Data interaction system, method, device and storage medium for passive Internet of Things terminal
Patent Information
- Application Number
- CN202510766017.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-06-10
Smart Images

Figure CN120343559B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet of Things technology, and in particular to a data interaction system, method, device and storage medium for a passive Internet of Things terminal. Background Art
[0002] As an emerging technology in the IoT field, the Ambient Internet of Things (Ambient IoT) boasts low power consumption and cost, ease of deployment, massive connectivity, and a rich array of typical application scenarios. As the IoT market continues to expand, the Ambient IoT industry is also experiencing rapid growth. An increasing number of companies are focusing on and investing in the research and development and application of Ambient IoT technology, driving continuous innovation in the technology and the growth of the industry.
[0003] Because Ambient IoT terminals primarily rely on energy harvesting from their surroundings—for example, by collecting light through solar panels, vibration energy through piezoelectric materials, or radio wave energy through RF antennas—they also rely on these limited energy resources to transmit and receive signals during data transmission. However, the 5G-Advanced IoT requires extensive signaling between the network side and terminals across all network elements, resulting in high power consumption for Ambient IoT terminals and a poor fit for their characteristics. Summary of the Invention
[0004] The main purpose of the embodiments of the present disclosure is to propose a data interaction system, method, device and storage medium for a passive Internet of Things terminal, aiming to reduce signaling interaction between the network side and the terminal and reduce the power consumption of the passive Internet of Things terminal.
[0005] To achieve the above objectives, one aspect of an embodiment of the present application provides a data interaction system for a passive Internet of Things terminal, the data interaction system for the passive Internet of Things terminal comprising a passive Internet of Things terminal and a lightweight core network, the lightweight core network comprising an access and mobility function module and a data management and authentication function module, the access and mobility function module comprising an acquisition unit and a verification unit;
[0006] The acquisition unit is configured to send a parsing request signal to the data management and authentication function module in response to the service request information sent by the passive Internet of Things terminal, wherein the service request information includes a subscription anonymity identifier and uplink service data;
[0007] The data management and authentication function module is configured to resolve the subscription anonymity identifier in response to the resolution request signal to obtain a subscription permanent identifier, and send the subscription permanent identifier to the access and mobility function module, wherein the resolution request signal includes the subscription anonymity identifier;
[0008] The verification unit is configured to obtain a corresponding user context according to the subscription permanent identifier, and verify the user context; if the verification passes, the uplink service data is sent to an external data network.
[0009] In some embodiments, the access and mobility function module further includes a registration unit and an authentication unit;
[0010] The registration unit is configured to send a first authentication request message to the data management and authentication function module in response to the initial registration request message initiated by the passive Internet of Things terminal, and send the initial registration request message to the authentication unit;
[0011] The data management and authentication function module is further configured to send a first authentication response message to the access and mobility function module in response to the first authentication request message, wherein the first authentication response message includes a first authentication parameter;
[0012] The authentication unit is configured to send enhanced authentication request information to the passive Internet of Things terminal in response to the first authentication response information; and send a registration success signal to the passive Internet of Things terminal in response to the enhanced authentication response information returned by the passive Internet of Things terminal.
[0013] In some embodiments, the authentication unit is specifically configured to:
[0014] Determining a protection algorithm for the passive Internet of Things terminal based on the terminal security capability information in the initial registration request information;
[0015] generating a first integrity protection key according to the first basic key of the first authentication parameter and the protection algorithm;
[0016] removing the first basic key from the first authentication parameter to obtain a second authentication parameter;
[0017] Encapsulating the protection algorithm, the terminal security capability information, and the second authentication parameter to obtain encapsulated data;
[0018] Encoding the encapsulated data using the first integrity protection key to obtain a message authentication code;
[0019] Enhanced authentication request information is obtained according to the message authentication code and the encapsulated data.
[0020] In some embodiments, the passive Internet of Things terminal is specifically used to:
[0021] Verifying the second authentication parameter in the enhanced authentication request information, and if the verification passes, obtaining a second basic key and a response value based on the second authentication parameter in the enhanced authentication request information;
[0022] Processing the second basic key using the protection algorithm to obtain a second integrity protection key and an encryption key;
[0023] Encrypting the initial registration request information using the encryption key and the second integrity protection key to obtain first registration request information;
[0024] Verifying the integrity of the enhanced authentication request information using the second integrity protection key;
[0025] If the integrity check of the enhanced authentication request information passes, the enhanced authentication response information is obtained according to the response value and the first registration request information.
[0026] In some embodiments, the authentication unit is further configured to:
[0027] Verifying the response value, and if the verification passes, parsing the first registration request information to obtain second registration request information;
[0028] Confirming, according to the initial registration request information and the second registration request information, whether the security context between the passive Internet of Things terminal and the lightweight core network is successfully negotiated;
[0029] If the negotiation is successful, a registration success signal is sent to the passive Internet of Things terminal.
