact through the blockchain network to achieve decentralization distributed deployment.
- blockchain network elements that interact with the blockchain in the network equipment, and the operator's operation platform compares the corresponding relationship between the target user ID and the contract database address, the corresponding relationship between the access method and the authentication server, and the user ID and key.
- the association relationship of the network is recorded in the blockchain, and the network element of the blockchain obtains the address of the authentication server corresponding to the access mode of the device, the address of the contract database corresponding to the user ID, and other information from the blockchain, and completes the identification through this method. Addressing flow during authentication.
- the operator's operating platform can open a card for the user, encrypt the user subscription data corresponding to the user card, store the target user identifier and the encrypted user subscription data in the subscription database and return the storage location; the operator The platform selects different authentication servers according to different access methods and returns the address of the authentication server corresponding to the access methods.
- the operating platform records the returned information and the decryption key on the blockchain.
- the operation platform generates a random number and sends it to the terminal, and generates a permission certificate based on the random number and sends it to the blockchain, which stores it locally.
- the addressing process of the authentication server and subscription database is done through the blockchain.
- the terminal device generates a security token according to the random number, and sends the registration request and the security token to the access control network element.
- the access control network element judges the access mode of the terminal and sends an authentication request to the blockchain network element.
- the blockchain network element queries the blockchain for the data required for authentication, and at the same time sends it a security token.
- the blockchain network element passes it to the access control network element, and the access control network element addresses according to the address of the authentication server, sends an authentication request, and carries the address and key of the contract database.
- the authentication server addresses according to the received address of the signing database, and sends the authentication request and the decryption key of the signing data to the signing database.
- the terminal and the network complete the authentication process and return the authentication result to the terminal.
- the authentication method corresponding to the system shown in FIG. 3 can be specifically described through the sequence diagrams shown in FIG. 4 and FIG. 5 .
- the operator's operating platform opens a card for the user, encrypts the user contract data corresponding to the user card, and stores the target user ID and the encrypted user contract data in the contract database.
- the subscription database returns the storage location of the subscription data corresponding to the target user identifier to the operation platform.
- the operation platform selects different authentication servers according to different access methods, and the operation platform associates the access methods with the corresponding authentication servers.
- the authentication server returns the address of the authentication server corresponding to the access mode.
- steps 1, 2 and steps 3, 4 are not limited, and steps 3, 4 can be performed before 1, 2 or at the same time.
- the operating platform records the returned information and the decryption key on the blockchain.
- the address of the authentication server, the address of the signing database, and the decryption key can be stored on the blockchain as a whole or stored separately on the blockchain.
- the operation platform provides the relevant information of the user card to the terminal.
- the user card is the unique identity of the mobile user in the network.
- the terminal accesses the network, it provides the user ID, performs calculations based on the authentication parameters (such as key K) and algorithms stored in the card, and provides an authentication response.
- USIM Universal Subscriber Identity Module
- OTA OTA data
- the USIM writing method allows the mobile device to obtain the SUCI generated by the USIM through the ME-UICC (ME: mobile device, UICC: Universal Integrated Circuit Card, Universal Integrated Circuit Card) machine card interface GET IDENTITY command; OTA (Over The Air, over the air download Technology)
- Data writing refers to the synchronization of card authentication configuration data with the card authentication system through OTA data SMS.
- the operation platform generates the first random number and sends it to the terminal.
- the operation platform generates an authorization certificate according to the first random number.
- the permission certificate can be generated by hashing the random number, or by hashing the user ID and the random number together.
- the operation platform sends the authority certificate to the blockchain.
- the blockchain stores the authority certificate locally, and then updates its own storage information.
- the terminal device generates a security token according to the first random number.
- the terminal device sends the registration request and the security token to the access control network element.
- the access control network element judges the access mode of the terminal, which can be satellite access, fixed network access, mobile access, etc.
- the access control network element sends an identity authentication request to the blockchain network element, including the terminal user ID, access method and security token.
