Data interaction system, method and device of passive Internet of Things terminal and storage medium
By designing a passive IoT terminal data interaction system for a lightweight core network, the signaling interaction between the network side and the terminal is reduced, the problem of high power consumption of passive IoT terminals is solved, and low-power data interaction is achieved.
Patent Information
- Application Number
- CN202510766017.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-10
AI Technical Summary
Passive IoT terminals in 5G-A network have high power consumption due to the high signaling interaction between the network side and the terminal in the 5G-A network, and cannot effectively adapt to their low-power consumption characteristics.
A data interaction system for passive IoT terminals is designed, including a lightweight core network and passive IoT terminal. Through access and mobility functional modules and data management and authentication functional modules, signaling interaction between the network side and the terminal is reduced and power consumption is reduced.
By reducing signaling interaction, the power consumption of passive IoT terminals is reduced, the low power consumption needs are met, and the service needs of Ambient IoT terminals are adapted.
Smart Images

Figure CN120343559A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of Internet of Things, and in particular to a data interaction system, method, device and storage medium for a passive Internet of Things terminal. Background Art
[0002] As an emerging technology in the field of IoT, Ambient Internet of Things (Ambient IoT) has the characteristics of low power consumption and low cost, easy deployment, massive connections, and rich typical application scenarios. With the continuous expansion of the IoT market, the passive IoT industry is also showing a rapid development trend. More and more companies are beginning to pay attention to and invest in the research and development and application of passive IoT technology, which has promoted the continuous innovation of passive IoT technology and the development and growth of the industry.
[0003] Since Ambient IoT terminals mainly rely on collecting energy from the surrounding environment, such as collecting light energy through solar panels, collecting vibration energy with piezoelectric materials, or capturing radio wave energy with RF antennas, etc. to power their own operation, and also rely on these limited energy resources to complete signal transmission and reception during data transmission, the Internet of Things based on 5G-A has more signaling interactions between the network side and the terminal of the entire network element, resulting in higher power consumption of Ambient IoT terminals, which cannot adapt well to the characteristics of Ambient IoT terminals. Summary of the invention
[0004] The main purpose of the embodiments of the present disclosure is to propose a data interaction system, method, device and storage medium for a passive Internet of Things terminal, aiming to reduce the signaling interaction between the network side and the terminal and reduce the power consumption of the passive Internet of Things terminal.
[0005] To achieve the above-mentioned purpose, an embodiment of the present application provides a data interaction system for a passive Internet of Things terminal, wherein the data interaction system for the passive Internet of Things terminal includes a passive Internet of Things terminal and a lightweight core network, wherein the lightweight core network includes an access and mobility function module and a data management and authentication function module, wherein the access and mobility function module includes an acquisition unit and a verification unit; The acquisition unit is used to send a parsing request signal to the data management and authentication function module in response to the service request information sent by the passive Internet of Things terminal, wherein the service request information includes a subscription anonymity identifier and uplink service data; The data management and authentication function module is used to resolve the subscription anonymity identifier in response to the resolution request signal to obtain a subscription permanent identifier, and send the subscription permanent identifier to the access and mobility function module, wherein the resolution request signal includes the subscription anonymity identifier; The verification unit is used to obtain the corresponding user context according to the subscription permanent identifier, verify the user context, and if the verification passes, send the uplink service data to an external data network.
[0006] In some embodiments, the access and mobility function module further includes a registration unit and an authentication unit; The registration unit is used to respond to the initial registration request information initiated by the passive IoT terminal, send a first authentication request information to the data management and authentication function module, and send the initial registration request information to the authentication unit; The data management and authentication function module is further used to respond to the first authentication request information, and send a first authentication response information to the access and mobility function module, wherein the first authentication response information includes a first authentication parameter; The authentication unit is used to respond to the first authentication response information, send an enhanced authentication request information to the passive IoT terminal; and in response to the enhanced authentication response information returned by the passive IoT terminal, send a registration success signal to the passive IoT terminal.
[0007] In some embodiments, the authentication unit is specifically used for: Determine the protection algorithm of the passive IoT terminal according to the terminal security capability information in the initial registration request information; Generate a first integrity protection key according to the first base key of the first authentication parameter and the protection algorithm; Remove the first base key of the first authentication parameter to obtain a second authentication parameter; Encapsulate the protection algorithm, the terminal security capability information and the second authentication parameter to obtain encapsulated data; Use the first integrity protection key to encode the encapsulated data to obtain a message authentication code; Obtain the enhanced authentication request information according to the message authentication code and the encapsulated data.
[0008] In some embodiments, the passive IoT terminal is specifically used for: Verify the second authentication parameter in the enhanced authentication request information, and if the verification passes, obtain a second base key and a response value according to the second authentication parameter in the enhanced authentication request information; Process the second base key through the protection algorithm to obtain a second integrity protection key and an encryption key; Use the encryption key and the second integrity protection key to encrypt the initial registration request information to obtain a first registration request information; Using the second integrity protection key, verify the integrity of the enhanced authentication request information; If the verification of the integrity of the enhanced authentication request information passes, obtain the enhanced authentication response information according to the response value and the first registration request information.
