Communication method and related device
By utilizing identification information obfuscation and temporary identification substitution in environmental IoT, the privacy leakage problem in reader-terminal communication is solved, communication security is improved, and attackers are prevented from obtaining the permanent identification of the target terminal.
Patent Information
- Application Number
- CN202410601504.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-11
- Publication Date
- 2025-11-11
AI Technical Summary
In the Internet of Things (IoT) of the environment, there is a risk of privacy leakage during the communication between the reader and the terminal, and existing technologies are insufficient to effectively improve communication security.
When the number of target terminal devices is less than or equal to a threshold, the reader broadcasts identification information corresponding to multiple terminal devices. This information obscures the relationship between the target terminal and other terminal devices, preventing attackers from obtaining the permanent identification of the target terminal. Instead, a temporary identification is used to replace the permanent identification or the identification information is encrypted.
It effectively avoids privacy leaks, improves the communication security between the reader and the terminal, and prevents attackers from determining the permanent identifier of the target terminal.
Smart Images

Figure CN120935557A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to a communication method and related apparatus. Background Technology
[0002] Ambient Internet of Things (AIoT), a low-power passive IoT technology, is currently widely used in scenarios such as warehousing, transportation, and fixed asset management. When an AIoT reader communicates with a terminal, the reader broadcasts a request message within its recognition range, triggering the target terminal to randomly connect and thus enabling data interaction.
[0003] However, there is a risk of privacy leakage during the communication between the reader and the terminal. How to improve the communication security of AIoT is an urgent technical problem to be solved. Summary of the Invention
[0004] This application provides a communication method and related apparatus, which aim to improve the security of communication and interaction between the reader and the terminal device and avoid privacy leakage.
[0005] In a first aspect, this application provides a communication method applied to a first device, the method comprising:
[0006] Receive a first request message, which is used to request an inventory operation and / or command operation on the target terminal device; send a second request message, which contains first identification information when the number of target terminal devices is less than or equal to a first threshold. The first identification information corresponds to multiple terminal devices, and the multiple terminal devices include the target terminal device and the number of multiple terminal devices is greater than the first threshold.
[0007] The first device can be a core network element, a reader, or a network element device with the same function as a reader. When the first device sends the second request message, the first identification information contained therein corresponds to multiple terminal devices. Therefore, when the first identification information is broadcast in the subsequent communication process, the attacker cannot determine the permanent identification information of the target terminal device based on the first identification information. That is, the target terminal device is confused with other terminal devices among the multiple terminal devices, thereby avoiding privacy leakage.
[0008] In some implementations, the quantity indicated by the first threshold above is one.
[0009] In some implementations, the first identification information is the group identification information of the first terminal group, and the first terminal group includes the target terminal device.
[0010] In some implementations, the first identification information includes at least one identifier from the permanent identity identifier of the target terminal device, and the permanent identity identifier of at least one other terminal device among the multiple terminal devices includes at least one identifier from the permanent identity identifier of the target terminal device; or, the first identification information includes mask information, and the mask information corresponds to multiple terminal devices.
[0011] When the first identification information is a one-to-many identification information, it can prevent attackers from obtaining the permanent identification information of the target terminal device through the first identification information, thus avoiding privacy leakage.
[0012] In some implementations, the first identification information includes multiple second identification information, and one of the multiple second identification information is the permanent identification information of the target terminal device.
[0013] In some implementations, the method further includes the following before sending the second request message:
[0014] When the number of target terminal devices is less than or equal to the first threshold, a third request message is sent to the data management network element. The third request message is used to request multiple second identification information. The first indication information is received, which indicates multiple second identification information.
[0015] When the first identification information includes multiple second identification information, each of the multiple second identification information corresponds to a different terminal device. The permanent identification information of the target terminal device has the same format as the permanent identification information of the other terminal devices, making it impossible for an attacker to obtain the identification information of the target terminal device through the first identification information.
[0016] In some implementations, multiple second identification information includes virtual identification information.
[0017] When the second identification information is virtual identification information, since the terminal device corresponding to the virtual identification information is a virtual terminal device, only the target terminal device initiates random access in the subsequent communication process, thus avoiding communication interference from non-target terminal devices.
[0018] In some implementations, the third request message contains a number of second identification information.
[0019] In some implementations, the temporary identification information of the target terminal device is unavailable, and / or the target terminal device supports permanent identification encryption.
[0020] In some implementations, the first device is a core network element, and the method also includes:
[0021] Receive third identification information, which corresponds to the first terminal device; when the first terminal device is not the target terminal device, send a fourth request message to the second device or the first terminal device, which is used to request the release of the connection between the second device and the first terminal device.
[0022] Core network elements determine whether a device is a target terminal device by using the identification information reported by the terminal device, and release non-target terminal devices to avoid communication interference from non-target terminal devices.
[0023] Secondly, this application provides a communication method applied to a core network element, the method comprising:
[0024] The system receives a first request message, which is used to request an inventory operation and / or command operation on the target terminal device; it sends a second request message to the communication device, wherein when the number of target terminal devices is less than or equal to a first threshold, the second request message contains fourth identification information, which contains at least one temporary identification information among multiple temporary identification information stored in the target terminal device.
[0025] When a core network element sends a second request message to a communication device, the fourth identification information contained therein includes temporary identification information of the target terminal device. The temporary identification information can be used to replace the permanent identification information of the target terminal device to prevent attackers from obtaining the permanent identification information of the target terminal device, thereby avoiding privacy leakage.
[0026] In some implementations, the quantity indicated by the first threshold above is one.
[0027] In some implementations, the fourth identification information includes temporary identification information that will be used for the first time.
[0028] In some implementations, the method also includes:
[0029] The fourth identification information is marked as a temporary identification information that has already been used.
[0030] Each time temporary identification information is used, the first used temporary identification information is used as the fourth identification information, thereby avoiding information leakage due to repeated use of temporary identification information. After the target terminal device reports identification information, the core network element can mark the fourth identification information as the used temporary identification information. The above marking operation can be triggered when the target terminal device first accesses the network, or it can be triggered during subsequent accesses.
[0031] In some implementations, the method also includes:
[0032] When the number of unused temporary identification information among the multiple temporary identification information stored by the target terminal device is less than or equal to the second threshold, a fifth request message is sent to the target terminal device. The fifth request message is used to request the writing of at least one fifth identification information, which is a temporary identification information allocated by the core network element to the target terminal device.
[0033] Core network elements can configure new temporary identifier information for target terminal devices through the fifth request message, which can avoid the repeated reuse of temporary identifier information due to the consumption of multiple pre-configured temporary identifier information and improve communication security.
[0034] Thirdly, this application provides a communication device, including modules or units for implementing the methods of the first aspect and any possible implementation thereof, or including modules for implementing the methods of the second aspect and any possible implementation thereof. Each module or unit can implement its corresponding function by executing a computer program.
[0035] Fourthly, this application provides a communication device, including a processor, which is configured to execute the communication method in the first aspect and any possible implementation of the first aspect, or to execute the communication method in the second aspect and any possible implementation of the second aspect.
[0036] Optionally, the apparatus may further include a memory for storing instructions and data. The memory is coupled to a processor, which, when executing the instructions stored in the memory, can implement the methods described in the foregoing aspects.
[0037] Optionally, the device may also include a communication interface for communicating with other communication devices. For example, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0038] For example, the communication device provided in the fourth aspect is a chip or chip system.
[0039] Fifthly, this application provides a communication device, including a processor and a communication interface. The communication interface is used to receive signals from other communication devices besides the communication device described in the fifth aspect and transmit them to the processor, or to send signals from the processor to other communication devices besides the communication device. The processor implements the communication method in the first aspect and any possible implementation of the first aspect through logic circuits or executing code instructions, or implements the communication method in the second aspect and any possible implementation of the second aspect. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0040] Optionally, the apparatus further includes a memory for storing instructions and data. The memory is coupled to a processor, and when the processor executes the instructions stored in the memory, it can implement the communication method of the first aspect and any possible implementation thereof, or implement the communication method of the second aspect and any possible implementation thereof.
