Communication method, device, system, and storage medium

CN121002918APending Publication Date: 2025-11-21BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480025456.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

In the prior art, IoT devices lack effective security strategies and materials to ensure the security of communications when powering with environmental energy, especially in backscatter communications. There is still an unmature solution to how to provide secure materials and strategies.

Method used

Secure communication is achieved by determining the first security material, including a security policy, for communication security protection between the first device and the second device. The secure material is provided by the first device or the third device, and the specific steps include requesting, receiving and verifying the secure material to ensure the integrity and confidentiality of the signal and data of the communication.

Benefits of technology

It realizes secure communication of IoT devices under environmental energy power supply, reduces communication energy consumption, simplifies equipment design, reduces costs, and improves the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121002918A_ABST
    Figure CN121002918A_ABST
Patent Text Reader

Abstract

The embodiment of the disclosure discloses a communication method, device and computer readable storage medium, and relates to the technical field of communication. The communication method comprises the following steps: determining a first security material; and performing secure communication with a second device according to the first security material; wherein the first security material comprises a security policy, and the security policy is used to determine a security protection method of communication between the first device and the second device. According to the embodiment of the disclosure, the security protection method of communication between the first device and the second device is determined based on the security policy in the determined first security material, so that the security protection of communication is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device, system and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a communication method, device, system, and storage medium. Background Art

[0002] In the field of communication technology, some Internet of Things (IoT) devices can harvest ambient energy for power. For example, these IoT devices can typically be powered by harvesting radio waves, light, motion, heat, or any other suitable power source.

[0003] Summary of the Invention

[0004] Embodiments of the present disclosure provide a communication method, device, system, and storage medium.

[0005] According to a first aspect of an embodiment of the present disclosure, a communication method is provided. The method is performed by a first device, and the method includes:

[0006] Identify the first safety material;

[0007] securely communicating with a second device based on the first security material;

[0008] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0009] A second aspect of the embodiments of the present disclosure provides a communication method, which is performed by a second device and includes:

[0010] sending a third message to the first device;

[0011] wherein the third message is security-protected based on the first security material;

[0012] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0013] A third aspect of the present disclosure provides a communication method, which is performed by a third device and includes:

[0014] sending first security material to the first device;

[0015] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0016] According to a fourth aspect of the present disclosure, a first device is provided, including:

[0017] a first processing module, configured to determine a first security material and perform secure communication with a second device based on the first security material;

[0018] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0019] According to a fifth aspect of the present disclosure, a second device is provided, including:

[0020] A second transceiver module, configured to send a third message to the first device;

[0021] wherein the third message is security-protected based on the first security material;

[0022] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0023] According to a sixth aspect of the embodiments of the present disclosure, a third device is provided, including:

[0024] a third transceiver module, configured to send the first security material to the first device;

[0025] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0026] According to a seventh aspect of the embodiments of the present disclosure, a first device is provided, including:

[0027] one or more processors;

[0028] The first device is used to execute an optional implementation of the aforementioned first aspect.

[0029] According to an eighth aspect of the embodiments of the present disclosure, a second device is provided, including:

[0030] one or more processors;

[0031] The second device is used to execute the optional implementation of the aforementioned second aspect.

[0032] According to a ninth aspect of the embodiments of the present disclosure, a third device is provided, including:

[0033] one or more processors;

[0034] The third device is used to execute the optional implementation of the aforementioned third aspect.

[0035] In the tenth aspect of the embodiments of the present disclosure, a communication system is proposed, including: a first device, a second device and a third device, wherein the first device is used to implement the method described in the optional implementation manner of the first aspect, the second device is used to implement the method described in the optional implementation manner of the second aspect, and the third device is used to implement the method described in the optional implementation manner of the third aspect.

[0036] According to the eleventh aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, in which executable instructions are stored. The executable instructions are loaded and executed by the processor to implement the method described in the optional implementation of the aforementioned first aspect, second aspect, or third aspect.

[0037] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0039] FIG1a is a schematic structural diagram of a wireless communication system according to an exemplary embodiment;

[0040] FIG1b is a schematic diagram of a network topology architecture according to an exemplary embodiment;

[0041] FIG2a is a flow chart showing a communication method according to an exemplary embodiment;

[0042] FIG2b is a flow chart showing a communication method according to an exemplary embodiment;

[0043] FIG3a is a flow chart of a communication method according to an embodiment of the present disclosure;

[0044] FIG3 b is a flow chart of a communication method according to an embodiment of the present disclosure;

[0045] FIG3c is a flow chart of a communication method according to an embodiment of the present disclosure;

[0046] FIG3 d is a flow chart of a communication method according to an embodiment of the present disclosure;

[0047] FIG3e is a flow chart of a communication method according to an embodiment of the present disclosure;

[0048] FIG4a is a flow chart of a communication method according to an embodiment of the present disclosure;

[0049] FIG4 b is a flow chart of a communication method according to an embodiment of the present disclosure;

[0050] FIG4c is a flow chart of a communication method according to an embodiment of the present disclosure;

[0051] FIG5a is a flow chart of a communication method according to an embodiment of the present disclosure;

[0052] FIG5 b is a flow chart of a communication method according to an embodiment of the present disclosure;

[0053] FIG6a is a schematic structural diagram of a first device proposed in an embodiment of the present disclosure;

[0054] FIG6 b is a schematic structural diagram of a second device proposed in an embodiment of the present disclosure;

[0055] FIG6c is a schematic structural diagram of a third device proposed in an embodiment of the present disclosure;

[0056] FIG7a is a flow chart showing a communication method according to an exemplary embodiment;

[0057] FIG7b is a flow chart showing a communication method according to an exemplary embodiment;

[0058] FIG8a is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure;

[0059] FIG8 b is a schematic structural diagram of a chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0060] The embodiments of the present disclosure provide a communication method, a device, a communication system, and a storage medium.

[0061] In a first aspect, an embodiment of the present disclosure provides a communication method, which is performed by a first device and includes:

[0062] Identify the first safety material;

[0063] securely communicating with a second device based on the first security material;

[0064] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0065] In the above embodiment, the security protection method for communication between the first device and the second device is determined based on the security policy in the determined first security material, thereby achieving security protection for the communication.

[0066] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0067] A third message sent by the second device is received, wherein the third message is security-protected based on the first security material.

[0068] In conjunction with some embodiments of the first aspect, in some embodiments, determining the first security material includes:

[0069] sending a first message to a third device, where the first message is used to request the first security material;

[0070] A second message sent by the third device is received, where the second message carries the first security material.

[0071] In the above embodiment, when the first device cannot obtain the first security material for secure communication with the second device from the pre-configured security material based on the third message from the second device, the first device sends a first message to the third device to request the third device to provide the first security material for secure communication with the second device.

[0072] In conjunction with some embodiments of the first aspect, in some embodiments, determining the first security material includes:

[0073] The first security material is determined based on pre-configured security materials.

[0074] In the above embodiment, the first device may determine the first security material used for secure communication between the first device and the second device based on the pre-configured security material.

[0075] In conjunction with some embodiments of the first aspect, in some embodiments, determining the first security material further includes:

[0076] The first security material is obtained from a third device.

[0077] In the above embodiment, if the first security material used for secure communication between the first device and the second device cannot be obtained based on the pre-configured security material, the first device may also obtain the first security material from the third device to provide security for subsequent secure communication with the second device.

[0078] In conjunction with some embodiments of the first aspect, in some embodiments, obtaining the first security material from a third device includes:

[0079] sending a first message to the third device, where the first message is used to request the first security material;

[0080] A second message sent by the third device is received, where the second message carries the first security material.

[0081] In the above embodiment, the first device may request the third device to provide the first security material for secure communication with the second device by sending the first message to the third device.

[0082] In conjunction with some embodiments of the first aspect, in some embodiments, the first safety material further includes at least one of the following:

[0083] Credential information;

[0084] device information of the second device;

[0085] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0086] service information used by the second device;

[0087] Candidate security algorithms.

[0088] In the above embodiments, the first security material is bound to the second device information, or to the device information of the group to which the second device belongs, or to the service information used by the second device, providing different levels of security protection methods.

[0089] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0090] A first signal is sent to the second device, wherein the first signal is used to stimulate the second device to send the third message.

[0091] In the above embodiment, the first device sends the first signal to stimulate the second device to send the third message, so as to complete the communication between the first device and the second device.

[0092] With reference to some embodiments of the first aspect, in some embodiments, the third message includes any one of the following:

[0093] First information, used to indicate a link establishment request;

[0094] data collected by the second device;

[0095] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0096] In conjunction with some embodiments of the first aspect, in some embodiments, the third message further includes at least one of the following:

[0097] device information of the second device;

[0098] service information used by the second device;

[0099] candidate security algorithms supported by the second device;

[0100] a security policy used by the second device;

[0101] The security verification parameter is used to perform security protection on the third message.

[0102] In the above embodiment, the third message provides the first device with information for determining the first security material, ensuring that the first device can determine the first security material based on the information and perform secure communication with the second device.

[0103] In conjunction with some embodiments of the first aspect, in some embodiments, performing secure communication with the second device based on the first security material includes at least one of the following:

[0104] authenticating the second device based on the first security material;

[0105] The third message is verified based on the first security material.

[0106] In the above embodiment, the method further includes:

[0107] If the third message is verified successfully, sending a fourth message in response to the third message to the second device; or

[0108] If the second device is authenticated and the third message is verified, a fourth message in response to the third message is sent to the second device.

[0109] In combination with some embodiments of the first aspect, in some embodiments, the fourth message is security protected based on the first security material.

[0110] In conjunction with some embodiments of the first aspect, in some embodiments, the fourth message carries at least one of the following:

[0111] First indication information, used to indicate that the third message is successfully received;

[0112] security parameters, used to generate a security context negotiated between the second device and the first device;

[0113] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0114] First security strategy.

[0115] In the above embodiment, when the second device passes authentication and the third message passes verification, a fourth message is sent to the second device to inform the second device that the third message is successfully received, or to inform the second device of relevant information required for secure communication with the first device.

[0116] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0117] Receive data transmitted by the second device, where the data is protected by the negotiated security context.

[0118] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0119] If the second device fails authentication, or the third message fails verification, the third message is rejected or discarded.

[0120] In conjunction with some embodiments of the first aspect, in some embodiments, the security policy includes at least one of the following:

[0121] an integrity protection strategy for communication signals between the first device and the second device;

[0122] a confidentiality protection strategy for communication signals between the first device and the second device;

[0123] an integrity protection policy for user plane data between the first device and the second device;

[0124] A confidentiality protection policy for user plane data between the first device and the second device.

[0125] In the above embodiment, the security policy for protecting integrity and / or confidentiality of signals and / or data is included in the first security material so that the first device can determine the security protection method used for secure communication with the second device.

[0126] In combination with some embodiments of the first aspect, in some embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0127] In a second aspect, an embodiment of the present disclosure provides a communication method, which is performed by a second device and includes:

[0128] sending a third message to the first device;

[0129] wherein the third message is security-protected based on the first security material;

[0130] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0131] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0132] A first signal sent by the first device is received, wherein the first signal is used to stimulate the second device to send the third message.