[0009] In some embodiments, the authentication unit is further configured to: Verify the response value, and if the verification passes, parse the first registration request information to obtain second registration request information; According to the initial registration request information and the second registration request information, confirm whether the security context negotiation between the passive Internet of Things terminal and the lightweight core network is successful; If the negotiation is successful, send a registration success signal to the passive Internet of Things terminal.
[0010] In some embodiments, the access and mobility function module further includes a session establishment unit; The session establishment unit is configured to, in response to a session establishment request signal initiated by the passive Internet of Things terminal, allocate an IP address to the passive Internet of Things terminal and send session establishment reception information to the passive Internet of Things terminal, where the session establishment reception information includes the IP address.
[0011] In some embodiments, the access and mobility function module further includes a data download unit; The data download unit is configured to obtain downlink service data, where the downlink service data includes an IP address; According to the IP address, determine the corresponding passive Internet of Things terminal; Send the downlink service data to the corresponding passive Internet of Things terminal.
[0012] On the other hand, an embodiment of the present invention provides a data interaction method for a passive Internet of Things terminal, including the following steps: In response to service request information sent by the passive Internet of Things terminal, send a parsing request signal to the data management and authentication function module, where the service request information includes a subscription concealment identifier and uplink service data; In response to the parsing request signal, parse the subscription concealment identifier to obtain a subscription permanent identifier, where the parsing request signal includes the subscription concealment identifier; According to the subscription permanent identifier, retrieve the corresponding user context, verify the user context, and if the verification passes, send the uplink service data to an external data network.
[0013] On the other hand, an embodiment of the present invention provides an electronic device, including: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the data interaction method of the passive Internet of Things terminal as described in the previous embodiment.
[0014] On the other hand, an embodiment of the present invention further provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the data interaction method of the passive Internet of Things terminal as described in the previous embodiment.
[0015] At least one of the above technical solutions of the present invention has at least the following advantages or beneficial effects: A data interaction system, method, device and storage medium for a passive Internet of Things terminal proposed in this application. The system includes a passive Internet of Things terminal and a lightweight core network. The lightweight core network includes an access and mobility function module and a data management and authentication function module. The access and mobility function module includes an acquisition unit and a verification unit. After receiving the service request information sent by the passive Internet of Things terminal, the acquisition unit sends a parsing request signal to the data management and authentication function module. The service request information includes a subscription concealment identifier and uplink service data. The data management and authentication function module receives the parsing request signal, parses the subscription concealment identifier to obtain a subscription permanent identifier, and sends the subscription permanent identifier to the access and mobility function module. The verification unit obtains the corresponding user context according to the subscription permanent identifier and verifies the user context. If the verification passes, the uplink service data is sent to an external data network. In this application, the passive Internet of Things terminal accesses the lightweight core network, and the service request information sent by the passive Internet of Things terminal carries a subscription concealment identifier, reducing the Identity Request process initiated by the terminal due to the 5G core network being unable to find the user corresponding to the temporary identity ID, and reducing the signaling for the terminal to confirm the 5G-GUTI allocated by the network side. Thus, the signaling interaction between the network side and the terminal is reduced, the power consumption of the passive Internet of Things terminal is reduced, and the service requirements of the Ambient IoT terminal are met. Description of the Drawings
[0016] Figure 1 is a flowchart of the data interaction method of the passive Internet of Things terminal provided by an embodiment of this application; Figure 2 is a schematic structural diagram of the data interaction system of the passive Internet of Things terminal provided by an embodiment of this application; Figure 3It is a schematic diagram of the data interaction system registration process of the passive Internet of Things terminal provided by the embodiment of the present application; Figure 4 It is a schematic diagram of the data interaction system session establishment process of the passive Internet of Things terminal provided by the embodiment of the present application; Figure 5 It is a schematic diagram of the data interaction system service data reception process of the passive Internet of Things terminal provided by the embodiment of the present application; Figure 6 It is a schematic diagram of the connection structure between the passive Internet of Things terminal and the core network provided by the embodiment of the present application; Figure 7 It is a schematic diagram of the registration process of the passive Internet of Things terminal provided by the embodiment of the present application; Figure 8 It is a schematic diagram of the session establishment process of the passive Internet of Things terminal provided by the embodiment of the present application; Figure 9 It is a schematic diagram of the service data sending and receiving process of the passive Internet of Things terminal provided by the embodiment of the present application; Figure 10 It is a schematic diagram of the hardware structure of the electronic device provided by the embodiment of the present application. Detailed implementation manners
[0017] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.
[0018] It should be noted that although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order from the module division in the device or the flowchart. The terms "first", "second", etc. in the specification, claims and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application, and are not intended to limit the present application.
[0020] First, several nouns involved in the present application are analyzed: 5G Core Network (5th Generation Core Network, 5GC): It refers to the core network of the fifth-generation mobile communication system, which is a new mobile network architecture that can provide faster, more secure, and more reliable mobile communication services. The main feature of 5GC is its distributed architecture, which has high scalability, high reliability, and high security, and can support more types of application services to meet the needs of different users. The network structure of 5GC consists of a control layer and a data layer, and the control layer is composed of a control plane and a user plane. The applications of 5GC mainly include smart home, vehicle networking, Internet of Things, intelligent manufacturing, intelligent health, etc., which can provide more efficient, more secure, and more reliable mobile communication services, realize the development of intelligence, networking, dataization, and serviceization, and promote the development and application of mobile communication technology.
