A building equipment life cycle management SaaS system and method

CN116980218BActive Publication Date: 2026-08-11浙江浙能数字科技有限公司 +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-11
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0003]然而,PNI-NPN可能会有安全风险,如何避免PNI-NPN的安全风险对PLMN造成影响是目前研究的热点问题

Benefits of technology

[0028]在PNI-NPN向运营商网络请求服务时,如请求运营商网络为PNI-NPN中的楼宇设备提供生命周期管控SaaS,运营商网络中的AF可以触发运营商网络对PNI-NPN进行主鉴权,以确定PNI-NPN可信的情况下为PNI-NPN中的楼宇设备提供生命周期管控SaaS,否则,拒绝为PNI-NPN中的楼宇设备提供生命周期管控SaaS,以避免PNI-NPN的安全风险对PLMN造成影响。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116980218B_ABST
    Figure CN116980218B_ABST
Patent Text Reader

Abstract

This application provides a SaaS system and method for lifecycle management of building equipment. In this method, when a PNI-NPN requests services from an operator network, such as requesting the operator network to provide lifecycle management SaaS for building equipment in the PNI-NPN, the AF in the operator network can trigger the operator network to perform master authentication on the PNI-NPN. If the PNI-NPN is trustworthy, the operator network will provide lifecycle management SaaS for the building equipment in the PNI-NPN. Otherwise, the operator network will refuse to provide lifecycle management SaaS for the building equipment in the PNI-NPN, so as to avoid the security risks of the PNI-NPN from affecting the PLMN.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and in particular to a SaaS method for lifecycle management of building equipment. Background Technology

[0002] New Radio (NR) networks can include an access network (AN) and a core network (CN). The CN has management functions and can provide services to non-public networks (NPNs), such as Public Network Integrated NPNs (PNI-NPNs). In other words, a PNI-NPN can be partially or fully hosted on the CN, i.e., the Public Land Mobile Network (PLMN) infrastructure, relying on the PLMN's network functions. For example, if building equipment is deployed in a PNI-NPN, it can rely on the PLMN to implement software as a service (SaaS) for equipment lifecycle management.

[0003] However, PNI-NPN may pose safety risks, and how to avoid the impact of PNI-NPN safety risks on PLMN is currently a hot research topic. Summary of the Invention

[0004] This application provides a SaaS system and method for lifecycle management of building equipment to avoid the impact of PNI-NPN security risks on PLMN.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] Firstly, a SaaS method for lifecycle management of building equipment is provided. A building equipment is deployed in a PNI-NPN, which relies on services provided by an operator network, including an AF corresponding to the PNI-NPN. The method includes: the AF receiving a service request from the PNI-NPN, wherein the service request requests the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN; the AF requesting the operator network to perform master authentication on the PNI-NPN based on the service request; and, if master authentication is successful, the AF sending a service response to the PNI-NPN, wherein the service response instructs the AF to provide lifecycle management SaaS for the building equipment in the PNI-NPN.

[0007] In one possible design, the AF receives a service request from the PNI-NPN, including: the AF receiving a first Nx message from the AMF in the operator network, wherein the first Nx message contains a service request, which includes: access indication information, identification information of the first terminal, and service request information. The access indication information is used to indicate that the PNI-NPN is accessing the operator network as a terminal and needs the AF to provide services. The identification information of the first terminal is used to identify the terminal that the PNI-NPN is acting as. The service request information is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN.

[0008] Optionally, the operator network's primary authentication of the PNI-NPN means that the operator network uses the PNI-NPN as the first terminal to access the operator network and performs two-way authentication between the first terminal and the operator network. Passing the primary authentication includes the first terminal authenticating the operator network and the operator network authenticating the first terminal.

[0009] Furthermore, based on the service request, the AF requests the operator network to authenticate the PNI-NPN, including: the AF sends a second Nx message to the UDM in the operator network based on the access indication information and the identification information of the first terminal, wherein the second Nx message is used to request the UDM to perform 5G AKA primary authentication for the first terminal.

[0010] Furthermore, the second Nx message includes the identification information of the first terminal and the identification information used to indicate that the main authentication is 5G AKA.

[0011] Optionally, the AF sends a service response to the PNI-NPN, including: the AF sends a service response encrypted by the AF's local key KAF to the PNI-NPN, wherein the key KAF is obtained by the AF hashing at least one of the access indication information, the identification information of the first terminal and the service request information and the key KAUSF as input parameters, the key KAUSF is derived in the main authentication process and provided by the AUSF in the operator network, and the key KAF serves as a security protection key for AF to communicate with the PNI-NPN via NAS.