- the blockchain network element queries the blockchain for the data required for identity authentication, and at the same time sends it a security token.
- the blockchain determines whether the security token is the same as the locally stored authority certificate, and then returns the address of the signing database according to the target user ID of the target device, and returns the address of the authentication server according to the access type.
- Different access types such as satellite, fixed network, and cellular network may be provided by different operators, so there may be different authentication servers and subscription databases.
- the same operator may adopt different authentication technologies for different access methods, and different authentication servers may complete the authentication.
- the subscription databases may be unified or different. This method supports all implementation methods.
- the blockchain network element sends the signing database, authentication server address and key to the access control network element.
- the access control network element finds the corresponding authentication server according to the address of the authentication server, sends an authentication request, and carries the address and key of the contract database.
- the authentication server performs addressing according to the received signing database address.
- the signing database decrypts the encrypted data according to the received key.
- the terminal and the network complete the authentication and authorization process, such as the EAP-AKA' authentication (an authentication method) process used in 5G or the 5G AKA authentication (an authentication method) process.
- EAP-AKA' authentication an authentication method
- 5G AKA authentication an authentication method
- AMF is the access control network element
- AUSF is the authentication server
- UDM is the subscription database.
- the technical solution provided by this embodiment uses block chain technology to solve the addressing problem of the attribution authentication server and the contract database, which greatly improves the reliability and flexibility of data sharing between operators.
- the technical solution provided in this embodiment can select different authentication servers according to different access types, and the subscription databases can be unified or different, and different implementation modes are supported.
- the present disclosure also provides an authentication system, which may include a target block chain, at least one authentication server address and at least one contract database address are stored in the target block chain, at least one authentication server includes the target authentication server, at least one The subscription database address includes the target subscription database address; the authentication system also includes a target access control network element, which is used to receive the registration request sent by the target device; determine the target user ID of the target device and the target device access network system according to the registration request Access method; request to the target block chain the address of the target authentication server corresponding to the target access method and the address of the target signing database corresponding to the target user ID; send an authentication certificate carrying the address of the target signing database to the target authentication server according to the address of the target authentication server Request, so that the target authentication server accesses the target contract database according to the address of the target contract database to obtain the target contract data corresponding to the target device, so as to authenticate the target device according to the target contract data.
- an authentication system may include a target block chain, at least one authentication server address and at least one contract database
- the registration request carries the target security token of the target device, and the target security token is generated by the target random number issued by the target operation platform;
- the address of the target authentication server corresponding to the access method and the address of the target subscription database corresponding to the target user ID including:
- the target access control network element sends the target user ID of the target device, the target security token and the target access method to the target blockchain;
- the target blockchain determines the target authority certificate corresponding to the target device according to the target user identification, and the target authority certificate is generated according to the target random number issued by the target operation platform to the target device;
- target block chain determines that the target authority credential matches the target security token, then determine the target authentication server address corresponding to the target access method, and the target signing database address corresponding to the target user ID;
- the target access control network element sending the target user identification of the target device, the target security token, and the target access method to the target block chain includes: the target access control network element sends the target block chain network element An authentication request carrying the target user ID, target security token, and target access mode; the target blockchain network element sends the target user ID, target security token, and target access mode to the target blockchain according to the authentication request, to send the target user ID, target security token, and target access mode to the target
- the block chain requests the target authentication server address corresponding to the target access mode and the target signing database address corresponding to the target user identification.
