Network connection equipment information security verification method and device, core network element and network connection equipment

By performing encrypted calculations and data comparisons on the identifiers of connected devices, the problem of verifying the authenticity of application domain identifiers in the network access process of connected devices is solved, thereby improving the security and reliability of network access.

CN121126342APending Publication Date: 2025-12-12CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511203216.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing technologies cannot effectively verify the authenticity of the application domain identifier of connected devices during the network access process, leading to identity forgery and security risks.

Method used

By obtaining security key information, the identifier of the connected device is encrypted and calculated. The first encrypted data is compared with the second encrypted data to obtain the security verification result, ensuring the authenticity of the device information.

Benefits of technology

It enhances the security and reliability of network access for connected devices, and meets the stringent requirements for task authorization and security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121126342A_ABST
    Figure CN121126342A_ABST
Patent Text Reader

Abstract

The invention provides a network connection equipment information security verification method and device, a core network element and network connection equipment, and the method comprises the steps: obtaining security key information in response to a first network registration request of the network connection equipment, and transmitting first key information in the security key information to the network connection equipment; receiving a second network registration request of the network connection equipment; the second network registration request comprises a network connection device identifier and corresponding first encrypted data; acquiring second encrypted data of the network connection equipment identifier according to second key information in the security key information; according to the first encrypted data and the second encrypted data, obtaining a security verification result of the network connection equipment identifier; and sending the security verification result to the network connection equipment. According to the method, the authenticity of the equipment information is effectively verified in the network access process of the network connection equipment, so that the network access security and credibility of the network connection equipment are improved, and the strict requirements on task authorization and security management in an actual service scene are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication security technology, and in particular to a method, apparatus, core network element and network-connected device for information security verification. Background Technology

[0002] With the rapid development of IoT technology and its widespread application in smart homes, industrial automation, intelligent transportation, and other fields, secure and controllable network access and management of various connected devices has become an important part of 5G and future communication networks. To achieve functions such as identification, status monitoring, remote control, and service authorization for connected devices, standardization organizations such as 3GPP have proposed technical solutions to support new terminal types accessing cellular networks.

[0003] In current standard solutions, connected devices are considered a special type of 3GPP User Equipment (UE), possessing a unique device identifier. This identifier is used to complete registration and authentication processes within the network core. However, existing solutions still have significant security flaws. The current process primarily relies on the core network obtaining the application domain identifier (such as device ID or related service tags) reported by the connected device and triggering interaction with the service platform based on this identifier. However, this solution does not effectively verify the authenticity of the application domain identifier, failing to prevent forgery, copying, or tampering. For example, attackers can copy the device ID of a legitimate connected device and impersonate it on another device to complete network registration and service requests, thereby bypassing the task authorization mechanism and causing serious security risks such as unauthorized device access, data leakage, or malicious operations.

[0004] Therefore, how to solve the problem that existing technologies cannot effectively verify the authenticity of application domain identifiers during the network access process of connected devices is an important issue that urgently needs to be addressed in the field of communication security. Summary of the Invention

[0005] This application provides a method, apparatus, core network element, and connected device for verifying information security of connected devices, which overcomes the shortcomings of existing technologies that cannot effectively verify the authenticity of device information during the process of connected devices accessing the network, improves the security and reliability of network access for connected devices, and meets the strict requirements for task authorization and security management in actual business scenarios.

[0006] On one hand, this application provides a method for verifying the information security of connected devices, applied to a first network element, comprising: responding to a first network registration request from a connected device, obtaining security key information, and sending the first key information in the security key information to the connected device; receiving a second network registration request from the connected device; the second network registration request including a connected device identifier and its corresponding first encrypted data, wherein the first encrypted data is obtained by encrypting the connected device identifier according to the first key information; obtaining second encrypted data of the connected device identifier according to the second key information in the security key information; obtaining a security verification result of the connected device identifier according to the first encrypted data and the second encrypted data; and sending security verification information to the connected device, wherein the security verification information includes the security verification result.