[0021] The Internet of Things (IoT) refers to a network system that connects various physical devices, sensors, software, and networks through Internet technology to achieve intelligent perception, data interaction, and collaborative control between devices. Its core is to endow objects with the ability to connect to the Internet through embedded technology, such as smart home appliances, wearable devices, industrial machines, etc. With real-time data collection and analysis, it optimizes resource utilization, improves efficiency, and expands automated application scenarios. The IoT is widely used in fields such as smart home, smart city, healthcare, agricultural monitoring, and Industry 4.0, and is reshaping the interaction methods between people, technology, and the environment, promoting the transformation of the digital society.
[0022] The data interaction system of the passive Internet of Things terminal in the embodiments of this application includes a passive Internet of Things terminal and a lightweight core network, and the lightweight core network is realized by optimizing the functions of the 5G core network. Among them, the access and mobility function module in the lightweight core network is equivalent to the enhanced access and mobility management function network element (Enhanced Access and Mobility Management Function, E-AMF) of the 5G core network, and the data management and authentication function module is equivalent to the combined functions of the unified data management function network element (Unified Data Management, UDM) and the authentication server function network element (Authentication Server Function, AUSF) of the 5G core network.
[0023] Please refer to Figure 2 , Figure 2It is a schematic structural diagram of the data interaction system of the passive Internet of Things terminal provided by the embodiments of the present application. The data interaction system of the passive Internet of Things terminal in the embodiments of the present application includes a passive Internet of Things terminal and a lightweight core network. The lightweight core network includes an access and mobility function module and a data management and authentication function module. The access and mobility function module includes an acquisition unit and a verification unit; The acquisition unit is configured to send a parsing request signal to the data management and authentication function module in response to a service request message sent by the passive Internet of Things terminal, where the service request message includes a subscribed concealment identifier and uplink service data; The data management and authentication function module is configured to parse the subscribed concealment identifier in response to the parsing request signal to obtain a subscribed permanent identifier, and send the subscribed permanent identifier to the access and mobility function module, where the parsing request signal includes the subscribed concealment identifier; The verification unit is configured to obtain a corresponding user context according to the subscribed permanent identifier, and verify the user context. If the verification is passed, the uplink service data is sent to an external data network.
[0024] In this embodiment, the passive Internet of Things terminal refers to an Internet of Things device that can operate without being powered by an internal power supply. It obtains the energy required for operation through environmental energy harvesting technology and realizes data transmission using low-power communication technology. Such terminals usually have a simple structure and low cost, and are suitable for large-scale deployment scenarios. The lightweight core network is obtained by highly integrating and optimizing network functions on the basis of the functions of the original 5G core network. The lightweight core network includes an access and mobility function module (E-AMF) and a data management and authentication function module (UDM+AUSF). The lightweight core network is composed of E-AMF (enhanced AMF) and UDM+AUSF. E-AMF is responsible for the mobility management of the terminal, the parsing and construction of NAS messages for session management, and the processing of terminal service requests. UDM+AUSF is responsible for the identity authentication of the access terminal and the generation of basic keys. The access and mobility function module includes an acquisition unit and a verification unit.
[0025] The passive Internet of Things (IoT) terminal accesses the lightweight core network. After completing registration and establishing a session, the passive IoT terminal will transmit service data. When uploading uplink service data, the passive IoT terminal will send a service request message to the acquisition unit in the access and mobility management function (AMF) module. The service request message includes a subscription concealed identifier (SUCI) and uplink service data. The subscription concealed identifier is a user identity protection mechanism introduced in 5G mobile communication. It is a temporary identifier generated by encrypting the user's subscription permanent identifier (SUPI), aiming to enhance user privacy and network security. After receiving the service request message, the acquisition unit will send a parsing request signal to the unified data management and authentication function module (UDM+AUSF). After receiving the parsing request signal, the unified data management and authentication function module parses the subscription concealed identifier to obtain the subscription permanent identifier and sends the subscription permanent identifier (SUPI) to the access and mobility management function module. After obtaining the SUPI, the verification unit in the access and mobility management function module will find the corresponding user context according to the SUPI. The user context includes, but is not limited to, user identity information, security information, and session status, which can be obtained during the terminal registration and session establishment process. The verification unit will verify whether the user context is complete. If the user context is complete, the verification passes, enabling the uplink service data to be securely and completely uploaded to the external data network. The service request message sent by the passive IoT terminal carries the subscription concealed identifier, reducing the IdentityRequest (identity authentication) process initiated by the network for the terminal due to the inability of the 5G core network to find the user corresponding to the temporary identity ID, and reducing the signaling for the terminal to confirm the 5G-GUTI (5G Globally Unique Temporary Identifier) allocated by the network side. Therefore, the signaling interaction between the network side and the terminal can be reduced, the power consumption of the passive IoT terminal can be reduced, and the service requirements of the Ambient IoT terminal can be met.