[0133] With reference to some embodiments of the second aspect, in some embodiments, the third message includes any one of the following:

[0134] First information, used to indicate a link establishment request;

[0135] data collected by the second device;

[0136] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0137] In conjunction with some embodiments of the second aspect, in some embodiments, the third message further includes at least one of the following:

[0138] device information of the second device;

[0139] service information used by the second device;

[0140] candidate security algorithms supported by the second device;

[0141] a security policy used by the second device;

[0142] The security verification parameter is used to perform security protection on the third message.

[0143] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0144] Receive a fourth message sent by the first device in response to the third message.

[0145] In combination with some embodiments of the second aspect, in some embodiments, the fourth message is security protected based on the first security material.

[0146] In conjunction with some embodiments of the second aspect, in some embodiments, the fourth message carries at least one of the following:

[0147] First indication information, used to indicate that the third message is successfully received;

[0148] security parameters, used to generate a security context negotiated between the second device and the first device;

[0149] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0150] First security strategy.

[0151] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0152] Data is transmitted to the first device, the data being protected by the negotiated security context.

[0153] In conjunction with some embodiments of the second aspect, in some embodiments, the security policy includes at least one of the following:

[0154] an integrity protection strategy for communication signals between the first device and the second device;

[0155] a confidentiality protection strategy for communication signals between the first device and the second device;

[0156] an integrity protection policy for user plane data between the first device and the second device;

[0157] A confidentiality protection policy for user plane data between the first device and the second device.

[0158] In combination with some embodiments of the second aspect, in some embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0159] In a third aspect, an embodiment of the present disclosure provides a communication method, which is performed by a third device and includes:

[0160] sending first security material to the first device;

[0161] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0162] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes:

[0163] receiving a first message sent by the first device, where the first message is used to request first security material;

[0164] The sending of the first security material to the first device includes:

[0165] A second message is sent to the first device, where the second message carries the first security material.

[0166] In conjunction with some embodiments of the third aspect, in some embodiments, the first safety material further includes at least one of the following:

[0167] Credential information;

[0168] device information of the second device;

[0169] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0170] service information used by the second device;

[0171] Candidate security algorithms.

[0172] In conjunction with some embodiments of the third aspect, in some embodiments, the security policy includes at least one of the following:

[0173] an integrity protection strategy for communication signals between the first device and the second device;

[0174] a confidentiality protection strategy for communication signals between the first device and the second device;

[0175] an integrity protection policy for user plane data between the first device and the second device;

[0176] A confidentiality protection policy for user plane data between the first device and the second device.

[0177] In combination with some embodiments of the third aspect, in some embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0178] In a fourth aspect, an embodiment of the present disclosure provides a first device, including:

[0179] a first processing module, configured to determine a first security material and perform secure communication with a second device based on the first security material;

[0180] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0181] In a fifth aspect, an embodiment of the present disclosure provides a second device, including:

[0182] A second transceiver module, configured to send a third message to the first device;

[0183] wherein the third message is security-protected based on the first security material;

[0184] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0185] In a sixth aspect, an embodiment of the present disclosure provides a third device, including:

[0186] a third transceiver module, configured to send the first security material to the first device;

[0187] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0188] In a seventh aspect, an embodiment of the present disclosure provides a first device, including:

[0189] one or more processors;

[0190] The first device executes the method described in the optional implementation manner of the first aspect.

[0191] In an eighth aspect, an embodiment of the present disclosure provides a second device, including:

[0192] one or more processors;

[0193] The second device executes the method described in the optional implementation manner of the second aspect.

[0194] In a ninth aspect, an embodiment of the present disclosure provides a third device, including:

[0195] one or more processors;

[0196] The third device is used to execute the method described in the optional implementation manner of the third aspect.

[0197] In the tenth aspect, an embodiment of the present disclosure proposes a communication system, comprising a first device, a second device and a third device, wherein the first device is used to implement the method described in the optional implementation manner of the first aspect, the second device is used to implement the method described in the optional implementation manner of the second aspect, and the third device is used to implement the method described in the optional implementation manner of the third aspect.

[0198] In the eleventh aspect, an embodiment of the present disclosure proposes a storage medium, which stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the optional implementation of the first aspect, the second aspect, or the third aspect.

[0199] In a twelfth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the optional implementation manner of the first aspect or the second aspect.

[0200] In a thirteenth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first or second aspect.

[0201] In a fourteenth aspect, an embodiment of the present disclosure proposes a chip or a chip system, which includes a processing circuit for executing the method described in the optional implementation of the first or second aspect above.

[0202] In a fifteenth aspect, an embodiment of the present disclosure provides a communication method, where the method is performed by a communication system including a first device and a second device, and the method includes:

[0203] The second device sends a third message to the first device;

[0204] The first device determines a first security material based on the third message, and performs secure communication with the second device based on the first security material;

[0205] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0206] It is understandable that the above-mentioned apparatus for random access, communication equipment, communication system, storage medium, program product, and computer program are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here. Among them, the communication equipment can be a terminal or a network device.

[0207] The embodiments of the present disclosure provide a communication method, an apparatus, a communication device, a communication system, and a storage medium.

[0208] In some embodiments, terms such as communication method, information processing method, and random access can be replaced with each other; terms such as device for random access, information processing device, and communication device can be replaced with each other; and terms such as information processing system and communication system can be replaced with each other.

[0209] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the embodiments of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0210] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0211] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the embodiments of the present disclosure.

[0212] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0213] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0214] In some embodiments, the terms "at least one of", "at least one of", "at least one of", "one or more", "a plurality of", "multiple", etc. can be used interchangeably.

[0215] In the embodiments of the present disclosure, descriptions such as “at least one of A, B, C…”, “A and / or B and / or C…”, etc. include the situation where any one of A, B, C… exists alone, and also include any combination of any multiple of A, B, C…, and each situation can exist alone; for example, “at least one of A, B, C” includes the situation where A exists alone, B exists alone, C exists alone, the combination of A and B, the combination of A and C, the combination of B and C, and the combination of A, B, and C; for example, A and / or B includes the situation where A exists alone, B exists alone, and the combination of A and B.

[0216] In some embodiments, descriptions such as "in one case A, in another case B," or "in response to one case A, in response to another case B," may include the following technical solutions depending on the situation: executing A independently of B (in some embodiments, A); executing B independently of A (in some embodiments, B); selectively executing A and B (in some embodiments, selecting between A and B); and executing both A and B (in some embodiments, A and B). The same applies when there are more branches, such as A, B, and C.

[0217] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different. For another example, if the description object is "information", then the "first configuration" and the "second configuration" can be the same information or different information, and their contents can be the same or different.

[0218] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0219] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0220] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0221] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.

[0222] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.

[0223] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.

[0224] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, which can also be referred to as device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it can also be set as a structure in which the terminal has all or part of the functions of the access network device. In addition, languages ​​such as "uplink" and "downlink" can also be replaced with languages ​​corresponding to communication between terminals (for example, "side").

[0225] For example, an uplink channel, a downlink channel, etc. may be replaced by a side channel, and an uplink, a downlink, etc. may be replaced by a side link.

[0226] In some embodiments, terms such as "uplink", "uplink", "physical uplink" can be interchangeable with each other, and terms such as "downlink", "downlink", "physical downlink" can be interchangeable with each other, and terms such as "side", "sidelink", "side communication", "sidelink communication", "direct connection", "direct link", "direct communication", "direct link communication" can be interchangeable with each other.

[0227] In some embodiments, the terms "downlink control information (DCI)", "downlink (DL) assignment", "DL DCI", "uplink (UL) grant", "UL DCI" and the like may be used interchangeably.

[0228] In some embodiments, terms such as "physical downlink shared channel (PDSCH)" and "DL data" can be used interchangeably, and terms such as "physical uplink shared channel (PUSCH)" and "UL data" can be used interchangeably.

[0229] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values ​​(for example, comparison with a predetermined value), but is not limited thereto.

[0230] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0231] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0232] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0233] FIG1a is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.

[0234] As shown in FIG. 1 a , a communication system 100 includes a terminal 101 and a network device 102 .

[0235] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0236] In some embodiments, the network device 102 may include at least one of an access network device and a core network device.

[0237] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network. The network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0238] In some embodiments, the technical solutions of the embodiments of the present disclosure may be applicable to the Open RAN architecture. In this case, the interfaces between or within the network devices involved in the embodiments of the present disclosure may become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.

[0239] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0240] In some embodiments, the access network device may be a single device, or may be multiple devices or a group of devices, each including all or part of a first network element, a second network element, etc. The network element may be virtual or physical. The network device may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0241] In some embodiments, a core network device may be a device including one or more network elements, or may be multiple devices or device groups, each including all or part of the one or more network elements. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0242] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.

[0243] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1a, or a portion thereof, but are not limited thereto. The entities shown in FIG1a are illustrative only. The communication system may include all or a portion of the entities shown in FIG1a, or may include other entities other than those shown in FIG1a. The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0244] The embodiments of the present disclosure may be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), other systems utilizing random access, and next-generation systems based on and extending these systems. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0245] An ambient-powered IoT device is an IoT device powered by energy harvesting, either without a battery or with limited energy storage capabilities (e.g. using capacitors), by harvesting radio waves, light, motion, heat, or any other suitable power source.

[0246] Energy obtained from the environment can drive data transmission and wireless communication of sensing nodes. The current low-power IoT communication chips (such as BLE, LoRa, and NB-IoT) have a transmit and receive power consumption of tens or even hundreds of milliwatts, while the energy obtained by environmental energy harvesting is only at the microwatt level, which is unable to drive these types of nodes. Therefore, a new wireless communication technology is needed to reduce communication energy consumption to tens of microwatts or even less than ten microwatts. Currently, backscatter communication technology is mostly used.

[0247] Backscatter communications is one of the key technologies for building the future Internet of Things (IoT), which is energy-efficient, low-cost, and flexibly deployable. It is also an important means of achieving the "Intelligent Connection of Everything." Backscatter transmission is a technology that can be used.

[0248] Backscatter transmission utilizes the principle of RF signal backscattering to design extremely low-power modulation and transmission technologies. The reader sends a physical layer signal to the Ambient IoT (A-IoT) device. This physical layer signal can be any AC signal, such as a pulse signal.

[0249] In some embodiments, the physical layer signal is used to provide energy for the Ambient IoT (A-IoT) device to transmit signals. Therefore, the physical layer signal can be referred to as an excitation signal or a trigger signal. For example, since a portion of the excitation signal will be reflected when it reaches the A-IoT device, the A-IoT device can adjust the matching between the receiving antenna and the impedance according to the information to be sent, thereby enhancing the reflection of the incident excitation signal and modulating the sensory data it has acquired onto the reflected signal to complete the transmission of the data. This process is similar to a reflector. Compared with other communication technologies, backscatter transmission does not require a complex RF structure, reducing the use of devices such as power amplifiers, high-precision crystal oscillators, duplexers, and high-precision filters. It also does not require complex baseband processing. Therefore, it can simplify the design of A-IoT devices and significantly reduce the cost of Ambient IoT device nodes. A-IoT devices are IoT devices that work using environmental energy. This environmental energy may include the signal energy of the aforementioned wireless signal, and may also include other environmental capabilities such as geothermal energy and / or light energy. A-IoT devices are devices that use a backscatter transmission mechanism for wireless communication.

[0250] In some embodiments, a network topology architecture for wireless communications based on ambient energy devices is implemented using backscatter technology. For example, the network topology illustrated in Figure 1b supports direct bidirectional communication between an ambient IoT device and a base station; this bidirectional communication can be downlink (DL) and uplink (UL). Communications between the base station and the ambient IoT device include ambient IoT device data and / or signaling.