[0012] Furthermore, AF provides lifecycle management SaaS for building equipment in PNI-NPN, including: AF receiving device information encrypted by PNI-NPN's local key KAF, where the device information includes the current aging time of the building equipment in PNI-NPN and the current working status data of the building equipment in PNI-NPN; AF decrypting the encrypted device information using AF's local key KAF; AF updating the current aging time of the building equipment in PNI-NPN according to the current working status data of the building equipment in PNI-NPN to obtain the updated aging time of the building equipment in PNI-NPN; AF sending service information encrypted by AF's local key KAF to PNI-NPN, where the service information is used to indicate the updated aging time of the building equipment in PNI-NPN.

[0013] Optionally, the service request may also include the identifier of the building equipment in the PNI-NPN. The method further includes: the AF sending a third Nx message to the UDM in the operator network based on the identifier of the building equipment in the PNI-NPN, wherein the third Nx message is used to request the UDM to perform 5G AKA master authentication on the building equipment.

[0014] Furthermore, if the main authentication of the building equipment passes, the AF will still send a service response to the PNI-NPN even if the main authentication of the PNI-NPN fails.

[0015] Secondly, a SaaS system for lifecycle management of building equipment is provided. A PNI-NPN is deployed with building equipment, and the PNI-NPN relies on services provided by an operator network, which includes an AF corresponding to the PNI-NPN. The system is configured as follows: the AF receives a service request from the PNI-NPN, wherein the service request is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN; the AF requests the operator network to perform master authentication on the PNI-NPN based on the service request; if the master authentication is successful, the AF sends a service response to the PNI-NPN, wherein the service response is used to instruct the AF to provide lifecycle management SaaS for the building equipment in the PNI-NPN.

[0016] In one possible design, the system is configured such that: the AF receives a first Nx message from the AMF in the operator network, wherein the first Nx message contains a service request, the service request including: access indication information, identification information of the first terminal and service request information, the access indication information is used to indicate that the PNI-NPN is accessing the operator network as a terminal and needs the AF to provide services, the identification information of the first terminal is used to identify the terminal that the PNI-NPN is acting as, and the service request information is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN.

[0017] Optionally, the operator network's primary authentication of the PNI-NPN means that the operator network uses the PNI-NPN as the first terminal to access the operator network and performs two-way authentication between the first terminal and the operator network. Passing the primary authentication includes the first terminal authenticating the operator network and the operator network authenticating the first terminal.

[0018] Furthermore, the system is configured such that: the AF sends a second Nx message to the UDM in the operator network based on the access indication information and the identification information of the first terminal, wherein the second Nx message is used to request the UDM to perform 5G AKA master authentication on the first terminal.

[0019] Furthermore, the second Nx message includes the identification information of the first terminal and the identification information used to indicate that the main authentication is 5G AKA.

[0020] Optionally, the system is configured such that: AF sends a service response encrypted with the AF's local key KAF to PNI-NPN, wherein the key KAF is obtained by AF hashing at least one of the access indication information, the identification information of the first terminal and the service request information, and the key KAUSF as input parameters, the key KAUSF is derived during the main authentication process and provided by the AUSF in the operator network, and the key KAF serves as a security protection key for AF to communicate with PNI-NPN via NAS.

[0021] Furthermore, the system is configured as follows: AF receives device information encrypted by the local key KAF of PNI-NPN from PNI-NPN, wherein the device information includes the current lifespan aging time of the building equipment in PNI-NPN and the current operating status data of the building equipment in PNI-NPN; AF decrypts the encrypted device information using the local key KAF of AF; AF updates the current lifespan aging time of the building equipment in PNI-NPN according to the current operating status data of the building equipment in PNI-NPN, thereby obtaining the updated lifespan aging time of the building equipment in PNI-NPN; AF sends service information encrypted by the local key KAF of AF to PNI-NPN, wherein the service information is used to indicate the updated lifespan aging time of the building equipment in PNI-NPN.

[0022] Optionally, the service request may also include the building equipment identifier in the PNI-NPN. The system is configured such that: the AF sends a third Nx message to the UDM in the operator network based on the building equipment identifier in the PNI-NPN, wherein the third Nx message is used to request the UDM to perform 5G AKA primary authentication on the building equipment.

[0023] Furthermore, if the main authentication of the building equipment passes, the AF will still send a service response to the PNI-NPN even if the main authentication of the PNI-NPN fails.

[0024] Thirdly, an electronic device is provided, including a processor and a memory; the memory is used to store a computer program, which, when executed by the processor, causes the electronic device to perform the aforementioned building equipment lifecycle management SaaS method.

[0025] In one possible design, the electronic device described in the fifth aspect may further include a transceiver. This transceiver may be a transceiver circuit or an interface circuit. The transceiver can be used for communication between the electronic device described in the fifth aspect and other devices.