[0026] In some embodiments, the access and mobility management function module further includes a registration unit and an authentication unit; The registration unit is configured to, in response to an initial registration request message initiated by the passive IoT terminal, send a first authentication request message to the unified data management and authentication function module and send the initial registration request message to the authentication unit; The unified data management and authentication function module is further configured to, in response to the first authentication request message, send a first authentication response message to the access and mobility management function module, where the first authentication response message includes first authentication parameters; The authentication unit is used to send enhanced authentication request information to the passive IoT terminal in response to the first authentication response information, and send a registration success signal to the passive IoT terminal in response to the enhanced authentication response information returned by the passive IoT terminal.
[0027] Please refer to Figure 3 , Figure 3 is a schematic diagram of the registration process of the data interaction system of the passive IoT terminal. In this embodiment, before the passive IoT terminal performs uplink and downlink data transmission, it needs to first register and establish a session. In the registration process, the passive IoT terminal first sends an initial registration request information to the lightweight IoT. The initial registration request information includes SUCI, 5GMM (5G Mobility Management) capabilities, and UE (terminal) security capability information. 5GMM capabilities are one of the core functions of the non-access stratum (NAS) in the 5G network, responsible for terminal registration, location update, status switching, and security context synchronization, enabling seamless handover and continuous service between different network nodes (base stations) for the terminal. UE (terminal) security capability information represents the list of encryption and integrity algorithms supported by the terminal. After the registration unit of the access and mobility function module receives the initial registration request information, the first authentication request information carrying SUCI is sent to the data management and authentication function module. The data management and authentication function module parses the SUCI reported by the terminal to obtain the user's true identity (SUPI), thereby verifying the legitimacy of the terminal's identity and generating the first authentication parameter. At the same time, the registration unit will send the initial registration request information to the authentication unit. The data management and authentication function module will send the first authentication response information carrying the first authentication parameter to the access and mobility function module. After receiving the first authentication response information, the authentication unit can use the first authentication parameter and the terminal security capability information in the initial registration request information for identity authentication and the establishment of a security context. The security context includes a basic secret key, encryption algorithms, integrity protection algorithms, etc. The authentication unit then sends information such as the encryption algorithm, integrity protection algorithm, and authentication parameter selected by the network side based on the terminal security capability information to the terminal through the enhanced authentication request information. The passive IoT terminal will return an enhanced authentication response information to the authentication unit according to the enhanced authentication request information. The authentication unit determines whether the registration is successful based on the enhanced authentication response information. If the registration is successful, a registration success signal will be sent to the passive IoT terminal. The registration process is the first step for the passive IoT terminal to access the core network, aiming to complete identity reporting, capability negotiation, and initialization of the security process.
[0028] In some embodiments, the data management and authentication functional module parses the SUCI in the first authentication request information to obtain the SUPI, and then generates Kseaf (the first basic key) using the SUPI. Kseaf can be used as the basis for generating the first integrity protection key and the first encryption key in the subsequent process.
[0029] In some embodiments, the authentication unit is specifically configured to: Determine the protection algorithm of the passive Internet of Things terminal according to the terminal security capability information in the initial registration request information; Generate a first integrity protection key according to the first basic key of the first authentication parameter and the protection algorithm; Remove the first basic key of the first authentication parameter to obtain a second authentication parameter; Encapsulate the protection algorithm, the terminal security capability information, and the second authentication parameter to obtain encapsulated data; Use the first integrity protection key to encode the encapsulated data to obtain a message authentication code; Obtain enhanced authentication request information according to the message authentication code and the encapsulated data.
[0030] In this embodiment, during the registration process of the passive Internet of Things terminal, the authentication unit obtains the initial registration request information, which includes the terminal security capability information. The terminal security capability information represents the list of protection algorithms supported by the terminal. The authentication unit selects the encryption algorithm and the integrity protection algorithm from the list of protection algorithms according to the specific situation. Subsequently, the terminal processes the basic key according to the encryption algorithm and the integrity protection algorithm selected by the network side to generate the second encryption key and the second integrity protection key. After obtaining the first authentication response information, the authentication unit can use the selected integrity protection algorithm to process the first basic key in the first authentication parameter to obtain the first integrity protection key, and use the selected encryption algorithm to process the first basic key to obtain the first encryption key. The first authentication parameter includes the authentication vector, Kseaf (the first basic key), and SUPI information. The first basic key is not sent to the terminal along with the enhanced authentication request information to prevent it from being tampered with during the transmission process, which is beneficial to improving the security performance. The authentication unit performs integrity protection on the enhanced authentication request information through the first integrity protection key. Specifically, the protection algorithm, the terminal security capability information, and the second authentication parameter are encapsulated to obtain encapsulated data, and the encapsulated data is encoded to obtain a message authentication code (MAC). The message authentication code and the encapsulated data form the enhanced authentication request information. The message authentication code will enter the passive Internet of Things terminal along with the enhanced authentication request information for the terminal to verify the integrity of the enhanced authentication request information. In addition, the enhanced authentication request information also includes RAND (random number challenge value) and AUTN (authentication token).