- the request from the target access control network element to the target block chain for the address of the target authentication server corresponding to the target access method and the address of the target subscription database corresponding to the target user identifier includes: the target access control network element sends the target The block chain requests the address of the target authentication server corresponding to the target access method, the address of the target subscription database corresponding to the target user ID, and the target key corresponding to the contract data of the target device; wherein, the target access control network element according to the target The authentication server address sends an authentication request carrying the target subscription database address to the target authentication server, so that the target authentication server accesses the target subscription database according to the target subscription database address to obtain the target subscription data corresponding to the target device, including: the target access control network element will authenticate The request, the address of the target signing database and the target key are sent to the target authentication server corresponding to the address of the target authentication server, so that the target authentication server accesses the target signing database according to the address of the target signing database to obtain the target signing data corresponding to the target
- the method before the target access control network element receives the registration request sent by the target device, the method includes: the target operation platform signs a card for the target device; The signing data is encrypted to obtain the target signing ciphertext; the target operation platform sends the target user identification corresponding to the target device and the target signing ciphertext to the target signing database for storage; the target operating platform receives the target signing database address and Target user identification; the target operation platform sends the target user identification, target contract database address and target key to the target block chain, so that the target block chain can associate and store the target user identification, target contract database address and target key.
- the target operation platform is also used to generate a target random number for the target device; the target operation platform generates a target authority certificate according to the target random number; the target operation platform sends the target authority certificate to the target block chain, so that the target The blockchain associates and stores the target authority credentials with the target user ID.
- the target access control network element before the target access control network element receives the registration request sent by the target device, it further includes: the target operation platform obtains multiple access methods, and the multiple access methods include the target access method; the target operation platform obtains The multiple authentication server addresses of the multiple authentication servers, the multiple authentication server addresses include the address of the target authentication server; the target operation platform determines the corresponding target authentication server address for each access mode according to the authentication mode of each authentication server.
- each block in a flowchart or block diagram may represent a module, program segment, or portion of code that includes one or more logical functions for implementing specified executable instructions.
- the functions noted in the block may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or they may sometimes be executed in the reverse order, depending upon the functionality involved.
- each block in the block diagrams or flowchart illustrations, and combinations of blocks in the block diagrams or flowchart illustrations can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a A combination of dedicated hardware and computer instructions.
- FIG. 6 shows a schematic structural diagram of an electronic device suitable for implementing an embodiment of the present disclosure. It should be noted that the electronic device 600 shown in FIG. 6 is only an example, and should not limit the functions and application scope of the embodiments of the present disclosure.
- an electronic device 600 includes a central processing unit (CPU) 601, which can operate according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603 Instead, various appropriate actions and processes are performed.
- ROM read-only memory
- RAM random access memory
- various programs and data necessary for the operation of the electronic device 600 are also stored.
- the CPU 601, ROM 602, and RAM 603 are connected to each other through a bus 604.
- An input/output (I/O) interface 605 is also connected to the bus 604 .
- the following components are connected to the I/O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage section 608 including a hard disk, etc. and a communication section 609 including a network interface card such as a LAN card, a modem, or the like.
- the communication section 609 performs communication processing via a network such as the Internet.
- a drive 610 is also connected to the I/O interface 605 as needed.
- a removable medium 611 such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc. is mounted on the drive 610 as necessary so that a computer program read therefrom is installed into the storage section 608 as necessary.
- the processes described above with reference to the flowcharts can be implemented as computer software programs.
- the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable storage medium, where the computer program includes program codes for executing the methods shown in the flowcharts.
- the computer program may be downloaded and installed from a network via communication portion 609 and/or installed from removable media 611 .
- this computer program is executed by a central processing unit (CPU) 601
- CPU central processing unit
- the computer-readable storage medium shown in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two.
- a computer readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, electrical connections with one or more wires, portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable Programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the above.
- a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
- a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, in which computer-readable program codes are carried. Such propagated data signals may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing.
- a computer-readable signal medium may also be any computer-readable storage medium other than a computer-readable storage medium that can be sent, propagated, or transported for use by or in conjunction with an instruction execution system, apparatus, or device program of.
- Program code embodied on a computer readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wires, optical cables, RF, etc., or any suitable combination of the foregoing.
- the present application also provides a computer-readable storage medium, which may be included in the device described in the above-mentioned embodiments; or exist independently without being assembled into the device middle.