[0026] Fourthly, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer causes the computer to execute the aforementioned SaaS method for lifecycle management of building equipment.

[0027] In summary, the above-mentioned method and apparatus achieve the following specific technical effects:

[0028] When a PNI-NPN requests services from an operator network, such as requesting the operator network to provide lifecycle management SaaS for building equipment within the PNI-NPN, the AF in the operator network can trigger the operator network to perform primary authentication on the PNI-NPN. If the PNI-NPN is trusted, the operator network will provide lifecycle management SaaS to the building equipment within the PNI-NPN. Otherwise, the operator network will refuse to provide lifecycle management SaaS to the building equipment within the PNI-NPN, in order to avoid the security risks of the PNI-NPN affecting the PLMN. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of the architecture of a 5G mobile communication system.

[0030] Figure 2 This is a schematic diagram of the architecture of a SaaS system for lifecycle management of building equipment provided in an embodiment of this application;

[0031] Figure 3 A flowchart illustrating the SaaS method for lifecycle management of building equipment provided in this application embodiment;

[0032] Figure 4 A schematic diagram of the structure of the SaaS device for lifecycle management of building equipment provided in this application embodiment;

[0033] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0034] For ease of understanding, the technical terms involved in the embodiments of this application will be introduced below.

[0035] 1. Fifth generation (5G) mobile communication system:

[0036] Figure 1 A schematic diagram of the 5G system architecture, such as Figure 1 As shown, a 5G system includes an access network (AN) and a core network (CN), and may also include terminals.

[0037] The aforementioned terminal can be a terminal with transceiver capabilities, or a chip or chip system that can be installed on the terminal. This terminal can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user equipment. The terminals in the embodiments of this application may be mobile phones, cellular phones, smartphones, tablets, wireless data cards, personal digital assistants (PDAs), wireless modems, handsets, laptop computers, machine-type communication (MTC) terminals, computers with wireless transceiver capabilities, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, vehicle-mounted terminals, roadside units (RSUs) with terminal functions, etc. The terminal of this application may also be an on-board module, on-board unit, on-board component, on-board chip or on-board unit that is built into a vehicle as one or more components or units.

[0038] The aforementioned AN is used to implement access-related functions. It can provide network access functionality for authorized users in a specific area and determine transmission links of different quality according to user level and service requirements to transmit user data. The AN forwards control signals and user data between the terminal and the CN. The AN may include access network equipment, also known as radio access network (RAN) equipment.

[0039] RAN equipment can be devices that provide access for terminals. For example, RAN equipment can include: 5G, such as a gNB in ​​a new radio (NR) system, or one or a group of antenna panels (including multiple antenna panels) of a 5G base station; or, network nodes constituting a gNB, transmission and reception point (TRP) or transmission point (TP), or transmission measurement function (TMF), such as a building base band unit (BBU), or a centralized unit (CU) or distributed unit (DU), an RSU with base station functionality, or a wired access gateway, or a 5G core network element. Alternatively, RAN equipment can also include access points (APs) in wireless fidelity (WiFi) systems, wireless relay nodes, wireless backhaul nodes, various forms of macro base stations, micro base stations (also known as small cells), relay stations, access points, wearable devices, vehicle-mounted equipment, etc. Alternatively, the RAN equipment may also include next-generation mobile communication systems, such as 6G access network equipment, such as 6G base stations, or in next-generation mobile communication systems, the network equipment may have other naming conventions, all of which are covered within the protection scope of the embodiments of this application, and this application does not impose any limitations on them.

[0040] The Network Center (CN) is primarily responsible for maintaining the subscription data of the mobile network and providing terminals with functions such as session management, mobility management, policy management, and security authentication. The CN mainly includes the following network elements: User Plane Function (UPF) network elements, Authentication Server Function (AUSF) network elements, Access and Mobility Management Function (AMF) network elements, Session Management Function (SMF) network elements, Network Slice Selection Function (NSSF) network elements, Network Exposure Function (NEF) network elements, Network Function Repository Function (NRF) network elements, Policy Control Function (PCF) network elements, Unified Data Management (UDM) network elements, Application Function (AF) network elements, and Network Slice-Specific and SNPN Authentication and Authorization Function (NSSAAF) network elements.

[0041] Among them, the UPF network element is mainly responsible for user data processing (forwarding, receiving, billing, etc.). For example, a UPF network element can receive user data from the data network (DN) and forward the user data to the terminal through access network equipment. A UPF network element can also receive user data from the terminal through access network equipment and forward the user data to the DN. DN network elements refer to the operator's network that provides data transmission services to users. Examples include Internet Protocol (IP), IP Multimedia Service (IMS), and the Internet.