[0030] In some embodiments, the access and mobility function module further includes a session establishment unit;
[0031] The session establishing unit is configured to allocate an IP address to the passive Internet of Things terminal in response to a session establishment request signal initiated by the passive Internet of Things terminal, and send session establishment reception information to the passive Internet of Things terminal, wherein the session establishment reception information includes the IP address.
[0032] In some embodiments, the access and mobility function module further includes a data sending unit;
[0033] The data sending unit is used to obtain downlink service data, wherein the downlink service data includes an IP address;
[0034] Determine the corresponding passive Internet of Things terminal according to the IP address;
[0035] The downlink service data is sent to the corresponding passive Internet of Things terminal.
[0036] On the other hand, an embodiment of the present invention provides a data interaction method for a passive Internet of Things terminal, comprising the following steps:
[0037] In response to the service request information sent by the passive Internet of Things terminal, sending a parsing request signal to the data management and authentication function module, wherein the service request information includes a subscription anonymity identifier and uplink service data;
[0038] Resolving the subscription anonymity identifier in response to the resolution request signal to obtain a subscription permanent identifier, wherein the resolution request signal includes the subscription anonymity identifier;
[0039] According to the subscription permanent identifier, a corresponding user context is retrieved, the user context is verified, and if the verification passes, the uplink service data is sent to an external data network.
[0040] In another aspect, an embodiment of the present invention provides an electronic device, including:
[0041] at least one processor;
[0042] at least one memory for storing at least one program;
[0043] When the at least one program is executed by the at least one processor, the at least one processor implements the data interaction method of the passive Internet of Things terminal as described in the previous embodiment.
[0044] On the other hand, an embodiment of the present invention further provides a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the data interaction method of the passive Internet of Things terminal as described in the previous embodiment.
[0045] The above technical solution of the present invention has at least one of the following advantages or beneficial effects:
[0046] The present application proposes a data interaction system, method, device and storage medium for a passive Internet of Things terminal. The system includes a passive Internet of Things terminal and a lightweight core network. The lightweight core network includes an access and mobility function module and a data management and authentication function module. The access and mobility function module includes an acquisition unit and a verification unit. After receiving service request information sent by the passive Internet of Things terminal, the acquisition unit sends a parsing request signal to the data management and authentication function module, wherein the service request information includes a subscription anonymity identifier and uplink service data. The data management and authentication function module receives the parsing request signal, parses the subscription anonymity identifier, obtains a subscription permanent identifier, and sends the subscription permanent identifier to the access and mobility function module. The verification unit obtains a corresponding user context based on the subscription permanent identifier and verifies the user context. If the verification passes, the uplink service data is sent to an external data network. In this application, the passive IoT terminal accesses the lightweight core network, and the service request information sent by the passive IoT terminal carries a subscription anonymity identifier, thereby reducing the Identity Request process initiated by the 5G core network due to the inability to find the user corresponding to the temporary identity ID, and reducing the signaling of the terminal to confirm the 5G-GUTI allocated by the network side, thereby reducing the signaling interaction between the network side and the terminal, reducing the power consumption of the passive IoT terminal, and meeting the business needs of the Ambient IoT terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 This is a flow chart of a data interaction method for a passive Internet of Things terminal provided in an embodiment of the present application;
[0048] Figure 2 This is a schematic diagram of the data interaction system structure of the passive Internet of Things terminal provided in an embodiment of the present application;
[0049] Figure 3 This is a schematic diagram of the data interaction system registration process for a passive Internet of Things terminal provided in an embodiment of the present application;
[0050] Figure 4 This is a schematic diagram of the process of establishing a data interaction system session for a passive Internet of Things terminal provided by an embodiment of the present application;
[0051] Figure 5 This is a schematic diagram of the service data receiving process of the data interaction system of the passive Internet of Things terminal provided in an embodiment of the present application;
[0052] Figure 6 This is a schematic diagram of the connection structure between the passive Internet of Things terminal and the core network provided in an embodiment of the present application;
[0053] Figure 7 This is a schematic diagram of the passive IoT terminal registration process provided by an embodiment of the present application;
[0054] Figure 8 This is a schematic diagram of the passive IoT terminal session establishment process provided by an embodiment of the present application;
[0055] Figure 9 This is a schematic diagram of the passive IoT terminal service data receiving and sending process provided by an embodiment of the present application;
[0056] Figure 10 This is a schematic diagram of the hardware structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0057] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0058] It should be noted that although the device schematics illustrate functional module divisions and the flowcharts illustrate logical sequences, in certain circumstances, the steps shown or described may be performed in a sequence that differs from the module divisions in the device or the sequence in the flowcharts. The terms "first," "second," and so on, in the specification, claims, and drawings, are used to distinguish similar items and are not necessarily used to describe a specific sequence or precedence.
[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0060] First, let’s analyze some of the terms used in this application:
[0061] 5G Core Network (5GC): refers to the core network of the fifth-generation mobile communication system. It is a new mobile network architecture that provides faster, more secure, and more reliable mobile communication services. The main feature of 5GC is its distributed architecture, which offers high scalability, reliability, and security. It can support a wider range of application services to meet the needs of diverse users. The 5GC network structure consists of a control layer and a data layer, with the control layer comprising a control plane and a user plane. 5GC applications mainly include smart homes, connected vehicles, the Internet of Things, smart manufacturing, and smart healthcare. It can provide more efficient, secure, and reliable mobile communication services, achieve intelligent, networked, data-driven, and service-oriented development, and promote the development and application of mobile communication technology.