[0007] Furthermore, the step of responding to the first network registration request of the connected device and obtaining security key information includes: receiving the first network registration request of the connected device; sending a user subscription configuration request to the second network element; and receiving the security key information fed back by the second network element; wherein, both the first network registration request and the user subscription configuration request include at least the identifier of the connected device.

[0008] Furthermore, the step of sending the user subscription configuration request to the second network element includes: performing access subscription authentication on the network-connected device; and sending the user subscription configuration request to the second network element if the access subscription authentication is successful.

[0009] Furthermore, obtaining the security verification result of the connected device identifier based on the first encrypted data and the second encrypted data includes: if the first encrypted data and the second encrypted data match, taking the security of the connected device information as the security verification result; if the first encrypted data and the second encrypted data do not match, taking the tampering of the connected device information as the security verification result.

[0010] Furthermore, if the first encrypted data and the second encrypted data match, the security of the network-connected device information is taken as the security verification result. This further includes: reporting the first encrypted data / second encrypted data to a second network element, whereby the second network element stores the security key information and the first encrypted data / second encrypted data.

[0011] Furthermore, the step of responding to the first network registration request of the connected device and obtaining security key information includes: triggering a key update mechanism if the key validity period in the security key information meets the near-expiration condition.

[0012] Secondly, this application also provides a method for verifying the information security of connected devices, applied to a second network element, comprising: receiving a user subscription configuration request from a first network element, the user subscription configuration request including at least a connected device identifier; responding to the user subscription configuration request and obtaining security key information of the connected device identifier; and sending the security key information to the first network element.

[0013] Furthermore, the step of responding to the user's subscription configuration request and obtaining the security key information of the network-connected device identifier includes, before: performing an initial authentication determination on the network-connected device identifier.

[0014] Furthermore, the initial authentication determination of the connected device identifier includes: if it is determined that encrypted data corresponding to the connected device identifier is stored, then the connected device identifier is for initial authentication; if it is determined that encrypted data corresponding to the connected device identifier is not stored, then the connected device identifier is not for initial authentication.

[0015] Furthermore, the step of responding to the user's subscription configuration request and obtaining the security key information of the connected device identifier includes: obtaining the security key information of the connected device identifier by requesting an external source when the connected device identifier is undergoing initial authentication; and directly retrieving the stored security key information when the connected device identifier is not undergoing initial authentication.

[0016] Furthermore, when the network-connected device identifier is under initial authentication, obtaining the security key information of the network-connected device identifier by requesting an external source includes: sending a security key request message to a data storage network element or a traffic management network element through a network open network element; receiving the security key information returned by the data storage network element or the traffic management network element; wherein the security key information includes first key information, second key information, key validity period, and network-connected device identifier validity information.

[0017] Furthermore, when the network-connected device identifier is undergoing initial authentication, obtaining the security key information of the network-connected device identifier by requesting an external source includes: sending a security key request message to the authentication, authorization, and accounting network element; and receiving the security key information returned by the authentication, authorization, and accounting network element; wherein the security key information includes first key information, second key information, key validity period, and network-connected device identifier validity information.

[0018] Furthermore, it also includes: receiving encrypted data reported by the first network element and storing the security key information and the encrypted data together.

[0019] Thirdly, this application also provides a method for verifying the information security of connected devices, applied to connected devices, comprising: receiving first key information sent by a first network element; performing encryption calculation on a connected device identifier based on the first key information to obtain first encrypted data; and sending a network registration request to the first network element; wherein the network registration request includes the connected device identifier and the first encrypted data of the connected device identifier, the first encrypted data being used for security verification of the connected device identifier. Further, the step of receiving the first key information sent by the first network element is preceded by: sending a first network registration request to the first network element, wherein the first network registration request includes at least the connected device identifier.