[0042] AUSF network elements can be used to perform security authentication for terminals.

[0043] AMF (Automatic Mobility Management) elements are primarily responsible for mobility management in mobile networks. This includes tasks such as user location updates, user network registration, and user handover.

[0044] SMF (Service Provider Function) elements are primarily responsible for session management in mobile networks. This includes session establishment, modification, and release. Specific functions include assigning Internet Protocol (IP) addresses to users and selecting a UPF (User Provider Function) to provide packet forwarding capabilities.

[0045] The PCF network element primarily supports providing a unified policy framework to control network behavior, providing policy rules to the control layer network functions, and is also responsible for acquiring user subscription information related to policy decisions. The PCF network element can provide policies to the AMF and SMF network elements, such as Quality of Service (QoS) policies and slice selection policies.

[0046] NSSF network elements can be used to select network slices for terminals.

[0047] NEF network elements can be used to support the opening of capabilities and events.

[0048] UDM network elements can be used to store user data, such as subscription data, authentication / authorization data, etc.

[0049] AF network elements primarily support interaction with CN to provide services, such as influencing data routing decisions, policy control functions, or providing third-party services to the network side.

[0050] NSSAAF network elements can be used to support slice authentication and authorization, as well as to support access to independent, non-public networks using the credentials of credential holders. NSSAAF network elements can interact with the authentication, authorization, and accounting server (AAA-S) through an authentication, authorization, and accounting proxy (AAA-P).

[0051] The technical solutions of this application embodiment can be applied to various systems, such as wireless fidelity (WiFi) systems, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle-to-everything (V2X) communication systems, 4th generation (4G) mobile communication systems, such as long term evolution (LTE) systems, worldwide interoperability for microwave access (WiMAX) communication systems, 5th generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 6th generation (6G) mobile communication systems, etc.

[0052] This application will present various aspects, embodiments, or features relating to systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that individual systems may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these approaches are also possible.

[0053] Furthermore, in the embodiments of this application, the words "exemplary," "for example," etc., are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design scheme described as "exemplary" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the term "exemplary" is intended to present the concept in a concrete manner.

[0054] In the embodiments of this application, the terms "information," "signal," "message," "channel," and "singaling" may sometimes be used interchangeably. It should be noted that, without emphasizing their distinction, their intended meanings are consistent. Similarly, "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing their distinction, their intended meanings are consistent. Furthermore, the " / " mentioned in this application can be used to indicate an "or" relationship.

[0055] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0056] To facilitate understanding of the embodiments of this application, let's first take... Figure 2 The system illustrated herein serves as an example to illustrate a SaaS system for lifecycle management of building equipment applicable to embodiments of this application. For example, Figure 2 This is a schematic diagram of the architecture of the SaaS system for lifecycle management of building equipment provided in this application embodiment.

[0057] like Figure 2 As shown, the building equipment lifecycle management SaaS system is applicable to the aforementioned 5G architecture, mainly including: PNI-NPN and AF. The PNI-NPN deploys building equipment and relies on services provided by the operator network. The operator network can be the aforementioned PLMN, and includes the AF corresponding to the PNI-NPN.

[0058] When a PNI-NPN requests services from an operator network, such as requesting the operator network to provide lifecycle management SaaS for building equipment within the PNI-NPN, the AF in the operator network can trigger the operator network to perform primary authentication on the PNI-NPN. If the PNI-NPN is trusted, the operator network will provide lifecycle management SaaS to the building equipment within the PNI-NPN. Otherwise, the operator network will refuse to provide lifecycle management SaaS to the building equipment within the PNI-NPN, in order to avoid the security risks of the PNI-NPN affecting the PLMN.

[0059] For ease of understanding, the following will combine... Figure 3 The interaction process between PNI-NPN and AF is described in detail through method implementation examples.

[0060] For example, Figure 3 This is a flowchart illustrating the SaaS method for lifecycle management of building equipment provided in an embodiment of this application. Figure 3 As shown, the process of this building equipment lifecycle management SaaS method is as follows:

[0061] S301, AF receives service requests from PNI-NPN.

[0062] The service request is used to request the operator's network to provide lifecycle management SaaS for building equipment in the PNI-NPN. The service request may include: access indication information, identification information of the first terminal, and service request information. The access indication information indicates that the PNI-NPN is accessing the operator's network as a terminal and requires AF services. The identification information of the first terminal identifies the terminal in which the PNI-NPN is located, and may be a Subscription Permanent Identifier (SUPI). The service request information requests the operator's network to provide lifecycle management SaaS for building equipment in the PNI-NPN; for example, it may be a newly defined information cell.