- the above-mentioned computer-readable storage medium carries one or more programs, and when the above-mentioned one or more programs are executed by one of the devices, enabling the device to implement functions includes: the target access control network element receives the registration request sent by the target device;
- the target access control network element determines the target user identifier corresponding to the target device and the target access method for the target device to access the network system according to the registration request; the target access control network element sends a message to the target area
- the block chain requests the target authentication server address corresponding to the target access method and the target subscription database address corresponding to the target user identifier; the target access control network element sends the target authentication server address to the target authentication server according to the target authentication server address an authentication request carrying the address of the target subscription database, so that the target authentication server accesses the target subscription database according to the address of the target subscription database to obtain the target contract data corresponding to the target device, so that the The target device is authenticated.
- a computer program product or computer program comprising computer instructions stored in a computer readable storage medium.
- the processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the methods provided in various optional implementation manners of the foregoing embodiments.
- Fig. 7 is a schematic structural diagram of an authentication device according to some embodiments of the present disclosure.
- the authentication device in the embodiment of the present disclosure is set in the target access control network element.
- the authentication device 700 includes: a receiving module 710 , a determining module 720 , a requesting module 730 , and a sending module 740 .
- the receiving module 710 is configured to receive the registration request sent by the target device.
- the determining module 720 is configured to determine a target user identifier corresponding to the target device and a target access method for the target device to access the network system according to the registration request.
- the requesting module 730 is configured to request from the target blockchain the address of the target authentication server corresponding to the target access method and the address of the target subscription database corresponding to the target user ID.
- the sending module 740 is configured to send an authentication request carrying a target subscription database address to the target authentication server according to the target authentication server address, so that the target authentication server accesses the target subscription database according to the target subscription database address to obtain target subscription data corresponding to the target device, thereby The target device is authenticated based on the target signing data.