[0020] Further, the step of receiving the first key information sent by the first network element includes: triggering a key update mechanism when the key validity period of the first key information meets the near-expiration condition.

[0021] Further, the step of performing encryption calculation on the network device identifier based on the first key information to obtain the first encrypted data includes: transmitting the network device identifier, the first key information, and the first encrypted data to the network device hardware system for local storage.

[0022] Further, the step of sending a network registration request to the first network element includes: receiving security verification information sent by the first network element, wherein the security verification information includes the security verification result of the network device identifier.

[0023] Fourthly, this application also provides a network-connected device information security verification device, applied to a first network element, comprising: a first network registration request response module, configured to respond to a first network registration request from a network-connected device, obtain security key information, and send the first key information in the security key information to the network-connected device; a second network registration request receiving module, configured to receive a second network registration request from the network-connected device; the second network registration request includes a network-connected device identifier and its corresponding first encrypted data, wherein the first encrypted data is obtained by encrypting the network-connected device identifier according to the first key information; a network-connected device identifier encryption module, configured to obtain second encrypted data of the network-connected device identifier according to the second key information in the security key information; a network-connected device identifier security verification module, configured to obtain a security verification result of the network-connected device identifier according to the first encrypted data and the second encrypted data; and a security verification information response module, configured to send security verification information to the network-connected device, wherein the security verification information includes the security verification result.

[0024] Fifthly, this application also provides a network-connected device information security verification device, applied to a second network element, comprising: a subscription configuration request receiving module, configured to receive a user subscription configuration request from a first network element, wherein the user subscription configuration request includes at least a network-connected device identifier; a subscription configuration request response module, configured to respond to the user subscription configuration request and obtain security key information of the network-connected device identifier; and a security key information sending module, configured to send security key information to the first network element.

[0025] Sixthly, this application also provides a network-connected device information security verification device, applied to a network-connected device, comprising: a first key information receiving module, used to receive first key information sent by a first network element; a network-connected device identifier encryption calculation module, used to perform encryption calculation on the network-connected device identifier according to the first key information to obtain first encrypted data; and a network registration request sending module, used to send a network registration request to the first network element; the network registration request includes the network-connected device identifier and the first encrypted data of the network-connected device identifier, the first encrypted data being used for security verification of the network-connected device identifier. Seventhly, this application also provides a core network access element, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, when the processor executes the computer program, it implements the network-connected device information security verification method applied to the first network element as described in any of the preceding claims.

[0026] Eighthly, this application also provides a core network function authentication network element, including a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, when the processor executes the computer program, it implements the network-connected device information security verification method applied to the second network element as described in any of the preceding claims.

[0027] Ninthly, this application also provides a network-connected device, including a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, when the processor executes the computer program, it implements the network-connected device information security verification method applied to the network-connected device as described in any of the preceding claims.

[0028] In a tenth aspect, this application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network device information security verification method as described above.

[0029] In the eleventh aspect, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the network device information security verification method described above.

[0030] The network-connected device information security verification method provided in this application, applied to a first network element, obtains security key information in response to a first network registration request from the network-connected device, sends the first key information from the security key information to the network-connected device, and then receives a second network registration request from the network-connected device. The second network registration request includes a network-connected device identifier and its corresponding first encrypted data. The first encrypted data is obtained by encrypting the network-connected device identifier based on the first key information. Then, based on the second key information in the security key information, the second encrypted data of the network-connected device identifier is obtained, and based on the first encrypted data and the second encrypted data, the security verification result of the network-connected device identifier is obtained, so as to send security verification information, including the security verification result, to the network-connected device. This method improves the security and trustworthiness of network access for network-connected devices by effectively verifying the authenticity of their device information during the network access process, and meets the strict requirements for task authorization and security management in actual business scenarios. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 This is a flowchart illustrating the network device information security verification method applied to the first network element provided in this application embodiment.

[0033] Figure 2 This is a flowchart illustrating the network device information security verification method applied to a second network element provided in this application embodiment.