[0062] The Internet of Things (IoT) refers to a network system that connects various physical devices, sensors, software, and networks through internet technology, enabling intelligent perception, data exchange, and collaborative control among devices. Its core concept is to empower connected objects, such as smart home appliances, wearable devices, and industrial machinery, through embedded technologies. By leveraging real-time data collection and analysis, IoT optimizes resource utilization, improves efficiency, and expands automation applications. The IoT is widely used in smart homes, smart cities, healthcare, agricultural monitoring, and Industry 4.0. It is reshaping how people interact with technology and the environment, driving the transformation of a digital society.
[0063] The data interaction system of the passive Internet of Things terminal in the embodiment of the present application includes a passive Internet of Things terminal and a lightweight core network. The lightweight core network is realized by optimizing the functions of the 5G core network, wherein the access and mobility function module in the lightweight core network is equivalent to the enhanced access and mobility management function network element (Enhanced Accessand Mobility Management Function, E-AMF) of the 5G core network, and the data management and authentication function module is equivalent to the unified data management function network element (Unified Data Management, UDM) and the authentication server function network element (Authentication Server Function, AUSF) of the 5G core network. The functional combination.
[0064] Please refer to Figure 2 , Figure 2 1 is a schematic diagram of the structure of a data interaction system for a passive IoT terminal provided in an embodiment of the present application. The data interaction system for a passive IoT terminal in an embodiment of the present application includes a passive IoT terminal and a lightweight core network. The lightweight core network includes an access and mobility function module and a data management and authentication function module. The access and mobility function module includes an acquisition unit and a verification unit.
[0065] The acquisition unit is configured to send a parsing request signal to the data management and authentication function module in response to service request information sent by the passive Internet of Things terminal, wherein the service request information includes a subscription anonymity identifier and uplink service data;
[0066] The data management and authentication function module is configured to resolve the subscription anonymity identifier in response to the resolution request signal to obtain the subscription permanent identifier and send the subscription permanent identifier to the access and mobility function module, wherein the resolution request signal includes the subscription anonymity identifier;
[0067] The verification unit is used to obtain the corresponding user context according to the subscription permanent identifier and verify the user context. If the verification passes, the uplink service data is sent to the external data network.
[0068] In this embodiment, passive IoT terminals refer to IoT devices that operate without an internal power supply. They obtain their operating energy through ambient energy harvesting and utilize low-power communication technologies for data transmission. These terminals typically have a simple structure and low cost, making them suitable for large-scale deployment scenarios. The lightweight core network is a highly integrated and optimized version of the existing 5G core network. The lightweight core network includes the Access and Mobility Functional Module (E-AMF) and the Data Management and Authentication Functional Module (UDM+AUSF). The lightweight core network consists of the E-AMF (enhanced AMF) and the UDM+AUSF. The E-AMF is responsible for terminal mobility management, parsing and constructing NAS messages for session management, and processing terminal service requests. The UDM+AUSF is responsible for access terminal identity authentication and basic key generation. The Access and Mobility Functional Module includes an acquisition unit and a verification unit.
[0069] After a passive IoT terminal accesses the lightweight core network and completes registration and establishes a session, it begins transmitting service data. When uploading uplink service data, the terminal sends a service request message to the acquisition unit in the access and mobility functional module. The service request message includes a Subscription Concealed Identifier (SUCI) and uplink service data. The SUCI is a user identity protection mechanism introduced in 5G mobile communications. It is a temporary identifier generated by encrypting the user's Subscription Permanent Identifier (SUPI) to enhance user privacy and network security. After receiving the service request information, the acquisition unit sends a resolution request signal to the data management and authentication function module (UDM+AUSF). After receiving the resolution request signal, the data management and authentication function module resolves the subscription anonymity identifier to obtain the subscription permanent identifier, and sends the subscription permanent identifier (SUPI) to the access and mobility function module. After the verification unit of the access and mobility function module obtains the SUPI, the verification unit uses the SUPI to find the corresponding user context. The user context includes but is not limited to user identity information, security information, and session status, and can be obtained during terminal registration and session establishment. The verification unit verifies whether the user context is complete. If the user context is complete, the verification passes, so that the uplink service data can be securely and completely uploaded to the external data network. The service request information sent by the passive IoT terminal carries a subscription anonymity identifier, reducing the IdentityRequest (identity authentication) process initiated by the 5G core network due to the inability to find the user corresponding to the temporary identity ID, and reducing the signaling required by the terminal to confirm the 5G-GUTI (5G Globally Unique Temporary Identifier) allocated by the network side. This can reduce the signaling interaction between the network side and the terminal, reduce the power consumption of the passive IoT terminal, and meet the business needs of the Ambient IoT terminal.