[0031] In some embodiments, the passive Internet of Things terminal is specifically configured to: Verify the second authentication parameter in the enhanced authentication request information. If the verification passes, obtain a second basic key and a response value according to the second authentication parameter in the enhanced authentication request information; Process the second basic key through a protection algorithm to obtain a second integrity protection key and an encryption key; Use the encryption key and the second integrity protection key to encrypt the initial registration request information to obtain a first registration request information; Use the second integrity protection key to verify the integrity of the enhanced authentication request information; If the verification of the integrity of the enhanced authentication request information passes, obtain the enhanced authentication response information according to the response value and the first registration request information.
[0032] In this embodiment, after obtaining the enhanced authentication request information, the passive Internet of Things terminal first verifies the second authentication parameter. Exemplarily, use the authentication vectors in the second authentication parameter, such as: RAND (random number challenge value), AUTN (authentication token), to generate a message authentication code on the terminal side, and compare the MAC on the terminal side with the MAC on the network side. If they are the same, it means the verification passes. Then use RAND and SUPI in the second authentication parameter to generate a second basic key (Kseaf) and a response value (Res value). The same Kseaf is independently generated on the terminal side and the network side, that is, the first basic key and the second basic key are the same. The terminal and the E-AMF independently derive the same integrity protection key and encryption key based on the same Kseaf and protection algorithm, so that the subsequent communication encryption and integrity protection between the terminal side and the network side can be consistent. In addition, before generating the second integrity protection key and the encryption key, the terminal will check whether the protection algorithm selected by the network side exists in the terminal security capability information. If not, it means that the enhanced authentication request information has been tampered with during transmission, and the terminal will reject the connection with the core network and terminate the subsequent actions. The terminal will use the encryption key to encrypt the initial registration request information, and then use the second integrity protection key for integrity protection to obtain the first registration request information. The terminal can use the second integrity protection key to verify the integrity of the enhanced authentication request information. If the verification passes, it means that the information has not been tampered with during transmission, and the Res value and the first registration request information are returned to the core network through the enhanced authentication response information.
[0033] In some embodiments, the authentication unit is further configured to: Verify the response value. If the verification passes, parse the first registration request information to obtain a second registration request information; According to the initial registration request information and the second registration request information, confirm whether the security context negotiation between the passive IoT terminal and the lightweight core network is successful; If the negotiation is successful, send a registration success signal to the passive IoT terminal.
[0034] In this embodiment, after receiving the enhanced authentication response information, the authentication unit first verifies the response value. Exemplarily, the expected response value pre-calculated by the network side is compared with the response value. If the two are the same, it indicates that the verification is passed, and the encrypted first registration request information is parsed to obtain the second registration request information. The second registration request information is consistent with the initial registration request information, indicating that the keys generated by the terminal and the network are the same, that is, the security context negotiation is successful. The initial registration request information carries the SUCI, quickly establishes the connection between the terminal and the lightweight core network, and performs security context negotiation. After the security context negotiation is completed, the initial registration request information is encrypted and integrity protected, and then the first registration request information is re-sent to confirm the effectiveness of the security context, and the tampering and eavesdropping are resisted through the encryption and integrity protection mechanism to ensure communication security. The E-AMF sends a Register Accept (registration success signal) to the terminal, does not allocate a temporary identity ID to the terminal, and the terminal does not need to reply with a Register Complete (registration complete signal), thereby reducing signaling interaction.
[0035] In some embodiments, the access and mobility function module further includes a session establishment unit; The session establishment unit is used to allocate an IP address to the passive IoT terminal in response to a session establishment request signal initiated by the passive IoT terminal, and send a session establishment received message to the passive IoT terminal, where the session establishment received message includes the IP address.
[0036] Please refer to Figure 4 , Figure 4 is a schematic diagram of the session establishment process of the data interaction system of the passive IoT terminal. In this embodiment, after the terminal completes registration, the session establishment process is carried out. The passive IoT terminal first initiates a session establishment request signal, and the session establishment request signal carries information such as the PDU (Protocol Data Unit) session type and DNN (Data Network Name). After receiving the session establishment request signal, the E-AMF allocates an IP address to the passive IoT terminal, returns a message of PDU session establishment received to the terminal, which includes information such as Qos Rule and Qos flow descriptions, and does not construct an N2 message related to the Pdu Session Resource sent to the base station, thereby further optimizing the signaling.
[0037] In some embodiments, the access and mobility function module further includes a data download unit; The data download unit is used to obtain downlink service data, where the downlink service data includes an IP address; Determine the corresponding passive Internet of Things terminal according to the IP address; Send the downlink service data to the corresponding passive Internet of Things terminal.
[0038] Please refer to Figure 5 , Figure 5 is a schematic diagram of the service data reception process of the data interaction system of the passive Internet of Things terminal. In this embodiment, the external data network sends downlink service data to the lightweight core network, and the data download unit in the E-AMF obtains the downlink service data. The data download unit searches for the user context corresponding to the IP address according to the IP address in the downlink service data. The user context includes information such as the security context, PDU session ID (PDU Session ID), and SUPI, and the corresponding passive Internet of Things terminal can be determined. The data download unit encapsulates the PDU Session ID and the downlink service data, and uses the key information in the security context to encrypt and protect the integrity of the encapsulated data to obtain the DL (downlink) NAS transport message. NAS (Non-Access Stratum) is the control plane protocol between the terminal (UE) and the core network, and is responsible for processing the high-layer signaling interaction unrelated to radio access. When the terminal receives the DL NAS transport message, it can decrypt the message and verify its integrity using the negotiated security context, so as to obtain the downlink service data.