[0041] In a sixth aspect, this application provides a communication device, including a processor and a memory, wherein the memory is used to store instructions and data, and when the processor executes the instructions stored in the memory, it can implement the communication method in the first aspect and any possible implementation of the first aspect, or implement the communication method in the second aspect and any possible implementation of the second aspect.
[0042] Optionally, the device further includes a communication interface for communicating with other communication devices. For example, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0043] In a seventh aspect, this application provides a chip system including at least one processor for supporting the implementation of the functions involved in the first aspect and any possible implementation of the first aspect, or for supporting the implementation of the functions involved in the second aspect and any possible implementation of the second aspect, such as receiving or processing data and / or information involved in the above methods.
[0044] In one possible design, the chip system also includes a memory for storing program instructions and data, which may be located inside or outside the processor.
[0045] The chip system can consist of chips or include chips and other discrete components.
[0046] Eighthly, this application provides a computer-readable storage medium including a computer program that, when run on a computer, causes the computer to implement the methods of the first or second aspect and any possible implementation of the first or second aspect.
[0047] Ninthly, this application provides a computer program product comprising: a computer program (also referred to as code or instructions) that, when run, causes a computer to perform the methods of the first or second aspect and any possible implementation thereof.
[0048] The third to ninth aspects of this application correspond to the technical solutions of the first and second aspects of this application. The beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be described again. Attached Figure Description
[0049] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0050] Figure 1 This is a schematic diagram of the Internet of Things (IoT) architecture used in the embodiments of this application;
[0051] Figure 2 A schematic diagram illustrating the communication process between a reader and a terminal under the AIoT architecture;
[0052] Figure 3 A flowchart illustrating a communication method provided in one embodiment of this application;
[0053] Figure 4 A flowchart illustrating a communication method provided in one embodiment of this application;
[0054] Figure 5 A flowchart illustrating a communication method provided in one embodiment of this application;
[0055] Figure 6 A flowchart illustrating a communication method provided in another embodiment of this application;
[0056] Figure 7 A schematic block diagram of a communication device provided in one embodiment of this application;
[0057] Figure 8 This is a schematic diagram of the structure of a communication device provided in another embodiment of this application.
[0058] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0059] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0060] It should be understood that in this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the preceding and following related objects, but does not exclude the possibility of indicating an "and" relationship; the specific meaning can be understood in context. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c; a and b; a and c; b and c; or a and b and c. Here, a, b, and c can be single or multiple.
[0061] In this application, the use of prefixes such as "first" and "second" is merely for the purpose of distinguishing and describing different things belonging to the same category, and does not constrain the order, size, or quantity of things. For example, "first parameter" and "second parameter" are simply different parameters, and there is no temporal or quantitative relationship between them.
[0062] This application will present various aspects, embodiments, or features relating to systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that individual systems may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these approaches are also possible.
[0063] Furthermore, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design scheme described as an "example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the term "example" is intended to present concepts in a concrete manner. In the embodiments of this application, "of," "corresponding, relevant," and "corresponding" may sometimes be used interchangeably, and it should be noted that their intended meanings are consistent unless their distinction is emphasized.
[0064] Ambient Internet of Things (AIoT), as an infrastructure based on cellular network communication, is also known as Passive Internet of Things (P-IoT). Figure 1 This is a schematic diagram of the Internet of Things (IoT) architecture used in the embodiments of this application. Figure 1As shown, the AIoT architecture can include terminals, readers, and servers.
[0065] Among them, the terminal can be a terminal device in Internet of Things (IoT) technology, including but not limited to passive terminal devices, semi-passive terminal devices, semi-active terminal devices, active terminal devices, low-power terminal devices, zero-power terminal devices, passive terminal devices, and active terminal devices.
[0066] Terminal equipment can also be called user equipment (UE), equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device. Beyond the Internet of Things (IoT), terminal equipment can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminal devices can be cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in 5G networks, and terminal devices in future evolved public land mobile networks (PLMNs) or non-terrestrial networks (NTNs). Terminal devices can also be end devices, logical entities, smart devices, such as mobile phones, smart terminals, or communication devices such as servers, gateways, base stations, and controllers, or IoT devices such as tags (e.g., passive tags, active tags, semi-active tags, semi-passive tags), sensors, electricity meters, and water meters. Terminal devices can also be unmanned aerial vehicles (UAVs) with communication capabilities.
[0067] It is understood that when a terminal device is a passive terminal, a semi-passive terminal, a semi-active terminal, an active terminal, or a tag, it can receive or transmit data by acquiring energy such as solar, radio frequency, wind, hydro, or tidal energy. The terminal in the AIoT architecture involved in this application can be in the form of a tag or any of the above-mentioned terminal forms.
[0068] A reader enables contactless, two-way data communication via radio frequency (RF) to establish a connection with a terminal. Readers can be access network devices, specifically base stations, pole-mounted stations, indoor base stations (e.g., lamps), home base stations (e.g., home NBs), micro base stations, integrated access and backhaul (IAB) nodes, mobile base stations, radio access networks, radio access network equipment, evolved NodeBs (eNodeBs) in long-term evolution (LTE) systems or evolved LTE-Advanced (LTE-A) systems, next-generation NodeBs (gNBs) in 5G communication systems, transmission reception points (TRPs), base band units (BBUs), WiFi access points (APs), and base stations or access nodes in future mobile communication systems or WiFi systems. Access network equipment can also be modules or units that perform some of the functions of a base station; for example, it can be a central unit (CU) or a distributed unit (DU). This application does not limit the specific technology or device form used in the access network equipment.
[0069] For example, in a network architecture, the access network equipment can be a CU node, a DU node, or an access network equipment including both CU and DU nodes. Specifically, CU nodes are used to support protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP); DU nodes are used to support radio link control (RLC) layer protocols, medium access control (MAC) layer protocols, and physical layer protocols.
[0070] In one possible scenario, Figure 1 The reader shown can also be the terminal device mentioned above, which will not be described in detail here.
[0071] The server can be a core network device, which includes one or more of the following network elements:
[0072] The access management network element (also known as the access management network element, mobility management network element, or access and mobility management network element) is a control plane network element provided by the operator's network. It is responsible for access control and mobility management of terminal equipment accessing the operator's network, including functions such as mobility state management, allocation of temporary user identities, authentication, and user management. In 5G communication systems, this access management network element can be an access and mobility management function (AMF) network element. In future communication systems, the access management network element can still be an AMF network element, or it can have other names; this application does not limit its scope.
[0073] An AIoT network function (AIoT NF) is used for access control and management of AIoT devices. It should be noted that an AIoT NF can be an independent network element or a logical network element within the core network equipment. For example, an AIoT NF can be co-located with an AMF; this application does not impose any limitations on this.
[0074] Network open elements are control plane network elements provided by operators. They securely expose the operator's network to third parties, providing access to services and capabilities offered by 3GPP (3rd Generation Partnership Project) network function equipment. For example, when a session management network element needs to communicate with a third-party network element, the network open element can act as a relay. As a relay, it can translate the identification information of subscribed users and third-party network elements. For instance, when a network open element sends a subscribed user's permanent identifier (SUPI) from the operator's network to a third party, it can translate the SUPI into its corresponding external identity (ID). Conversely, when sending an external ID (the third-party network element ID) to the operator's network, it can translate it into a SUPI. In 5G communication systems, network open function elements can be network exposure function (NEF) elements. In future communication systems, network open function elements can still be NEF elements, or they can have other names; this application does not limit this.
[0075] The data management network element is used for generating authentication credentials, processing user identifiers (such as storing and managing permanent user identities), access control, and managing subscription data. In 5G communication systems, this data management network element can be a unified data management (UDM) network element. In future communication systems, unified data management can still be a UDM network element, or it can have other names; this application does not limit this.