[0251] Based on the above topology, ambient IoT devices can transmit and report sensor data or their identities to the core network (CN) and / or application servers. Before an A-IoT device transmits collected data or its identity, the A-IoT device and the base station should be able to establish a security context based on the provided security materials and security policies. However, there is currently no solution for how to provide security policies and security materials.

[0252] Based on the above wireless communication system, various embodiments of the communication method proposed in the present disclosure are described in detail below.

[0253] FIG2a is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2a , the communication method is used in a communication system 100, and the method includes:

[0254] S201. A first device sends a first signal to a second device.

[0255] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0256] The term "stimulation" herein may be understood as a trigger. The first signal may be a signal for triggering the second device to send a message. The first signal may also be described as a trigger signal.

[0257] In some embodiments, the first signal may provide wireless transmission energy to the second device, so that the second device uses the energy of the first signal to send a message.

[0258] In some embodiments, the first signal may be a signal that does not carry any information, such as a pulse signal.

[0259] In some embodiments, the first device may broadcast, multicast, or unicast the first signal.

[0260] In some embodiments, assuming that the first device is an access network device and / or a relay device or an auxiliary node at a fixed location, the first signal may be broadcast, multicast, or unicast periodically or irregularly.

[0261] In some embodiments, the first signal is used to motivate the second device to return a third message.

[0262] In some embodiments, the second device receives the first signal.

[0263] S202. The second device sends a third message to the first device.

[0264] In some embodiments, the third message includes data collected by the second device.

[0265] In some embodiments, the data collected by the second device may include business data and / or device data of the second device, but is not limited thereto.

[0266] In some embodiments, the third message may further include at least one of the following:

[0267] device information of the second device;

[0268] service information used by the second device;

[0269] candidate security algorithms supported by the second device;

[0270] a security policy used by the second device;

[0271] The security verification parameter is used to perform security protection on the third message.

[0272] In some embodiments, security protection, for the sender, can be understood as encryption and / or integrity protection of the sent signal and / or data; for the receiver, it can be understood as decryption and / or integrity verification of the received signal and / or data.

[0273] In some embodiments, the second device may utilize the security verification parameter to encrypt or encode the third message, but is not limited thereto.

[0274] In some embodiments, the device information of the second device may include at least one of the following:

[0275] Identification information, indicating identity information of the second device;

[0276] Service information indicates service information performed between the first device and the second device.

[0277] In some embodiments, the service information used by the second device may include service identification information indicating the service used by the second device.

[0278] For example, the service ID is used when taking inventory of the second device in a specific park, or the service ID is called when obtaining data collected by the second device.

[0279] In some embodiments, the security algorithm may include an algorithm identifier and / or an algorithm type.

[0280] Optionally, the algorithm type may include but is not limited to an integrity encryption algorithm, a confidentiality encryption algorithm, and / or a scrambling algorithm.

[0281] In some embodiments, the security verification parameter may be a MAC value.

[0282] Optionally, the second device may use a MAC value to protect or encode the third message.

[0283] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0284] S203: The first device performs secure communication with the second device based on the first security material.

[0285] In some embodiments, the first security material is the security material corresponding to the second device, and different second devices may correspond to different first security materials.

[0286] In some embodiments, the name of the security material is not limited, and may be, for example, security information, security data, policy and security material, or second information, etc. The second information may be any information used for security protection and / or security verification.

[0287] In some embodiments, a communication signal (also described as a signal, message, etc.) and / or data sent by the first device to the second device is securely protected using a first security material. Optionally, the security protection may include at least one of integrity protection and confidentiality protection.

[0288] In some embodiments, the first device performs security verification on the communication signal (also described as a signal, message, etc.) and / or data from the second device using the first security material. Optionally, the security verification may include at least one of integrity verification and confidentiality verification.

[0289] In some embodiments, if the security protection mode of the third message is integrity protection, the first device needs to verify whether the third message has been tampered with or whether the third message is damaged after receiving the third message.

[0290] In some embodiments, if the security protection mode of the third message is confidentiality protection, the first device needs to verify whether the third message can be correctly decoded / decrypted after receiving the third message.

[0291] In some embodiments, if the third message verification passes, step S204 is executed.

[0292] In some embodiments, the first device may determine the first security material based on pre-configured security material.

[0293] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0294] In some embodiments, the security policy in the first security material is a preconfigured security policy.

[0295] Optionally, the first device may obtain a pre-configured security policy.

[0296] In some embodiments, the first device may determine the first security material corresponding to the second device from pre-configured security materials.

[0297] In some embodiments, the first device is pre-configured with multiple sets of security materials, and the first security material corresponding to the second device can be obtained according to the relevant information of the second device.

[0298] Optionally, the relevant information of the second device may include at least one of device information of the second device (eg, second device ID), information of the group to which the second device belongs (eg, group ID), and service information used by the second device (eg, service ID).

[0299] In some embodiments, the first device may unicast a first signal to a second device, and determine the first security material corresponding to the second device or the group to which the second device belongs from pre-configured security materials.

[0300] In some embodiments, the first device may broadcast a first signal to the second device, and after receiving a third message sent by a second device, determine the first security material corresponding to the second device or the group to which the second device belongs from pre-configured security materials.

[0301] In some embodiments, based on the device information of a specific second device, or the information of the group to which a specific A-IOT device belongs, or the service information of the service to which a specific A-IOT device belongs, the corresponding security material is searched in the pre-configured security materials.

[0302] For example, based on the ID of a specific A-IoT device, or based on the group ID of the group to which a specific A-IOT device belongs, or based on the service ID of the service to which a specific A-IOT device belongs, the security material corresponding to the ID can be searched in the pre-configured security materials.

[0303] In some embodiments, the security policy includes at least one of the following:

[0304] an integrity protection strategy for communication signals between the first device and the second device;

[0305] a confidentiality protection strategy for communication signals between the first device and the second device;

[0306] an integrity protection policy for user plane data between the first device and the second device;

[0307] A confidentiality protection policy for user plane data between the first device and the second device.

[0308] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is required protection. Optionally, the security policy is a signal integrity protection policy, and the security policy is configured to require protection.

[0309] In some embodiments, if the privacy (also described as confidentiality) security policy is configured to require protection, the first device is only allowed to establish a connection with the second device using a non-NULL privacy algorithm.

[0310] In some embodiments, if the integrity security policy is configured to require protection, the first device is only allowed to establish a connection with the second device using a non-NULL integrity algorithm.

[0311] In some embodiments, if the confidentiality and integrity security policy is configured to require protection, the first device is only allowed to establish a connection with the second device that uses a non-NULL confidentiality and integrity algorithm.

[0312] In some embodiments, the security policy for determining the security protection method for communication between the first device and the second device is configured to NOT NEEDED protection.

[0313] In some embodiments, if the security policy is configured to not require protection, the first device only establishes a connection without security protection.

[0314] In some embodiments, if the confidentiality security policy is configured to not require protection, the first device only establishes a connection with the second device without security protection.

[0315] In some embodiments, if the integrity security policy is configured to not require protection, the first device only establishes a connection with the second device without security protection.

[0316] In some embodiments, if the confidentiality and integrity security policy is configured to not require protection, the first device simply establishes a connection with the second device without security protection.

[0317] In some embodiments, the security policy for determining a security protection method for communications between the first device and the second device is configured as optional (PREFERRED) protection.

[0318] In some embodiments, if the security policy is configured as optional protection, the first device may attempt to establish a connection with security protection, or accept a connection without security protection. At this time, the first device may negotiate with the second device to determine the specific security protection method, or the first device may determine whether to turn on or off the security policy configured as optional protection.

[0319] In some embodiments, if the confidentiality security policy is configured as optional protection, the first device may determine whether to turn the confidentiality security policy on or off.

[0320] Optionally, if the first device determines to enable the confidentiality security policy, the first device is only allowed to establish a connection with a second device that uses a non-NULL confidentiality algorithm.

[0321] Optionally, if the first device determines to turn off the confidentiality security policy, the first device only establishes a connection without security protection with the second device.

[0322] In some embodiments, if the integrity security policy is configured as optional protection, the first device may determine whether to turn the integrity security policy on or off.

[0323] Optionally, if the first device determines to enable the integrity security policy, the first device is only allowed to establish a connection with a second device that uses a non-NULL integrity algorithm.

[0324] In some embodiments, if the first device determines to turn off the integrity security policy, the first device only establishes a connection without security protection with the second device.

[0325] In the above embodiments, the confidentiality and / or integrity security policy may be a security policy for the communication signal between the first device and the second device, or a security policy for the user plane data between the first device and the second device, or a security policy for the communication signal and user plane data between the first device and the second device.

[0326] In the above embodiments, the first security material may further include at least one of the following:

[0327] Credential information;

[0328] device information of the second device;

[0329] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0330] service information used by the second device;

[0331] Candidate security algorithms.

[0332] In some embodiments, the credential information may include at least one of a root key and a symmetric key.

[0333] In some embodiments, the first security material may include device information of a group of devices. Optionally, the device information of a group of devices may be identification information of a group of devices, such as a set of IDs of the group of devices, or a group ID of the group.

[0334] In some embodiments, the second device may be one of the group of devices.

[0335] S204. The first device sends a fourth message to the second device.

[0336] In some embodiments, the first device sends a fourth message to the second device in response to the third message.

[0337] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0338] Optionally, the fourth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0339] In some embodiments, the fourth message may be an ACK message.

[0340] In the above embodiment, the first device can obtain a preconfigured security policy for determining a security protection method for communicating with the second device based on preconfigured security materials, and when receiving a report message from the second device, it can send a message to the second device carrying first indication information indicating that the report message has been successfully received.

[0341] In some embodiments, the above method may further include:

[0342] S200 (not shown in the figure): the first device obtains the first security material from the third device.

[0343] In some embodiments, the third device may be any one of a core network function (CN NF) entity and a third-party server (eg, an AAA server and an A-IoT application server (A-IoT AS)).

[0344] In some embodiments, the CN NF may include a Policy Control Function (PCF), an Access and Mobility Management Function (AMF), or an A-IoT Management Function (A-IoT MF).

[0345] Optionally, the first device can obtain security policies from network elements such as PCF, AMF, or A-IoT MF.

[0346] Optionally, the first device may also obtain a security policy from a third-party server such as an AAA server or an A-IoT AS.

[0347] In some embodiments, the third device may provide a security policy for communicating with the second device by configuring a list of applications / services of the second device that require security protection and a security policy for each second device in the list.

[0348] Optionally, the second device may be an ambient Internet of Things (A-IoT) device.

[0349] In some embodiments, if the third device is a CN NF (eg, PCF or A-IoT MF), the first security material may be pre-provided to the CN NF by the AAA server or the A-IoT AS.

[0350] In some embodiments, step S200 may be performed before the above-mentioned step S203 .

[0351] In some embodiments, the first device may determine whether to send the first message to the third device based on the third message.

[0352] In some embodiments, when the first device receives the third message, it can determine whether there is the first security material corresponding to the second device or the group to which the second device belongs based on the pre-configured security material. If not, it sends the first message to the third device, requesting the third device to provide the first security material corresponding to the second device or the group to which the second device belongs.

[0353] Optionally, if the first device fails to find the corresponding first security material in the pre-configured security materials based on the device information of the second device in the third message, the first device requests the third device to provide the first security material.