[0034] Figure 3 This is a flowchart illustrating the network device information security verification method applied to network devices provided in this application embodiment.

[0035] Figure 4 This is a schematic diagram of the overall process of the network device information security verification method provided in the embodiments of this application.

[0036] Figure 5 This is a logical schematic diagram of the network device information security verification method provided in the embodiments of this application.

[0037] Figure 6 This is a schematic diagram of the structure of the network-connected device information security verification device applied to the first network element provided in the embodiments of this application.

[0038] Figure 7This is a schematic diagram of the structure of the network-connected device information security verification device applied to the second network element provided in the embodiments of this application.

[0039] Figure 8 This is a schematic diagram of the structure of the network device information security verification device applied to network devices provided in the embodiments of this application.

[0040] Figure 9 This is a schematic diagram of the physical structure of the core network access network element provided in the embodiments of this application.

[0041] Figure 10 This is a schematic diagram of the physical structure of the core network function authentication network element provided in the embodiments of this application.

[0042] Figure 11 This is a schematic diagram of the physical structure of the network device provided in the embodiments of this application. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0044] It should be noted that in the current standard scheme, connected devices are considered a special type of 3GPP User Equipment (UE), possessing a unique device identifier, which is used to complete the registration and authentication process in the network core. The network identifies the device identifier and combines it with the user's subscription information to achieve access control and service authorization for connected devices. To support diverse device-related services, the standard introduces new network function entities—such as Device Service NF. This function can be implemented by combining Network Exposure Function (NEF) or Service Capability Exposure Function (SCEF) with NEF, or it can be deployed independently to connect the device service platform and the operator's core network, enabling cross-domain information exchange and service invocation.

[0045] Furthermore, existing core network elements such as the Access and Mobility Management Function (AMF) and Session Management Function (SMF) have been enhanced to support control plane interaction with the device service platform. For example, device authentication and authorization processes (such as UUAA-MM or UUAA-SM) are implemented through control plane policy (CP-based) mechanisms, enabling the service platform to participate in verifying the device's identity and service permissions during the device registration process.

[0046] However, the current process mainly relies on the core network to obtain the application domain identifier (such as device ID or related service tag) reported by the connected devices, and triggers interaction with the service platform based on this identifier. However, this solution does not effectively verify the authenticity of the application domain identifier, and cannot prevent the identifier from being forged, copied, or tampered with. For example, attackers can copy the device ID of a legitimate connected device, impersonate it on another device to complete network registration and service requests, thereby bypassing the task authorization mechanism and causing serious security risks such as unauthorized device access, data leakage, or malicious operation.

[0047] Especially in scenarios with high security requirements, such as remote control devices in smart grids, sensor networks in autonomous vehicles, or critical equipment in medical and health monitoring systems, it is not only necessary to confirm whether the device can access the network, but also to ensure the authenticity and uniqueness of its identity to prevent identity cloning and deception. However, existing standard solutions lack a mechanism to protect the integrity and credibility of application identifiers of connected devices during the authentication process, resulting in a fundamental vulnerability in the entire authorization system.

[0048] In view of this, this application proposes a method for verifying the information security of connected devices, applied to the first network element, specifically, Figure 1 A flowchart illustrating the network device information security verification method applied to a first network element provided in an embodiment of this application is shown.

[0049] like Figure 1As shown, the method includes: S110, responding to a first network registration request from a connected device, obtaining security key information, and sending the first key information in the security key information to the connected device; S120, receiving a second network registration request from the connected device; the second network registration request includes a connected device identifier and its corresponding first encrypted data, the first encrypted data being obtained by encrypting the connected device identifier according to the first key information; S130, obtaining second encrypted data of the connected device identifier according to the second key information in the security key information; S140, obtaining a security verification result of the connected device identifier according to the first encrypted data and the second encrypted data; S150, sending security verification information to the connected device, the security verification information including the security verification result.