[0039] Please refer to Figure 1 , Figure 1 is an optional flowchart of the data interaction method of the passive Internet of Things terminal provided by some embodiments of the present application. A data interaction method of a passive Internet of Things terminal in an embodiment of the present invention includes but is not limited to steps S100 to S300: Step S100, in response to the service request information sent by the passive Internet of Things terminal, send a parsing request signal to the data management and authentication function module, where the service request information includes a subscription concealment identifier and uplink service data; Step S200, in response to the parsing request signal, parse the subscription concealment identifier to obtain a subscription permanent identifier, where the parsing request signal includes the subscription concealment identifier; Step S300, according to the subscription permanent identifier, retrieve the corresponding user context, verify the user context, and if the verification passes, send the uplink service data to the external data network.
[0040] The data interaction method of the passive Internet of Things terminal provided by the embodiments of the present application can be applied to the terminal, the server side, or software running on the terminal or the server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the method for digital management of indoor items, etc., but is not limited to the above forms.
[0041] The present application can be used in numerous general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet-type devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0042] In some embodiments, please refer to Figure 6 , Figure 6This is a schematic diagram of the connection structure between a passive IoT terminal and the core network. Specifically, the Ambient IoT terminal accesses the core network through the RAN. The core network consists of E-AMF (enhanced AMF) and UDM+AUSF. E-AMF is responsible for the mobility management of the terminal, the parsing and construction of NAS messages for session management, and the processing of terminal service requests. The amount of data for Ambient IoT services is not large, and often only necessary device status and sensor data are transmitted. In order to reduce the scheduling and use of air interface resources and reduce the energy consumption of Ambient IoT terminals, the lightweight core network does not construct N2 messages related to PDU Session Resource for Ambient IoT terminals during the PDU session establishment process. After the terminal registration and PDU session establishment are completed, the uplink and downlink data packets are sent and received through NAS message encapsulation. E-AMF is responsible for the connection between service data and the DN side. UDM+AUSF in the core network is responsible for the identity authentication of the access terminal and the generation of basic keys.
[0043] In some embodiments, please refer to Figure 7 , Figure 7 This is a schematic diagram of the registration process of a passive IoT terminal. First, the terminal initiates a Register Request message (initial registration request information), which contains SUCI, 5GMM capabilities, and UE security capability information.
[0044] E-AMF sends a Nausf_UEAuthRequest message (first authentication request information) to UDM+AUSF, requesting authentication parameters from UDM+AUSF.
[0045] UDM+AUSF returns a Nausf_UEAuthResponse message (first authentication response message) to E-AMF, which contains the authentication vector, Kseaf and SUPI information. The security between E-AMF and UDM+AUSF is protected by the authentication between network elements.
[0046] E-AMF generates security and encryption keys based on Kseaf, and sends an E-AuthRequest message (enhanced authentication request information) to the terminal. The E-AuthRequest message contains RAND, AUTN, UE security capability information, and the selected algorithm (protection algorithm). This message uses the new security key for completeness protection. This process not only authenticates the identity, but also negotiates the security context.
[0047] After the terminal receives the E-AuthRequest message, it verifies the authentication parameters in the message. If the verification passes, it generates the Kseaf and Res values, then verifies the UE security capabilities, generates the confidentiality key and encryption key according to the algorithm selected by the network side, and uses the confidentiality key to verify the integrity of the E-AuthRequest message. If the integrity verification passes, the generated Res value is returned to the core network through the E-AuthResponse message (Enhanced Authentication Response Information). The E-AuthResponse message uses a new confidentiality protection algorithm for confidentiality protection, and the E-AuthResponse contains the completed confidentiality-protected encrypted Register Request message (Initial Registration Request Information).
[0048] After the E-AMF receives the E-AuthResponse message, it first verifies the Res value in the message. After the Res value verification passes, it verifies the carried confidentiality-protected encrypted Register Request message. If the parsing passes, it is considered that the negotiation of the new security context is successful. The E-AMF sends a Register Accept message (Registration Success Signal) to the terminal without allocating a temporary identity ID, and the terminal does not need to reply with a Register Complete message.
[0049] In some implementations, please refer to Figure 8 , Figure 8 which is a schematic diagram of the session establishment process for passive IoT terminals. Specifically, the terminal initiates a PDU session establishment request message, that is, the PduSesssionEstRequest message (Session Establishment Request Signal), carrying information such as the PDU session type and DNN. After the E-AMF receives the PDU session establishment request message, it allocates an IP address and returns a PDU session establishment acceptance message, that is, PduSesssionEstAccept (Session Establishment Acceptance Information) to the terminal. The PDU session establishment acceptance message contains information such as Qos Rule and Qos flow descriptions. The E-AMF no longer constructs the N2 message related to PduSession Resource sent to the base station.
[0050] In some embodiments, please refer to Figure 9 , Figure 9 which is a schematic diagram of the process of receiving and transmitting service data for passive IoT terminals. Specifically, Ambient IoT sends a Control Plane Service request message (Service Request Information), and the ControlPlane Service request message carries the SUCI, PDU Session ID, and encapsulated service data. This message is integrity protected using the current security context.