[0076] It is understood that network elements can also be referred to as "devices," "entities," etc. The aforementioned network elements or functions can be network components within hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). These network elements or functions can be divided into one or more services; furthermore, services that exist independently of network functions may also exist. In this application, instances of the aforementioned functions, instances of services included in the aforementioned functions, or instances of services that exist independently of network functions can all be referred to as service instances.
[0077] It should be understood that Figure 1 This is merely one example of an applicable AIoT architecture; real-world AIoT architectures can include more than... Figure 1More or fewer network elements. The names of the various network elements used in the embodiments of this application may remain functionally the same in future communication systems, but their names may change.
[0078] Given that terminals in the AIoT architecture can obtain energy from sources such as solar, radio frequency, wind, hydro, or tidal power, AIoT boasts the advantage of low power consumption. Leveraging this advantage, AIoT is widely used across various industries, for example:
[0079] In warehousing / transportation / materials scenarios, AIoT terminals can be embedded or attached to goods. During the circulation of goods stored in warehouses, shopping malls, etc., relevant information about the goods is automatically collected by the reader. Managers can quickly query the information of the goods in the system, reducing the risk of loss or theft, improving the speed of goods handover, improving accuracy, and preventing cross-selling and counterfeiting.
[0080] In fixed asset management scenarios, such as libraries, art galleries, and museums, which have large assets or valuable items, there is a need for complete management procedures or rigorous protection measures. When there are abnormal changes in the storage information of books or valuable items, the system will immediately alert the administrator to handle the relevant situation.
[0081] In the AIoT architecture, the reader establishes a connection with the terminal via radio frequency (RF) to identify targets and exchange data. There are two operating modes: First, when the terminal enters the reader's effective recognition range, it receives the RF signal emitted by the reader. The terminal then uses induced current to obtain energy and transmits information stored in its chip. Second, the terminal can store some electrical energy through solar power or other means, and actively transmit a signal of a specific frequency using this stored energy. The reader receives and decodes the information, then sends it to the central information system for data processing.
[0082] Figure 2 This is a schematic diagram illustrating the communication process between a reader and a terminal in an AIoT architecture. Figure 2 As shown, this process corresponds to the first working mode mentioned above, and specifically includes the following steps:
[0083] S201, the requesting party sends a first request message to the core network element. The first request message may contain the requesting party's identification information, service type, or target terminal information. Correspondingly, the core network element receives the first request message from the requesting party.
[0084] In this context, the requester can be understood as the device sending the operation command, such as a server, P-IoT server, application server (AS), application function (AF), or other device that sends operation commands. As an example, Figure 2 The operation requester can be an AF network element or a NEF network element, and the core network element is an AIoT NF network element of the management environment IoT.
[0085] In this step, the first request message contains at least one of the following: the requester's identification information, service type, or target terminal information. For example, when the requester is an AF network element, the requester's identification information may specifically be an AF ID.
[0086] The service types include two main categories of operations: inventory operations and command operations. Inventory operations, also known as inventory checks, can obtain the identification information of terminals (such as electronic tags, labels, and other different types of terminals; the following explanation uses labels as an example, but is not limited to labels). For instance, terminal identification information can be obtained through commands such as query and ack. Terminal identification information includes, for example, electronic product codes (EPCs), tag identifiers (TIDs), or SUPIs.
[0087] Command operations include read, write, kill, and lock operations. Specifically, a read operation reads data from the terminal's storage area. For example, the data in the storage area may include identification information (such as EPC, TID, or SUPI), content stored in the reserved area, or content stored in the user storage area. A write operation writes data to the terminal's storage area. For example, it may write or modify identification information (such as EPC or TID) in the storage area. Alternatively, it may write or modify data in the reserved area or user storage area. A kill operation disables the terminal. For example, a disabled terminal cannot function. A lock operation locks the terminal's information, preventing read or write operations on the tag. Alternatively, a lock operation may lock memory banks, preventing or allowing read or write operations on those memory banks.
[0088] The target terminal information may include regional location information, terminal group information, and terminal identification information. That is, the first request message can indicate relevant information about the target terminal through one or more of the regional location information, terminal group information, and terminal identification information. Specifically, the regional location information indicates that the target terminal being requested is any terminal at that location. In the AIoT architecture, different types of terminals can be divided into different terminal groups. The group information indicates the target group to which the target terminal belongs; for example, the group information can be the group identification information of a terminal group. The terminal identification information can be a permanent or temporary identity identifier, used to indicate that the target terminal is the specific terminal corresponding to the identification information.
[0089] In step S202, the core network element sends a second request message to the reader, which contains identification information for paging terminals. Correspondingly, the reader receives the second request message from the core network element.
[0090] In step S201, when the first request message contains target terminal information, the core network element can determine the target terminal indicated by the operation requester based on the target terminal information. In subsequent communication processes, the reader needs to broadcast a radio frequency signal similar to a paging message to the terminal for paging the target terminal. Therefore, while determining the target terminal based on the target terminal information, the core network element can also determine the identification information used for paging the terminal. For example, this identification information can be called "MASK".
[0091] In this embodiment of the application, "MASK" is used to indicate the identification information used for paging terminals. Specifically, it can be the complete identification information of the terminal or a part of the terminal identification information. "MASK" can be one identification information or multiple identification information. This will be explained uniformly here and will not be elaborated on later.
[0092] For example, the identification information "MASK" used for paging terminals can correspond one-to-one with the identification information of the target terminal. For instance, if the target terminal's identification can be represented as "12345678", then the identification information "MASK" used to paging the target terminal is also "12345678". This "MASK" is equivalent to the complete identification information of the target terminal. The identification information of the terminal device is used to indicate the terminal device. Therefore, when "MASK" corresponds one-to-one with the identification information of the terminal device, it is equivalent to "MASK" and the terminal device being one-to-one. The terminal device can also be indicated through "MASK".
[0093] There can also be a one-to-many relationship between "MASK" and the identification information of the target terminal, that is, one "MASK" can correspond to multiple target terminals. For example, if the "MASK" is "****1234", the "MASK" can be understood as part of the target terminal's identification. If the identification information of a terminal device is 8 characters long and the last four digits are "1234", it can be regarded as the target terminal corresponding to the "MASK".
[0094] In this step, the core network element may carry one or more "MASK" tags in the second request message sent to the reader. Simultaneously, based on the service type information in the first request message, the core network element can instruct the reader to perform inventory operations and / or command operations on the target terminal through the second request message.
[0095] Understandably, in the AIoT architecture, when the reader is an access network device, the second request message can be an N2 message; when the reader is a terminal device, the second request message can be a non-access stratum (NAS) message.
[0096] S203, the reader broadcasts a third request message, which contains identification information for paging terminals.
[0097] In this step, the reader broadcasts a third request message to the terminal devices within the identification range based on the "MASK" contained in the second request message in step S202. The third request message contains the "MASK" obtained from step S202.
[0098] S204, The terminal device that matches the identification information initiates random access to the reader.
[0099] In this process, after receiving a third request message broadcast by a reader, if the terminal device's identification information corresponds to the "MASK" identification information used for paging terminals, then that terminal device is the target terminal, and the target terminal initiates a random access request to the reader. For example, if the "MASK" contained in the third request message is "****1234", then the terminal device with identification information "12341234" is the terminal device corresponding to "MASK", while the terminal device with identification information "12341235" is not the terminal device corresponding to "MASK". Therefore, the terminal device with identification information "12341234" is the target terminal, and after receiving the third request message, it initiates a random access request to the reader. The process of random access is not explained in detail here.
[0100] It should be noted that, based on the service type contained in the first request message, after the target terminal establishes a connection with the reader via random access, different operations are performed in subsequent communication interactions. For example, when the service type is inventory operation, the corresponding... Figure 2 In step S205 shown, when the service type is a command operation, the corresponding... Figure 2 Steps S206 and S207 are shown.
[0101] S205, the target terminal reports its identification information to the core network element. Correspondingly, the core network element receives the identification information from the target terminal.