[0070] In some embodiments, the access and mobility function module further includes a registration unit and an authentication unit;
[0071] The registration unit is configured to send a first authentication request message to the data management and authentication function module in response to the initial registration request message initiated by the passive Internet of Things terminal, and send the initial registration request message to the authentication unit;
[0072] The data management and authentication function module is further configured to send a first authentication response message to the access and mobility function module in response to the first authentication request message, wherein the first authentication response message includes a first authentication parameter;
[0073] The authentication unit is configured to send enhanced authentication request information to the passive Internet of Things terminal in response to the first authentication response information; and send a registration success signal to the passive Internet of Things terminal in response to the enhanced authentication response information returned by the passive Internet of Things terminal.
[0074] Please refer to Figure 3 , Figure 3 This is a schematic diagram of the data interaction system registration process for a passive IoT terminal. In this embodiment, before a passive IoT terminal can transmit uplink or downlink data, it must first register and establish a session. During the registration process, the passive IoT terminal first sends an initial registration request message to the lightweight IoT. The initial registration request message includes the SUCI, 5GMM (5G Mobility Management) capabilities, and UE (terminal) security capability information. 5GMM capabilities are one of the core functions of the non-access stratum (NAS) in 5G networks, responsible for terminal registration, location updates, state handovers, and security context synchronization, enabling seamless handover and continuous service between different network nodes (base stations). UE (terminal) security capability information indicates a list of encryption and integrity algorithms supported by the terminal. After receiving the initial registration request message, the registration unit of the access and mobility function module sends a first authentication request message carrying the SUCI to the data management and authentication function module. The data management and authentication function module parses the SUCI reported by the terminal to obtain the user identity (SUPI), thereby verifying the legitimacy of the terminal identity and generating the first authentication parameter. Simultaneously, the registration unit sends the initial registration request message to the authentication unit. The data management and authentication function module will send the first authentication response information carrying the first authentication parameter to the access and mobility function module. After the authentication unit receives the first authentication response information, it can use the first authentication parameter and the terminal security capability information in the initial registration request information to perform identity authentication and establish a security context. The security context includes the basic key, encryption algorithm, integrity protection algorithm, etc. The authentication unit then sends the encryption algorithm, integrity protection algorithm, and authentication parameters selected by the network side based on the terminal security capability information to the terminal through an enhanced authentication request information. The passive Internet of Things terminal will return an enhanced authentication response information to the authentication unit based on the enhanced authentication request information. The authentication unit will determine whether the registration is successful based on the enhanced authentication response information. If the registration is successful, it will send a registration success signal to the passive Internet of Things terminal. The registration process is the first step for a passive Internet of Things terminal to access the core network. Its purpose is to complete identity reporting, capability negotiation, and initialization of security processes.
[0075] In some embodiments, the data management and authentication function module parses the SUCI in the first authentication request information to obtain the SUPI, and then uses the SUPI to generate Kseaf (a first basic key). Kseaf can serve as the basis for subsequently generating the first integrity protection key and the first encryption key.
[0076] In some embodiments, the authentication unit is specifically configured to:
[0077] Determining a protection algorithm for the passive Internet of Things terminal based on the terminal security capability information in the initial registration request information;
[0078] generating a first integrity protection key according to the first basic key of the first authentication parameter and the protection algorithm;
[0079] Removing the first basic key from the first authentication parameter to obtain a second authentication parameter;
[0080] Encapsulating the protection algorithm, the terminal security capability information, and the second authentication parameter to obtain encapsulated data;
[0081] Encoding the encapsulated data using the first integrity protection key to obtain a message authentication code;
[0082] According to the message authentication code and the encapsulated data, enhanced authentication request information is obtained.
[0083] In this embodiment, during the registration process of a passive IoT terminal, the authentication unit obtains an initial registration request message, which includes terminal security capability information. This information represents a list of supported protection algorithms. The authentication unit then selects an encryption algorithm and an integrity protection algorithm from the list of protection algorithms based on the specific situation. Subsequently, the terminal processes the base key based on the encryption and integrity protection algorithms selected by the network to generate a second encryption key and a second integrity protection key. After receiving the first authentication response message, the authentication unit processes the first base key in the first authentication parameters using the selected integrity protection algorithm to obtain the first integrity protection key, and then processes the first base key using the selected encryption algorithm to obtain the first encryption key. The first authentication parameters include the authentication vector, Kseaf (first base key), and SUPI information. The first base key is not sent to the terminal along with the enhanced authentication request message to prevent tampering during transmission, thereby improving security. The authentication unit uses the first integrity protection key to perform integrity protection on the enhanced authentication request message. Specifically, it encapsulates the protection algorithm, terminal security capability information, and the second authentication parameter to obtain encapsulated data. This encapsulated data is then encoded to obtain a message authentication code (MAC). The MAC and encapsulated data form the enhanced authentication request message, which is then transmitted to the passive IoT terminal. The MAC is used by the terminal to verify the integrity of the enhanced authentication request message. The enhanced authentication request message also includes a random number challenge value (RAND) and an authentication token (AUTN).
