Authentication certificate updating method, device and system of Internet of Things equipment

The UICC card generates encrypted public-private key pairs in IoT devices, and uses the operator's two-way verification mechanism to solve the problem of difficulty in ensuring security and reliability during the update of IoT device authentication credentials, achieving higher security and reliability.

CN120091305APending Publication Date: 2025-06-03CHINA MOBILE M2M +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510191065.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

During the process of updating authentication credentials for IoT devices, there are problems that are difficult to guarantee security and reliability. Especially when there are backdoors or vulnerabilities in the device program, it is easy to forge update commands or re-package the public key of the UICC card.

Method used

Directly generate public and private key pairs through UICC cards and encrypt the public keys using the original operator's public key to avoid the risk of IoT devices directly contacting plaintext keys. The operator's UDM decrypts the public key through the original operator's private key and UICC public key encryption credentials to form a two-way verification of the public and private key system, and builds an end-to-end dual encryption channel.

Benefits of technology

Effectively prevent IoT devices from forging update commands or replacing the public key of UICC card, solve the risks of man-in-the-middle attacks and data tampering, and improve the security and reliability of authentication credential updates of IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091305A_ABST
    Figure CN120091305A_ABST
Patent Text Reader

Abstract

The invention provides an authentication credential updating method, device and system for Internet of Things equipment. The method comprises the following steps: acquiring an authentication credential updating request sent by a universal integrated circuit card and a subscription permanent identifier sent by an access and mobility management network element of first network equipment; the authentication credential updating request comprises an authentication credential updating command and an encryption public key for encrypting a public key generated by the universal integrated circuit card by the universal integrated circuit card based on a public key of an operator to which the first network equipment belongs; and according to the authentication credential updating request, acquiring an updating authentication credential corresponding to the subscription permanent identifier and a public key generated by the universal integrated circuit card, and according to the public key generated by the universal integrated circuit card, encrypting and forwarding the updating authentication credential to the universal integrated circuit card so as to update the authentication credential. According to the method and the device, the Internet of Things equipment is effectively prevented from forging an updating command or switching the public key of the UICC card, so that the security and the reliability of updating the authentication credential are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the Internet of Things, and in particular, to a method, device, and system for updating authentication credentials of Internet of Things devices. Background Art

[0002] With the rapid development of the Internet of Things technology, more and more Internet of Things devices are connected to the operator network as terminal devices to achieve data exchange and automated management through network connections. Updating authentication credentials is an important link in the security management of Internet of Things devices, and its significance lies in ensuring the authenticity of device identities, the confidentiality and integrity of data transmission, thereby preventing unauthorized access and data leakage. Therefore, how to effectively update the authentication credentials of Internet of Things devices is an important issue that needs to be studied urgently at present.

[0003] Currently, the Embedded Universal Integrated Circuit Card (eUICC) in Internet of Things devices interacts with the network through the Internet of Things devices, that is, any interaction data in the eUICC card is forwarded by the Internet of Things devices. If there is a backdoor or a vulnerability in the program of the Internet of Things device that is exploited, it will cause the Internet of Things device to forge an update command or replace the public key of the Universal Integrated Circuit Card (UICC) provided by the eUICC card, thereby making it difficult to guarantee the security and reliability of the authentication credential update of the Internet of Things device.

[0004] Therefore, there is an urgent need for a method, device, and system for updating authentication credentials of Internet of Things devices to solve the above problems. Summary of the Invention

[0005] The present invention provides a method, device, and system for updating authentication credentials of Internet of Things devices to solve the defect that it is difficult to guarantee the security and reliability of the authentication credential update of Internet of Things devices in the prior art, and to effectively prevent Internet of Things devices from forging update commands or replacing the public key of the UICC card, so as to improve the security and reliability of the authentication credential update of Internet of Things devices.

[0006] The present invention provides a method for updating authentication credentials of Internet of Things devices, which is applied to a unified data management network element of a first network device. The method includes: Obtain an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by the access and mobility management entity of the first network device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card with the public key of the operator to which the first network device belongs. According to the authentication credential update request, obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and forward the updated authentication credential encrypted according to the public key generated by the universal integrated circuit card to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0007] According to an authentication credential update method for an Internet of Things device provided by the present invention, obtaining an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device includes: When it is determined that the authentication credential update command is initiated by the access and mobility management entity, sign the authentication credential update command with the private key of the operator to which the first network device belongs. Forward the signed authentication credential update command to the Internet of Things device based on the access and mobility management entity. Based on the access and mobility management entity, receive the authentication credential update request generated by the universal integrated circuit card according to the encrypted public key and the authentication credential update command when the signature verification of the signed authentication credential update command by the universal integrated circuit card using the public key of the operator to which the first network device belongs is successful.

[0008] According to an authentication credential update method for an Internet of Things device provided by the present invention, obtaining an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device includes: When it is determined that the authentication credential update command is initiated by the universal integrated circuit card, receive the authentication credential update request generated by the universal integrated circuit card according to the encrypted public key and the authentication credential update command.

[0009] According to an authentication credential update method for an Internet of Things device provided by the present invention, the step of, according to the authentication credential update request, obtaining the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and forwarding the updated authentication credential encrypted according to the public key generated by the universal integrated circuit card to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card includes: When it is confirmed that the target control object corresponding to the authentication credential update request is the first network device, decrypt the encrypted public key according to the private key of the operator to which the first network device belongs to obtain the public key generated by the universal integrated circuit card; Generate an updated authentication credential corresponding to the subscription permanent identifier according to the authentication credential update command; Encrypt the updated authentication credential according to the public key generated by the universal integrated circuit card, and forward the encrypted updated authentication credential to the universal integrated circuit card through the access and mobility management network element to update the authentication credential of the universal integrated circuit card.

[0010] According to an authentication credential update method for an Internet of Things device provided by the present invention, the method of obtaining an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card according to the authentication credential update request, and encrypting and forwarding the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card to update the authentication credential of the universal integrated circuit card includes: When it is confirmed that the target control object corresponding to the authentication credential update request is the second network device, if it is detected that the first network device has the authentication credential update permission corresponding to the authentication credential update request, decrypt the encrypted public key according to the private key of the operator to which the first network device belongs to obtain the public key generated by the universal integrated circuit card; Forward the public key generated by the universal integrated circuit card and the authentication credential update request to the unified data management network element of the second network device; Receive the encrypted updated authentication credential returned by the unified data management network element of the second network device. The encrypted updated authentication credential is obtained by encrypting the updated authentication credential corresponding to the subscription permanent identifier generated by the unified data management network element of the second network device according to the authentication credential update command in the authentication credential update request according to the public key generated by the universal integrated circuit card; Forward the encrypted updated authentication credential to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0011] The present invention also provides an authentication credential update method for an Internet of Things device, which is applied to the access and mobility management network element of the first network device. The method includes: Receive an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by the universal integrated circuit card encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs. Update the globally unique temporary identifier corresponding to the authentication credential update request, and the corresponding relationship between the globally unique temporary identifier and the subscription permanent identifier, and perform an associated search for the subscription permanent identifier corresponding to the authentication credential update request; Forward the authentication credential update request and the subscription permanent identifier to the unified data management network element of the first network device; Among them, the authentication credential update request is used to request the unified data management network element of the first network device to obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card for updating the authentication credential of the universal integrated circuit card.

[0012] According to an authentication credential update method for an Internet of Things device provided by the present invention, receiving an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device includes: When it is determined that the authentication credential update command is initiated by the access and mobility management network element, send the authentication credential update command to the unified data management network element; Receive the signed authentication credential update command generated by the unified data management network element by signing the authentication credential update command with the private key of the operator to which the first network device belongs; Forward the signed authentication credential update command to the Internet of Things device; Receive the authentication credential update request generated by the universal integrated circuit card in the Internet of Things device according to the encrypted public key and the authentication credential update command when the signature verification of the signed authentication credential update command based on the public key of the operator to which the first network device belongs is successful.