[0051] The E-AMF sends the interface message Nausf_SupiDecRequest (resolution request signal) for adding N12 / N8 to the UDM+AUSF, requesting the UDM / AUSF to resolve the SUCI. The security between the E-AMF and the UDM+AUSF is ensured by the authentication between network elements.
[0052] The UDM+AUSF returns the resolved SUPI to the E-AMF through the Nausf_SupiDecRequest message.
[0053] The E-AMF finds the corresponding user context according to the SUPI and verifies the integrity. If the verification passes, the uplink service data in the ControlPlane Service request message is taken out and sent to the DN side.
[0054] When there is downlink service data on the DN side, after receiving the downlink service data, the E-AMF finds the corresponding user context according to the destination IP in the downlink service data, constructs a DL NAS transport message, and sends the DL NAS transport message to the terminal, including the Pdu Session Id and the downlink service data.
[0055] In this embodiment, based on the original 5G core network, aiming at the characteristics of energy limitation of passive terminals, it adapts to the scenario of passive Internet of Things, and gives a lightweight core network design and network architecture solution, as well as a method for Ambient IoT to access this network. The lightweight core network aggregates the original session management function, designs an enhanced AMF, and does not integrate the original SMF and UPF. On the premise of ensuring the normal operation of the passive Internet of Things, the network architecture is clearer and the network construction cost is lower.
[0056] In the method for the Ambient IoT terminal to access the lightweight core network in this embodiment, by planning the carrying of the user ID, integrating the authentication and SMC functions, optimizing the registration, PDU session establishment and CP Service processes, reducing the signaling interaction between the terminal and the network side, and meeting the service requirements of the Ambient IoT terminal.
[0057] In some embodiments, when the Ambient IoT terminal accesses the lightweight core network, the signaling optimization is reflected in: 1. The network side no longer allocates a temporary identity ID 5G-GUTI. The SUCI is carried in the initial signaling initiated by the terminal in the idle state, reducing the Identity Request process initiated by the core network due to its inability to find the user corresponding to the temporary identity ID, and reducing the signaling for the terminal to confirm the 5G-GUTI allocated by the network side. To meet the decryption of SUCI in the non-authentication process, the E-AMF and UDM+AUSF need to enhance the processing on the original N12 / N8 interfaces.
[0058] 2. Optimize the original AUTH / SMC process to reduce the signaling interaction between the network side and the terminal.
[0059] 3. During the PDU session establishment process, the base station is not notified to apply for N2 resources.
[0060] In this embodiment, on the premise of ensuring the secure access of Ambient IoT devices, a lightweight core network is designed, highly integrating and optimizing network functions, reducing network equipment costs, and facilitating large-scale promotion. At the same time, considering the special situation of energy limitation of Ambient IoT devices and the small amount of Ambient IoT service data, the optimized transmission process can minimize the signaling interaction between the terminal and the network side. The minimalist mode ensures necessary data transmission to enable data to be transmitted quickly and accurately under energy-limited conditions, meeting the information transmission requirements of different application scenarios.
[0061] The following combines Figure 10 to introduce the electronic device of the embodiment of the present application in detail.
[0062] As Figure 10 , Figure 10 schematically shows the hardware structure of the electronic device of another embodiment. The electronic device includes: A processor 1100, which can be implemented in ways such as a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present disclosure; The memory 1200 can be implemented in the form of a Read Only Memory (ROM), a static storage device, a dynamic storage device, or a Random Access Memory (RAM), etc. The memory 1200 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1200 and are called by the processor 1100 to execute the data interaction method of the passive Internet of Things terminal in the embodiments of the present disclosure; The input / output interface 1300 is used to implement information input and output; The communication interface 1400 is used to implement communication interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or through wireless means (such as mobile network, WIFI, Bluetooth, etc.); The bus 1500 transmits information between various components of the device (such as the processor 1100, the memory 1200, the input / output interface 1300, and the communication interface 1400); Among them, the processor 1100, the memory 1200, the input / output interface 1300, and the communication interface 1400 are communicatively connected to each other inside the device through the bus 1500.
[0063] The embodiments of the present disclosure also provide a storage medium. This storage medium is a computer-readable storage medium, and this computer-readable storage medium stores computer-executable instructions. These computer-executable instructions are used to cause a computer to execute the above-mentioned data interaction method of the passive Internet of Things terminal.
[0064] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory can include memories remotely provided with respect to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0065] The embodiments described in the embodiments of the present disclosure are for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided in the embodiments of the present disclosure. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present disclosure are equally applicable to similar technical problems.
[0066] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present disclosure, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0067] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0068] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations.
[0069] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0070] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.
[0071] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0072] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0073] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store programs.
[0074] The preferred embodiments of the present disclosure have been described above with reference to the accompanying drawings. This does not limit the scope of the rights of the embodiments of the present disclosure. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present disclosure shall be within the scope of the rights of the embodiments of the present disclosure.