- the authentication device in the embodiment of the present disclosure can dynamically adapt different authentication servers for devices with different access modes, and can adapt the subscription database without relying on the user number segment.
- the technical solutions of the embodiments of the present disclosure can be embodied in the form of software products, which can be stored in a non-volatile storage medium (which can be CD-ROM, U disk, mobile hard disk, etc.), including several instruction It is used to make a computing device (which may be a personal computer, a server, a mobile terminal, or a smart device, etc.) execute the method according to the embodiment of the present disclosure, such as the steps shown in FIG. 3 .
- a computing device which may be a personal computer, a server, a mobile terminal, or a smart device, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (16)
- 一种认证方法,包括:目标接入控制网元接收目标设备发送的注册请求;所述目标接入控制网元根据所述注册请求确定所述目标设备对应的目标用户标识、和所述目标设备接入网络系统的目标接入方式;所述目标接入控制网元向目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址,目标区块链中存储有至少一个认证服务器地址和至少一个签约数据库地址,所述至少一个认证服务器包括目标认证服务器,所述至少一个签约数据库地址包括目标签约数据库地址;所述目标接入控制网元根据所述目标认证服务器地址向目标认证服务器发送携带所述目标签约数据库地址的认证请求,以便所述目标认证服务器根据所述目标签约数据库地址访问目标签约数据库以获得所述目标设备对应的目标签约数据,从而根据所述目标签约数据对所述目标设备进行认证。
- 根据权利要求1所述的认证方法,其中,所述目标接入控制网元向目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址,包括:所述目标接入控制网元向所述目标区块链发送所述目标设备的目标用户标识、目标安全令牌以及所述目标接入方式;所述目标接入控制网元接收所述目标区块链返回的与所述目标接入方式对应的目标认证服务器地址、和与所述目标用户标识对应的目标签约数据库地址。
- 根据权利要求2所述的认证方法,其中,所述目标接入控制网元向所述目标区块链发送所述目标设备的目标用户标识、目标安全令牌以及所述目标接入方式包括:所述目标接入控制网元,通过目标区块链网元,向所述目标区块链发送所述目标设备的目标用户标识、目标安全令牌以及所述目标接入方式。
- 根据权利要求1所述的认证方法,其中,所述注册请求携带所述目标设备的目标安全令牌,所述目标安全令牌是由目标运营平台下发的目标随机数生成;其中, 所述目标接入控制网元向目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址,包括:所述目标接入控制网元向所述目标区块链发送所述目标设备的目标用户标识、所述目标安全令牌以及所述目标接入方式;所述目标区块链根据所述目标用户标识确定与所述目标设备对应的目标权限凭证,所述目标权限凭证是根据所述目标运营平台下发给所述目标设备的目标随机数生成的;若所述目标区块链确定所述目标权限凭证与所述目标安全令牌匹配,则确定与所述目标接入方式对应的目标认证服务器地址、和与所述目标用户标识对应的目标签约数据库地址;所述目标区块链将与所述目标接入方式对应的目标认证服务器地址、和与所述目标用户标识对应的目标签约数据库地址返回给所述目标接入控制网元。
- 根据权利要求4所述的认证方法,其中,所述目标接入控制网元向所述目标区块链发送所述目标设备的目标用户标识、所述目标安全令牌以及所述目标接入方式,包括:所述目标接入控制网元向目标区块链网元发送携带所述目标用户标识、所述目标安全令牌以及所述目标接入方式的认证请求;所述目标区块链网元根据所述认证请求向所述目标区块链发送所述目标用户标识、所述目标安全令牌以及所述目标接入方式,以向所述目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址。
- 根据权利要求1所述的认证方法,其中,所述目标接入控制网元向目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址,包括:所述目标接入控制网元向目标区块链请求与所述目标接入方式对应的目标认证服务器地址、与所述目标用户标识对应的目标签约数据库地址、和与所述目标设备的签约数据对应的目标密钥;其中,所述目标接入控制网元根据所述目标认证服务器地址向目标认证服务器发 送携带所述目标签约数据库地址的认证请求,以便所述目标认证服务器根据所述目标签约数据库地址访问目标签约数据库以获得所述目标设备对应的目标签约数据,包括:所述目标接入控制网元将携带所述目标签约数据库地址和所述目标密钥的认证请求发送给所述目标认证服务器地址对应的目标认证服务器,以便所述目标认证服务器根据所述目标签约数据库地址访问目标签约数据库以通过所述目标密钥获得所述目标设备对应的目标签约数据。