[0013] The present invention also provides an authentication credential update device for an Internet of Things device. The device is constructed based on the unified data management network element of the first network device, and the device includes: A first acquisition unit, configured to acquire an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by the access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encrypted public key for encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; An update unit, configured to obtain an updated authentication credential corresponding to the subscription permanent identifier and a public key generated by the universal integrated circuit card according to the authentication credential update request, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

[0014] The present invention further provides an authentication credential update device for an Internet of Things device. The device is formed based on an access and mobility management network element of a first network device, and the device includes: A second acquisition unit, configured to receive an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting a public key generated by the universal integrated circuit card based on a public key of an operator to which the first network device belongs. A lookup unit, configured to perform an associated lookup of a subscription permanent identifier corresponding to the authentication credential update request according to a globally unique temporary identifier corresponding to the authentication credential update request and a correspondence between the globally unique temporary identifier and the subscription permanent identifier. A forwarding unit, configured to forward the authentication credential update request and the subscription permanent identifier to a unified data management network element of the first network device. Wherein, the authentication credential update request is used to request the unified data management network element of the first network device to obtain an updated authentication credential corresponding to the subscription permanent identifier and a public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

[0015] The present invention further provides an authentication credential update system for an Internet of Things device, including a plurality of network devices and an Internet of Things device; Each of the network devices includes a unified data management network element, an access and mobility management network element, a radio access network network element, and an authentication server function network element; The unified data management network element is configured to execute the authentication credential update method for the Internet of Things device as described in any one of the above, so as to update the authentication credential of the universal integrated circuit card in the Internet of Things device; The access and mobility management network element is configured to execute the authentication credential update method for the Internet of Things device as described in any one of the above, so as to update the authentication credential of the universal integrated circuit card in the Internet of Things device.

[0016] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the authentication credential update method of any one of the above-mentioned Internet of Things devices is implemented.

[0017] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the authentication credential update method of any one of the above-mentioned Internet of Things devices is implemented.

[0018] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, the authentication credential update method of any one of the above-mentioned Internet of Things devices is implemented.

[0019] The authentication credential update method, device, and system for Internet of Things devices provided by the present invention directly generate a public-private key pair through the UICC card and encrypt the public key with the original operator's public key, avoiding the risk of the Internet of Things device directly contacting the plaintext key and preventing the Internet of Things device from forging update commands or invoking the public key. In addition, a two-way verification of the public-private key system formed by the operator UDM decrypting the public key with the original operator's private key and encrypting the credential with the UICC public key is used to build an end-to-end double-encryption channel, enabling the Internet of Things device to only play the role of ciphertext transparent transmission and unable to tamper with core data, effectively ensuring the legality and transmission confidentiality of the updated authentication credential. Moreover, this architecture limits key operations to be executed between the UICC card and the operator network through a cryptographic mechanism. Even if there is a backdoor or vulnerability in the program of the Internet of Things device that is exploited, attackers cannot forge valid update requests or steal sensitive keys, effectively preventing the Internet of Things device from forging update commands or swapping the public key of the UICC card, solving the risks of man-in-the-middle attacks and data tampering, and thus effectively improving the security and reliability of the authentication credential update of the Internet of Things device. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0021] Figure 1 is one of the schematic flowcharts of the authentication credential update method for Internet of Things devices provided by the present invention.

[0022] Figure 2 is the second schematic flowchart of the authentication credential update method for Internet of Things devices provided by the present invention.

[0023] Figure 3It is the third schematic flowchart of the authentication credential update method for Internet of Things devices provided by the present invention.

[0024] Figure 4 It is the fourth schematic flowchart of the authentication credential update method for Internet of Things devices provided by the present invention.

[0025] Figure 5 It is the fifth schematic flowchart of the authentication credential update method for Internet of Things devices provided by the present invention.

[0026] Figure 6 It is the sixth schematic flowchart of the authentication credential update method for Internet of Things devices provided by the present invention.

[0027] Figure 7 It is one of the schematic structural diagrams of the authentication credential update device for Internet of Things devices provided by the present invention.

[0028] Figure 8 It is the second schematic structural diagram of the authentication credential update device for Internet of Things devices provided by the present invention.

[0029] Figure 9 It is the schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners

[0030] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0031] Regarding the update of authentication credentials for Internet of Things devices, some existing technologies propose that first, the Internet of Things device sends an authentication credential update request to the visited network, and the authentication credential update request at least includes: the public key of the pluggable card or the non-pluggable card; then, receive the authentication credential update response sent by the visited network, and the authentication credential update response at least includes: the newly generated authentication credential encrypted by the public key, the identifier of the newly generated authentication credential, and the temporary credential for the Internet of Things terminal to verify the visited network; then decrypt the newly generated authentication credential, the identifier of the newly generated authentication credential, and the temporary credential with the private key corresponding to the public key of the pluggable card or the non-pluggable card; if the verification result of verifying the visited network through the temporary credential is verified to be passed, bind and store the newly generated authentication credential and the identifier of the newly generated authentication credential.

[0032] In addition, some existing technologies propose that the Internet of Things device first sends an authentication credential update request to the network side. The authentication credential update request at least includes: a public key generated by a pluggable card or a non-pluggable card. Then, it receives an authentication credential update response sent by the network side. The authentication credential update response at least includes: a new authentication credential encrypted by the public key and an identifier of the new authentication credential, where the new authentication credential and the identifier of the new authentication credential are allocated by the network side for the Internet of Things device according to the authentication credential update request. At least decrypt the new authentication credential and the identifier of the new authentication credential through the private key generated by the pluggable card or the non-pluggable card. Update the previously stored authentication credential with the new authentication credential.

[0033] However, in the above technical solution, it is only applicable to the update of the authentication credentials of Internet of Things devices in the 4th Generation Mobile Communication Technology (4G) network scenario, and does not support the update of the authentication credentials of Internet of Things devices in the 5th Generation Mobile Communication Technology (5G) network scenario. Moreover, the eUICC in the Internet of Things device interacts with the network device for data, that is, any interaction data in the eUICC card is forwarded by the Internet of Things device. If there is a backdoor or vulnerability in the program of the Internet of Things device that is exploited, there will be the following security risks. First, the Internet of Things device forges a command to falsely initiate an update of the authentication credential, and then generates an authentication credential by itself and sends it to the eUICC card, resulting in the loss of the original legitimate credential of the eUICC card, causing a communication failure, and this failure cannot be remotely repaired. Second, the public key of the UICC card provided by the eUICC card may be tampered with by the Internet of Things device, that is, the Internet of Things device acts as a man-in-the-middle attack, tampers with the public key of the UICC card into its own public key, decrypts the encrypted authentication credential with its own private key after obtaining it, and then encrypts it with the public key of the UICC card and gives it to the UICC. The UICC cannot perceive that the Internet of Things device has learned the encrypted authentication credential. As a result, once the public key of the UICC card is tampered with, the subsequent encrypted authentication credential can be easily decrypted and obtained by the Internet of Things device, there is a risk of leakage of the authentication credential, and further the security and reliability of the update of the authentication credential of the Internet of Things device are difficult to be guaranteed.

[0034] In response to this, the present application provides a method for updating the authentication credential of an Internet of Things device. This method is applicable to the update of the authentication credential in the 5G network scenario, and at the same time can effectively prevent the Internet of Things device from forging an update command or tampering with the public key of the UICC card, thereby effectively improving the security and reliability of the update of the authentication credential of the Internet of Things device.

[0035] Figure 1It is one of the schematic flowcharts of the authentication credential update method for Internet of Things devices provided by the present invention; as Figure 1 shown, the present invention provides an addressing method for a policy control network element, which can be used for authentication credential update in a 5G network scenario. It is applied to the Unified Data Management (UDM) network element of a first network device, that is, the execution entity of this method is the UDM of the first network device. The UDM here can be changed from the Home Subscriber Server (HSS) / Home Location Register (HLR) in a 4G network scenario. The first network device here is the network-side device of the original operator. For simplicity of description, the unified data management network element of the first network device can be simply referred to as the original operator UDM. This method specifically includes step 110 and step 120.

[0036] Step 110, obtain an authentication credential update request sent by a Universal Integrated Circuit Card in the Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by the access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the Universal Integrated Circuit Card based on the public key of the operator to which the first network device belongs. It should be noted that for the convenience of description, the eUICC card and SIM card mentioned below are simply referred to as UICC cards. Among them, the UICC card has a built-in operator public key, which can be specifically generated by the operator public key loading unit built in the UICC card.