Claims
1. A data interaction system for a passive Internet of Things terminal, characterized in that, The data interaction system of the passive Internet of Things terminal includes a passive Internet of Things terminal and a lightweight core network. The lightweight core network includes an access and mobility function module and a data management and authentication function module. The access and mobility function module includes an acquisition unit and a verification unit; The acquisition unit is configured to send a parsing request signal to the data management and authentication function module in response to a service request message sent by the passive Internet of Things terminal. The service request message includes a subscription concealment identifier and uplink service data; The data management and authentication function module is configured to parse the subscription concealment identifier in response to the parsing request signal to obtain a subscription permanent identifier, and send the subscription permanent identifier to the access and mobility function module. The parsing request signal includes the subscription concealment identifier; The verification unit is configured to obtain a corresponding user context according to the subscription permanent identifier, and verify the user context. If the verification is passed, the uplink service data is sent to an external data network.
2. The data interaction system of the passive Internet of Things terminal according to claim 1, characterized in that The access and mobility function module further includes a registration unit and an authentication unit; The registration unit is configured to send a first authentication request message to the data management and authentication function module and send an initial registration request message to the authentication unit in response to an initial registration request message initiated by the passive Internet of Things terminal; The data management and authentication function module is further configured to send a first authentication response message to the access and mobility function module in response to the first authentication request message. The first authentication response message includes a first authentication parameter; The authentication unit is configured to send an enhanced authentication request message to the passive Internet of Things terminal in response to the first authentication response message; and send a registration success signal to the passive Internet of Things terminal in response to an enhanced authentication response message returned by the passive Internet of Things terminal.
3. The data interaction system of the passive Internet of Things terminal according to claim 2, characterized in that, Specifically, the authentication unit is configured to: Determine the protection algorithm of the passive Internet of Things terminal according to the terminal security capability information in the initial registration request message; Generate a first integrity protection key according to the first base key of the first authentication parameter and the protection algorithm; Remove the first base key of the first authentication parameter to obtain a second authentication parameter; Package the protection algorithm, the terminal security capability information, and the second authentication parameter to obtain packaged data; Encode the packaged data by using the first integrity protection key to obtain a message authentication code; Obtain an enhanced authentication request message according to the message authentication code and the packaged data.
4. The data interaction system of the passive Internet of Things terminal according to claim 3, wherein, Specifically, the passive Internet of Things terminal is configured to: Verify the second authentication parameter in the enhanced authentication request message. If the verification is passed, obtain a second base key and a response value according to the second authentication parameter in the enhanced authentication request message; Process the second base key through the protection algorithm to obtain a second integrity protection key and an encryption key; Encrypt the initial registration request message by using the encryption key and the second integrity protection key to obtain a first registration request message; Using the second integrity protection key, verify the integrity of the enhanced authentication request information; If the verification of the integrity of the enhanced authentication request information passes, obtain the enhanced authentication response information according to the response value and the first registration request information.
5. The data interaction system of the passive Internet of Things terminal according to claim 4, wherein, The authentication unit is further configured to: Verify the response value, and if the verification passes, parse the first registration request information to obtain the second registration request information; According to the initial registration request information and the second registration request information, confirm whether the security context negotiation between the passive Internet of Things terminal and the lightweight core network is successful; If the negotiation is successful, send a registration success signal to the passive Internet of Things terminal.
6. The data interaction system of the passive Internet of Things terminal according to claim 1, characterized in that The access and mobility function module further includes a session establishment unit; The session establishment unit is configured to, in response to a session establishment request signal initiated by the passive Internet of Things terminal, allocate an IP address to the passive Internet of Things terminal and send session establishment reception information to the passive Internet of Things terminal, where the session establishment reception information includes the IP address.
7. The data interaction system of the passive Internet of Things terminal according to claim 6, characterized in that, The access and mobility function module further includes a data download unit; The data download unit is configured to obtain downlink service data, where the downlink service data includes an IP address; Determine the corresponding passive Internet of Things terminal according to the IP address; Send the downlink service data to the corresponding passive Internet of Things terminal.
8. A data interaction method for a passive Internet of Things terminal, characterized in that Include the following steps: In response to service request information sent by the passive Internet of Things terminal, send a parsing request signal to the data management and authentication function module, where the service request information includes a subscription hidden identifier and uplink service data; In response to the parsing request signal, parse the subscription hidden identifier to obtain a subscription permanent identifier, where the parsing request signal includes the subscription hidden identifier; According to the subscription permanent identifier, retrieve the corresponding user context, verify the user context, and if the verification passes, send the uplink service data to an external data network.
9. An electronic device, characterized in that, Include: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, enabling at least one of the processors to implement the data interaction method of the passive Internet of Things terminal as claimed in claim 8.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that, The program executable by the processor, when executed by the processor, implements the data interaction method of the passive Internet of Things terminal as claimed in claim 8.
Citation Information
Patent Citations
Method and system for testing non-access stratum authentication function conformance of narrow-band Internet-of-things terminal
CN107708150A
Terminal management method and device
CN116321083A
Lightweight Internet of Things equipment bidirectional authentication and secure communication method and system
CN117997516A
Passive Internet of Things terminal management method and device, communication system and storage medium
CN119316926A
Passive Internet of Things charging method, charging system, network device and storage medium
CN119562222A