- 根据权利要求1所述的认证方法,在目标接入控制网元接收目标设备发送的注册请求之前,还包括:目标运营平台将所述目标设备对应的目标用户标识和目标签约数据存储至目标签约数据库,并将所述目标用户标识和目标签约数据库地址存储至目标区块链。
- 根据权利要求1所述的认证方法,在目标接入控制网元接收目标设备发送的注册请求之前,还包括:目标运营平台为所述目标设备进行签约开卡;所述目标运营平台通过目标密钥对所述目标设备对应的目标签约数据进行加密以获得目标签约密文;所述目标运营平台将所述目标设备对应的目标用户标识和所述目标签约密文发送至目标签约数据库以进行存储;所述目标运营平台接收所述目标签约数据库返回的目标签约数据库地址和所述目标用户标识;所述目标运营平台将所述目标用户标识、所述目标签约数据库地址以及所述目标密钥发送给所述目标区块链,以便所述目标区块链将所述目标用户标识、所述目标签约数据库地址以及所述目标密钥进行关联存储。
- 根据权利要求8所述的认证方法,还包括:所述目标运营平台为所述目标设备生成目标随机数;所述目标运营平台根据所述目标随机数生成目标权限凭证;所述目标运营平台将所述目标权限凭证发送给所述目标区块链,以便所述目标区块链将所述目标权限凭证与所述目标用户标识进行关联存储。
- 根据权利要求1所述的认证方法,在目标接入控制网元接收目标设备发送的注册请求之前,还包括:目标运营平台获取多个接入方式,所述多个接入方式包括所述目标接入方式;所述目标运营平台获取多个认证服务器的多个认证服务器地址,所述多个认证服务器地址包括所述目标认证服务器地址;所述目标运营平台根据各个认证服务器的认证方式为各个接入方式分别确定对应的目标认证服务器地址。
- 一种认证装置,设置在目标接入控制网元中,包括:接收模块,被配置为接收目标设备发送的注册请求;确定模块,被配置为根据所述注册请求确定所述目标设备对应的目标用户标识、和所述目标设备接入网络系统的目标接入方式;请求模块,被配置为向目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址;发送模块,被配置为根据所述目标认证服务器地址向目标认证服务器发送携带所述目标签约数据库地址的认证请求,以便所述目标认证服务器根据所述目标签约数据库地址访问目标签约数据库以获得所述目标设备对应的目标签约数据,从而根据所述目标签约数据对所述目标设备进行认证。
- 一种认证系统,包括:目标区块链,所述目标区块链中存储有至少一个认证服务器地址和至少一个签约数据库地址,所述至少一个认证服务器包括目标认证服务器,所述至少一个签约数据库地址包括目标签约数据库地址;和目标接入控制网元,被配置为:接收目标设备发送的注册请求;根据所述注册请求确定所述目标设备的目标用户标识、和所述目标设备接入网络系统的目标接入方式;向目标区块链请求与所述目标接入方式对应的目标认证服务器地址和与所述目标用户标识对应的目标签约数据库地址;根据所述目标认证服务器地址向目标认证服务器发送携带所述目标签约数据 库地址的认证请求,以便所述目标认证服务器根据所述目标签约数据库地址访问目标签约数据库以获得所述目标设备对应的目标签约数据,从而根据所述目标签约数据对所述目标设备进行认证。
- 根据权利要求12所述的认证系统,还包括:目标运营平台,被配置为将所述目标设备对应的目标用户标识和目标签约数据存储至目标签约数据库,并将所述目标用户标识和目标签约数据库地址存储至目标区块链。
- 一种电子设备,其特征在于,包括:存储器;以及耦合到所述存储器的处理器;所述电子设备被用于基于存储在所述存储器中的指令,执行如权利要求1-10任一项所述的认证方法。
- 一种计算机可读存储介质,其上存储有程序,该程序被处理器执行时实现如权利要求1-10任一项所述的认证方法。
- 一种计算机程序,包括:指令,所述指令当由处理器执行时使所述处理器执行根据权利要求1-10中任一项所述的认证方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202111559465.7A CN114286342B (zh) | 2021-12-20 | 2021-12-20 | 认证方法、系统、电子设备和计算机可读存储介质 |
| CN202111559465.7 | 2021-12-20 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023115913A1 true WO2023115913A1 (zh) | 2023-06-29 |
Family
ID=80873379
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/105156 Ceased WO2023115913A1 (zh) | 2021-12-20 | 2022-07-12 | 认证方法、系统、电子设备和计算机可读存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN114286342B (zh) |
| WO (1) | WO2023115913A1 (zh) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114286342B (zh) * | 2021-12-20 | 2024-01-02 | 中国电信股份有限公司 | 认证方法、系统、电子设备和计算机可读存储介质 |
| CN115001707B (zh) * | 2022-05-27 | 2023-06-27 | 珠海复旦创新研究院 | 基于区块链的设备认证方法和相关设备 |
| CN116709322B (zh) * | 2023-06-27 | 2026-01-13 | 中国电信股份有限公司 | 网络认证方法、装置、通信设备及计算机可读存储介质 |
| CN119109974A (zh) * | 2024-08-12 | 2024-12-10 | 珠海格力电器股份有限公司 | 一种联网设备的注册方法、装置、电子设备和存储介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108702622A (zh) * | 2017-11-30 | 2018-10-23 | 深圳前海达闼云端智能科技有限公司 | 移动网络接入认证方法、装置、存储介质及区块链节点 |
| US20190305964A1 (en) * | 2018-03-27 | 2019-10-03 | Workday, Inc. | Digital credentials for user device authentication |
| US20200280851A1 (en) * | 2019-03-01 | 2020-09-03 | Hewlett Packard Enterprise Development Lp | Remote access point clustering for user authentication in wireless networks |