[0037] Optionally, when the Internet of Things device (hereinafter also referred to as the Internet of Things UE) needs to update the authentication credential, the original operator UDM can first obtain the authentication credential update request sent by the UICC card in the Internet of Things device.

[0038] The authentication credential update request here can be adaptively obtained according to the initiating end that initiates the authentication credential update command. For example, when the initiating end that initiates the authentication credential update command is the network device of the original operator, the obtaining step of the authentication credential update request can be that after the UICC card receives the signed authentication credential update command sent by the network device of the original operator (that is, the authentication credential update command processed by signature), it first uses the public key of the operator to which the built-in first network device belongs (that is, the original operator) to verify the signature of the signed authentication credential update command. When the signature authentication passes, it generates its own private key and public key, encrypts the public key generated by itself with the public key of the original operator to obtain the encrypted public key, and combines the encrypted public key and the authentication credential update command to generate an authentication credential update request and then forwards it to the original operator UDM. Another example, when the initiating end that initiates the authentication credential update command is the IoT UE, the obtaining step of the authentication credential update request can be that after the UICC card receives the authentication credential update application sent by the user, it generates its own private key and public key, encrypts the public key generated by itself with the public key of the original operator to obtain the encrypted public key, and combines the encrypted public key and the authentication credential update command to generate an authentication credential update request and then forwards it to the original operator UDM.

[0039] The authentication credential update application here is used to apply for the update of the authentication credential of the IoT device, and it can be the user input entered by the user on the front-end interface. The so-called user input can be information input through a command-line interface, a graphical interface, touch input, drop-down selection input, voice input, gesture input, visual input, brain-computer input, etc. This embodiment does not make specific limitations on this.

[0040] In addition, the original operator UDM can also receive the Subscription Permanently Identifier (SUPI) determined for the authentication credential update request sent by the Access and Mobility Management Function (AMF) of the first network device, that is, the SUPI corresponding to the authentication credential update request.

[0041] The AMF here can be a network element with access and mobility management functions obtained by changing the mobile management entity (MME, Mobility Management Entity) / Serving Gateway Support Node (SGSN, Serving GPRS Support Node) / Mobile Switching Center (Mobile Switching Center, MSC) in the 4G network scenario. AMF stores at least one correspondence table between the Globally Unique Temporary Identifier (GUTI) and SUPI under different sessions, that is, when the UICC card initiates an authentication credential update request, it is no longer necessary to carry the card identifier. After the IoT UE completes the registration process in the early stage, the AMF can identify the temporary GUTI of this UE, and then the card identifier SUPI can be mapped according to the GUTI.

[0042] Accordingly, in some embodiments, the SUPI here can be obtained by AMF after receiving the authentication credential update request sent by the universal integrated circuit card, according to the GUTI corresponding to the authentication credential update request and the correspondence between the GUTI and SUPI stored by the Internet of Things UE during the previous registration, so that AMF can independently obtain the UICC identifier based on the GUTI-SUPI mapping mechanism to prevent the device from forging the UICC SUPI.

[0043] Step 120: According to the authentication credential update request, the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card are obtained, and according to the public key generated by the universal integrated circuit card, the updated authentication credential is encrypted and forwarded to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0044] After obtaining the authentication credential update request and the subscription permanent identifier corresponding to the authentication credential update request, the original operator UDM can obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card according to the authentication credential update request.

[0045] The steps for obtaining the updated authentication credential corresponding to the subscription permanent identifier here and the public key generated by the universal integrated circuit card can be adaptively determined according to the authentication credential update type corresponding to the authentication credential update request. The update types here include local update by the same operator or cross-operator update. For example, when the update type is local update by the same operator, that is, when the target control object corresponding to the authentication credential update request is the first network device, the original operator UDM can directly use the private key of the original operator to decrypt the encrypted public key in the authentication credential update request to obtain the public key generated by the UICC card. Then, a new authentication credential corresponding to the SUPI is generated according to the authentication credential update command in the authentication credential update request, that is, the updated authentication credential. Another example is when the update type is cross-operator update, that is, when the target control object corresponding to the authentication credential update request is the network-side device of a new operator other than the first network device, that is, the second network device (also called the new operator network device). In this case, the original operator UDM can detect whether it has the authentication credential update permission corresponding to the authentication credential update request. If it does, it uses the private key of the original operator to decrypt the encrypted public key in the authentication credential update request to obtain the public key generated by the UICC card, and then forwards the public key generated by the UICC card and the authentication credential update request to the UDM of the second network device (also called the new operator UDM) so that the new operator UDM can generate a new authentication credential corresponding to the SUPI according to the authentication credential update request, that is, the updated authentication credential.

[0046] After obtaining the updated authentication credential and the public key generated by the UICC card, the original operator UDM can encrypt and forward the updated authentication credential to the UICC card according to the public key generated by the UICC card, so that the UICC card can encrypt the encrypted updated authentication credential according to the private key generated by itself, update the old authentication credential stored locally according to the decrypted updated authentication credential, and after the update is completed, forward the updated authentication credential to the AMF of the target control object so that the updated authentication credential is attached to the network.

[0047] Here, the implementation steps for encrypting and forwarding the updated authentication credential to the UICC card can be adaptively determined according to the authentication credential update type corresponding to the authentication credential update request. For example, in the case where the update type is local update by the same operator, the original operator UDM can directly use the public key generated by the UICC card to encrypt the updated authentication credential and forward it to the UICC card through the AMF. Another example is that in the case where the update type is cross-operator update, the original operator UDM can first forward the public key generated by the UICC card and the authentication credential update request to the new operator UDM, and receive the encrypted updated authentication credential generated by the new operator UDM by encrypting the updated authentication credential generated according to the authentication credential update request with the public key generated by the UICC card, and directly forward the received encrypted updated authentication credential to the UICC card.

[0048] The method provided in this embodiment generates a public-private key pair directly by the UICC card and encrypts the public key with the public key of the original operator, avoiding the risk of the Internet of Things device directly contacting the plaintext key and preventing the Internet of Things device from forging update commands or swapping public keys. In addition, the public-private key system formed by decrypting the public key with the private key of the operator UDM of the original operator and encrypting the credential with the UICC public key performs two-way verification to build an end-to-end double-encryption channel, enabling the Internet of Things device to only play the role of ciphertext transparent transmission and unable to tamper with core data, effectively ensuring the legality and transmission confidentiality of the updated authentication credential. Moreover, this architecture limits key operations to be executed between the UICC card and the operator network through cryptographic mechanisms. Even if there are backdoors or vulnerabilities in the program of the Internet of Things device that are exploited, attackers cannot forge valid update requests or steal sensitive keys, effectively preventing the Internet of Things device from forging update commands or swapping the public key of the UICC card, solving the risks of man-in-the-middle attacks and data tampering, and thus effectively improving the security and reliability of the authentication credential update of the Internet of Things device.

[0049] In some embodiments, step 110 specifically includes: when it is determined that the authentication credential update command is initiated by the access and mobility management network element, signing the authentication credential update command based on the private key of the operator to which the first network device belongs; based on the access and mobility management network element, forwarding the signed authentication credential update command to the Internet of Things device; based on the access and mobility management network element, receiving, when the general integrated circuit card successfully verifies the signature of the signed authentication credential update command based on the public key of the operator to which the first network device belongs, the authentication credential update request generated according to the encrypted public key and the authentication credential update command.

[0050] Optionally, when the original operator's UDM receives the authentication credential update command generated by AMF after receiving the authentication credential update application sent by the user, it confirms that the initiator of the authentication credential update command is the AMF in the network side device of the original operator.

[0051] When it is confirmed that the initiator of the authentication credential update command is the AMF in the network-side device of the original operator, the original operator UDM may first sign the authentication credential update command using the private key of the original operator, and forward the signed authentication credential update command including the authentication credential update command and the signature to the IoT UE via the AMF, so that after the UICC card in the IoT UE receives the signed authentication credential update command sent by the network-side device of the original operator, it first uses its built-in public key of the original operator to verify the signature of the signed authentication credential update command. If the signature verification passes, the UICC card generates its own private key and public key, and encrypts the public key generated by itself using the public key of the original operator to obtain the encrypted public key, and generates an authentication credential update request based on the encrypted public key and the authentication credential update command, and then forwards it to the AMF.