[0102] When the service type is inventory operation, the target terminal reports its identification information to the core network element through a reader, and the reader realizes the transparent transmission of the identification information.
[0103] S206, the core network element sends a fourth request message to the target terminal. Correspondingly, the target terminal receives the fourth request message from the core network element.
[0104] When the service type is a command operation, the core network element sends a fourth request message to the target terminal through a reader, and the reader realizes the transparent transmission of the fourth request message.
[0105] For example, when the service type is specifically a write operation, the fourth request message includes a write operation command and data 1, where data 1 represents the specific data to be written to the target terminal. It is understood that if the service type is specifically a read operation, the fourth request message only contains a read operation command.
[0106] S207, the target terminal sends a fourth request response message to the core network element. Correspondingly, the core network element receives the fourth request response message from the target terminal.
[0107] In this step, the target terminal sends a fourth request response message to the target terminal through a reader, and the reader realizes the transparent transmission of the fourth request response message.
[0108] The fourth request response message is the response message corresponding to the fourth request message. Therefore, when the service type is a write operation, the fourth request response message is used to indicate whether the write operation was successful. If the service type is a read operation, the fourth request response message contains data 2, which represents the specific data read from the target terminal.
[0109] S208, the core network element sends a first request-response message to the requesting party. Accordingly, the requesting party requests the first request-response message from the core network element.
[0110] It should be noted that, in Figure 2 In the communication flow shown, when the target terminal information in the first request message indicates that the number of target terminals is one, in subsequent steps S203 and S205, the reader and the terminal transmit the permanent identity of the target terminal over the air interface. That is, the third request message broadcast by the reader in step S203 contains the permanent identity of the target terminal, and in step S205, the target terminal reports the permanent identity to the core network element. In steps S203 and S205, the permanent identity transmitted over the air interface lacks security protection. Therefore, attackers can obtain the permanent identity of the terminal device in the above communication flow and, based on the time and location of the permanent identity, determine the terminal device's behavioral trajectory, leading to privacy leaks.
[0111] To address the aforementioned privacy leakage issues, the terminal device can pre-configure key information for encryption and encrypt its permanent identity. The encrypted ciphertext is carried in step S205 to prevent the identification information from being leaked over the air. As an example, the terminal device's permanent identity can be indicated by SUPI. Encrypting the SUPI yields the terminal device's subscription concealed identifier (SUCI). It is understood that in the AIoT architecture, the terminal device's permanent identity may have other names besides SUPI, and the encrypted ciphertext of the permanent identity may also have other names besides SUCI; this application does not limit this.
[0112] Or, suppose Figure 2 The illustrated process describes the communication flow when a target terminal initially accesses the reader. In step S206, when the core network element sends a fourth request message to the target terminal, the fourth request message may include a temporary identifier (temp ID) assigned to the target terminal by the core network element. Accordingly, the target terminal saves the temporary identifier. In subsequent access processes, when the requesting party requests to communicate with the target terminal again, the identifier information transmitted over the air interface can be replaced by the target terminal's permanent identity identifier with the aforementioned temporary identifier.
[0113] However, in the above methods, whether it's encrypting the permanent identity of the target terminal device or configuring a temporary identity for the target terminal during the initial access process, in Figure 2In step S203, when the reader broadcasts a third request message to the terminal device, the identification information contained in the third request message is the permanent identity of the target terminal. When the number of target terminals requested by the requester is small, such as when there is only one target terminal, the attacker can still determine the permanent identity of the individual terminal device that will be accessed later based on the identification information in this step, ultimately leading to privacy leakage.
[0114] To address the aforementioned technical problems, this application provides a communication method and related apparatus, aiming to enhance the security of communication and interaction between the reader and the terminal, and to prevent privacy leaks.
[0115] The technical concept of this application is as follows: when the number of target terminals is less than or equal to a preset threshold, the identification information broadcast by the reader corresponds to multiple terminal devices, including the target terminal indicated by the requester. By using the correspondence between the identification information and the terminal devices, the target terminal is confused with other terminal devices, making it impossible for attackers to obtain the permanent identification of the target terminal, thereby avoiding privacy leakage and improving communication security.
[0116] Figure 3 This is a flowchart illustrating a communication method provided in one embodiment of this application. Exemplarily, the method is applied to... Figure 1 In the AIoT architecture shown or a future AIoT architecture, the method may include steps S301 and S302.
[0117] S301, the first device receives a first request message, which is used to request an inventory operation and / or command operation on the target terminal device.
[0118] In this step, the first device can specifically be Figure 2 The core network elements in the architecture shown, such as the AIoT NF network elements used for access control and management of AIoT devices, can also be... Figure 2 The reader or network element with the same function as the reader, such as a base station or relay UE.
[0119] As one possible implementation, the first device is a core network element, and in this step, the first device receives the first request message corresponding to... Figure 2 The core network element receives a first request message from the operation requester. The first request message contains service type information and target terminal information. When the number of target terminal devices is one, the target terminal information can be a permanent identity identifier for a specific terminal. The service type information indicates that an inventory operation and / or command operation should be performed on the target terminal device.
[0120] It should be noted that the number of target terminal devices indicated by the operation requester through the first request message may be more than one. For example, the operation requester may indicate terminal devices within an area through target terminal information. However, if the core network element determines, based on the first request message, that only one terminal device exists within the specified area, then from the core network element's perspective, the number of target terminal devices is equivalent to one. In this application, when the core network element determines that only one operable terminal device exists, the number of target terminal devices can be determined to be one.
[0121] In another possible implementation, the first device is a reader or a network element with the same function as a reader. In this implementation, the first device receiving the first request message in step S301 corresponds to... Figure 2 In step S202 shown, the reader receives a second request message from the core network element, that is, the instruction from the operation requester to perform an inventory operation and / or command operation on the target terminal device has been transmitted from the core network element to the reader.
[0122] It is understandable that if the core network element determines the number of target terminal devices to be one based on the target terminal information, the core network element will also indicate the number of target terminal devices to the first device to be one.
[0123] S302, the first device sends a second request message. When the number of target terminal devices is less than or equal to a first threshold, the second request message contains first identification information. The first identification information corresponds to multiple terminal devices, and the multiple terminal devices include the target terminal devices and the number of multiple terminal devices is greater than the first threshold.
[0124] In some implementations, when the number of target terminal devices indicated by the first request message is less than or equal to a first threshold, the first device can construct first identification information based on the permanent identity of the target terminal devices. The first identification information corresponds to multiple terminal devices, including the target terminal device. The first threshold is a preset threshold, and when constructing the first identification information, it must be ensured that the number of multiple terminal devices corresponding to the first identification information is greater than the first threshold.
[0125] As an example, the number of the first threshold indication can be one, that is, when the number of target terminal devices is one, the first device can construct the corresponding first identification information based on the permanent identity of a single target terminal device.
[0126] In this step, after determining the first identification information corresponding to multiple terminal devices, the first device can send a second request message, which contains the aforementioned first identification information. It can be understood that if the first device is a core network element, then the first device sends the aforementioned second request message to a reader or a network element with the same function as a reader. Step S302 is equivalent to the first device sending a second request message to a second device, where the second device is a reader or a network element with the same function as a reader. Figure 2 In step S202, the core network element sends a second request message to the reader.
[0127] If the first device is a reader or a network element with the same function as a reader, then the first device broadcasts a second request message. Step S302 is equivalent to the first device broadcasting a second request message, corresponding to... Figure 2 In step S203, the reader broadcasts a third request message.
[0128] In this embodiment, the first device replaces the permanent identity of the target terminal device with the first identification information. The first identification information corresponds to multiple terminal devices, causing the target terminal device to be confused with other terminal devices among the multiple terminal devices. Therefore, when a network element with the same function as a reader broadcasts the first identification information, the attacker cannot determine the permanent identification information of the target terminal device based on the first identification information, thereby avoiding privacy leakage.