| CN114286342A (zh) * | 2021-12-20 | 2022-04-05 | 中国电信股份有限公司 | 认证方法、系统、电子设备和计算机可读存储介质 |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106533696B (zh) * | 2016-11-18 | 2019-10-01 | 江苏通付盾科技有限公司 | 基于区块链的身份认证方法、认证服务器及用户终端 |
| CN110581860B (zh) * | 2019-09-19 | 2022-08-26 | 腾讯科技(深圳)有限公司 | 基于区块链的身份认证方法、装置、存储介质和设备 |
-
2021
- 2021-12-20 CN CN202111559465.7A patent/CN114286342B/zh active Active
-
2022
- 2022-07-12 WO PCT/CN2022/105156 patent/WO2023115913A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108702622A (zh) * | 2017-11-30 | 2018-10-23 | 深圳前海达闼云端智能科技有限公司 | 移动网络接入认证方法、装置、存储介质及区块链节点 |
| US20190305964A1 (en) * | 2018-03-27 | 2019-10-03 | Workday, Inc. | Digital credentials for user device authentication |
| US20200280851A1 (en) * | 2019-03-01 | 2020-09-03 | Hewlett Packard Enterprise Development Lp | Remote access point clustering for user authentication in wireless networks |
| CN114286342A (zh) * | 2021-12-20 | 2022-04-05 | 中国电信股份有限公司 | 认证方法、系统、电子设备和计算机可读存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN114286342B (zh) | 2024-01-02 |
| CN114286342A (zh) | 2022-04-05 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2023115913A1 (zh) | 认证方法、系统、电子设备和计算机可读存储介质 | |
| CN100592827C (zh) | 用于联合单点登录服务的系统、方法和设备 | |
| US8196188B2 (en) | Systems and methods for providing network credentials | |
| US20070254630A1 (en) | Methods, devices and modules for secure remote access to home networks | |
| TWI455558B (zh) | 通訊網路之認證 | |
| US20080060066A1 (en) | Systems and methods for acquiring network credentials | |
| US20080209206A1 (en) | Apparatus, method and computer program product providing enforcement of operator lock | |
| JP2022541760A (ja) | コアネットワークドメインにおける証明書ハンドリングのための技法 | |
| US11070980B1 (en) | Secondary device authentication proxied from authenticated primary device | |
| JP5276593B2 (ja) | ネットワーク信用証明書を獲得するためのシステムおよび方法 | |
| US12289310B2 (en) | Decentralized application authentication | |
| KR20160127167A (ko) | 다중 팩터 인증 기관 | |
| JP2018517367A (ja) | サービスプロバイダ証明書管理 | |
| WO2022160124A1 (zh) | 一种服务授权管理方法及装置 | |
| US12074859B2 (en) | Password-less wireless authentication | |
| WO2019056971A1 (zh) | 一种鉴权方法及设备 | |
| CN112512048A (zh) | 移动网络接入系统、方法、存储介质及电子设备 | |
| CN112423300A (zh) | 无线网络接入认证方法及装置 | |
| CN114584967B (zh) | 数据管理方法、装置、系统及计算机可读存储介质 | |
| WO2024240192A1 (zh) | 通信方法、通信设备、介质及程序产品 | |
| JP7312279B2 (ja) | モバイルネットワークアクセスシステム、方法、記憶媒体及び電子機器 | |
| CN117528513A (zh) | 一种通信认证方法及相关设备 | |
| WO2018119608A1 (zh) | 应用处理方法、网络设备及终端设备 | |
| CN117135635B (zh) | 用户身份验证系统、方法、装置、网络设备及存储介质 | |
| CN115913584B (zh) | 鉴权方法、装置、电子设备和计算机可读存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22909244 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22909244 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 09-07-2025) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22909244 Country of ref document: EP Kind code of ref document: A1 |