According to the foregoing authentication system, the network device may obtain the first virtual interface information that represents the current service type of the home network element and the second virtual interface information of the residential gateway, and may verify the validity of the current service of the residential gateway based on the first virtual interface information and the second virtual interface information. Therefore, according to the authentication system provided in the embodiment of this application, the validity of the current service of the residential gateway can be verified in the fixed-mobile convergence architecture.
Optionally,
The mobility management network element 201 is configured to obtain a first key. The first key is a temporary key between the mobility management network element 201 and a residential gateway.
The mobility management network element 201 is further configured to determine a second key based on the first key, an identifier of a non-3GPP network, and a classification identifier of the non-3GPP network, and send the second key to the access gateway function network element 202. The second key is a temporary key between the access gateway function network element 202 and the residential gateway.
The access gateway function network element 202 is configured to receive the second key from the mobility management network element 201.