[0052] Then, the original operator's UDM can receive the authentication credential update request generated by the UICC card in real time based on the AMF, and update the authentication credential of the IoT device based on the authentication credential update request.

[0053] In the method provided in this embodiment, when the initiator of the authentication credential update is the network side of the operator, the authentication credential command needs to be issued after being digitally signed by the operator, so that after the UICC card receives it, it uses the operator's public key to verify the signature before generating an authentication credential update request, thereby enhancing the security of the IoT device authentication process and effectively preventing unauthorized authentication credential updates, such as IoT devices forging update commands. Moreover, when the UICC card provides the card identification and its own public key, it uses the operator's public key in the card to encrypt the provided card identification and public key, thereby effectively preventing the IoT UE from swapping the public key of the UICC card and avoiding initiating a man-in-the-middle attack, thereby effectively improving the security and reliability of the authentication credential update.

[0054] In some embodiments, step 110 further includes: when it is determined that the authentication credential update command is initiated by the universal integrated circuit card, receiving the authentication credential update request generated by the universal integrated circuit card according to the encrypted public key and the authentication credential update command.

[0055] Optionally, in the case where the initiator of the authentication credential update command is an IoT UE, the authentication credential update request in step 110 may be generated by the UICC card after receiving the authentication credential update application sent by the user, generating the UICC card's own private key and public key, and encrypting the public key generated by itself with the public key of the original operator to obtain an encrypted public key, and generating an authentication credential update request based on the encrypted public key and the authentication credential update command combination, and then forwarding it to the original operator's UDM via AMF.

[0056] According to the method provided in this embodiment, in the authentication credential update process of the IoT device, when the authentication credential update command is initiated by the UICC card, the card can autonomously generate a public-private key pair, and use the public key of the original operator to encrypt the generated public key, and then generate an authentication credential update request in combination with the encrypted public key and the authentication credential update command, and securely send it to the original operator UDM through the AMF to update the authentication credential, which not only avoids the risk of the IoT device directly contacting the plaintext key and prevents the IoT device from forging the update command, but also when the UICC card provides the card identification and its own public key, it uses the operator public key in the card to encrypt the provided card, which can effectively prevent the IoT UE from swapping the public key of the UICC card and avoid launching a man-in-the-middle attack, and also enhances the security of data transmission through encryption means, thereby effectively ensuring the accuracy and reliability of the IoT device authentication credential update.

[0057] In some embodiments, step 120 specifically includes: when confirming that the target control object corresponding to the authentication credential update request is the first network device, decrypting the encrypted public key according to the private key of the operator to which the first network device belongs to obtain the public key generated by the universal integrated circuit card; generating an updated authentication credential corresponding to the subscription permanent identifier according to the authentication credential update command; encrypting the updated authentication credential according to the public key generated by the universal integrated circuit card, and forwarding the encrypted updated authentication credential to the universal integrated circuit card through the access and mobility management network element to update the authentication credential of the universal integrated circuit card.

[0058] Optionally, when the update type is local update by the same operator, that is, when the target control object corresponding to the authentication credential update request is the first network device, the original operator UDM can directly use the private key of the original operator to decrypt the encrypted public key in the authentication credential update request to obtain the public key generated by the UICC card. Then, according to the authentication credential update command in the authentication credential update request, a new authentication credential corresponding to the SUPI is generated, that is, the authentication credential is updated. Then, according to the public key generated by the UICC card, the updated authentication credential is encrypted, and the encrypted updated authentication credential is first forwarded to the AMF and then forwarded by the AMF to the UICC card, so that the UICC card can encrypt the encrypted updated authentication credential according to its own generated private key, update the old authentication credential stored locally according to the decrypted updated authentication credential, and after the update is completed, forward the updated authentication credential to the AMF of the target control object, so that the updated authentication credential is attached to the network.

[0059] In the method provided in this embodiment, when it is confirmed that the update type is local update by the same operator, the original operator UDM can use the operator's private key to decrypt the encrypted public key, and then generate and encrypt the updated authentication credential, and finally update it to the UICC card securely through the AMF, which not only ensures the security and accuracy of the authentication credential update, but also realizes the efficiency of local update by the same operator, effectively improving the authentication efficiency and reliability of the IoT device in the network.

[0060] In some embodiments, step 120 further includes: according to the authentication credential update request, obtaining the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and according to the public key generated by the universal integrated circuit card, encrypting and forwarding the updated authentication credential to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card, including: when it is confirmed that the target control object corresponding to the authentication credential update request is the second network device, if it is detected that the first network device has the authentication credential update permission corresponding to the authentication credential update request, decrypting the encrypted public key according to the private key of the operator to which the first network device belongs to obtain the public key generated by the universal integrated circuit card; forwarding the public key generated by the universal integrated circuit card and the authentication credential update request to the unified data management network element of the second network device; receiving the encrypted updated authentication credential returned by the unified data management network element of the second network device, where the encrypted updated authentication credential is obtained by the unified data management network element of the second network device encrypting the updated authentication credential corresponding to the subscription permanent identifier after generating the updated authentication credential according to the authentication credential update command in the authentication credential update request according to the public key generated by the universal integrated circuit card; and forwarding the encrypted updated authentication credential to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0061] Optionally, when the update type is cross-operator update, that is, when the target control object corresponding to the authentication credential update request is a network-side device of a new operator other than the first network device, that is, the second network device, the original operator UDM can detect whether it has the authentication credential update permission corresponding to the authentication credential update request. If it has, it uses the private key of the original operator to decrypt the encrypted public key in the authentication credential update request to obtain the public key generated by the UICC card, and then forwards the public key generated by the UICC card and the authentication credential update request to the UDM of the second network device (also called the new operator UDM) so that the new operator UDM generates a new authentication credential corresponding to the SUPI according to the authentication credential update request, that is, the updated authentication credential.

[0062] Subsequently, the original operator UDM can receive in real time the encrypted updated authentication credential generated by the new operator UDM by encrypting the updated authentication credential generated by it according to the authentication credential update request with the public key generated by the UICC card, and directly forward the received encrypted updated authentication credential to the UICC card, so that the UICC card encrypts the encrypted updated authentication credential with the private key generated by itself, updates the old authentication credential stored locally according to the decrypted updated authentication credential, and after the update is completed, forwards the updated authentication credential to the AMF of the target control object so that the updated authentication credential is attached to the network.

[0063] In the method provided in this embodiment, when the update type is cross-operator update, on the premise of ensuring the update permission, the original operator decrypts the encrypted public key and forwards it to the unified data management network element of the new operator. The new operator generates and encrypts the update authentication credential, and then forwards it to the universal integrated circuit card through the original operator to complete the update. This not only ensures the security and effectiveness of the update of the authentication credential in the cross-operator scenario, but also promotes the cooperation between operators, improves the authentication efficiency and flexibility of the IoT device in the network, and enhances the interoperability and scalability of the IoT system.

[0064] The following uses a specific example scenario to describe the authentication credential update method for the IoT device provided in this embodiment.

[0065] Figure 2 It is the second flow diagram of the authentication credential update method for the IoT device provided by the present invention. As Figure 2 shown, in Example Scenario 1, that is, when the update type is local update by the same operator, when the user sends an authentication credential update application and the network-side device of the operator initiates an authentication credential update command, the process of the authentication credential update method for the IoT device specifically includes: Step 200, the user inputs an authentication credential update application to the network-side device of the original operator; Step 201, the AMF on the original operator side initiates an authentication credential update command according to the authentication credential update application, and forwards the authentication credential update command to the UDM on the original operator side; Step 202, the UDM on the original operator side signs the authentication credential update command with the private key of the original operator, and the signed authentication credential update command including the authentication credential update command and the signature; Step 203, the UDM on the original operator side forwards the signed authentication credential update command including the authentication credential update command and the signature to the AMF on the original operator side; Step 204, the AMF on the original operator side forwards the signed authentication credential update command including the authentication credential update command and the signature to the IoT UE; Step 205, the UICC card in the IoT UE uses the public key of the original operator built in it to verify the signature of the signed authentication credential update command. If the signature authentication passes, it generates its own private key and public key, encrypts the public key generated by itself with the public key of the original operator to obtain an encrypted public key, and generates an authentication credential update request based on the encrypted public key and the authentication credential update command, that is, a request carrying the encrypted public key; Step 206, the UICC card in the IoT UE forwards the authentication credential update request to the AMF on the original operator side; Step 207: After the AMF on the original operator side receives the authentication credential update request, it obtains the GUTI of the session to which the authentication credential update request belongs, and then finds the SUPI corresponding to the authentication credential update request according to the correspondence table between the GUTI and the SUPI stored during the previous registration of the IoT UE. Step 208: The AMF on the original operator side forwards the authentication credential update request and the SUPI to the UDM on the original operator side. Step 209: The UDM on the original operator side decrypts the encrypted public key in the authentication credential update request using the private key of the original operator to obtain the public key generated by the UICC card. Then, it generates a new authentication credential for the corresponding SUPI according to the authentication credential update command in the authentication credential update request, that is, updates the authentication credential, and encrypts the updated authentication credential using the public key generated by the UICC card to obtain the encrypted updated authentication credential. Step 210: The UDM on the original operator side returns the encrypted updated authentication credential to the AMF on the original operator side. Step 211: The AMF on the original operator side forwards the encrypted updated authentication credential to the IoT UE. Step 212: The UICC card decrypts the encrypted updated authentication credential according to the private key generated by itself to obtain the updated authentication credential, and uses the updated authentication credential to update the credential. Step 213: After the credential update is completed, the UICC card forwards the updated authentication credential to the AMF on the original operator side so that the updated authentication credential is attached to the network.