[0354] In some embodiments, if the third message is security-protected (e.g., integrity-protected) based on the first security material, the first device may request the security material that the first device can use from the third device, or request the security material corresponding to the second device from the third device based on part of the content in the third message (e.g., information related to the second device), and then perform integrity verification.

[0355] The information related to the second device may be any one or more of the following:

[0356] Device information of the second device; service information used by the second device; and information of the group to which the second device belongs.

[0357] In some embodiments, the above step S200 may be performed before step S201.

[0358] In some embodiments, the first device may request a third device to provide security materials, and after receiving a third message from the second device, determine the first security material corresponding to the second device or the group to which the second device belongs from the provided security materials based on the relevant information of the second device in the third message.

[0359] In some embodiments, the first device may obtain any one or more of the following information from the third message:

[0360] device information of the second device;

[0361] service information used by the second device;

[0362] Information about the group to which the second device belongs.

[0363] Optionally, the first device may obtain multiple sets of security materials from the third device, and after receiving the third message sent by the second device, determine the first security material corresponding to the second device from the multiple sets of security materials.

[0364] In some embodiments, the first message may include at least one of the following information:

[0365] device information of the first device;

[0366] device information of the second device;

[0367] service information used by the second device;

[0368] Information about the group to which the second device belongs.

[0369] In some embodiments, the device information of the first device is used to inform the third device that it needs to provide security materials to the first device.

[0370] In some embodiments, the relevant information of the second device is used to inform the third device that the security material to be provided is related to the second device.

[0371] Optionally, the relevant information of the second device includes at least one of: device information, used service information, and information of the group to which the second device belongs.

[0372] In some embodiments, step S200 may include:

[0373] S200-1. The first device sends a first message to the third device.

[0374] In some embodiments, the first message is used to request the third device to provide the first security material.

[0375] In some embodiments, the first message may be a security material request message, but the message name is not limited thereto.

[0376] S200-2. The third device sends a second message to the first device.

[0377] In some embodiments, the second message is a response message to the first message.

[0378] In some embodiments, the second message may be a security material response message, but the message name is not limited thereto.

[0379] In some embodiments, the third device may transmit the first security material to the first device by including it in a second message in response to the first message.

[0380] In some embodiments, the above method may further include: the first device rejecting or discarding the third message.

[0381] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", and "data" can be used interchangeably.

[0382] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0383] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.

[0384] In some embodiments, terms such as "in the case of", "at the time of", "when", "if", and "if" can be used interchangeably.

[0385] The method according to the embodiments of the present disclosure may include at least one of steps S200-1 to S204. For example, step S203 may be implemented as an independent embodiment, steps S201, S202, and S203 may be implemented as independent embodiments, and steps S200-1, S200-2, S201, S202, and S203 may be implemented as independent embodiments, but are not limited thereto.

[0386] In some embodiments, steps S201 and S202 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0387] In some embodiments, steps S200 - 1 and S200 - 2 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0388] In some embodiments, step S204 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0389] FIG2b is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2b , the communication method is used in a communication system 100, and the method includes:

[0390] S211. The first device sends a first signal to the second device.

[0391] The optional implementation of step S211 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0392] S212. The second device sends a third message to the first device.

[0393] In some embodiments, the third message includes data collected by the second device

[0394] In some embodiments, the third message includes: first information for indicating a link establishment request

[0395] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request. Optionally, the first information is used to request to establish a link with the first device.

[0396] In some embodiments, the first information may be carried in a field or information domain of the third message. Optionally, the first information may be indicated by a 1-bit value, for example, a bit value of "1" indicates that the first device requests to establish a link with the first device.

[0397] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0398] In some embodiments, the third message further includes at least one of the following:

[0399] device information of the second device;

[0400] service information used by the second device;

[0401] candidate security algorithms supported by the second device;

[0402] a security policy used by the second device;

[0403] The security verification parameter is used to perform security protection on the third message.

[0404] In some embodiments, the device information of the second device may include at least one of the following:

[0405] Identification information, indicating identity information of the second device;

[0406] Service information indicates service information performed between the first device and the second device.

[0407] In some embodiments, the service information used by the second device may include service identification information indicating the service used by the second device.

[0408] For example, the service ID is used when taking inventory of the second device in a specific park, or the service ID is called when obtaining data collected by the second device.

[0409] In some embodiments, the security algorithm may include an algorithm identifier and / or an algorithm type.

[0410] Optionally, the algorithm type may include but is not limited to an integrity encryption algorithm, a confidentiality encryption algorithm, and / or a scrambling algorithm.

[0411] Optionally, the algorithm identifier is used to indicate the algorithm used for integrity protection and / or the algorithm used for confidentiality protection.

[0412] In some embodiments, the security verification parameter may be a MAC value.

[0413] Optionally, the second device may use a MAC value to protect or encode the third message.

[0414] In some embodiments, the first device may determine the first security material based on pre-configured security material.

[0415] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0416] In some embodiments, based on the device information of a specific second device, or the information of the group to which a specific A-IOT device belongs, or the service information of the service to which a specific A-IOT device belongs, the corresponding security material is searched in the pre-configured security materials.

[0417] For example, based on the ID of a specific A-IoT device, or based on the group ID of the group to which a specific A-IOT device belongs, or based on the service ID of the service to which a specific A-IOT device belongs, the security material corresponding to the ID can be searched in the pre-configured security materials.

[0418] In some embodiments, the security policy includes at least one of the following:

[0419] an integrity protection strategy for communication signals between the first device and the second device;

[0420] a confidentiality protection strategy for communication signals between the first device and the second device;

[0421] an integrity protection policy for user plane data between the first device and the second device;

[0422] A confidentiality protection policy for user plane data between the first device and the second device.

[0423] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is required protection. Optionally, the security policy is a signal integrity protection policy, and the security policy is configured to require protection.

[0424] In some embodiments, if the privacy (also described as confidentiality) security policy is configured to require protection, the first device is only allowed to establish a connection with the second device using a non-NULL privacy algorithm.

[0425] In some embodiments, if the integrity security policy is configured to require protection, the first device is only allowed to establish a connection with the second device using a non-NULL integrity algorithm.

[0426] In some embodiments, if the confidentiality and integrity security policy is configured to require protection, the first device is only allowed to establish a connection with the second device that uses a non-NULL confidentiality and integrity algorithm.

[0427] In some embodiments, the security policy for determining the security protection method for communication between the first device and the second device is configured to NOT NEEDED protection.

[0428] In some embodiments, if the security policy is configured to not require protection, the first device only establishes a connection without security protection.

[0429] In some embodiments, if the confidentiality security policy is configured to not require protection, the first device only establishes a connection with the second device without security protection.

[0430] In some embodiments, if the integrity security policy is configured to not require protection, the first device only establishes a connection with the second device without security protection.

[0431] In some embodiments, if the confidentiality and integrity security policy is configured to not require protection, the first device simply establishes a connection with the second device without security protection.

[0432] In some embodiments, the security policy for determining a security protection method for communications between the first device and the second device is configured as optional (PREFERRED) protection.

[0433] In some embodiments, if the security policy is configured as optional protection, the first device may attempt to establish a connection with security protection, or accept a connection without security protection. At this time, the first device may negotiate with the second device to determine the specific security protection method, or the first device may determine whether to turn on or off the security policy configured as optional protection.

[0434] In some embodiments, if the confidentiality security policy is configured as optional protection, the first device may determine whether to turn the confidentiality security policy on or off.

[0435] Optionally, if the first device determines to enable the confidentiality security policy, the first device is only allowed to establish a connection with a second device that uses a non-NULL confidentiality algorithm.

[0436] Optionally, if the first device determines to turn off the confidentiality security policy, the first device only establishes a connection without security protection with the second device.

[0437] In some embodiments, if the integrity security policy is configured as optional protection, the first device may determine whether to turn the integrity security policy on or off.

[0438] Optionally, if the first device determines to enable the integrity security policy, the first device is only allowed to establish a connection with a second device that uses a non-NULL integrity algorithm.

[0439] In some embodiments, if the first device determines to turn off the integrity security policy, the first device only establishes a connection without security protection with the second device.

[0440] In the above embodiments, the confidentiality and / or integrity security policy may be a security policy for the communication signal between the first device and the second device, or a security policy for the user plane data between the first device and the second device, or a security policy for the communication signal and user plane data between the first device and the second device.

[0441] In the above embodiments, the first security material may further include at least one of the following:

[0442] Credential information;

[0443] device information of the second device;

[0444] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0445] service information used by the second device;

[0446] Candidate security algorithms.

[0447] In some embodiments, the credential information may include at least one of a root key and a symmetric key.

[0448] In some embodiments, the first security material may include device information of a group of devices. Optionally, the device information of a group of devices may be identification information of a group of devices, such as a set of IDs of the group of devices, or a group ID of the group.

[0449] In some embodiments, the second device may be one of the group of devices.

[0450] S213: The first device authenticates the second device and / or verifies the third message based on the first security material.

[0451] In some embodiments, the third message may be protected using security verification parameters.

[0452] In some embodiments, if the security verification parameter that can be generated by the first device according to the third message and the first security material is the same as the security verification parameter in the third message, the third message is verified successfully.

[0453] Optionally, if the security protection mode of the third message is integrity protection, the first device needs to verify whether the third message is tampered with or whether the third message is damaged after receiving the third message.

[0454] Exemplarily, if the third message has not been tampered with or damaged, it is determined that the verification is successful (ie, the verification is passed); otherwise, the verification fails (ie, the verification is not passed).

[0455] In some embodiments, if the security protection mode of the third message is confidentiality protection, the first device needs to verify whether the third message can be correctly decoded after receiving the third message.

[0456] Exemplarily, if the third message can be decoded correctly, it is determined that the verification is successful (ie, the verification is passed); otherwise, the verification fails (ie, the verification is not passed).

[0457] In some embodiments, the first device may authenticate whether the second device is a legitimate device based on the device information in the first security material.

[0458] Optionally, if the received device information of the second device is included in the device information included in the first security material, or can be mapped to a device information in the device information of the second device included in the first security material, the second device is determined to be a legal device, that is, the second device is authenticated; otherwise, the authentication fails (that is, the authentication fails), and the second device is determined to be an illegal device (can also be described as an illegal device).

[0459] In some embodiments, if the second device is authenticated as a legitimate device and the third message verification passes, step S214 is executed.

[0460] Optionally, if the received device information of the second device is included in the device information included in the first security material, or can be mapped to a piece of device information of the second device included in the first security material, and the security verification parameter verification passes, step S214 is executed.

[0461] S214. The first device sends a fourth message to the second device.

[0462] In some embodiments, the first device sends a fourth message to the second device in response to the third message.

[0463] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0464] In some embodiments, if the fourth message includes: first indication information for indicating that the third message is successfully received, the fourth message may also include: security parameters for generating a security context negotiated between the second device and the first device.

[0465] Optionally, the fourth message includes success indication information and security parameters used to generate a security context negotiated between the second device and the first device.

[0466] In some embodiments, the fourth message may further include at least one of the following:

[0467] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0468] First security strategy.

[0469] In some embodiments, the security parameters may include, but are not limited to, an algorithm identifier and / or an algorithm length.

[0470] Optionally, the algorithm identifier is used to indicate the algorithm used for integrity protection and / or the algorithm used for confidentiality protection.