[0084] In some embodiments, the passive IoT terminal is specifically used to:
[0085] Verify the second authentication parameter in the enhanced authentication request information, and if the verification passes, obtain a second basic key and a response value based on the second authentication parameter in the enhanced authentication request information;
[0086] Processing the second basic key through a protection algorithm to obtain a second integrity protection key and an encryption key;
[0087] Encrypt the initial registration request information using the encryption key and the second integrity protection key to obtain first registration request information;
[0088] Verifying the integrity of the enhanced authentication request information using the second integrity protection key;
[0089] If the integrity check of the enhanced authentication request information passes, enhanced authentication response information is obtained according to the response value and the first registration request information.
[0090] In this embodiment, after receiving an enhanced authentication request, the passive IoT terminal first verifies the second authentication parameter. For example, it uses the authentication vector in the second authentication parameter, such as RAND (random challenge value) and AUTN (authentication token), to generate a message authentication code on the terminal side. The terminal's MAC is compared with the network's MAC. If they are identical, the verification succeeds. The terminal then uses the RAND and SUPI in the second authentication parameter to generate a second base key (Kseaf) and a response value (Res value). The terminal and network independently generate the same Kseaf, meaning the first and second base keys are identical. Based on the same Kseaf and protection algorithm, the terminal and E-AMF independently derive the same integrity protection key and encryption key, ensuring consistent encryption and integrity protection for subsequent communications on the terminal and network sides. Furthermore, before generating the second integrity protection key and encryption key, the terminal verifies whether the protection algorithm selected by the network is present in the terminal's security capability information. If not, this indicates that the enhanced authentication request was tampered with during transmission. The terminal will then refuse to connect to the core network and terminate subsequent actions. The terminal encrypts the initial registration request message using the encryption key and then protects it with the second integrity protection key to obtain the first registration request message. The terminal can use the second integrity protection key to verify the integrity of the enhanced authentication request message. If the verification passes, it indicates that the message has not been tampered with during transmission. The terminal then returns the Res value and the first registration request message to the core network in an enhanced authentication response message.
[0091] In some embodiments, the authentication unit is further configured to:
[0092] Verify the response value. If the verification passes, parse the first registration request information to obtain the second registration request information.
[0093] Confirm whether the security context negotiation between the passive IoT terminal and the lightweight core network is successful based on the initial registration request information and the second registration request information;
[0094] If the negotiation is successful, a registration success signal is sent to the passive IoT terminal.
[0095] In this embodiment, after receiving the enhanced authentication response, the authentication unit first verifies the response value. For example, it compares the expected response value pre-calculated by the network with the response value. If the two values match, verification succeeds. The encrypted first registration request is then parsed to obtain a second registration request. The second registration request matches the initial registration request, indicating that the keys generated by the terminal and the network are consistent, indicating a successful security context negotiation. The initial registration request carries the SUCI, quickly establishing a connection between the terminal and the lightweight core network and conducting security context negotiation. After security context negotiation is complete, the initial registration request is encrypted and integrity-protected, and the first registration request is resent to confirm the security context is in effect. Encryption and integrity protection ensure communication security by preventing tampering and eavesdropping. The E-AMF sends a Register Accept signal to the terminal without assigning a temporary identity ID. The terminal does not need to respond with a Register Complete signal, thus reducing signaling interactions.
[0096] In some embodiments, the access and mobility function module further includes a session establishment unit;
[0097] The session establishment unit is used to allocate an IP address to the passive Internet of Things terminal in response to a session establishment request signal initiated by the passive Internet of Things terminal, and send session establishment reception information to the passive Internet of Things terminal, wherein the session establishment reception information includes the IP address.
[0098] Please refer to Figure 4 , Figure 4 This figure illustrates the process for establishing a data interaction system session for a passive IoT terminal. In this embodiment, after a terminal completes registration, the session establishment process begins. The passive IoT terminal first initiates a session establishment request signal, which carries information such as the PDU (Protocol Data Unit) session type and DNN (Data Network Name). Upon receiving the session establishment request signal, the E-AMF assigns an IP address to the passive IoT terminal and returns a PDU session establishment receipt message containing information such as QoS rules and QoS flow descriptions. The E-AMF does not construct an N2 message related to the PDU Session Resource to be sent to the base station, thereby further optimizing signaling.
[0099] In some embodiments, the access and mobility function module further includes a data sending unit;
[0100] The data sending unit is used to obtain downlink service data, wherein the downlink service data includes an IP address;
[0101] Determine the corresponding passive IoT terminal based on the IP address;
[0102] Send downlink business data to the corresponding passive IoT terminal.
[0103] Please refer to Figure 5 , Figure 5 This diagram illustrates the service data reception process for a data interaction system in a passive IoT terminal. In this embodiment, an external data network sends downlink service data to the lightweight core network. The data delivery unit in the E-AMF obtains the downlink service data and, based on the IP address in the downlink service data, searches the corresponding user context. The user context includes information such as the security context, PDU Session ID, and SUPI, which can be used to identify the corresponding passive IoT terminal. The data delivery unit encapsulates the PDU Session ID and downlink service data and encrypts and integrity-protects the encapsulated data using the key information in the security context, resulting in a DL (downlink) NAS transport message. NAS (Non-Access Stratum) is the control plane protocol between the terminal (UE) and the core network, responsible for handling higher-layer signaling interactions unrelated to radio access. Upon receiving the DL NAS transport message, the terminal can decrypt and verify the integrity of the message using the negotiated security context, thereby obtaining the downlink service data.