[0129] Understandable, Figure 3 The illustrated embodiments demonstrate the technical solution of this application. Figure 2 As shown in the flowchart, the above communication method only illustrates a part of the communication process between the reader and the terminal device under the AIoT architecture. The complete communication process between the reader and the terminal device will be explained below, taking the case where the first device is a core network element.
[0130] Figure 4 This is a flowchart illustrating a communication method provided in one embodiment of this application. Exemplarily, Figure 4 The communication method shown can be applied to Figure 1 In the AIoT architecture shown or a future AIoT architecture, the method may include S401 to S406.
[0131] S401, the requesting party sends a first request message to the core network element. The first request message is used to request an inventory operation and / or command operation on the target terminal equipment. Accordingly, the core network element receives the first request message.
[0132] This step can be combined with Figure 2 Corresponding to step S201, the core network element receives a first request message from the operation requester. The first request message contains service type information and target terminal information. When the number of target terminal devices is one, the target terminal information can be a permanent identity identifier of a specific terminal. The service type information indicates that an inventory operation and / or command operation should be performed on the target terminal device.
[0133] It should be noted that when the operation requester indicates the terminal devices in a region through the target terminal information, and the core network element determines that there is only one terminal device in the specified region based on the first request message, the core network element can determine that the number of target terminal devices is one.
[0134] By combining service type information and target terminal information, core network elements can determine that the first request message is used to request an inventory operation and / or command operation on the target terminal device.
[0135] S402, the core network element sends a second request message to the communication device. When the number of target terminal devices is less than or equal to a first threshold, the second request message includes first identification information. The first identification information corresponds to multiple terminal devices, including the target terminal devices, and the number of multiple terminal devices is greater than the first threshold. Accordingly, the communication device receives the second request message from the core network element.
[0136] exist Figure 1 In the AIoT architecture shown, the communication device is a reader. In future AIoT architectures, the communication device can still be a reader, or it can be a network element with the same function as a reader. This application does not limit this.
[0137] In some implementations, when the number of target terminal devices indicated by the first request message in step S401 is less than or equal to a first threshold, the first device can construct first identification information based on the permanent identity of the target terminal devices. The first identification information corresponds to multiple terminal devices including the target terminal device, and the number of multiple terminal devices is greater than the first threshold.
[0138] For example, the number indicated by the first threshold can be one. Figure 4 The illustrated embodiment is described in detail with the case where the number indicated by the first threshold is one. In this step, if the number of target terminal devices indicated by the first request message in step S401 is one, the core network element can construct first identification information based on the permanent identity of the target terminal device. The first identification information corresponds to multiple terminal devices, and the multiple terminal devices include the target terminal device.
[0139] In some implementations, the first identification information can be the group identification information of a first terminal group, which includes the target terminal device. Based on the aforementioned content contained in the target terminal information, it can be seen that different types of terminals can be divided into different terminal groups, and each different terminal group corresponds to a group identification information; that is, each group identification information can indicate a unique terminal group.
[0140] Since the group identification information corresponds to an entire terminal group, and the terminal devices contained in each terminal group are clearly defined, the core network element can determine the terminal devices in the terminal group corresponding to the group identification information based on the group identification information. In this implementation, the core network element can determine the first terminal group to which the target terminal belongs based on the permanent identity of the target terminal device, and then look up the group identification information of the first terminal group, thereby setting the first identification information as the group identification information of the first terminal group.
[0141] In some implementations, the first identifier information can also be understood as Figure 2 The illustrated process uses identification information for paging terminals. Considering that the first identification information corresponds to multiple terminal devices, as an example, the first identification information includes at least one identifier from the permanent identity of the target terminal device, and the permanent identity of at least one other terminal device among the multiple terminal devices includes the aforementioned at least one identifier. Alternatively, the first identification information may include mask information, which corresponds to multiple terminal devices.
[0142] It is understandable that, referring to the aforementioned description of one "MASK" corresponding to multiple terminal devices, when the first identification information contains at least one identifier of the permanent identity of the target terminal device, that is, when the first identification information and the permanent identity of the target terminal device have the same identifier at the same character position, it is equivalent to the first identification information corresponding to the target terminal device. Similarly, when the permanent identity of at least one other terminal device among the multiple terminal devices contains the aforementioned at least one identifier at the same position, it means that the permanent identity of at least one other terminal device among the multiple terminal devices and the first identification information have the same identifier at the same character position, which is equivalent to the first identification information also corresponding to the aforementioned at least one terminal device. Therefore, the first identification information can correspond to multiple terminal devices.
[0143] Alternatively, relative to the complete permanent identity of the target terminal device, the mask information contained in the first identification information can mask a specified number of bits in the permanent identity. Through the remaining unmasked identity bits, the mask information can establish a mapping relationship with multiple terminal devices, thereby making the mask information correspond to multiple terminal devices.
[0144] For example, if the SUPI of the target terminal device is "460030012345678" and the first identification information is "46003**********", where "*" indicates that the identifier at the corresponding position is not limited, and the first five digits of the first identification information "46003" are consistent with the first five digits of the target terminal device's SUPI, then the first identification information contains the identifier in the target terminal device's SUPI, and the first identification information corresponds to that target terminal device. If, among multiple terminal devices, one terminal device has a SUPI of "460030001234567", and the first five digits of that terminal device's SUPI are also "46003", then the first identification information also corresponds to that terminal device.
[0145] The multiple identifiers in the first identification information are not limited. For example, the first identification information may also include filters, filters, or wildcards. The core network element may represent the unrestricted identifiers in the first identification information as wildcards, or the core network element may directly set the unrestricted identifiers in the first identification information to empty.
[0146] In some implementations, the first identification information may also include multiple second identification information, one of which corresponds to the target terminal device.
[0147] As one possible implementation, the second identification information can be understood as the identification information "MASK" used for paging terminals. Therefore, multiple second identification information can correspond one-to-one with multiple terminal devices, where each of the multiple second identification information is a permanent identity information different from the corresponding terminal device.
[0148] For example, the SUPI of the target terminal device is "460030012345678". The second identification information is different from the SUPI of the target terminal device. The second identification information corresponding to the target terminal device is "460030000000000". Both have the first five digits "46003", meaning the first five digits of the terminal device's SUPI are the same as the first digits of the second identification information, but the last ten digits are different. Because there is a one-to-one correspondence between the second identifier and the terminal device, the target terminal device with the SUPI of "460030000000000" can be identified by using the second identification information "460030012345678" from multiple sets of second identification information.
[0149] For example, referring to the aforementioned case where one "MASK" corresponds to multiple terminal devices, there can also be a one-to-many association between the second identification information and the terminal devices.
[0150] It is understandable that when the second identification information is the identification information "MASK" used for paging terminals, the core network element can directly generate multiple second identification information locally, and the number of second identification information can be determined by the preset local policies or rules in the core network element.
[0151] As another possible implementation, the second identification information can also be the identification information of the terminal device, with one of the multiple second identification information pieces serving as the permanent identification information of the target terminal device. It should be noted that, unlike the "MASK" identification information used for paging terminals, core network elements cannot generate terminal device identification information locally; therefore, as... Figure 5 As shown in step S402-0, the core network element sends a third request message to the data management network element. This third request message is used to request multiple pieces of second identification information. Correspondingly, after receiving the third request message, the data management network element, as follows... Figure 4 As shown in step S402-1, the data management network element sends a first indication information to the core network element. The first indication information is used to indicate multiple second identification information.
[0152] It is understandable that if the first device is a reader or a network element with the same function as a reader, that is, the first device is... Figure 4 The communication device in the illustrated embodiment also cannot locally generate the identification information of the terminal device, therefore... Figure 5 The core network elements in steps S402-0 and S402-1 can be replaced by the first device, i.e. Figure 4 The communication devices used in this project will not be described in detail here.
[0153] Among them, the multiple second identification information indicated by the first instruction information can be multiple permanent identity identifiers corresponding to multiple terminal devices, that is, each of the multiple second identification information is the real identification information of the corresponding terminal device.