[0063] The AF receiving service requests from PNI-NPN may include: the AF receiving a first Nx message from the AMF in the operator network. The first Nx message refers to the service interface message between the AMF and the AF, and it contains the service request.

[0064] Understandably, the difference from existing technologies lies in the fact that when a UE registers with an operator's network, the AMF triggers the UE's primary authentication. However, when a PNI-NPN registers with an operator's network, the PNI-NPN carries access indication information. This access indication information indicates that the current access is not the physical terminal's access, but rather the PNI-NPN's access as a terminal. In this case, the AMF should determine the AF corresponding to the PNI-NPN based on the access indication information (because the PNI-NPN is subsequently serviced and managed by the AF). Which AF corresponds to the PNI-NPN can be pre-configured in the AMF. Thus, the AMF can encapsulate the service request into the first Nx message and send it to the AF, which then triggers the PNI-NPN's primary authentication.

[0065] Furthermore, sending a service request by PNI-NPN can be understood as sending a service request by the PNI-NPN's ingress gateway. In other words, the interactions between PNI-NPN and the operator's network mentioned below are all interactions conducted by the PNI-NPN's ingress gateway. The PNI-NPN's ingress gateway can be a physical device or a virtual device; there are no restrictions on this. In addition, the PNI-NPN's ingress gateway can also interact with devices within the PNI-NPN, such as building equipment, to enable subsequent lifecycle management SaaS.

[0066] S302, AF requests the operator network to perform primary authentication for PNI-NPN based on the service request.

[0067] The operator network's primary authentication of PNI-NPN refers to the operator network using PNI-NPN as the first terminal to access the operator network and performing two-way authentication between the first terminal and the operator network. Passing the primary authentication includes the first terminal authenticating the operator network and the operator network authenticating the first terminal.

[0068] Based on this, the AF, in accordance with the service request, requests the operator network to authenticate the PNI-NPN. This may include the AF sending a second Nx message to the UDM in the operator network, based on the access indication information and the identification information of the first terminal. The second Nx message requests the UDM to perform primary authentication for 5G AKA on the first terminal. For example, the second Nx message may include the identification information of the first terminal and identification information indicating that the primary authentication is 5G AKA. The 5G AKA process can be found in the relevant description in TS33.501, and will not be elaborated here.

[0069] S303, if the primary authentication is successful, AF sends a service response to PNI-NPN.

[0070] The service response can be used to instruct the AF to provide lifecycle management SaaS for building equipment in PNI-NPN, for example, by carrying a newly defined information element that instructs the AF to provide lifecycle management SaaS for building equipment in PNI-NPN.

[0071] The AF sending a service response to the PNI-NPN can include: the AF sending a service response encrypted with its local key KAF. The key KAF is obtained by hashing at least one of the access indication information, the identification information of the first terminal, and the service request information, along with the key KAUSF, as input parameters. The key KAUSF is derived during the main authentication process and provided by the AUSF in the operator network. The key KAF serves as a security protection key for non-access stratum (NAS) communication between the AF and the PNI-NPN. Correspondingly, the PNI-NPN can also deduce its local KAF during the main authentication process. For example, if the PNI-NPN verifies successful verification of the operator network, it can deduce the KAUSF and hash it using at least one of the access indication information, the identification information of the first terminal, and the service request information, along with the key KAUSF, as input parameters to achieve synchronization with the network side. Furthermore, the derivation of the key KAUSF is existing technology, which can be found in the relevant description in TS 33.501, and will not be elaborated further here.

[0072] It is understood that, unlike existing technologies, the existing NAS interaction of a UE refers to the communication interaction between the UE and the AMF (Access Controller), because the AMF is responsible for the access and mobility management of the UE, and its interaction with the UE is defined as NAS interaction. However, since the location of the PNI-NPN is fixed, the PNI-NPN does not involve mobility and therefore does not require management by the AMF. Furthermore, since the management of the PNI-NPN is provided by the AF (Active Front-End), this application defines the interaction between the PNI-NPN and the AF as NAS interaction, or in other words, a newly defined NAS interaction. Additionally, the AS interaction of the PNI-NPN is similar to existing technologies, which is the communication interaction between the PNI-NPN's ingress gateway and the RAN (Radio Access Network) equipment it accesses. However, when the RAN equipment receives signaling from the PNI-NPN, it needs to forward it to the AF, not the AMF, to achieve the NAS interaction referred to in this application embodiment.