[0104] Please refer to Figure 1 , Figure 1 This is an optional flow chart of a data interaction method for a passive Internet of Things terminal provided in some embodiments of the present application. A data interaction method for a passive Internet of Things terminal in an embodiment of the present invention includes but is not limited to steps S100 to S300:
[0105] Step S100, in response to the service request information sent by the passive IoT terminal, sending a parsing request signal to the data management and authentication function module, wherein the service request information includes a subscription anonymity identifier and uplink service data;
[0106] Step S200: In response to a resolution request signal, the subscription anonymity identifier is resolved to obtain a subscription permanent identifier, wherein the resolution request signal includes the subscription anonymity identifier;
[0107] Step S300: retrieve the corresponding user context according to the subscription permanent identifier, verify the user context, and if the verification passes, send the uplink service data to the external data network.
[0108] The data interaction method for a passive IoT terminal provided in the embodiments of the present application can be applied to the terminal, can be applied to the server side, and can also be software running on the terminal or the server side. In some embodiments, the terminal can be a smart phone, tablet computer, laptop computer, desktop computer, etc.; the server side can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements a digital management method for indoor items, etc., but is not limited to the above forms.
[0109] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.
[0110] In some embodiments, please refer to Figure 6 , Figure 6This diagram illustrates the connection structure between a passive IoT terminal and the core network. Specifically, an Ambient IoT terminal accesses the core network through the RAN. The core network consists of the Enhanced AMF (E-AMF) and the UDM+AUSF. The E-AMF is responsible for terminal mobility management, parsing and constructing NAS messages for session management, and processing terminal service requests. Ambient IoT services typically transmit only essential device status and sensor data, with minimal data volume. To reduce air interface resource scheduling and usage and lower energy consumption for Ambient IoT terminals, the lightweight core network does not construct N2 messages related to PDU Session Resources for Ambient IoT terminals during PDU session establishment. After terminal registration and PDU session establishment are complete, uplink and downlink data packets are encapsulated and sent and received using NAS messages. The E-AMF is responsible for interfacing service data with the DN. The UDM+AUSF in the core network is responsible for access terminal authentication and basic key generation.
[0111] In some embodiments, please refer to Figure 7 , Figure 7 This is a diagram of the registration process for a passive IoT terminal. First, the terminal initiates a Register Request message (initial registration request information), which contains SUCI, 5GMM capabilities, and UE security capability information.
[0112] The E-AMF sends a Nausf_UEAuthRequest message (first authentication request information) to the UDM+AUSF, requesting authentication parameters from the UDM+AUSF.
[0113] The UDM+AUSF returns a Nausf_UEAuthResponse message (first authentication response message) to the E-AMF, which contains the authentication vector, Kseaf, and SUPI information. Security between the E-AMF and the UDM+AUSF is protected by inter-network element authentication.
[0114] The E-AMF generates security and encryption keys based on Kseaf and sends an E-AuthRequest message (enhanced authentication request) to the terminal. The E-AuthRequest message contains RAND, AUTN, UE security capability information, and the selected algorithm (protection algorithm). This message uses the new security key for completeness protection. This process not only authenticates the identity but also negotiates the security context.
[0115] After receiving the E-AuthRequest message, the terminal verifies the authentication parameters in the message. If the verification passes, it generates the Kseaf and Res values. It then verifies the UE's security capabilities and, based on the algorithm selected by the network, generates a security key and an encryption key. The integrity of the E-AuthRequest message is verified using the security key. If the integrity check passes, the generated Res value is returned to the core network via an E-AuthResponse message (enhanced authentication response). The E-AuthResponse message is secured using the new security algorithm and contains the completed, fully encrypted Register Request message (initial registration request).
[0116] After receiving the E-AuthResponse message, the E-AMF first verifies the Res value in the message. If the Res value verification passes, it examines the fully encrypted Register Request message carried in the message. If the parsing passes, the new security context negotiation is considered successful. The E-AMF sends a Register Accept message (registration success signal) to the terminal, but does not allocate a temporary identity ID. The terminal does not need to respond with a Register Complete message.
[0117] In some implementations, see Figure 8 , Figure 8 This diagram illustrates the session establishment process for a passive IoT terminal. Specifically, the terminal initiates a PDU session establishment request message, the PduSessionEstRequest message (session establishment request signal), which carries information such as the PDU session type and DNN. Upon receiving the PDU session establishment request message, the E-AMF allocates an IP address and returns a PDU session establishment acceptance message, the PduSessionEstAccept message (session establishment acceptance information), to the terminal. The PDU session establishment acceptance message contains information such as the QoS Rule and QoS flow descriptions. The E-AMF no longer constructs the N2 message related to the PduSession Resource to be sent to the base station.