[0066] Figure 3 It is the third flow chart of the authentication credential update method for IoT devices provided by the present invention. As Figure 3 shown, in instance scenario 2, that is, when the update type is local update by the same operator and the IoT UE initiates an authentication credential update command after the user sends an authentication credential update application, the process of the authentication credential update method for IoT devices specifically includes: Step 300: The user inputs an authentication credential update application to the network device of the original operator. Step 301: The UICC card in the IoT UE generates its own private key and public key, encrypts the public key generated by itself using the public key of the original operator to obtain the encrypted public key, and generates an authentication credential update request according to the encrypted public key and the authentication credential update command, that is, a request carrying the encrypted public key. Step 302: The UICC card in the IoT UE forwards the authentication credential update request to the AMF on the original operator side. Step 303: After the AMF on the original operator side receives the authentication credential update request, it obtains the GUTI of the session to which the authentication credential update request belongs, and then finds the SUPI corresponding to the authentication credential update request according to the correspondence table between the GUTI and the SUPI stored during the previous registration of the IoT UE. Step 304: The AMF on the original operator side forwards the authentication credential update request and the SUPI to the UDM on the original operator side. Step 305: The UDM on the original operator side decrypts the encrypted public key in the authentication credential update request using the private key of the original operator to obtain the public key generated by the UICC card. Then, it generates a new authentication credential for the corresponding SUPI according to the authentication credential update command in the authentication credential update request, that is, updates the authentication credential, and encrypts the updated authentication credential using the public key generated by the UICC card to obtain the encrypted updated authentication credential. Step 306: The UDM on the original operator side returns the encrypted updated authentication credential to the AMF on the original operator side. Step 307: The AMF on the original operator side forwards the encrypted updated authentication credential to the IoT UE. Step 308: The UICC card decrypts the encrypted updated authentication credential using the private key generated by itself to obtain the updated authentication credential, and updates the credential using the updated authentication credential. Step 309: After the credential update is completed, the UICC card forwards the updated authentication credential to the AMF on the original operator side so that the updated authentication credential is attached to the network.

[0067] It should be noted that Figure 2 and Figure 3 the Radio Access Network (RAN) network element, AMF, Authentication Server Function (AUSF) network element, and UMD in

[0068] Figure 4 are network elements in the network side devices of the original operator side. Figure 4 As shown in Step 400: The user inputs an authentication credential update application to the UDM on the original operator side and the UDM on the new operator side. Step 401: The AMF on the original operator side initiates an authentication credential update command based on the authentication credential update request and forwards the authentication credential update command to the UDM on the original operator side; Step 402: The UDM on the original operator side signs the authentication credential update command using the private key of the original operator and sends the signed authentication credential update command including the authentication credential update command and the signature; Step 403: The UDM on the original operator side forwards the signed authentication credential update command including the authentication credential update command and the signature to the AMF on the original operator side; Step 404: The AMF on the original operator side forwards the signed authentication credential update command including the authentication credential update command and the signature to the IoT UE; Step 405: The UICC card in the IoT UE uses the public key of the original operator built in it to verify the signature of the signed authentication credential update command. If the signature authentication passes, the UICC card generates its own private key and public key, encrypts the public key generated by itself using the public key of the original operator to obtain the encrypted public key, and generates an authentication credential update request based on the encrypted public key and the authentication credential update command, that is, a request carrying the encrypted public key; Step 406: The UICC card in the IoT UE forwards the authentication credential update request to the AMF on the original operator side; Step 407: After receiving the authentication credential update request, the AMF on the original operator side obtains the GUTI of the session to which the authentication credential update request belongs, and then finds the SUPI corresponding to the authentication credential update request according to the correspondence table between the GUTI and the SUPI stored during the previous registration of the IoT UE; Step 408: The AMF on the original operator side forwards the authentication credential update request and the SUPI to the UDM on the original operator side; Step 409: The UDM on the original operator side checks whether it has the authentication credential update permission corresponding to the authentication credential update request. If it does, it executes Step 410; Step 410: The UDM on the original operator side decrypts the encrypted public key in the authentication credential update request using the private key of the original operator to obtain the public key generated by the UICC card; Step 411: The UDM on the original operator side forwards the public key generated by the UICC card and the authentication credential update request to the UDM on the new operator side; Step 412: The new operator UDM generates a new authentication credential for the corresponding SUPI according to the authentication credential update request, that is, updates the authentication credential, and encrypts the updated authentication credential using the public key generated by the UICC card to obtain the encrypted updated authentication credential; Step 413: The new operator's UDM returns the encrypted updated authentication credential to the UDM on the original operator's side; Step 414: The UDM on the original operator's side returns the encrypted updated authentication credential to the IoT UE; Step 415: The UICC card decrypts the encrypted updated authentication credential using its self-generated private key to obtain the updated authentication credential, and updates the credential using the updated authentication credential; Step 416: After the credential update is completed, the UICC card forwards the updated authentication credential to the AMF on the new operator's side so that the updated authentication credential is attached to the network.

[0069] It should be noted that when performing the steps before Step 416, Figure 4 the network elements on the right side of the UE such as RAN and AMF are all network elements of the original operator; when attaching to the network with the new credential in Step 416, Figure 4 the network elements on the right side of the UE such as RAN and AMF are all those of the new operator, not the original operator.

[0070] Figure 5 is the fifth flowchart of the authentication credential update method for IoT devices provided by the present invention. As Figure 5 shown, in Instance Scenario 4, that is, when the update type is cross-operator update and the IoT UE initiates an authentication credential update command after the user sends an authentication credential update application, the process of the authentication credential update method for IoT devices specifically includes: Step 500: The user inputs an authentication credential update application to the UDM on the original operator's side and the UDM on the new operator's side; Step 501: The UICC card in the IoT UE generates its own private key and public key, encrypts the self-generated public key using the public key of the original operator to obtain the encrypted public key, and combines the encrypted public key and the authentication credential update command to generate an authentication credential update request, that is, a request carrying the encrypted public key; Step 502: The UICC card in the IoT UE forwards the authentication credential update request to the AMF on the original operator's side; Step 503: After receiving the authentication credential update request, the AMF on the original operator's side obtains the GUTI of the session to which the authentication credential update request belongs, and then finds the SUPI corresponding to the authentication credential update request according to the correspondence table between the GUTI and SUPI stored during the previous registration of the IoT UE; Step 504: The AMF on the original operator's side forwards the authentication credential update request and the SUPI to the UDM on the original operator's side; Step 505: The UDM on the original operator's side checks whether it has the authentication credential update permission corresponding to the authentication credential update request. If it does, it executes Step 506; Step 506, the UDM on the original operator side decrypts the encrypted public key in the authentication credential update request using the private key of the original operator to obtain the public key generated by the UICC card; Step 507, the UDM on the original operator side forwards the public key generated by the UICC card and the authentication credential update request to the UDM on the new operator side; Step 508, the new operator UDM generates a new authentication credential for the corresponding SUPI according to the authentication credential update request, that is, updates the authentication credential, and encrypts the updated authentication credential according to the public key generated by the UICC card to obtain the encrypted updated authentication credential; Step 509, the new operator UDM returns the encrypted updated authentication credential to the UDM on the original operator side; Step 510, the UDM on the original operator side returns the encrypted updated authentication credential to the IoT UE; Step 511, the UICC card decrypts the encrypted updated authentication credential according to the private key generated by itself to obtain the updated authentication credential, and updates the credential using the updated authentication credential; Step 512, after the credential update is completed, the UICC card forwards the updated authentication credential to the AMF on the new operator side so that the updated authentication credential is attached to the network.