[0154] In some implementations, multiple second identification information sets may also include virtual identification information. Virtual identification information refers to fake identification information generated by the data management network element, and the terminal device indicated by the virtual identification information is a terminal device that does not actually exist. The multiple second identification information sets may contain only some virtual identification information, or, except for the permanent identity identifier of a single target terminal device, the remaining second identification information in the multiple second identification information sets may all be virtual identification information. It is understood that regardless of the number of virtual identification information sets contained in the multiple second identification information sets, at least one of the multiple second identification information sets corresponds to a target terminal device.
[0155] When a core network element requests multiple second identification information from a data management network element, the number of the multiple second identification information can be determined by a preset local policy or rule in the data management network element. In some implementations, the third request message in step S402-0 may also include the number of multiple second identification information, that is, the core network element can directly indicate the specific number of the required multiple second identification information through the third request message.
[0156] It should be noted that if the number of target terminal devices is one, the core network element can construct the first identification information based on the permanent identity of the target terminal device. In some implementations, the core network element must also meet the following conditions when constructing the first identification information: the temporary identification information of the target terminal device is unavailable, and / or the target terminal device supports permanent identification encryption.
[0157] Among these, the temporary identifier information of the target terminal device is unavailable. For example, this could mean that the core network element has not assigned a temporary identifier to the target terminal device, or that the core network element has not been able to find the temporary identifier of the target terminal device based on its permanent identity identifier.
[0158] The security capability information of a terminal device can indicate whether the terminal device supports permanent identifier encryption. As an example, the first request message may also include the security capability information of the target terminal device, which indicates that the target terminal device supports permanent identifier encryption. In another example, if the first request message does not contain the security capability information of the target terminal device, the core network element can request the security capability information of the target terminal device from the data management network element to determine whether the target terminal device supports permanent identifier encryption.
[0159] In this step, after the core network element constructs the first identification information, it sends a second request message to the communication device. The second request message contains the aforementioned first identification information. It can be understood that step S402 and... Figure 2 The difference between step S202 in the communication process shown is that when the number of target terminals is one, the identification information "MASK" for paging terminals included in the second request message in step S202 is the permanent identity identifier of the target terminal device, while the first identification information included in the second request message in step S402 corresponds to both the target terminal device and multiple other terminal devices.
[0160] S403, the communication device broadcasts a paging request message, which includes first identification information.
[0161] Step S403 corresponds to Figure 2In step S203, since the communication device is a reader in the AIoT architecture or a network element with the same function as a reader in the future AIoT architecture, after receiving the second request message, the communication device broadcasts a paging request message to the terminal devices within the identification range. The paging request message contains the first identification information obtained from the second request message.
[0162] S404, Multiple terminal devices corresponding to the first identification information initiate random access to the communication device.
[0163] Step S404 corresponds to Figure 2 Step S204 as shown, Figure 4 As shown, assuming the first identification information is "46003**********", the SUPI of the second terminal device is "460030012345678", and the SUPI of the first terminal device is "460030001234567", after the second terminal device receives the paging request message broadcast by the communication device, since the first five digits of the second terminal device's SUPI, "46003", are the same as "46003" in the first identification information, the second terminal device can determine that it is the terminal device corresponding to the first identification information, and thus initiate random access to the communication device. Similarly, the first terminal device, combining the first identification information and its permanent identity, can determine that it is the terminal device corresponding to the first identification information and initiate random access to the communication device.
[0164] It is understood that, as can be seen from step S402, the first identification information may include multiple second identification information, and the second identification information may also include virtual identification information. When one of the multiple second identification information corresponds to a target terminal device, while the other second identification information is virtual identification information, since the terminal device indicated by the virtual identification information is a terminal device that does not actually exist, only one target terminal device will initiate random access to the communication device in step S404.
[0165] S405, the terminal device reports its identification information to the core network element. Correspondingly, the core network element receives the identification information from the terminal device.
[0166] Step S405 corresponds to Figure 2 As can be understood from step S205, considering the risk of privacy leakage, when the terminal device reports identification information to the core network element in this step, the identification information may, for example, be temporary identification information of the terminal device. If the terminal device supports permanent identification encryption, the terminal device may also report encrypted identification information to the core network element in this step.
[0167] It should be noted that when the requesting party requests an inventory operation and / or command operation on the target terminal device through the first request message, if the number of target terminal devices is one, it is equivalent to the requesting party expecting one target terminal device to communicate with the communication device. However, since the first identification information corresponds to multiple terminal devices, in step S404, the multiple terminal devices corresponding to the first identification information initiate random access to the communication device, resulting in multiple terminal devices communicating with the communication device.
[0168] In some implementations, when the core network element constructs the first identification information based on the permanent identity of the target terminal device, it records the permanent identity of the target terminal device. Based on the identification information reported by the terminal device in step S405, the core network element can determine whether the corresponding terminal device is the target terminal device indicated in the first request message. When the terminal device accessing the communication device is not the target terminal device, the core network element instructs the release of the connection between the communication device and the terminal device. Simultaneously, in the subsequent step S406, when the core network element sends the first request response message to the requester, the first request response message only contains the identification information reported by the target terminal device, discarding the identification information reported by non-target terminal devices.
[0169] Understandably, if the identification information reported by the terminal device in step S405 is temporary identification information, the core network element can use the temporary identification information to find the corresponding permanent identification information and compare it with the recorded permanent identity to determine whether the corresponding terminal device is the target terminal device. If the identification information reported by the terminal device in step S405 is encrypted identification information, the core network element first decrypts the encrypted identification information to obtain the permanent identification information of the terminal device, and then compares it with the recorded permanent identity to determine whether the corresponding terminal device is the target terminal device.
[0170] because Figure 4 In the illustrated embodiment, a core network element is used as the first device. As an example, the core network element can receive third identification information, which corresponds to the first terminal device, i.e., the first terminal device reporting the third identification information to the core network element in step S405. Figure 5 As shown in step S405-1, when the first terminal device is not the target terminal device, the core network element sends a fourth request message to the second device or the first terminal device. This fourth request message is used to request the release of the connection between the second device and the first terminal device. It can be understood that when the first device is a core network element, the second device corresponds to... Figure 4 In the illustrated embodiment, the communication device or the first terminal device receives a fourth request message.
[0171] When the core network element determines that the first terminal device is not the target terminal device requested by the operation requester, it can release the connection between the communication device and the non-target terminal device through the fourth request message, thereby avoiding communication interference between the non-target terminal device and the target terminal device.
[0172] S405-2, the core network element sends a fifth request message to the target terminal device. Correspondingly, the target terminal receives the fifth request message from the core network element.
[0173] S405-3, the target terminal device sends a fifth request response message to the core network element. Correspondingly, the core network element receives the fifth request response message from the target terminal device.
[0174] S406, the core network element sends a first request-response message to the requesting party. Accordingly, the requesting party requests the first request-response message from the core network element.
[0175] It is understandable that when the first request message in step S401 contains a command operation, execution is performed. Figure 4 The steps S405-2 and S405-3 shown above, and the steps S405-2, S405-3 and S406 above are related to... Figure 2 Steps S206 to S208 in the communication process shown are the same and will not be repeated here.
[0176] In this embodiment, the core network element can construct the first identification information based on the permanent identification information of a single target terminal device. The first identification information corresponds to multiple terminal devices. The target terminal device is confused with other terminal devices among the multiple terminal devices. Therefore, when a communication device with the same function as a reader broadcasts the first identification information, the attacker cannot determine the permanent identification information of the target terminal device based on the first identification information, thereby avoiding privacy leakage.
[0177] In the above Figure 4 and Figure 5 In the illustrated embodiment, when broadcasting a random access request, the communication device can prevent attackers from determining the permanent identification information of the target terminal device by broadcasting the first identification information corresponding to multiple terminal devices. Regarding the issue of preventing attackers from determining the permanent identification information of the target terminal device, as a possible implementation, further improvements can be made to the method described above for configuring temporary identification information for the target terminal device by the core network element.