[0471] In some embodiments, the first security algorithm can be determined based on the candidate security algorithms supported by the second device and the candidate security algorithms in the first security material, for example: selecting a security algorithm that appears in both the candidate security algorithms supported by the second device and the candidate security algorithms in the first security material.

[0472] In some embodiments, the candidate security algorithms may be ranked from high to low according to their respective priorities.

[0473] In some embodiments, the first security policy may be determined by the first device.

[0474] In some embodiments, the first device may further inform the second device of the security policy determined by the first device, that is, the first security policy.

[0475] Optionally, the first security policy is one of the candidate security policies included in the first security material. For example, the security policy is configured to not require protection, or to require protection.

[0476] Optionally, the first security policy can be determined based on the security policy used by the second device and the candidate security policy in the first security material. For example, if a candidate security policy in the first security material and the security policy used by the second device are both configured as optional protection, the first device can determine whether to enable the security policy.

[0477] In some embodiments, if one of the candidate security policies in the first security material is the integrity security policy of the user plane data between the first device and the second device, and the security policy used by the second device is the integrity security policy of the user plane data between the second device and the first device, and the integrity security policy of the user plane data is configured as optional protection, the first device can determine whether to enable the integrity security policy of the user plane data.

[0478] Optionally, if the first device determines to enable the integrity security policy for the user plane data, the first device is only allowed to establish a connection with the second device that uses a non-NULL integrity algorithm.

[0479] In some embodiments, the first device may respond to the second device with an ACK message. Alternatively, the first device may send an ACK message to the second device to inform the second device that the third message is successfully received.

[0480] In some embodiments, the ACK message is security-protected based on the first security material. Optionally, the ACK is protected or encoded by the first security material.

[0481] S215: The second device transmits data to the first device by using the negotiated security context.

[0482] In some embodiments, the second device may generate a security context negotiated between the second device and the first device based on the security parameters in the fourth message, and transmit the UL data by using the negotiated security context.

[0483] In some embodiments, the above method may further include:

[0484] S210 (not shown in the figure): the first device obtains the first security material from the third device.

[0485] The optional implementation of step S210 can refer to the optional implementation of step S200 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0486] In some embodiments, the third device may be any one of a CN NF entity (e.g., PCF, AMF, A-IoT MF) and a third-party server (e.g., AAA server, A-IoT AS).

[0487] In some embodiments, step S210 may be performed before the above-mentioned step S213.

[0488] In some embodiments, the first device may determine whether to send the first message to the third device based on the third message.

[0489] In some embodiments, after receiving the third message, the first device may determine whether there is the first security material corresponding to the second device based on the pre-configured security material. If not, the first device may send the first message to the third device, requesting the third device to provide the first security material.

[0490] Optionally, if the first device fails to find the corresponding first security material in the pre-configured security materials based on the device information of the second device in the third message, the first device requests the third device to provide the first security material.

[0491] In some embodiments, the above step S210 may be performed before step S211.

[0492] In some embodiments, the above method may further include: the first device rejecting or discarding the third message.

[0493] In some embodiments, if the received device information of the second device is not included in the device information included in the first security material, or cannot be mapped to one of the device information of the second device included in the first security material, the second device is an illegal device (also described as an illegal device), so the third message is rejected or discarded.

[0494] In some embodiments, if the security verification parameter fails to be verified (ie, the verification fails), the third message is rejected or discarded.

[0495] Optionally, the security verification parameter can be a MAC value, which is generated based on the third message and security material. If the third message is tampered with or damaged, the same MAC value as in the third message cannot be generated, thereby determining that the security verification parameter verification has failed.

[0496] In some embodiments, if the received device information of the second device is not included in the device information included in the first security material, or cannot be mapped to one of the device information of the second device included in the first security material, and the security verification parameter verification fails, the third message is rejected or discarded.

[0497] The method involved in the embodiments of the present disclosure may include at least one of steps S210 to S215. For example, step S213 can be implemented as an independent embodiment, steps S211, S212, and S213 can be implemented as independent embodiments, steps S211, S212, S213, and S214 can be implemented as independent embodiments, steps S210, S211, S212, and S213 can be implemented as independent embodiments, and steps S210, S211, S212, S213, and S214 can be implemented as independent embodiments, but are not limited thereto.

[0498] In some embodiments, steps S211 and S212 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0499] In some embodiments, step S210 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0500] In some embodiments, step S214 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0501] In some embodiments, step S215 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0502] FIG3a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3a, the communication method can be executed by a first device, and the method includes:

[0503] S301. Send a first signal to a second device.

[0504] The optional implementation of step S301 can refer to the optional implementation of step S201 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0505] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0506] S302: Receive a third message sent by the second device.

[0507] The optional implementation of step S302 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0508] In some embodiments, the third message includes data collected by the second device.

[0509] In some embodiments, the third message may further include at least one of the following:

[0510] device information of the second device;

[0511] service information used by the second device;

[0512] candidate security algorithms supported by the second device;

[0513] a security policy used by the second device;

[0514] The security verification parameter is used to perform security protection on the third message.

[0515] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0516] S303: The first device performs secure communication with the second device based on the first security material.

[0517] The optional implementation of step S303 can refer to the optional implementation of step S203 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0518] In some embodiments, the first device may obtain the first security material based on pre-configured security material.

[0519] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0520] In some embodiments, the security policy in the first security material is a preconfigured security policy.

[0521] Optionally, the first device may obtain a pre-configured security policy.

[0522] In some embodiments, based on the device information of a specific second device, or the information of the group to which a specific A-IOT device belongs, or the service information of the service to which a specific A-IOT device belongs, the corresponding security material is searched in the pre-configured security materials.

[0523] In some embodiments, the first security material may further include at least one of the following:

[0524] Credential information;

[0525] device information of the second device;

[0526] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0527] service information used by the second device;

[0528] Candidate security algorithms.

[0529] In this embodiment, the specific content of the security policy can refer to the relevant content in the embodiment involved in the optional implementation of step S203 in Figure 2a, and will not be repeated here.

[0530] S304: Send a fourth message to the second device.

[0531] The optional implementation of step S304 can refer to the optional implementation of step S204 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0532] In some embodiments, if the third message passes verification, a fourth message is sent to the second device.

[0533] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0534] Optionally, the fourth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0535] In some embodiments, the above method may further include: rejecting or discarding the third message.

[0536] In some embodiments, if the third message fails verification, the third message may be rejected or discarded.

[0537] FIG3b is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3b , the communication method may be executed by a first device, and the method includes:

[0538] S311. Send a first signal to a second device.

[0539] The optional implementation of step S311 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0540] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0541] S312: Receive a third message sent by the second device.

[0542] The optional implementation of step S312 can refer to the optional implementation of step S212 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0543] In some embodiments, the third message includes: first information for indicating a link establishment request.

[0544] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0545] In some embodiments, the third message may further include at least one of the following:

[0546] device information of the second device;

[0547] service information used by the second device;

[0548] candidate security algorithms supported by the second device;

[0549] a security policy used by the second device;

[0550] The security verification parameter is used to perform security protection on the third message.

[0551] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request.

[0552] In some embodiments, the first information may be carried in a field or information domain in the third message.

[0553] S313: The first device authenticates the second device and / or verifies the third message based on the first security material.

[0554] The optional implementation of step S313 can refer to the optional implementation of step S213 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0555] In some embodiments, the first device may obtain the first security material based on pre-configured security material.

[0556] In some embodiments, the security policy in the first security material is a preconfigured security policy.

[0557] Optionally, the first device may obtain a pre-configured security policy.

[0558] In this embodiment, the specific contents of the first security material and the security policy can be found in the optional implementation of step S203 in FIG. 2a or the optional implementation of step S213 in FIG. 2b and the related contents involved, which will not be repeated here.

[0559] S314. Send a fourth message to the second device.

[0560] The optional implementation of step S314 can refer to the optional implementation of step S214 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0561] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0562] In some embodiments, if the fourth message includes: first indication information for indicating that the third message is successfully received, the fourth message may also include: security parameters for generating a security context negotiated between the second device and the first device.

[0563] In some embodiments, the fourth message may further include at least one of the following:

[0564] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0565] First security strategy.

[0566] S315: Receive data sent by the second device.

[0567] The optional implementation of step S315 can refer to the optional implementation of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0568] In some embodiments, the above method may further include: rejecting or discarding the third message.

[0569] In some embodiments, if the second device is authenticated as an illegal device and / or the third message fails verification, the third message may be rejected or discarded.

[0570] Figure 3c is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 3c, the communication method can be performed by a first device, and the method includes:

[0571] S321. Send a first signal to a second device.

[0572] The optional implementation of step S321 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0573] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0574] S322. Receive a third message sent by the second device.

[0575] The optional implementation of step S322 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0576] In some embodiments, the third message includes data collected by the second device.

[0577] In some embodiments, the third message may further include at least one of the following:

[0578] device information of the second device;

[0579] service information used by the second device;

[0580] candidate security algorithms supported by the second device;

[0581] a security policy used by the second device;

[0582] The security verification parameter is used to perform security protection on the third message.

[0583] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0584] S323. Send the first message to the third device based on the third message.

[0585] The optional implementation of step S323 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0586] In some embodiments, the first device may obtain the first security material through a third device.

[0587] In some embodiments, the first message may include at least one of the following information:

[0588] device information of the first device;

[0589] device information of the second device;

[0590] service information used by the second device;

[0591] Information about the group to which the second device belongs.

[0592] S324. Receive a second message sent by a third device.

[0593] The optional implementation of step S324 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0594] In some embodiments, the second message is a response message to the first message.

[0595] In some embodiments, the third device may transmit the first security material to the first device by including it in a second message in response to the first message.

[0596] S325: The first device performs secure communication with the second device based on the first security material.

[0597] The optional implementation of step S325 can refer to the optional implementation of step S203 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0598] In this embodiment, the specific contents of the first security material and the security policy can be found in the optional implementation of step S203 in FIG. 2a or the optional implementation of step S213 in FIG. 2b and the related contents involved, which will not be repeated here.

[0599] S324. Send a fourth message to the second device.

[0600] The optional implementation of step S326 can refer to the optional implementation of step S204 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0601] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0602] Optionally, the fourth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0603] In some embodiments, the above method may further include: rejecting or discarding the third message.

[0604] In some embodiments, if the third message fails verification, the third message may be rejected or discarded.

[0605] Figure 3d is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 3d, the communication method can be executed by a first device, and the method includes:

[0606] S331. Send a first signal to a second device.

[0607] The optional implementation of step S331 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0608] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0609] S332. Receive a third message sent by the second device.

[0610] The optional implementation of step S332 can refer to the optional implementation of step S212 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0611] In some embodiments, the third message includes: first information for indicating a link establishment request.

[0612] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0613] In some embodiments, the third message may further include at least one of the following:

[0614] device information of the second device;

[0615] service information used by the second device;

[0616] candidate security algorithms supported by the second device;

[0617] a security policy used by the second device;

[0618] The security verification parameter is used to perform security protection on the third message.

[0619] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request.

[0620] In some embodiments, the first information may be carried in a field or information domain in the third message.

[0621] S333. Send the first message to the third device based on the third message.

[0622] The optional implementation of step S333 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0623] In some embodiments, the first device may obtain the first security material through a third device.

[0624] S334. Receive a second message sent by a third device.

[0625] The optional implementation of step S334 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0626] S335: The first device authenticates the second device and / or verifies the third message based on the first security material.