[0073] Optionally, the AF's lifecycle management SaaS for building equipment in PNI-NPN may include: AF receiving device information encrypted by the PNI-NPN's local key KAF. This device information includes the current aging time of the building equipment in PNI-NPN and its current operational status data. AF can decrypt the encrypted device information using its local key KAF. AF can update the current aging time of the building equipment in PNI-NPN based on its current operational status data (such as the number of current fault repairs, the number of current error alarms, and the current reliable operating time), thus obtaining the updated aging time. For example, if the current operational status data is accurate and has a small error, AF can extend the current aging time of the building equipment; otherwise, it can shorten the current aging time. The AF can send service information encrypted with the AF's local key KAF to the PNI-NPN. This service information is used to indicate the lifespan of building equipment in the PNI-NPN after an update.

[0074] Optionally, the service request may also include the identifier of the building equipment in the PNI-NPN. The method further includes: the AF sending a third Nx message to the UDM in the operator network based on the identifier of the building equipment in the PNI-NPN. The third Nx message is used to request the UDM to perform 5G AKA master authentication on the building equipment. Furthermore, if the master authentication of the building equipment is successful, the AF can still send a service response to the PNI-NPN even if the master authentication of the PNI-NPN fails. That is, even if the master authentication of the PNI-NPN itself fails, as long as the building equipment in the PNI-NPN is trustworthy, the PNI-NPN is considered trustworthy.

[0075] In summary, when a PNI-NPN requests services from an operator network, such as requesting the operator network to provide lifecycle management SaaS for building equipment within the PNI-NPN, the AF in the operator network can trigger the operator network to perform primary authentication on the PNI-NPN. If the PNI-NPN is trustworthy, the operator network can provide lifecycle management SaaS to the building equipment within the PNI-NPN. Otherwise, the operator network will refuse to provide lifecycle management SaaS to the building equipment within the PNI-NPN, in order to avoid the security risks of the PNI-NPN affecting the PLMN.

[0076] The above combination Figure 3 This application provides a detailed description of the SaaS method for lifecycle management of building equipment, as illustrated in its embodiments. The following is in conjunction with... Figure 4 This document describes in detail a SaaS system for lifecycle management of building equipment used to execute the SaaS method for lifecycle management of building equipment provided in the embodiments of this application.

[0077] For example, Figure 4 This is a schematic diagram of the structure of the building equipment lifecycle management SaaS system provided in this application embodiment. Figure 1 .like Figure 4 As shown, the building equipment lifecycle management SaaS system 400 includes: a transceiver module 401 and a processing module 402. For ease of explanation, Figure 4 Only the main components of the building equipment lifecycle management SaaS system 400 are shown.

[0078] The PNI-NPN is deployed with building equipment and relies on services provided by the operator network, which includes the AF corresponding to the PNI-NPN. The system 400 is configured as follows: the AF receives service requests from the PNI-NPN, whereby the service request is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN; based on the service request, the AF requests the operator network to perform master authentication on the PNI-NPN; if the master authentication is successful, the AF sends a service response to the PNI-NPN, whereby the service response is used to instruct the AF to provide lifecycle management SaaS for the building equipment in the PNI-NPN.

[0079] In one possible design, the system 400 is configured such that: the AF receives a first Nx message from the AMF in the operator network, wherein the first Nx message contains a service request, the service request including: access indication information, identification information of the first terminal and service request information, the access indication information is used to indicate that the PNI-NPN is accessing the operator network as a terminal and needs the AF to provide services, the identification information of the first terminal is used to identify the terminal that the PNI-NPN is acting as, and the service request information is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN.

[0080] Optionally, the operator network's primary authentication of the PNI-NPN means that the operator network uses the PNI-NPN as the first terminal to access the operator network and performs two-way authentication between the first terminal and the operator network. Passing the primary authentication includes the first terminal authenticating the operator network and the operator network authenticating the first terminal.

[0081] Furthermore, the system 400 is configured such that: the AF sends a second Nx message to the UDM in the operator network based on the access indication information and the identification information of the first terminal, wherein the second Nx message is used to request the UDM to perform 5GAKA master authentication on the first terminal.

[0082] Furthermore, the second Nx message includes the identification information of the first terminal and the identification information used to indicate that the main authentication is 5G AKA.

[0083] Optionally, the system 400 is configured such that: AF sends a service response encrypted with the AF's local key KAF to PNI-NPN, wherein the key KAF is obtained by AF hashing at least one of the access indication information, the identification information of the first terminal and the service request information, and the key KAUSF as input parameters, the key KAUSF is derived during the main authentication process and provided by the AUSF in the operator network, and the key KAF serves as a security protection key for AF to communicate with PNI-NPN via NAS.