[0071] It should be noted that when performing the steps before step 512, Figure 5 the network elements on the right side of the UE such as RAN and AMF are all network elements of the original operator; when attaching to the network with the new credential in step 512, Figure 5 the network elements on the right side of the UE such as RAN and AMF are all of the new operator, not the original operator.

[0072] In summary, compared with the method for updating the authentication credential of the IoT device provided by the prior art, the method for updating the authentication credential of the IoT device provided in this embodiment can effectively support the method for updating the authentication credential in the 5G scenario, and through the technology of directly generating the authentication credential update request by the UICC card and signing the authentication credential update command, it can effectively prevent the IoT UE from forging the update command, and prevent the IoT terminal from replacing (man-in-the-middle attack) the public key by encrypting the UICC card public key with the operator public key in the UICC card, leaking the updated authentication credential, effectively eliminating the possibility of the IoT terminal forging the update command and the update credential, and eliminating the possibility of the IoT terminal replacing (man-in-the-middle attack) the UICC card public key and illegally obtaining the new authentication credential, thereby effectively improving the security and reliability of the authentication credential update of the IoT device.

[0073] Figure 6 is the sixth flowchart of the method for updating the authentication credential of the IoT device provided by the present invention. As Figure 6As shown, this method is applied to the access and mobility management network element of the first network device (i.e., the AMF of the original operator). This method includes step 610, step 620, and step 630.

[0074] Step 610, receiving an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs.

[0075] When the authentication credentials of an Internet of Things device (hereinafter also referred to as an Internet of Things UE) need to be updated, the AMF of the original operator may receive an authentication credential update request sent by the UICC card in the Internet of Things UE.

[0076] The authentication credential update request here can be adaptively obtained according to the initiator of the authentication credential update command.

[0077] For example, when the initiator of the authentication credential update command is a network-side device of the original operator, the obtaining step of the authentication credential update request can be that after the UICC card receives the signed authentication credential update command sent by the network-side device of the original operator (i.e., the authentication credential update command after signature processing), it first uses the public key of the operator to which the first network device belongs (i.e., the original operator) built in it to verify the signature of the signed authentication credential update command. When the signature authentication passes, it generates its own private key and public key, encrypts the public key generated by itself using the public key of the original operator to obtain an encrypted public key, and combines the encrypted public key and the authentication credential update command to generate an authentication credential update request and then forwards it to the original operator UDM. Another example is when the initiator of the authentication credential update command is an Internet of Things UE. The obtaining step of the authentication credential update request can be that after the UICC card receives an authentication credential update application sent by the user, it generates its own private key and public key, encrypts the public key generated by itself using the public key of the original operator to obtain an encrypted public key, and combines the encrypted public key and the authentication credential update command to generate an authentication credential update request and then forwards it to the original operator UDM.

[0078] Step 620, based on the globally unique temporary identifier corresponding to the authentication credential update request and the corresponding relationship between the globally unique temporary identifier and the subscription permanent identifier, associatively searching for the subscription permanent identifier corresponding to the authentication credential update request.

[0079] After receiving the authentication credential update request, the AMF of the original operator can perform an associated search based on the GUTI corresponding to the authentication credential update request and the correspondence between the GUTI stored during the previous registration of the IoT UE and the SUPI to obtain the SUPI corresponding to the authentication credential update request, so that the AMF independently obtains the UICC identifier based on the GUTI-SUPI mapping mechanism, avoiding the device forging the SUPI of the UICC.

[0080] Step 630, forward the authentication credential update request and the subscription permanent identifier to the unified data management network element of the first network device; wherein, the authentication credential update request is used to request the unified data management network element of the first network device to obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and according to the public key generated by the universal integrated circuit card, encrypt and forward the updated authentication credential to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0081] Optionally, after obtaining the authentication credential update request and the subscription permanent identifier corresponding to the authentication credential update request, the AMF of the original operator can forward the authentication credential update request and the subscription permanent identifier corresponding to the authentication credential update request to the UDM of the original operator. After the UDM of the original operator obtains the authentication credential update request and the subscription permanent identifier corresponding to the authentication credential update request, according to the authentication credential update request, obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and after obtaining the updated authentication credential and the public key generated by the UICC card, the UDM of the original operator can encrypt and forward the updated authentication credential to the UICC card according to the public key generated by the UICC card. After the UICC card encrypts the encrypted updated authentication credential based on its own generated private key, update the old authentication credential stored locally according to the decrypted updated authentication credential, and after the update is completed, forward the updated authentication credential to the AMF of the target control object, so that the updated authentication credential is attached to the network, thereby realizing the update of the authentication credential of the IoT device. The specific authentication credential update steps performed by the UDM of the original operator after obtaining the authentication credential update request and the subscription permanent identifier corresponding to the authentication credential update request can be specifically referred to in Step 120 and will not be elaborated here.

[0082] The method provided in this embodiment directly generates a public-private key pair through the UICC card and encrypts the public key with the original operator's public key, avoiding the risk of the Internet of Things device directly accessing the plaintext key and preventing the Internet of Things device from forging update commands or invoking the public key. In addition, the AMF independently obtains the user identifier based on the GUTI-SUPI mapping mechanism to avoid the device forging the SUPI, and the operator UDM performs two-way verification through the public-private key system formed by decrypting the public key with the original operator's private key and encrypting the credential with the UICC public key, constructing an end-to-end double-encryption channel, enabling the Internet of Things device to only play the role of ciphertext transparent transmission and unable to tamper with core data, effectively ensuring the legality and transmission confidentiality of the update authentication credential. Moreover, this architecture limits key operations to be executed between the UICC card and the operator network through cryptographic mechanisms. Even if there is a backdoor or vulnerability in the program of the Internet of Things device that is exploited, the attacker cannot forge a valid update request or steal sensitive keys, effectively preventing the Internet of Things device from forging update commands or swapping the public key of the UICC card, solving the risks of man-in-the-middle attacks and data tampering, and thus effectively improving the security and reliability of the update of the authentication credential of the Internet of Things device.

[0083] In some embodiments, step 610 specifically includes: when it is determined that the authentication credential update command is initiated by the access and mobility management network element, sending the authentication credential update command to the unified data management network element; receiving the signed authentication credential update command generated by the unified data management network element by signing the authentication credential update command with the private key of the operator to which the first network device belongs; forwarding the signed authentication credential update command to the Internet of Things device; receiving, by the universal integrated circuit card in the Internet of Things device, the authentication credential update request generated according to the encrypted public key and the authentication credential update command when the signature verification of the signed authentication credential update command based on the public key of the operator to which the first network device belongs is successful.

[0084] Optionally, when it is confirmed that the initiating end of the authentication credential update command is the AMF in the network side device of the original operator, the AMF of the original operator may first send the authentication credential update command to the UDM of the original operator, so that the UDM of the original operator may first sign the authentication credential update command with the private key of the original operator.

[0085] Then, the AMF of the original operator can receive the signed authentication credential update command including the authentication credential update command and the signature returned by the UDM of the original operator, and forward the signed authentication credential update command to the IoT UE, so that the UICC card in the IoT UE can first use its built-in public key of the original operator to verify the signature of the signed authentication credential update command after receiving the signed authentication credential update command sent by the network-side device of the original operator. If the signature verification passes, the UICC card generates its own private key and public key, and encrypts the public key generated by itself with the public key of the original operator to obtain the encrypted public key, and generates an authentication credential update request based on the encrypted public key and the authentication credential update command.

[0086] Then, the AMF of the original operator can receive the authentication credential update request containing the encrypted public key returned by the UICC card, and update the authentication credential of the IoT device based on this authentication credential update request.