[0627] The optional implementation of step S335 can refer to the optional implementation of step S213 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0628] S336. Send a fourth message to the second device.

[0629] Optional implementations of step S336 can be found in step S214 of FIG. 2b , optional implementations of step S314 of FIG. 3b , and other related parts of the embodiments involved in FIG. 2b and FIG. 3b , which will not be described in detail here.

[0630] S337. Receive data sent by the second device.

[0631] The optional implementation of step S337 can refer to the optional implementation of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0632] In some embodiments, the above method may further include: rejecting or discarding the third message.

[0633] In some embodiments, if the second device is authenticated as an illegal device and / or the third message fails verification, the third message may be rejected or discarded.

[0634] Figure 3e is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 3e, the communication method can be performed by a first device, and the method includes:

[0635] S341. Determine the first safety material.

[0636] In some embodiments, the first security material includes a security policy, where the security policy is used to determine a security protection method for communication between the first device and the second device.

[0637] In some embodiments, the first security material may be determined based on pre-configured security materials.

[0638] In some embodiments, the first security material is obtained from a third device.

[0639] In some embodiments, the third device may be any one of a CN NF, an AAA server, and an A-IoT AS.

[0640] In some embodiments, obtaining the first security material from a third device includes:

[0641] sending a first message to the third device, where the first message is used to request the first security material;

[0642] A second message sent by the third device is received, where the second message carries the first security material.

[0643] In some embodiments, the method further comprises:

[0644] receiving a third message sent by the second device, wherein the third message is security-protected based on the first security material;

[0645] Determining to send the first message to the third device based on the third message.

[0646] In some embodiments, the first security material further comprises at least one of the following:

[0647] Credential information;

[0648] device information of the second device;

[0649] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0650] service information used by the second device;

[0651] Candidate security algorithms.

[0652] In some embodiments, the third message includes any of the following:

[0653] First information, used to indicate a link establishment request;

[0654] data collected by the second device;

[0655] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0656] In some embodiments, the third message includes at least one of the following:

[0657] device information of the second device;

[0658] service information used by the second device;

[0659] candidate security algorithms supported by the second device;

[0660] a security policy used by the second device;

[0661] The security verification parameter is used to perform security protection on the third message.

[0662] The above optional implementation methods can refer to the optional implementation methods of step S200-1 and step S200-2 in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0663] In some embodiments, the method further comprises:

[0664] A first signal is sent to the second device, wherein the first signal is used to stimulate the second device to send the third message.

[0665] The above optional implementation methods can refer to the optional implementation methods of step S201 and step S202 in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0666] S342: Perform secure communication with a second device based on the first security material.

[0667] The optional implementation of step S342 can refer to the optional implementation of step S203 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0668] In some embodiments, securely communicating with the second device based on the first security material includes at least one of the following:

[0669] authenticating the second device based on the first security material;

[0670] The third message is verified based on the first security material.

[0671] In some embodiments, the method further comprises:

[0672] If the third message is verified successfully, sending a fourth message in response to the third message to the second device; or

[0673] If the second device is authenticated and the third message is verified, a fourth message in response to the third message is sent to the second device.

[0674] The above optional implementation manner can refer to the optional implementation manner of step S204 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0675] In some embodiments, the fourth message is security-protected based on the first security material.

[0676] In some embodiments, the fourth message carries at least one of the following:

[0677] First indication information, used to indicate that the third message is successfully received;

[0678] security parameters, used to generate a security context negotiated between the second device and the first device;

[0679] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0680] First security strategy.

[0681] In some embodiments, the method further comprises:

[0682] Receive data transmitted by the second device, where the data is protected by the negotiated security context.

[0683] The above optional implementation manner can refer to the optional implementation manner of step S205 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0684] In some embodiments, the method further comprises:

[0685] If the second device fails authentication, or the third message fails verification, the third message is rejected or discarded.

[0686] The above optional implementation manner can refer to the optional implementation manner of step S206 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0687] In the above embodiment, the security policy includes at least one of the following:

[0688] an integrity protection strategy for communication signals between the first device and the second device;

[0689] a confidentiality protection strategy for communication signals between the first device and the second device;

[0690] an integrity protection policy for user plane data between the first device and the second device;

[0691] A confidentiality protection policy for user plane data between the first device and the second device.

[0692] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is protection required.

[0693] FIG4a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4a , the communication method may be performed by a second device, and the method includes:

[0694] S401: Receive a first signal sent by a first device.

[0695] The optional implementation of step S401 can refer to the optional implementation of step S201 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0696] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0697] S402: Send a third message to the first device.

[0698] The optional implementation of step S402 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0699] In some embodiments, the third message includes data collected by the second device.

[0700] In some embodiments, the third message may further include at least one of the following:

[0701] device information of the second device;

[0702] service information used by the second device;

[0703] candidate security algorithms supported by the second device;

[0704] a security policy used by the second device;

[0705] The security verification parameter is used to perform security protection on the third message.

[0706] In some embodiments, the third message is a report message, for example, a data report message or an identification report message.

[0707] In some embodiments, the third message is security-protected based on the first security material.

[0708] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0709] S403: Receive a fourth message sent by the first device.

[0710] The optional implementation of step S403 can refer to the optional implementation of step S204 in FIG2a and other related parts in the embodiment involved in FIG2a, which will not be described in detail here.

[0711] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0712] Optionally, the fourth message includes: first indication information, which is used to indicate that the third message is successfully received. The exemplary first indication information can also be described as success indication information.

[0713] FIG4 b is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4 b , the communication method may be performed by a second device, and the method includes:

[0714] S411. Receive a first signal sent by a first device.

[0715] The optional implementation of step S411 can refer to the optional implementation of step S201 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0716] In some embodiments, the first signal may be an excitation signal for the second device, and the first signal excites the second device to send designated information. That is, the second device may utilize the energy of the first signal to backscatter and transmit other signals.

[0717] S412: Send a third message to the first device.

[0718] The optional implementation of step S412 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0719] In some embodiments, the third message includes: first information for indicating a link establishment request.

[0720] In some embodiments, the third message may further include at least one of the following:

[0721] device information of the second device;

[0722] service information used by the second device;

[0723] candidate security algorithms supported by the second device;

[0724] a security policy used by the second device;

[0725] The security verification parameter is used to perform security protection on the third message.

[0726] In some embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0727] In some embodiments, the third message may include first information, where the first information is used to indicate a link establishment request.

[0728] In some embodiments, the first information may be carried in a field or information domain in the third message.

[0729] In some embodiments, the third message is security-protected based on the first security material.

[0730] In some embodiments, the first security material includes a security policy for determining a security protection method for communication between the first device and the second device.

[0731] S413. Receive a fourth message sent by the first device.

[0732] The optional implementation of step S413 can refer to the optional implementation of step S214 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0733] In some embodiments, the fourth message carries indication information for indicating whether the third message is received successfully or failed.

[0734] In some embodiments, if the fourth message includes: first indication information for indicating that the third message is successfully received, the fourth message may also include: security parameters for generating a security context negotiated between the second device and the first device.

[0735] In some embodiments, the fourth message may further include at least one of the following:

[0736] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0737] First security strategy.

[0738] S414: Transmit data to the first device.

[0739] The optional implementation of step S414 can refer to the optional implementation of step S215 in Figure 2b and other related parts in the embodiment involved in Figure 2b, which will not be repeated here.

[0740] In some embodiments, the second device may generate a security context negotiated between the second device and the first device based on the security parameters in the fourth message.

[0741] In some embodiments, the second device may transmit UL data by using the negotiated security context.

[0742] Figure 4c is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 4c, the method involved in the embodiment of the present disclosure is performed by the second device, and the method includes:

[0743] S421. Send a third message to the first device.

[0744] In some embodiments, the third message is security-protected based on the first security material.

[0745] The optional implementation of step S421 can refer to the optional implementation of step S202 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0746] In some embodiments, the first security material includes a security policy, where the security policy is used to determine a security protection method for communication between the first device and the second device.

[0747] In some embodiments, it further includes:

[0748] A first signal sent by the first device is received, wherein the first signal is used to stimulate the second device to send the third message.

[0749] For the optional implementation of the above optional embodiment, reference may be made to the optional implementation of step S201 in FIG. 2 a and other related parts of the embodiment involved in FIG. 2 a , which will not be described in detail here.

[0750] In some embodiments, the third message includes any of the following:

[0751] First information, used to indicate a link establishment request;

[0752] data collected by the second device;

[0753] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0754] In some embodiments, the third message further includes at least one of the following:

[0755] device information of the second device;

[0756] service information used by the second device;

[0757] candidate security algorithms supported by the second device;

[0758] a security policy used by the second device;

[0759] The security verification parameter is used to perform security protection on the third message.

[0760] In some embodiments, it further includes:

[0761] Receive a fourth message sent by the first device in response to the third message.

[0762] For the optional implementation of the above optional embodiment, reference may be made to the optional implementation of step S204 in FIG. 2 a and other related parts of the embodiment involved in FIG. 2 a , which will not be described in detail here.

[0763] In some embodiments, the fourth message is security-protected based on the first security material.

[0764] In some embodiments, the fourth message carries at least one of the following:

[0765] First indication information, used to indicate that the third message is successfully received;

[0766] security parameters, used to generate a security context negotiated between the second device and the first device;

[0767] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0768] First security strategy.

[0769] In some embodiments, the method further comprises:

[0770] Data is transmitted to the first device, the data being protected by the negotiated security context.

[0771] For the optional implementation of the above optional embodiment, reference may be made to the optional implementation of step S205 in FIG. 2 a and other related parts of the embodiment involved in FIG. 2 a , which will not be described in detail here.

[0772] In the above embodiment, the security policy includes at least one of the following:

[0773] an integrity protection strategy for communication signals between the first device and the second device;

[0774] a confidentiality protection strategy for communication signals between the first device and the second device;

[0775] an integrity protection policy for user plane data between the first device and the second device;

[0776] A confidentiality protection policy for user plane data between the first device and the second device.

[0777] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is protection required.

[0778] Figure 5a is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in Figure 5a, the communication method can be performed by a third device, and the method includes:

[0779] S501: Receive a first message sent by a first device.

[0780] The optional implementation of step S501 can refer to the optional implementation of step S200-1 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0781] In some embodiments, the first message is used to request the third device to provide the first security material.

[0782] In some embodiments, the first message may be a security material request message, but the message name is not limited thereto.

[0783] In this embodiment, the first message may include at least one of the following information:

[0784] device information of the first device;

[0785] device information of the second device;

[0786] service information used by the second device;

[0787] Information about the group to which the second device belongs.

[0788] S502: Send a second message to the first device.

[0789] The optional implementation of step S502 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0790] In some embodiments, the second message carries the first security material.

[0791] In some embodiments, the third device may transmit the first security material to the first device by including it in a second message in response to the first message.

[0792] In this embodiment, the specific contents of the first security material and the security policy can be found in the optional implementation of step S203 in FIG. 2a or the optional implementation of step S213 in FIG. 2b and the related contents involved, which will not be repeated here.

[0793] FIG5b is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG5b, the method according to the embodiment of the present disclosure is used for a third device, and the method includes:

[0794] S511. Send first security material to a first device.