[0118] In some embodiments, please refer to Figure 9 , Figure 9 This diagram illustrates the process of sending and receiving service data from a passive IoT terminal. Specifically, the Ambient IoT sends a Control Plane Service Request message, which carries the SUCI, PDU Session ID, and encapsulated service data. This message is integrity-protected using the current security context.
[0119] The E-AMF sends the newly added N12 / N8 interface message Nausf_SupiDecRequest (resolution request signal) to the UDM / AUSF, requesting the UDM / AUSF to resolve the SUCI. Security between the E-AMF and UDM+AUSF is ensured by inter-network element authentication.
[0120] UDM+AUSF returns the parsed SUPI to E-AMF through the Nausf_SupiDecRequest message.
[0121] The E-AMF finds the corresponding user context based on the SUPI and verifies its integrity. If the verification passes, it extracts the uplink service data from the ControlPlane Service Request message and sends it to the DN.
[0122] When there is downlink service data on the DN side, after receiving the downlink service data, the E-AMF finds the corresponding user context according to the target IP in the downlink service data, constructs a DL NAS transport message, and sends the DL NAS transport message to the terminal, which includes the Pdu Session Id and downlink service data.
[0123] This embodiment, based on the existing 5G core network and addressing the energy constraints of passive terminals, adapts to the passive IoT scenario and presents a lightweight core network design and architecture solution, as well as a method for Ambient IoT to access this network. The lightweight core network aggregates existing session management functions and designs an enhanced AMF, without integrating the existing SMF and UPF. This clarifies the network architecture and reduces network construction costs while ensuring the normal operation of the passive IoT.
[0124] In this embodiment, the method for accessing a lightweight core network for an Ambient IoT terminal plans to carry user IDs, integrates authentication and SMC functions, optimizes registration, PDU session establishment, and CP Service processes, reduces signaling interactions between the terminal and the network, and meets the service needs of the Ambient IoT terminal.
[0125] In some embodiments, Ambient IoT terminals access a lightweight core network, and signaling optimization is reflected in:
[0126] 1. The network side no longer allocates temporary identity IDs (5G-GUTIs). Initial signaling initiated by the terminal in idle state carries SUCI. This reduces the number of Identity Request processes initiated by the core network due to the inability to find the user corresponding to the temporary identity ID, and reduces the signaling required by the terminal to confirm the 5G-GUTI allocated by the network side. To support SUCI decryption in non-authentication processes, E-AMF and UDM+AUSF need to perform enhancements on the original N12 / N8 interfaces.
[0127] 2. Optimize the original AUTH / SMC process to reduce the signaling interaction between the network side and the terminal.
[0128] 3. During the PDU session establishment process, the base station is not notified to apply for N2 resources.
[0129] While ensuring secure access for Ambient IoT devices, this embodiment designs a lightweight core network that highly integrates and optimizes network functions, reducing network equipment costs and facilitating large-scale deployment. Furthermore, considering the energy constraints of Ambient IoT devices and the relatively small volume of Ambient IoT service data, the optimized transmission process minimizes signaling interactions between terminals and the network. A minimalist mode ensures necessary data transmission, enabling fast and accurate data transmission under energy-constrained conditions and meeting the information transmission requirements of diverse application scenarios.
[0130] The following combination Figure 10 The electronic device according to the embodiment of the present application is introduced in detail.
[0131] like Figure 10 , Figure 10 The hardware structure of an electronic device according to another embodiment is shown. The electronic device includes:
[0132] The processor 1100 may be implemented as a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present disclosure.
[0133] The memory 1200 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1200 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1200 and is called by the processor 1100 to execute the data interaction method for the passive Internet of Things terminal of the embodiments of this disclosure.
[0134] Input / output interface 1300, used for information input and output;
[0135] Communication interface 1400, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0136] Bus 1500 , which transmits information between various components of the device (e.g., processor 1100 , memory 1200 , input / output interface 1300 , and communication interface 1400 );
[0137] The processor 1100 , the memory 1200 , the input / output interface 1300 , and the communication interface 1400 are communicatively connected to each other within the device via a bus 1500 .
[0138] An embodiment of the present disclosure further provides a storage medium, which is a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions, which are used to enable a computer to execute the above-mentioned data interaction method for the passive Internet of Things terminal.
[0139] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device or other non-transient solid-state storage device. In some embodiments, the memory may include a memory remotely located relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0140] The embodiments described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0141] Those skilled in the art will understand that the technical solutions shown in the drawings do not constitute a limitation on the embodiments of the present disclosure, and may include more or fewer steps than shown in the drawings, or a combination of certain steps, or different steps.
[0142] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0143] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.
[0144] The terms "first," "second," "third," "fourth," and the like (if any) in the specification of the present application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in orders other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such process, method, product, or apparatus.
[0145] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0146] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0147] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0148] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for enabling an electronic device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store programs, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.
[0149] The preferred embodiments of the present disclosure are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present disclosure. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present disclosure should be within the scope of the present disclosure.