[0178] Figure 6 This is a flowchart illustrating a communication method provided in another embodiment of this application. Exemplarily, Figure 6 The communication method shown can be applied to Figure 1In the AIoT architecture shown or a future AIoT architecture, the method may include S601 to S609.
[0179] S600: Terminal devices are pre-configured with multiple temporary identification information.
[0180] As an example, terminal devices are configured with multiple temporary identification information at the factory, and core network elements can obtain this information before the requesting party initiates a request. In some implementations, core network elements can also pre-configure multiple temporary identification information for the terminal device.
[0181] S601, the requesting party sends a first request message to the core network element. The first request message is used to request an inventory operation or command operation on the target terminal equipment. Correspondingly, the core network element receives the first request message from the requesting party.
[0182] This step and Figure 4 Step S401 in the illustrated embodiment is the same and will not be repeated here.
[0183] S602, the core network element sends a second request message to the communication device. When the number of target terminal devices is less than or equal to a first threshold, the second request message includes fourth identification information, which includes at least one temporary identification information from a plurality of temporary identification information stored by the target terminal devices. Accordingly, the communication device receives the second request message from the core network element.
[0184] This step and Figure 4 Step S402 in the illustrated embodiment is similar, except that the core network element stores multiple temporary identification information of the target terminal device. Therefore, the core network element no longer needs to construct the first identification information, but can directly apply the multiple temporary identification information of the target terminal device.
[0185] Accordingly, the first identification information contained in the second request message in step S402 can be replaced with the fourth identification information, which includes at least one of the multiple temporary identification information stored by the target terminal device.
[0186] In some implementations, if the number of the first threshold indications in step S602 is one, then the fourth identification information may include at least one of the multiple temporary identification information stored by a single target terminal device. Figure 6 The illustrated embodiment uses a quantity indicated by a first threshold as an example.
[0187] In some implementations, the fourth identification information includes temporary identification information that will be used for the first time. It is understood that temporary identification information is used to replace the permanent identification information of the terminal device to avoid privacy leaks. However, when temporary identification information is used multiple times, attackers can track the location and activity status of the target terminal device based on the repeatedly used temporary identification information, still raising the issue of privacy leaks. In this implementation, the fourth identification information includes temporary identification information that will be used for the first time, preventing the temporary identification information from being reused multiple times, thereby improving communication security.
[0188] S603, the communication device broadcasts a paging request message, which includes fourth identification information.
[0189] S604, The target terminal device corresponding to the fourth identification information initiates random access to the communication device.
[0190] S605, the target terminal device reports its identification information to the core network element. Correspondingly, the core network element receives the identification information from the target terminal device.
[0191] The above steps S603 to S605 and Figure 4 Steps S403 to S405 in the illustrated embodiment are similar, except that the identification information involved in steps S603 and S604 is replaced by fourth identification information instead of first identification information. It is understood that at least one temporary identification information contained in the fourth identification information corresponds to a target terminal device, and when the number of target terminal devices is one, only one target terminal device accesses the communication device.
[0192] S606, the core network element marks the fourth identification information as a used temporary identification information.
[0193] Since the paging request message in step S603 contains fourth identification information, after the target terminal device initiates random access to the communication device, at least one temporary identification information contained in the fourth identification information is a used temporary identification information.
[0194] To prevent the temporary identification information of the target terminal device from being reused multiple times, thus leading to privacy leaks, in this step, the core network element marks the fourth identification information as used temporary identification information. It is understood that the core network element can mark the fourth identification information as used temporary identification information when the target terminal device first accesses the network, or it can trigger the above marking operation in subsequent access procedures.
[0195] Accordingly, in the subsequent access process, the core network element selects unused temporary identification information based on the markings of multiple temporary identification information of the target terminal device.
[0196] S607, the core network element sends a first request-response message to the requesting party. Accordingly, the requesting party requests the first request-response message from the core network element.
[0197] It is understandable that if the first request message in step S601 includes an inventory operation, then after the target terminal device reports the identification information to the core network element, it can execute step S607, which is similar to... Figure 4 Step S406 in the illustrated embodiment is the same and will not be repeated here.
[0198] It should be noted that, Figure 6 Steps S601 to S607 shown can be understood as the operation requesting party initially requesting to perform inventory operations and / or command operations on the target terminal device. In subsequent communication interactions, the operation requesting party can request to perform inventory operations and / or command operations on the target terminal device again. The communication process is the same as the above steps S601 to S607, and will not be repeated here.
[0199] It should be noted that if the operation requester requests to perform an inventory operation and / or command operation on the target terminal equipment again, and the number of target terminal equipment is less than or equal to the first threshold, then the core network element needs to select an unused temporary identification information as the fourth identification information from the multiple temporary identification information of the target terminal equipment based on the marking of the multiple temporary identification information of the target terminal equipment.
[0200] In some implementations, when a core network element selects unused temporary identification information as the fourth identification information, the following condition must also be met: the target terminal device supports permanent identification encryption.
[0201] It should be understood that the number of pre-configured temporary identification information for the target terminal device is fixed. Therefore, if the operation requester repeatedly requests to perform inventory operations or command operations on the target terminal device, all the pre-configured temporary identification information may be marked as used. In some implementations, when the number of unused temporary identification information among the multiple temporary identification information of the target terminal device is less than or equal to a second threshold, the core network element can configure new temporary identification information for the target terminal device.
[0202] As an example, such as Figure 6 As shown in step S608, when the number of unused temporary identification information among the multiple temporary identification information stored by the target terminal device is less than or equal to the second threshold, a fifth request message is sent to the target terminal device. The fifth request message is used to request the writing of at least one fifth identification information. The fifth identification information is temporary identification information allocated by the core network element to the target terminal device.
[0203] In this step, the fifth identification information is a new temporary identification information allocated by the core network element, in addition to the multiple pre-configured temporary identification information. This step requires writing the fifth identification information into the target terminal device, which corresponds to the write operation in the command operation. By writing at least one fifth identification information into the target terminal device, the fifth identification information can be used as the new temporary identification information when the subsequent operation requester initiates a new operation request, avoiding the repeated use of the pre-configured temporary identification information, thereby preventing privacy leakage and improving communication security.
[0204] In this embodiment, by pre-configuring multiple temporary identification information, the permanent identification information of the target terminal device can be avoided from being leaked when broadcasting the fourth identification information in step S603, thus protecting the privacy of the terminal device and improving communication security. Furthermore, compared to... Figure 4 and Figure 5 In the embodiment shown, since the fourth identification information only corresponds to the target terminal device, there is no situation where non-target terminal devices access the communication device, and communication interference from non-target terminal devices can also be avoided.
[0205] Figure 7 and Figure 8 This is a schematic diagram illustrating the structure of a possible communication device provided in the embodiments of this application. These communication devices can be used to implement the functions of the first device in the above method embodiments, and therefore can also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the communication device can be as follows: Figures 4 to 6 The core network element or communication device in the method embodiment shown can also be a component configured therein (such as a chip, chip system, processor, etc.), or a logic module or software capable of implementing some or all of the functions of the core network element or communication device.
[0206] Figure 7 This is a schematic block diagram of a communication device 700 provided in one embodiment of this application. Figure 7 As shown, the communication device 700 includes a processing module 710 and a transceiver module 720.
[0207] The transceiver module 720 can implement corresponding communication functions and can also be referred to as an input / output interface or a communication unit. The processing module 710 can be used to perform processing operations. It should be understood that if the device 700 is a component configured in the first device, such as a chip, the transceiver module 720 can be an input / output interface.
[0208] Optionally, the transceiver module 720 may include a sending module and a receiving module. The sending module is used to perform the above-described... Figures 4 to 6 The receiving module performs the above-mentioned transmitting operations of the core network elements or communication devices. Figures 4 to 6Receiving operations of core network elements or communication devices.
[0209] It should be understood that when the device 700 is a component configured in the first device, such as a chip, the transmitting module can be an output interface, and the transmitting operation involved in the embodiments of this application can be performed by the output interface; the receiving module can be an input interface, and the receiving operation involved in the embodiments of this application can be performed by the input interface.