[0795] The optional implementation of step S511 can refer to the optional implementation of step S200-2 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0796] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0797] In some embodiments, it further includes:

[0798] receiving a first message sent by the first device, where the first message is used to request first security material;

[0799] The above step S511 may include:

[0800] A second message is sent to the first device, where the second message carries the first security material.

[0801] The above optional implementation methods can refer to the optional implementation methods of step S200-1 and step S200-2 in Figure 2a, and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.

[0802] In the above embodiment, the first security material further includes at least one of the following:

[0803] Credential information;

[0804] device information of the second device;

[0805] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0806] service information used by the second device;

[0807] Candidate security algorithms.

[0808] In the above embodiment, the security policy includes at least one of the following:

[0809] an integrity protection strategy for communication signals between the first device and the second device;

[0810] a confidentiality protection strategy for communication signals between the first device and the second device;

[0811] an integrity protection policy for user plane data between the first device and the second device;

[0812] A confidentiality protection policy for user plane data between the first device and the second device.

[0813] In some embodiments, the integrity protection policy of the communication signal between the first device and the second device is protection required.

[0814] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0815] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units or modules are realized by designing the logical relationship of the elements in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be implemented by a programmable logic device (PLD), taking a field programmable gate array (FPGA) as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, thereby realizing the functions of some or all of the above units or modules.

[0816] All units or modules of the above devices can be implemented in the form of software called by the processor, or in the form of hardware circuits, or partially implemented in the form of software called by the processor, and the remaining part implemented in the form of hardware circuits. In the embodiment of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0817] FIG6 a is a schematic diagram of the structure of a first device according to an embodiment of the present disclosure. As shown in FIG6 a , the first device may include at least one of a first transceiver module 611 and a first processing module 612 .

[0818] In some embodiments, the first processing module 612 is configured to determine a first security material and securely communicate with the second device based on the first security material;

[0819] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0820] In some optional embodiments, the first transceiver module 611 is configured to receive a third message sent by the second device, wherein the third message is security-protected based on the first security material.

[0821] In some optional embodiments, the first transceiver module 611 is used to: send a first message to a third device, where the first message is used to request the first security material; receive a second message sent by the third device, where the second message carries the first security material; or, the first processing module 612 is used to determine the first security material based on pre-configured security materials.

[0822] In some optional embodiments, the first transceiver module 611 is specifically used to: send a first message to a third device, where the first message is used to request the first security material; and receive a second message sent by the third device, where the second message carries the first security material.

[0823] In some optional embodiments, the first security material further includes at least one of the following:

[0824] Credential information;

[0825] device information of the second device;

[0826] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0827] service information used by the second device;

[0828] Candidate security algorithms.

[0829] In some optional embodiments, the first transceiver module 611 is further used to: send a first signal to the second device, wherein the first signal is used to stimulate the second device to send a third message.

[0830] In some optional embodiments, the third message includes any one of the following:

[0831] First information, used to indicate a link establishment request;

[0832] The second device collects data.

[0833] In some optional embodiments, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0834] In some optional embodiments, the third message further includes at least one of the following:

[0835] device information of the second device;

[0836] service information used by the second device;

[0837] candidate security algorithms supported by the second device;

[0838] a security policy used by the second device;

[0839] The security verification parameter is used to perform security protection on the third message.

[0840] In some optional embodiments, the first processing module 612 is specifically configured to perform at least one of the following:

[0841] authenticating the second device based on the first security material;

[0842] The third message is verified based on the first security material.

[0843] In some optional embodiments, the first transceiver module 611 is also used to: if the third message is verified to be successful, send a fourth message in response to the third message to the second device; or if the second device is authenticated and the third message is verified to be successful, send a fourth message in response to the third message to the second device.

[0844] In some optional embodiments, the fourth message is security-protected based on the first security material.

[0845] In some optional embodiments, the fourth message carries at least one of the following:

[0846] First indication information, used to indicate that the third message is successfully received;

[0847] security parameters, used to generate a security context negotiated between the second device and the first device;

[0848] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0849] First security strategy.

[0850] In some optional embodiments, the first transceiver module 611 is further configured to: receive data transmitted by the second device, where the data is protected by the negotiated security context.

[0851] In some optional embodiments, the first processing module 612 is further configured to: if the second device fails authentication, or the third message fails verification, reject or discard the third message.

[0852] In some optional embodiments, the security policy includes at least one of the following:

[0853] an integrity protection strategy for communication signals between the first device and the second device;

[0854] a confidentiality protection strategy for communication signals between the first device and the second device;

[0855] an integrity protection policy for user plane data between the first device and the second device;

[0856] A confidentiality protection policy for user plane data between the first device and the second device.

[0857] In some optional embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0858] FIG6 b is a schematic diagram of the structure of the second device proposed in an embodiment of the present disclosure. As shown in FIG6 b , the second device includes at least one of a second transceiver module 621 and a second processing module 622 .

[0859] In some embodiments, the second transceiver module 621 is configured to send a third message to the first device;

[0860] wherein the third message is security-protected based on the first security material;

[0861] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0862] In some optional embodiments, the second transceiver module 621 is further used to: receive a first signal sent by the first device, wherein the first signal is used to stimulate the second device to send the third message.

[0863] In some optional embodiments, the third message includes first information for indicating a link establishment request; and / or data collected by the second device;

[0864] Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

[0865] In some optional embodiments, the third message further includes at least one of the following:

[0866] device information of the second device;

[0867] service information used by the second device;

[0868] candidate security algorithms supported by the second device;

[0869] a security policy used by the second device;

[0870] The security verification parameter is used to perform security protection on the third message.

[0871] In some optional embodiments, the second transceiver module 621 is further configured to receive a fourth message sent by the first device in response to the third message.

[0872] In some optional embodiments, the fourth message is security-protected based on the first security material.

[0873] In some optional embodiments, the fourth message carries at least one of the following:

[0874] First indication information, used to indicate that the third message is successfully received;

[0875] security parameters, used to generate a security context negotiated between the second device and the first device;

[0876] a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material;

[0877] First security strategy.

[0878] In some optional embodiments, the second transceiver module 621 is further configured to: transmit data to the first device, where the data is protected by the negotiated security context.

[0879] In some optional embodiments, the security policy includes at least one of the following:

[0880] an integrity protection strategy for communication signals between the first device and the second device;

[0881] a confidentiality protection strategy for communication signals between the first device and the second device;

[0882] an integrity protection policy for user plane data between the first device and the second device;

[0883] A confidentiality protection policy for user plane data between the first device and the second device.

[0884] In some optional embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0885] FIG6c is a schematic diagram of the structure of the third device proposed in an embodiment of the present disclosure. As shown in FIG6c, the third device includes: at least one of a third transceiver module 631 and a third processing module 632.

[0886] In some embodiments, the third transceiver module 631 is used to send the first security material to the first device;

[0887] The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

[0888] In some optional embodiments, the third transceiver module 631 is further used to: receive a first message sent by the first device, where the first message is used to request a first security material; and send a second message to the first device, where the second message carries the first security material.

[0889] In some optional embodiments, the first security material further includes at least one of the following:

[0890] Credential information;

[0891] device information of the second device;

[0892] Device information of a group of devices, wherein the second device is one of the devices in the group;

[0893] service information used by the second device;

[0894] Candidate security algorithms.

[0895] In some optional embodiments, the security policy includes at least one of the following:

[0896] an integrity protection strategy for communication signals between the first device and the second device;

[0897] a confidentiality protection strategy for communication signals between the first device and the second device;

[0898] an integrity protection policy for user plane data between the first device and the second device;

[0899] A confidentiality protection policy for user plane data between the first device and the second device.

[0900] In some optional embodiments, the integrity protection policy of the communication signal between the first device and the second device is that protection is required.

[0901] The present disclosure also provides an optional implementation scheme, in which a RAN node is used as the first device. It is assumed that the A-IoT device is pre-configured with security materials for device authentication and message protection (which may correspond to the first security materials mentioned above).

[0902] In an optional embodiment, the method shown in FIG7a includes the following steps:

[0903] S701. The RAN node sends an excitation signal (which may correspond to the first signal mentioned above) to an A-IoT device (which may correspond to the second device mentioned above).

[0904] In some embodiments, the RAN node may send an unmodulated stimulus signal and wait for a reply message from the A-IoT device.

[0905] S702. The A-IoT device sends an initial request message (which may correspond to the third message above) to the RAN node.

[0906] Once the A-IoT device receives the excitation signal, it reflects the backscattered signal and forms an initial device message (eg, a report message or a link establishment request message), which is protected or encoded by the first security material.

[0907] Optionally, if the initial device message is a report message, it may include: the ID of the A-IoT device, the data collected by the A-IoT device, and the MAC value (which may correspond to the security verification parameters mentioned above).

[0908] Optionally, if the initial device message is a link establishment request message, it may include: the ID and MAC value of the A-IoT device (which may correspond to the security verification parameters mentioned above).

[0909] S703a: The RAN node sends a message (which may correspond to the first message above) requesting security material to the CN NF (which may correspond to the third device above).

[0910] In some embodiments, if the relevant security material is not stored in the RAN node, the RAN node sends a request message to the CN NF requesting the security material associated with the A-IoT device ID.

[0911] In some embodiments, the security material associated with the A-IoT device ID includes: associated credentials and associated security policies.

[0912] In the above embodiment, the RAN node may use the received security material to authenticate the A-IoT device and verify the received message.

[0913] or,

[0914] S703b. The RAN node sends a message requesting security materials (which may correspond to the first message above) to the AAA server or A-IoT AS (which may correspond to the third device above) via the CN NF.

[0915] In some embodiments, if the relevant security material is not stored in the RAN node, the RAN node sends a request message to the AAA server or A-IoT AS via the CN NF.

[0916] The implementation of steps S703a and S703b can refer to the relevant description of step S200-1 in FIG2a, which will not be repeated here.

[0917] In some embodiments, in response to the received request, the CN NF or AAA server or A-IoT AS may provide security materials associated with the indicated A-IoT device, or provide security materials associated with the group to which the indicated A-IoT device belongs. In the latter case, the IDs of all A-IoT devices in the group are provided to the RAN node.

[0918] S704. The RAN node verifies the received third message and / or authenticates the A-IoT device by using the provided security material (which may correspond to the first security material mentioned above).

[0919] S705. The RAN node sends an ACK message (which may correspond to the fourth message above) in response to the A-IoT device to the A-IoT device.

[0920] In some embodiments, if the device ID of the received A-IoT device is included in the ID of the A-IoT device included in the provided first security material, or can be mapped to an ID of an A-IoT device among the IDs of the A-IoT devices included in the provided first security material, and the MAC value verification is passed, the RAN node can respond to the AIoT device with an ACK message.

[0921] Otherwise, the RAN node rejects or discards the third message.

[0922] In some embodiments, the ACK message may include security parameters used to generate a security context negotiated between the AIoT device and the RAN node.

[0923] In some embodiments, the ACK message is security-protected based on the first security material. Optionally, the ACK is protected or encoded by the first security material.

[0924] S706 : The A-IoT device transmits data to the RAN node by using the negotiated security context.

[0925] In some embodiments, if no data is reported in the above step S702, once the A-IoT device receives the ACK message, it can generate a security context negotiated between the A-IoT device and the RAN node based on the security parameters in the ACK message, and transmit UL data by using the negotiated security context.

[0926] In another optional embodiment, the RAN node may send a message requesting security materials to the CN NF or AAA server or A-IoT AS before sending the excitation signal. For details, see step S711a or S711b as shown in Figure 7b.