Claims
1. A data interaction system for a passive Internet of Things terminal, characterized in that: The data interaction system of the passive Internet of Things terminal includes a passive Internet of Things terminal and a lightweight core network, the lightweight core network includes an access and mobility function module and a data management and authentication function module, and the access and mobility function module includes an acquisition unit and a verification unit; The acquisition unit is configured to send a parsing request signal to the data management and authentication function module in response to the service request information sent by the passive Internet of Things terminal, wherein the service request information includes a subscription anonymity identifier and uplink service data; The data management and authentication function module is configured to resolve the subscription anonymity identifier in response to the resolution request signal to obtain a subscription permanent identifier, and send the subscription permanent identifier to the access and mobility function module, wherein the resolution request signal includes the subscription anonymity identifier; The verification unit is configured to obtain a corresponding user context according to the subscription permanent identifier, and verify the user context. If the verification passes, the uplink service data is sent to an external data network; The access and mobility function module also includes a registration unit and an authentication unit; The registration unit is configured to send a first authentication request message to the data management and authentication function module in response to the initial registration request message initiated by the passive Internet of Things terminal, and send the initial registration request message to the authentication unit; The data management and authentication function module is further configured to send a first authentication response message to the access and mobility function module in response to the first authentication request message, wherein the first authentication response message includes a first authentication parameter; The authentication unit is configured to send an enhanced authentication request message to the passive Internet of Things terminal in response to the first authentication response message; and send a registration success signal to the passive Internet of Things terminal in response to the enhanced authentication response message returned by the passive Internet of Things terminal; The authentication unit is specifically used for: Determining a protection algorithm for the passive Internet of Things terminal based on the terminal security capability information in the initial registration request information; generating a first integrity protection key according to the first basic key of the first authentication parameter and the protection algorithm; removing the first basic key from the first authentication parameter to obtain a second authentication parameter; Encapsulating the protection algorithm, the terminal security capability information, and the second authentication parameter to obtain encapsulated data; Encoding the encapsulated data using the first integrity protection key to obtain a message authentication code; Enhanced authentication request information is obtained according to the message authentication code and the encapsulated data.
2. The data interaction system of the passive Internet of Things terminal according to claim 1, characterized in that: The passive Internet of Things terminal is specifically used for: Verifying the second authentication parameter in the enhanced authentication request information, and if the verification passes, obtaining a second basic key and a response value based on the second authentication parameter in the enhanced authentication request information; Processing the second basic key using the protection algorithm to obtain a second integrity protection key and an encryption key; Encrypting the initial registration request information using the encryption key and the second integrity protection key to obtain first registration request information; Verifying the integrity of the enhanced authentication request information using the second integrity protection key; If the integrity check of the enhanced authentication request information passes, the enhanced authentication response information is obtained according to the response value and the first registration request information.
3. The data interaction system of the passive Internet of Things terminal according to claim 2, characterized in that: The authentication unit is further configured to: Verifying the response value, and if the verification passes, parsing the first registration request information to obtain second registration request information; Confirming, according to the initial registration request information and the second registration request information, whether the security context between the passive Internet of Things terminal and the lightweight core network is successfully negotiated; If the negotiation is successful, a registration success signal is sent to the passive Internet of Things terminal.
4. The data interaction system of the passive Internet of Things terminal according to claim 1, characterized in that: The access and mobility function module also includes a session establishment unit; The session establishing unit is configured to allocate an IP address to the passive Internet of Things terminal in response to a session establishment request signal initiated by the passive Internet of Things terminal, and send session establishment reception information to the passive Internet of Things terminal, wherein the session establishment reception information includes the IP address.
5. The data interaction system of the passive Internet of Things terminal according to claim 4 is characterized in that: The access and mobility function module also includes a data sending unit; The data sending unit is used to obtain downlink service data, wherein the downlink service data includes an IP address; Determine the corresponding passive Internet of Things terminal according to the IP address; The downlink service data is sent to the corresponding passive Internet of Things terminal.
6. A data interaction method for a passive Internet of Things terminal, characterized in that: The method is applied to the data interaction system of the passive Internet of Things terminal according to any one of claims 1 to 5, and the method comprises the following steps: In response to the service request information sent by the passive Internet of Things terminal, sending a parsing request signal to the data management and authentication function module, wherein the service request information includes a subscription anonymity identifier and uplink service data; Resolving the subscription anonymity identifier in response to the resolution request signal to obtain a subscription permanent identifier, wherein the resolution request signal includes the subscription anonymity identifier; According to the subscription permanent identifier, a corresponding user context is retrieved, the user context is verified, and if the verification passes, the uplink service data is sent to an external data network.
7. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the data interaction method for the passive Internet of Things terminal as described in claim 6.
8. A computer-readable storage medium storing a program executable by a processor, characterized in that: When the program executable by the processor is executed by the processor, the data interaction method of the passive Internet of Things terminal as claimed in claim 6 is implemented.
Citation Information
Patent Citations
Passive Internet of Things charging method, charging system, network device and storage medium
CN119562222A
IP address assignment method, device, and readable storage medium
WO2023143412A1