[0084] Furthermore, the system 400 is configured as follows: AF receives device information encrypted by the local key KAF of PNI-NPN from PNI-NPN, wherein the device information includes the current lifespan aging time of the building equipment in PNI-NPN and the current working status data of the building equipment in PNI-NPN; AF decrypts the encrypted device information using the local key KAF of AF; AF updates the current lifespan aging time of the building equipment in PNI-NPN according to the current working status data of the building equipment in PNI-NPN, thereby obtaining the updated lifespan aging time of the building equipment in PNI-NPN; AF sends service information encrypted by the local key KAF of AF to PNI-NPN, wherein the service information is used to indicate the updated lifespan aging time of the building equipment in PNI-NPN.

[0085] Optionally, the transceiver module 401 may include a transmitting module ( Figure 4 (not shown in the image) and receiving module ( Figure 4 (Not shown in the image). The sending module is used to implement the sending function of the building equipment lifecycle management SaaS device 400, and the receiving module is used to implement the receiving function of the building equipment lifecycle management SaaS device 400.

[0086] Optionally, the building equipment lifecycle management SaaS device 400 may also include a storage module ( Figure 4 (Not shown in the image), this storage module stores programs or instructions. When the processing module 402 executes the program or instruction, the building equipment lifecycle management SaaS device 400 can perform... Figure 3 The illustrated SaaS approach for lifecycle management of building equipment.

[0087] In addition, the technical effectiveness of the SaaS device 400 for lifecycle management of building equipment can be referenced. Figure 3 The technical effects of the SaaS approach for lifecycle management of building equipment shown are not elaborated here.

[0088] For example, Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device can be a terminal or network device, or it can be a chip (system) or other component or assembly that can be disposed in a terminal or network device. Figure 5 As shown, the electronic device 500 may include a processor 501. Optionally, the electronic device 500 may also include a memory 502 and / or a transceiver 503. The processor 501 is coupled to the memory 502 and the transceiver 503, for example, via a communication bus.

[0089] The following is combined Figure 5A detailed introduction to each component of the electronic device 500 is provided below:

[0090] The processor 501 is the control center of the electronic device 500. It can be a single processor or a collective term for multiple processing elements. For example, the processor 501 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).

[0091] Optionally, the processor 501 can perform various functions of the electronic device 500 by running or executing software programs stored in the memory 502 and calling data stored in the memory 502, such as performing the aforementioned functions. Figure 3 The illustrated SaaS approach for lifecycle management of building equipment.

[0092] In a specific implementation, as one example, the processor 501 may include one or more CPUs, for example... Figure 5 CPU0 and CPU1 are shown in the diagram.

[0093] In a specific implementation, as one embodiment, the electronic device 1200 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, a processor may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0094] The memory 502 is used to store the software program that executes the solution of this application, and is controlled by the processor 501 to execute it. The specific implementation method can be referred to the above method embodiment, and will not be repeated here.

[0095] Optionally, the memory 502 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory 502 may be integrated with the processor 501 or exist independently, and may be accessed through the interface circuit of the electronic device 500. Figure 5 (Not shown in the image) is coupled to processor 501, and this embodiment does not specifically limit this.

[0096] Transceiver 503 is used for communication with other electronic devices. For example, if electronic device 500 is a terminal, transceiver 503 can be used to communicate with a network device or with another terminal device. As another example, if electronic device 500 is a network device, transceiver 503 can be used to communicate with a terminal or with another network device.

[0097] Alternatively, transceiver 503 may include a receiver and a transmitter. Figure 5 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0098] Optionally, the transceiver 503 can be integrated with the processor 501, or it can exist independently and be connected via the interface circuit of the electronic device 500. Figure 5 (Not shown in the image) is coupled to processor 501, and this embodiment does not specifically limit this.

[0099] It should be noted that, Figure 5 The structure of the electronic device 500 shown does not constitute a limitation on the electronic device. Actual electronic devices may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0100] Furthermore, the technical effects of electronic device 500 can be referenced from the technical effects of the building equipment lifecycle management SaaS method described in the above method embodiments, and will not be repeated here.

[0101] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0102] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0103] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0104] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0105] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.