[0927] It should be understood that the optional implementation of step S711a in this embodiment can refer to the relevant description of step S703a shown in Figure 7a, and will not be repeated here.

[0928] It should be understood that the optional implementation of step S711b in this embodiment can refer to the relevant description of step S703b shown in Figure 7a, and will not be repeated here.

[0929] It should be understood that optional implementations of steps S712 to S716 in this embodiment can be found in the relevant descriptions of steps S701, S702, and S704 to S706 shown in FIG. 7 a, and will not be repeated here.

[0930] In the above embodiments, the CN (e.g., PCF or AIoT MF) or AAA server or A-IoT AS can provide a security policy for communicating with the ambient IoT devices by configuring a list of ambient IoT applications or services that require security protection, and a security policy for each ambient IoT in the list.

[0931] In some embodiments, the security policy is configured as follows:

[0932] Signal integrity protection: required

[0933] Signal confidentiality protection: required / optional (PREFERRED) / not needed (NOT NEEDED)

[0934] User plane integrity protection: Required / Preferred / Not required

[0935] User plane confidentiality protection: Required / Preferred / Not required

[0936] Here, "required" means that the UE will accept the connection only if a non-NULL confidentiality or integrity algorithm is used to protect the communication between the UE and the ambient IoT.

[0937] “Not required” means that the UE can only establish a connection without security protection.

[0938] "Optional" means that the UE may attempt to establish a connection with security protection, but may accept a connection without security protection. One use of optional protection is to enable security policy to be changed without updating all involved UEs at the same time.

[0939] In some embodiments, there are several situations for setting security policies:

[0940] 1. If the security policy is provided by PCF or AMF through the control plane, or AIoTMF through the control plane or user plane, the configuration data of the security policy should be provided in the security material or policy request process.

[0941] 2. If security policies are pre-configured, how to pre-configure security policies is out of scope.

[0942] 3. If the security policy is provided by the AAA server or A-IoT AS, the configuration data of the security policy should be provided at the application layer.

[0943] Figure 8a is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0944] As shown in Figure 8a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, baseband chip, terminal device, terminal device chip, DU or CU, etc.), execute programs, and process program data. The processor 8101 is used to call instructions to enable the communication device 8100 to perform any of the above methods.

[0945] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps such as sending and / or receiving in the above method (for example, at least one of steps S200-1, S200-2, S201, S202, S204 shown in FIG. 2a, and steps S210-1, S210-2, S211, S212, S214, and S215 shown in FIG. 2b, but not limited thereto), and the processor 8101 performs at least one of the other steps (for example, at least one of step S203 shown in FIG. 2a and step S213 shown in FIG. 2b, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be replaced with each other, terms such as transmitter, transmitting unit, transmitter, and transmitting circuit can be replaced with each other, and terms such as receiver, receiving unit, receiver, and receiving circuit can be replaced with each other.

[0946] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may be located outside the communication device 8100.

[0947] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.

[0948] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0949] The communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in the embodiments of the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8a. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0950] FIG8b is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, reference can be made to the schematic diagram of the structure of the chip 8200 shown in FIG8b, but the present disclosure is not limited thereto.

[0951] The chip 8200 includes one or more processors 8201. The chip 8200 is configured to execute any of the above methods.

[0952] In some embodiments, chip 8200 further includes one or more interface circuits 8202. Optionally, terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 8200 further includes one or more memories 8203 for storing data. Optionally, all or part of memory 8203 may be located outside chip 8200. Optionally, interface circuit 8202 is connected to memory 8203 and may be used to receive data from memory 8203 or other devices, or may be used to send data to memory 8203 or other devices. For example, interface circuit 8202 may read data stored in memory 8203 and send the data to processor 8201.

[0953] In some embodiments, the interface circuit 8202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., at least one of steps S200-1, S200-2, S201, S202, S204 shown in FIG. 2a , and steps S210-1, S210-2, S211, S212, S214, and S215 shown in FIG. 2b , but not limited thereto). The interface circuit 8202 performing the communication steps such as sending and / or receiving in the above method, for example, means that the interface circuit 8202 performs data exchange between the processor 8201, the chip 8200, the memory 8203, or the transceiver device. In some embodiments, the processor 8201 performs at least one of the other steps (e.g., at least one of step S203 shown in FIG. 2a and step S213 shown in FIG. 2b , but not limited thereto).

[0954] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0955] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

[0956] The technical solutions described in the embodiments of the present disclosure can be arbitrarily combined without conflict.

[0957] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow from the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.

[0958] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A communication method, characterized in that: The method is performed by a first device, and includes: Identify the first safety material; securely communicating with a second device based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

2. The method according to claim 1, characterized in that The method further comprises: A third message sent by the second device is received, wherein the third message is security-protected based on the first security material.

3. The method according to claim 1 or 2, characterized in that The determining of the first security material includes: sending a first message to a third device, where the first message is used to request the first security material; receiving a second message sent by the third device, where the second message carries the first security material; or The first security material is determined based on pre-configured security materials.

4. The method according to claim 1 or 3, characterized in that The determining of the first security material includes: sending a first message to the third device, where the first message is used to request the first security material; A second message sent by the third device is received, where the second message carries the first security material.

5. The solution according to any one of claims 1 to 4, characterized in that: The first security material further includes at least one of the following: Credential information; device information of the second device; Device information of a group of devices, wherein the second device is one of the devices in the group; service information used by the second device; Candidate security algorithms.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: A first signal is sent to the second device, wherein the first signal is used to stimulate the second device to send a third message.

7. The method according to claim 6, characterized in that The third message includes any one of the following: First information, used to indicate a link establishment request; The second device collects data.

8. The method according to claim 6, characterized in that The third message is a link establishment request message, and the third message includes data collected by the second device.

9. The method according to claim 7 or 8, characterized in that The third message further includes at least one of the following: device information of the second device; service information used by the second device; candidate security algorithms supported by the second device; a security policy used by the second device; The security verification parameter is used to perform security protection on the third message.

10. The method according to any one of claims 7 to 9, characterized in that The secure communication with the second device based on the first security material includes at least one of the following: authenticating the second device based on the first security material; The third message is verified based on the first security material.

11. The method according to claim 10, characterized in that The method further comprises: If the third message is verified successfully, sending a fourth message in response to the third message to the second device; or If the second device is authenticated and the third message is verified, a fourth message in response to the third message is sent to the second device.

12. The method according to claim 11, characterized in that The fourth message is security-protected based on the first security material.

13. The method according to claim 11 or 12, characterized in that The fourth message carries at least one of the following: First indication information, used to indicate that the third message is successfully received; security parameters, used to generate a security context negotiated between the second device and the first device; a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material; First security strategy.

14. The method according to claim 13, wherein: The method further comprises: Receive data transmitted by the second device, where the data is protected by the negotiated security context.

15. The method according to claim 10, characterized in that The method further comprises: If the second device fails authentication, or the third message fails verification, the third message is rejected or discarded.

16. The method according to any one of claims 1 to 15, characterized in that The security policy includes at least one of the following: an integrity protection strategy for communication signals between the first device and the second device; a confidentiality protection strategy for communication signals between the first device and the second device; an integrity protection policy for user plane data between the first device and the second device; A confidentiality protection policy for user plane data between the first device and the second device.

17. The method according to claim 16, characterized in that The integrity protection policy of the communication signal between the first device and the second device is that protection is required.

18. A communication method, characterized in that: The method is performed by a second device, and includes: sending a third message to the first device; wherein the third message is security-protected based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

19. The method according to claim 18, characterized in that Also includes: A first signal sent by the first device is received, wherein the first signal is used to stimulate the second device to send the third message.

20. The method according to claim 18 or 19, characterized in that The third message includes first information for indicating a link establishment request; and / or data collected by the second device; Alternatively, the third message is a link establishment request message, and the third message includes data collected by the second device.

21. The method according to claim 20, characterized in that The third message further includes at least one of the following: device information of the second device; service information used by the second device; candidate security algorithms supported by the second device; a security policy used by the second device; The security verification parameter is used to perform security protection on the third message.

22. The method according to any one of claims 18 to 21, characterized in that Also includes: Receive a fourth message sent by the first device in response to the third message.

23. The method according to claim 22, characterized in that The fourth message is security-protected based on the first security material.

24. The method according to claim 22 or 23, characterized in that The fourth message carries at least one of the following: First indication information, used to indicate that the third message is successfully received; security parameters, used to generate a security context negotiated between the second device and the first device; a first security algorithm, comprising a security algorithm determined based on a candidate security algorithm supported by the second device and a candidate security algorithm in the first security material; First security strategy.

25. The method according to claim 24, characterized in that The method further comprises: Data is transmitted to the first device, the data being protected by the negotiated security context.

26. The method according to any one of claims 18 to 25, characterized in that The security policy includes at least one of the following: an integrity protection strategy for communication signals between the first device and the second device; a confidentiality protection strategy for communication signals between the first device and the second device; an integrity protection policy for user plane data between the first device and the second device; A confidentiality protection policy for user plane data between the first device and the second device.

27. The method according to claim 26, characterized in that The integrity protection policy of the communication signal between the first device and the second device is that protection is required.

28. A communication method, characterized in that: The method is performed by a third device, and includes: sending first security material to the first device; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

29. The method according to claim 28, characterized in that Also includes: receiving a first message sent by the first device, where the first message is used to request first security material; The sending of the first security material to the first device includes: A second message is sent to the first device, where the second message carries the first security material.

30. The method according to claim 28 or 29, characterized in that The first security material further includes at least one of the following: Credential information; device information of the second device; Device information of a group of devices, wherein the second device is one of the devices in the group; service information used by the second device; Candidate security algorithms.

31. The method according to any one of claims 28 to 30, characterized in that The security policy includes at least one of the following: an integrity protection strategy for communication signals between the first device and the second device; a confidentiality protection strategy for communication signals between the first device and the second device; an integrity protection policy for user plane data between the first device and the second device; A confidentiality protection policy for user plane data between the first device and the second device.

32. The method according to claim 31, wherein The integrity protection policy of the communication signal between the first device and the second device is that protection is required.

33. A communication method, characterized in that: The method is performed by a communication system, the communication system including a first device and a second device, and the method includes: The second device sends a third message to the first device; The first device determines a first security material based on the third message, and performs secure communication with the second device based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

34. A first device, characterized in that include: a first processing module, configured to determine a first security material and perform secure communication with a second device based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

35. A second device, characterized in that: include: A second transceiver module, configured to send a third message to the first device; wherein the third message is security-protected based on the first security material; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

36. A third device, characterized in that: include: a third transceiver module, configured to send the first security material to the first device; The first security material includes a security policy, and the security policy is used to determine a security protection method for communication between the first device and the second device.

37. A first device, characterized in that include: one or more processors; The first device is configured to execute the communication method described in any one of claims 1 to 17.

38. A second device, characterized in that: include: one or more processors; The second device is configured to execute the communication method described in any one of claims 18 to 27.

39. A third device, characterized in that: include: one or more processors; The third device is configured to execute the communication method described in any one of claims 28 to 32.

40. A computer-readable storage medium having a computer program stored thereon, characterized in that: The computer-readable storage medium stores executable instructions, which are loaded and executed by a processor to implement the communication method described in any one of claims 1 to 17, or claims 18 to 27, or claims 28 to 32.