[0087] In the method provided in this embodiment, when the initiator of the authentication credential update is the network side of the operator, the authentication credential command needs to be issued after being digitally signed by the operator, so that after the UICC card receives it, it uses the operator's public key to verify the signature before generating an authentication credential update request, thereby enhancing the security of the IoT device authentication process and effectively preventing unauthorized authentication credential updates, such as IoT devices forging update commands. Moreover, when the UICC card provides the card identification and its own public key, it uses the operator's public key in the card to encrypt the provided card identification and public key, thereby effectively preventing the IoT UE from swapping the public key of the UICC card and avoiding initiating a man-in-the-middle attack, thereby effectively improving the security and reliability of the authentication credential update.

[0088] The following is a description of the authentication credential updating device for an Internet of Things device provided by the present invention. The authentication credential updating device for an Internet of Things device described below and the authentication credential updating method for an Internet of Things device described above can be referenced to each other.

[0089] Figure 7 This is one of the structural diagrams of the authentication credential updating device for the Internet of Things device provided by the present invention; Figure 7 As shown, the device may be formed based on a unified data management network element of the first network device, that is, the original operator UDM, and the device includes: The first acquisition unit 710 is used to acquire an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by the access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encryption public key that is used by the universal integrated circuit card to encrypt a public key generated by the universal integrated circuit card based on a public key of an operator to which the first network device belongs; The update unit 720 is configured to obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card according to the authentication credential update request, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

[0090] The device provided in this embodiment generates a public-private key pair directly through the UICC card and encrypts the public key with the public key of the original operator, avoiding the risk of the Internet of Things device directly accessing the plaintext key and preventing the Internet of Things device from forging update commands or invoking the public key; and a public-private key system formed by the operator UDM decrypting the public key with the original operator's private key and encrypting the credential with the UICC public key is used for two-way verification to build an end-to-end double-encryption channel, enabling the Internet of Things device to only play the role of ciphertext transparent transmission and unable to tamper with core data, effectively ensuring the legality and transmission confidentiality of the updated authentication credential. Moreover, this architecture limits key operations to be executed between the UICC card and the operator network through cryptographic mechanisms. Even if there is a backdoor or vulnerability in the program of the Internet of Things device that is exploited, attackers cannot forge valid update requests or steal sensitive keys, effectively preventing the Internet of Things device from forging update commands or swapping the public key of the UICC card, solving the risks of man-in-the-middle attacks and data tampering, and thus effectively improving the security and reliability of the authentication credential update of the Internet of Things device.

[0091] Figure 8 It is the second structural schematic diagram of the authentication credential update device for Internet of Things devices provided by the present invention. As Figure 8 shown, this device is constructed based on the access and mobility management network element of the first network device, that is, the AMF of the original operator. This device includes: The second acquisition unit 810 is configured to receive an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by the universal integrated circuit card encrypting the public key generated by the universal integrated circuit card with the public key of the operator to which the first network device belongs. The lookup unit 820 is configured to perform an associated lookup of the subscription permanent identifier corresponding to the authentication credential update request according to the globally unique temporary identifier corresponding to the authentication credential update request and the corresponding relationship between the globally unique temporary identifier and the subscription permanent identifier. The forwarding unit 830 is configured to forward the authentication credential update request and the subscription permanent identifier to the unified data management network element of the first network device. The authentication credential update request is used to request the unified data management network element of the first network device to obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

[0092] The device provided in this embodiment directly generates a public-private key pair by the UICC card and encrypts the public key with the original operator's public key, avoiding the risk of the Internet of Things device directly contacting the plaintext key and preventing the Internet of Things device from forging an update command or invoking the public key. In addition, the AMF independently obtains the user identifier based on the GUTI-SUPI mapping mechanism to avoid the device forging the SUPI. Moreover, the operator UDM decrypts the public key with the original operator's private key and encrypts the credential with the UICC public key to form a public-private key system for two-way verification, constructing an end-to-end double-encryption channel, so that the Internet of Things device only plays the role of ciphertext transparent transmission and cannot tamper with the core data, effectively ensuring the legality and transmission confidentiality of the updated authentication credential. And this architecture restricts key operations to be executed between the UICC card and the operator network through a cryptographic mechanism. Even if there is a backdoor or vulnerability in the program of the Internet of Things device that is exploited, the attacker cannot forge a valid update request or steal sensitive keys, effectively preventing the Internet of Things device from forging an update command or swapping the public key of the UICC card, solving the risks of man-in-the-middle attacks and data tampering, and thus effectively improving the security and reliability of the authentication credential update of the Internet of Things device.

[0093] This embodiment also provides an authentication credential update system for an Internet of Things device. The system includes multiple network devices and an Internet of Things device; Each of the network devices includes a unified data management network element, an access and mobility management network element, a radio access network network element, and an authentication server function network element; The unified data management network element is used to execute the authentication credential update method for the Internet of Things device provided in the above embodiments, and specifically, reference can be made to Figure 1 the authentication credential update process shown to update the authentication credential of the universal integrated circuit card in the Internet of Things device; The access and mobility management network element is used for the authentication credential update method for the Internet of Things device provided in the above embodiments, and specifically, reference can be made to Figure 6 the authentication credential update process shown to update the authentication credential of the universal integrated circuit card in the Internet of Things device.

[0094] This embodiment provides a system that directly generates a public-private key pair through the UICC card, encrypts the public key with the original operator's public key, and independently obtains the user identifier by the AMF based on the GUTI-SUPI mapping mechanism, avoiding device forgery of the SUPI. The operator UDM decrypts the public key with the original operator's private key, and the UICC public key encrypts the credentials to form a two-way verification of the public-private key system, constructing an end-to-end double-encryption channel. And through the cryptography mechanism, key operations are limited to be executed between the UICC card and the operator network. Even if there is a backdoor or vulnerability in the program of the IoT device that is exploited, attackers cannot forge valid update requests or steal sensitive keys, effectively preventing the IoT device from forging update commands or swapping the public key of the UICC card, solving the risks of man-in-the-middle attacks and data tampering, and thus effectively improving the security and reliability of the authentication credential update of the IoT device.

[0095] The device or system provided by the present invention is used to execute the above method embodiments. For the specific process and detailed content, please refer to the above embodiments and will not be elaborated here.

[0096] Figure 9 An entity structure diagram of an electronic device is exemplified, as Figure 9As shown in the figure, the electronic device may include: a processor 910, a communications interface 920, a memory 930, and a communication bus 940. Among them, the processor 910, the communications interface 920, and the memory 930 complete communication with each other through the communication bus 940. The processor 910 may call logical instructions in the memory 930 to execute an authentication credential update method for an Internet of Things device. The method includes: obtaining an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by an access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; according to the authentication credential update request, obtaining an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypting and forwarding the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card to update the authentication credential of the universal integrated circuit card, or executing an authentication credential update method for an Internet of Things device. The method includes: receiving an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; according to the globally unique temporary identifier corresponding to the authentication credential update request and the correspondence between the globally unique temporary identifier and the subscription permanent identifier, associatively searching for the subscription permanent identifier corresponding to the authentication credential update request; forwarding the authentication credential update request and the subscription permanent identifier to a unified data management network element of the first network device; where the authentication credential update request is used to request the unified data management network element of the first network device to obtain an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0097] In addition, when the logical instructions in the above-mentioned memory 930 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0098] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the authentication credential update method for the Internet of Things device provided by each of the above methods. The method includes: obtaining an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by an access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; according to the authentication credential update request, obtaining an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypting and forwarding the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card to update the authentication credential of the universal integrated circuit card, or executing the authentication credential update method for the Internet of Things device, the method includes: receiving an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; according to the globally unique temporary identifier corresponding to the authentication credential update request and the corresponding relationship between the globally unique temporary identifier and the subscription permanent identifier, associatively searching for the subscription permanent identifier corresponding to the authentication credential update request; forwarding the authentication credential update request and the subscription permanent identifier to the unified data management network element of the first network device; wherein, the authentication credential update request is used to request the unified data management network element of the first network device to obtain an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0099] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the authentication credential update method for Internet of Things devices provided by the above-mentioned various methods. The method includes: obtaining an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by the access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; according to the authentication credential update request, obtaining an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypting and forwarding the updated authentication credential to the universal integrated circuit card based on the public key generated by the universal integrated circuit card to update the authentication credential of the universal integrated circuit card, or implementing the authentication credential update method for Internet of Things devices. The method includes: receiving an authentication credential update request sent by a universal integrated circuit card in the Internet of Things device; the authentication credential update request includes an authentication credential update command, and an encrypted public key obtained by encrypting the public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs; according to the globally unique temporary identifier corresponding to the authentication credential update request and the corresponding relationship between the globally unique temporary identifier and the subscription permanent identifier, associatively searching for the subscription permanent identifier corresponding to the authentication credential update request; forwarding the authentication credential update request and the subscription permanent identifier to the unified data management network element of the first network device; wherein, the authentication credential update request is used to request the unified data management network element of the first network device to obtain an updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and based on the public key generated by the universal integrated circuit card, encrypt and forward the updated authentication credential to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