[0106] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0107] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0108] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0109] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0110] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0111] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0112] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0113] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A SaaS method for lifecycle management of building equipment, characterized in that, The PNI-NPN is deployed with building equipment, and the PNI-NPN relies on services provided by an operator network, which includes the AF corresponding to the PNI-NPN. The method includes: The AF receives a service request from the PNI-NPN, wherein the service request is used to request the operator network to provide lifecycle management SaaS for building equipment in the PNI-NPN; The AF requests the operator network to perform primary authentication for the PNI-NPN based on the service request. If the primary authentication is successful, the AF sends a service response to the PNI-NPN, wherein the service response is used to instruct the AF to provide lifecycle management SaaS for building equipment in the PNI-NPN; The AF receives service requests from the PNI-NPN, including: The AF receives a first Nx message from the AMF in the operator network, wherein the first Nx message contains the service request, the service request including: access indication information, identification information of the first terminal and service request information, the access indication information is used to indicate that the PNI-NPN is accessing the operator network as a terminal and needs the AF to provide services, the identification information of the first terminal is used to identify the terminal that the PNI-NPN is acting as, and the service request information is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN; The AF sends a service response to the PNI-NPN, including: The AF sends the service response encrypted with the AF's local key KAF to the PNI-NPN. The key KAF is obtained by the AF by hashing at least one of the access indication information, the identification information of the first terminal, and the service request information, as well as the key KAUSF, as input parameters. The key KAUSF is derived from the main authentication process and provided by the AUSF in the operator network. The key KAF serves as a security protection key for NAS communication between the AF and the PNI-NPN.

2. The method according to claim 1, characterized in that, The operator network's primary authentication of the PNI-NPN means that the operator network uses the PNI-NPN as the first terminal to access the operator network and performs bidirectional authentication between the first terminal and the operator network. The primary authentication includes the first terminal authenticating the operator network and the operator network authenticating the first terminal.

3. The method according to claim 2, characterized in that, The AF, based on the service request, requests the operator network to authenticate the PNI-NPN, including: The AF sends a second Nx message to the UDM in the operator network based on the access indication information and the identification information of the first terminal. The second Nx message is used to request the UDM to perform 5G AKA master authentication on the first terminal.

4. The method according to claim 3, characterized in that, The second Nx message includes the identification information of the first terminal and the identification information used to indicate that the main authentication is 5G AKA.

5. The method according to claim 1, characterized in that, The AF provides lifecycle management SaaS for building equipment in the PNI-NPN, including: The AF receives device information encrypted by the key KAF local to the PNI-NPN from the PNI-NPN, wherein the device information includes the current lifespan of the building equipment in the PNI-NPN and the current working status data of the building equipment in the PNI-NPN; The AF uses its local key KAF to decrypt the encrypted device information; The AF updates the current life aging time of the building equipment in the PNI-NPN based on the current working status data of the building equipment in the PNI-NPN, and obtains the updated life aging time of the building equipment in the PNI-NPN. The AF sends service information encrypted with the key KAF local to the PNI-NPN, wherein the service information is used to indicate the life aging time of building equipment in the PNI-NPN after the update.

6. The method according to claim 1, characterized in that, The service request also includes the identifier of the building equipment in the PNI-NPN, and the method further includes: The AF sends a third Nx message to the UDM in the operator network based on the building equipment identifier in the PNI-NPN, wherein the third Nx message is used to request the UDM to perform 5G AKA master authentication on the building equipment.

7. The method according to claim 6, characterized in that, If the primary authentication of the building equipment is successful, the AF will send the service response to the PNI-NPN even if the primary authentication of the PNI-NPN fails.

8. A SaaS system for lifecycle management of building equipment, characterized in that, The PNI-NPN is deployed with building equipment. The PNI-NPN relies on services provided by a carrier network, which includes the AF (Automatic Application) corresponding to the PNI-NPN. The system is configured as follows: The AF receives a service request from the PNI-NPN, wherein the service request is used to request the operator network to provide lifecycle management SaaS for building equipment in the PNI-NPN; The AF requests the operator network to perform primary authentication for the PNI-NPN based on the service request. If the primary authentication is successful, the AF sends a service response to the PNI-NPN, wherein the service response is used to instruct the AF to provide lifecycle management SaaS for building equipment in the PNI-NPN; The AF receives service requests from the PNI-NPN, including: The AF receives a first Nx message from the AMF in the operator network, wherein the first Nx message contains the service request, the service request including: access indication information, identification information of the first terminal and service request information, the access indication information is used to indicate that the PNI-NPN is accessing the operator network as a terminal and needs the AF to provide services, the identification information of the first terminal is used to identify the terminal that the PNI-NPN is acting as, and the service request information is used to request the operator network to provide lifecycle management SaaS for the building equipment in the PNI-NPN; The AF sends a service response to the PNI-NPN, including: The AF sends the service response encrypted with the AF's local key KAF to the PNI-NPN. The key KAF is obtained by the AF by hashing at least one of the access indication information, the identification information of the first terminal, and the service request information, as well as the key KAUSF, as input parameters. The key KAUSF is derived from the main authentication process and provided by the AUSF in the operator network. The key KAF serves as a security protection key for NAS communication between the AF and the PNI-NPN.

Citation Information

Patent Citations

  • Non-public network authentication in 5g

    US20220159460A1