[0210] Optionally, the device 700 may further include a storage module for storing instructions and / or data, and the processing module 710 may read the instructions and / or data from the storage module to enable the device to perform the preceding operations. Figures 4 to 6 The method embodiment shown.
[0211] In one possible design, the aforementioned device 700 can be used to implement the above. Figures 4 to 6 The method embodiment shown may include the functions of the core network element or communication device, or the device 700 may include components for implementing the above. Figures 4 to 6 The unit of any function or operation of the core network element or communication device in the method embodiment shown can be implemented in whole or in part by software, hardware, firmware or any combination thereof.
[0212] When device 700 is used to implement the function of the first device in the above embodiments, transceiver module 720 (specifically, a receiving module) can be used to perform... Figure 4 In step S401, the first request message is received; the processing module 710 can be used to execute... Figure 4 In step S402, a first identification information is constructed based on the permanent identity of the target terminal device. The first identification information corresponds to multiple terminal devices, including the target terminal device. The transceiver module 720 (specifically, a sending module) can also be used to perform... Figure 4 In step S402, a second request message is sent.
[0213] For a more detailed description of the aforementioned processing module 710 and transceiver module 720, please refer to [link / reference needed]. Figures 4 to 6 The relevant descriptions in the method embodiments shown are directly obtained and will not be repeated here.
[0214] It should be noted that the transceiver module can also be called a transceiver unit, transceiver, transceiver machine, or transceiver device, etc. The processing module can also be called a processor, processing board, processing unit, or processing device, etc. Optionally, the transceiver module is used to perform the sending and receiving operations on the network device side in the above method. The device in the communication module that implements the receiving function can be considered as the receiving module, and the device in the communication module that implements the sending function can be considered as the sending module; that is, the transceiver module includes both a receiving module and a sending module.
[0215] In another possible design, the aforementioned transceiver module and / or processing module can be implemented using virtual modules. For example, the processing module can be implemented using software functional modules or virtual devices, and the transceiver module can also be implemented using software functional modules or virtual devices. In another possible design, the processing module or transceiver module can also be implemented using physical devices. For example, if the device is implemented using a chip / chip circuit, the transceiver module can be an input / output circuit and / or a communication interface, performing input operations (corresponding to the aforementioned receiving operation) and output operations (corresponding to the aforementioned sending operation); the processing module is an integrated processor, microprocessor, or integrated circuit.
[0216] It should be understood that the module division in the embodiments of this application is illustrative and only represents a logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional modules in the various embodiments of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0217] Figure 8 This is a schematic diagram of the structure of a communication device provided in another embodiment of this application. Figure 8 The apparatus 800 shown can be used to perform any of the methods described above that are executed by the communication device.
[0218] like Figure 8 As shown, the device 800 in this embodiment includes a memory 801, a processor 802, a communication interface 803, and a bus 804. The memory 801, processor 802, and communication interface 803 are interconnected via the bus 804.
[0219] The memory 801 can be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 801 can store programs, and when the program stored in the memory 801 is executed by the processor 802, the processor 802 performs any of the aforementioned methods.
[0220] The processor 802 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for executing relevant programs.
[0221] The processor 802 can also be an integrated circuit chip with signal processing capabilities. In implementation, the various related steps in the embodiments of this application can be completed by the integrated logic circuitry in the processor 802 or by software instructions.
[0222] The processor 802 described above can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0223] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory 801, and processor 802 reads the information in memory 801 and, in conjunction with its hardware, completes the functions required by the units included in the device of this application.
[0224] The communication interface 803 can use, but is not limited to, transceivers to enable communication between the device 800 and other devices or apparatuses.
[0225] Bus 804 may include a pathway for transmitting information between various components of device 800 (e.g., memory 801, processor 802, communication interface 803).
[0226] This application also provides a computer-readable storage medium storing computer instructions, which, when executed by a processor, implement the steps of the methods described above.
[0227] This application also provides a computer program product, including computer instructions that, when executed by a processor, implement the various steps in the methods described above.
[0228] It should be noted that the modules or components shown in the above embodiments can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors, or one or more field-programmable gate arrays (FPGAs). Furthermore, when a module is implemented by a processing element calling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling program code, such as a controller. Moreover, these modules can be integrated together to implement a system-on-a-chip (SoC).
[0229] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, software modules, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)).
[0230] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0231] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A communication method, characterized in that, Applied to a first device, the method includes: Receive a first request message, the first request message being used to request an inventory operation and / or command operation on the target terminal device; A second request message is sent. When the number of the target terminal devices is less than or equal to a first threshold, the second request message contains first identification information. The first identification information corresponds to multiple terminal devices, the multiple terminal devices include the target terminal devices, and the number of the multiple terminal devices is greater than the first threshold.
2. The method according to claim 1, characterized in that, The first threshold indicates a quantity of one.
3. The method according to claim 1 or 2, characterized in that, The first identification information is the group identification information of the first terminal group, and the first terminal group includes the target terminal device.
4. The method according to claim 1 or 2, characterized in that, The first identification information includes at least one identifier from the permanent identity identifier of the target terminal device, and the permanent identity identifier of at least one other terminal device among the plurality of terminal devices includes the at least one identifier; or, The first identification information includes mask information, which corresponds to the plurality of terminal devices.
5. The method according to claim 1 or 2, characterized in that, The first identification information includes multiple second identification information, and one of the multiple second identification information is the permanent identification information of the target terminal device.
6. The method according to claim 5, characterized in that, Before sending the second request message, the method further includes: When the number of target terminal devices is less than or equal to the first threshold, a third request message is sent to the data management network element, the third request message being used to request the plurality of second identification information; Receive first indication information, which indicates the plurality of second identification information.
7. The method according to claim 6, characterized in that, The plurality of second identification information includes virtual identification information.
8. The method according to claim 6 or 7, characterized in that, The third request message contains the number of the plurality of second identification information.
9. The method according to any one of claims 1 to 8, characterized in that, The temporary identification information of the target terminal device is unavailable, and / or the target terminal device supports permanent identification encryption.
10. The method according to any one of claims 1 to 9, characterized in that, The first device is a core network element, and the method further includes: Receive third identification information, the third identification information corresponding to the first terminal device; When the first terminal device is not the target terminal device, a fourth request message is sent to the second device or the first terminal device. The fourth request message is used to request the release of the connection between the second device and the first terminal device.
11. A communication method, characterized in that, Applied to core network elements, the method includes: Receive a first request message, the first request message being used to request an inventory operation and / or command operation on the target terminal device; A second request message is sent to the communication device. When the number of target terminal devices is less than or equal to a first threshold, the second request message contains fourth identification information, which includes at least one temporary identification information among a plurality of temporary identification information stored by the target terminal device.
12. The method according to claim 11, characterized in that, The first threshold indicates a quantity of one.
13. The method according to claim 11 or 12, characterized in that, The fourth identification information includes temporary identification information that will be used for the first time.
14. The method according to claim 13, characterized in that, The method further includes: The fourth identification information is marked as a used temporary identification information.
15. The method according to claim 14, characterized in that, The method further includes: When the number of unused temporary identifiers among the multiple temporary identifiers stored in the target terminal device is less than or equal to the second threshold, a fifth request message is sent to the target terminal device. The fifth request message is used to request the writing of at least one fifth identifier, which is a temporary identifier allocated by the core network element to the target terminal device.
16. A communication device, characterized in that, The communication device includes a functional module for implementing the communication method as described in any one of claims 1 to 10, or includes a functional module for implementing the communication method as described in any one of claims 11 to 15.
17. A communication device, characterized in that, include: Processor and memory; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the communication device to perform the communication method as described in any one of claims 1 to 10, or the communication method as described in any one of claims 11 to 15.
18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the communication method as described in any one of claims 1 to 10, or the communication method as described in any one of claims 11 to 15.
19. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the communication method as claimed in any one of claims 1 to 10, or any one of claims 11 to 15.