[0100] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0101] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0102] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for updating authentication credentials of an Internet of Things device, characterized in that: A unified data management network element applied to a first network device, the method comprising: Obtaining an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by an access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encryption public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs, using the universal integrated circuit card to encrypt the public key generated by the universal integrated circuit card; According to the authentication credential update request, the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card are obtained, and according to the public key generated by the universal integrated circuit card, the updated authentication credential is encrypted and forwarded to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

2. The method for updating the authentication credentials of an Internet of Things device according to claim 1, characterized in that: Obtain the authentication credential update request sent by the universal integrated circuit card in the IoT device, including: When it is determined that the authentication credential update command is initiated by the access and mobility management network element, signing the authentication credential update command based on a private key of the operator to which the first network device belongs; Based on the access and mobility management network element, forwarding the signed authentication credential update command to the Internet of Things device; Based on the access and mobility management network element, the authentication credential update request generated by the universal integrated circuit card according to the encrypted public key and the authentication credential update command is received when the signature verification of the signed authentication credential update command based on the public key of the operator to which the first network device belongs is successful.

3. The authentication credential updating method of an Internet of Things device according to claim 1, characterized in that: Obtain the authentication credential update request sent by the universal integrated circuit card in the IoT device, including: When it is determined that the authentication credential update command is initiated by the universal integrated circuit card, the authentication credential update request generated by the universal integrated circuit card according to the encrypted public key and the authentication credential update command is received.

4. The method for updating the authentication credentials of an Internet of Things device according to any one of claims 1 to 3, characterized in that: The obtaining, according to the authentication credential update request, the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypting and forwarding the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card, comprises: When confirming that the target control object corresponding to the authentication credential update request is the first network device, decrypting the encrypted public key according to the private key of the operator to which the first network device belongs to obtain the public key generated by the universal integrated circuit card; generating, according to the authentication credential update command, an updated authentication credential corresponding to the subscription permanent identifier; The updated authentication credential is encrypted according to the public key generated by the universal integrated circuit card, and the encrypted updated authentication credential is forwarded to the universal integrated circuit card through the access and mobility management network element to update the authentication credential of the universal integrated circuit card.

5. The method for updating the authentication credentials of an Internet of Things device according to any one of claims 1 to 3, characterized in that: The obtaining, according to the authentication credential update request, the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypting and forwarding the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card, comprises: In the case where it is confirmed that the target control object corresponding to the authentication credential update request is the second network device, if it is detected that the first network device has the authentication credential update authority corresponding to the authentication credential update request, decrypting the encrypted public key according to the private key of the operator to which the first network device belongs to obtain the public key generated by the universal integrated circuit card; forwarding the public key generated by the universal integrated circuit card and the authentication credential update request to a unified data management network element of the second network device; receiving an encrypted update authentication credential returned by the unified data management network element of the second network device, wherein the encrypted update authentication credential is generated by the unified data management network element of the second network device according to the authentication credential update command in the authentication credential update request, and then encrypting the update authentication credential according to the public key generated by the universal integrated circuit card; The encrypted updated authentication credential is forwarded to the universal integrated circuit card to update the authentication credential of the universal integrated circuit card.

6. A method for updating authentication credentials of an Internet of Things device, characterized in that: The access and mobility management network element applied to the first network device comprises: Receiving an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device; the authentication credential update request includes an authentication credential update command and an encrypted public key generated by the universal integrated circuit card based on the public key of the operator to which the first network device belongs, using the universal integrated circuit card to encrypt the public key; According to the globally unique temporary identifier corresponding to the authentication credential update request and the corresponding relationship between the globally unique temporary identifier and the subscription permanent identifier, associatively searching for the subscription permanent identifier corresponding to the authentication credential update request; forwarding the authentication credential update request and the subscription permanent identifier to a unified data management network element of the first network device; Among them, the authentication credential update request is used to request the unified data management network element of the first network device to obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

7. The method for updating the authentication credentials of an Internet of Things device according to claim 6, characterized in that: The receiving the authentication credential update request sent by the universal integrated circuit card in the Internet of Things device includes: In the case where it is determined that the authentication credential update command is initiated by the access and mobility management network element, sending the authentication credential update command to the unified data management network element; Receive a signed authentication credential update command generated by the unified data management network element by signing the authentication credential update command based on a private key of the operator to which the first network device belongs; Forwarding the signed authentication credential update command to the IoT device; Receive the authentication credential update request generated according to the encrypted public key and the authentication credential update command when the signature of the signed authentication credential update command is successfully verified based on the public key of the operator to which the first network device belongs by the universal integrated circuit card in the Internet of Things device.

8. An authentication credential updating device for an Internet of Things device, characterized in that: The device is constructed based on a unified data management network element of a first network device, and the device includes: A first acquisition unit is configured to acquire an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device, and a subscription permanent identifier corresponding to the authentication credential update request sent by an access and mobility management network element of the first network device; the authentication credential update request includes an authentication credential update command, and an encryption public key generated by the universal integrated circuit card and encrypted by the universal integrated circuit card based on a public key of an operator to which the first network device belongs. An updating unit is used to obtain, according to the authentication credential update request, the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

9. An authentication credential updating device for an Internet of Things device, characterized in that: The device is constructed based on an access and mobility management network element of a first network device, and includes: A second acquisition unit is configured to receive an authentication credential update request sent by a universal integrated circuit card in an Internet of Things device; the authentication credential update request includes an authentication credential update command and an encrypted public key generated by the universal integrated circuit card based on a public key of an operator to which the first network device belongs, and encrypted by the universal integrated circuit card. a search unit, configured to associate and search for a subscription permanent identifier corresponding to the authentication credential update request according to the globally unique temporary identifier corresponding to the authentication credential update request and a correspondence between the globally unique temporary identifier and the subscription permanent identifier; a forwarding unit, configured to forward the authentication credential update request and the subscription permanent identifier to a unified data management network element of the first network device; Among them, the authentication credential update request is used to request the unified data management network element of the first network device to obtain the updated authentication credential corresponding to the subscription permanent identifier and the public key generated by the universal integrated circuit card, and encrypt and forward the updated authentication credential to the universal integrated circuit card according to the public key generated by the universal integrated circuit card, so as to update the authentication credential of the universal integrated circuit card.

10. An authentication credential updating system for an Internet of Things device, characterized in that: Includes multiple network devices and IoT devices; Each of the network devices includes a unified data management network element, an access and mobility management network element, a wireless access network network element and an authentication server function network element; The unified data management network element is used to execute the authentication credential updating method of the Internet of Things device according to any one of claims 1 to 5, and update the authentication credential of the universal integrated circuit card in the Internet of Things device; The access and mobility management network element is used to execute the authentication credential updating method of the Internet of Things device as described in any one of claims 6-7, and update the authentication credential of the universal integrated circuit card in the Internet of Things device.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method for updating the authentication credentials of the Internet of Things device as described in any one of claims 1 to 5, or the method for updating the authentication credentials of the Internet of Things device as described in any one of claims 6 to 7 is implemented.

12. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for updating the authentication credentials of an Internet of Things device as described in any one of claims 1 to 5 or the method for updating the authentication credentials of an Internet of Things device as described in any one of claims 6 to 7 is implemented.

13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for updating the authentication credentials of an Internet of Things device as described in any one of claims 1 to 5 or the method for updating the authentication credentials of an Internet of Things device as described in any one of claims 6 to 7 is implemented.