[0050] It should be noted that the network device information security verification method provided in this embodiment is applied to the first network element, which is the core network access network element. The core network access network element here can be either the AMF under the 5G network or the MME (Mobility Management Entity) under the 4G LTE network, and no specific limitation is made here.

[0051] The following will provide a detailed description of steps S110-S150 and related steps.

[0052] S110, responding to the first network registration request from the connected device, obtaining security key information, and sending the first key information in the security key information to the connected device.

[0053] Connected devices are those that can connect to the Internet or other communication networks via wired or wireless networks. These devices have data acquisition, processing, and transmission capabilities, and can interact with other devices, systems, or cloud platforms.

[0054] The connected devices in this embodiment include, but are not limited to, smartphones, smart TVs, wearable devices, smart air conditioners, cameras, vehicle networking terminals, and smart meters, and are not specifically limited thereto. For example, in a specific embodiment, the connected device is a connected drone, which not only has the basic flight and mission execution capabilities of a drone, but can also achieve real-time data interaction with the command center, other devices, or cloud platforms through communication networks (such as 4G / 5G, satellite, dedicated wireless links, etc.).

[0055] It is easy to understand that when a connected device first enters a mobile communication network, it sends a network registration request to the core network access element (hereinafter referred to as the AMF / MME), which is denoted as the first network registration request. The first network registration request carries a reporting code number, including the connected device's Device ID, IMEI, IMSI, and MSISDM.

[0056] Device ID is a unique identifier for connected devices, a globally unique number assigned to each device and written by the manufacturer or operator at the time of manufacture. For example, the UAV ID of a connected drone. IMEI (International Mobile Equipment Identity) is the international mobile device identification code for connected devices, used to identify the physical device itself. The network can use the IMEI to determine whether the corresponding connected device is legitimate or has been stolen.

[0057] IMSI (International Mobile Subscriber Identity) is the international mobile subscriber identification code for network-connected devices, used to identify mobile communication users. Networks can use IMSI for network authentication and user identification. MSISDM (Mobile Station International Subscriber Directory Number) represents the mobile station's international subscriber directory number, used for call, SMS, and data communication addressing; it is the user's (network-connected device's) external contact method.

[0058] After receiving the first network registration request from the connected device, the AMF / MME responds to the request and begins to obtain the security key information of the connected device's identifier. The connected device identifier here includes, but is not limited to, the Device ID, IMEI, IMSI, and MSISDM of the connected device.

[0059] Obtaining security key information can be achieved by the AMF / MME sending a user subscription configuration request to the second network element, and this is not specifically limited here. The security key information includes at least one key pair: a first key and a second key. In addition, the security key information may also include key validity period and network device identification validity information. The key validity period is used to trigger the security key information update mechanism, and the network device identification validity information specifically includes the validity information of the Device ID.

[0060] After obtaining the security key information of the connected device identifier, the AMF / MME will send the first key information in the security key information to the connected device as a response to the connected device's first network registration request.

[0061] Next, proceed to step S120.

[0062] S120, Receive the second network registration request of the connected device; the second network registration request includes the connected device identifier and its corresponding first encrypted data, the first encrypted data being obtained by encrypting the connected device identifier according to the first key information.

[0063] Specifically, after the AMF / MME sends the first key information from the security key information to the connected device, the connected device will perform encryption calculation on the connected device identifier based on the first key information to obtain the first encrypted data corresponding to the connected device identifier.

[0064] The connected device then packages its identifier and corresponding first encrypted data into a second network registration request and sends it to the AMF / MME. The AMF / MME can then receive the connected device's second network registration request.

[0065] Further, proceed with steps S130-S140.

[0066] S130, based on the second key information in the security key information, obtain the second encrypted data of the network device identifier.

[0067] S140, based on the first encrypted data and the second encrypted data, obtain the security verification result of the network device identifier.

[0068] Specifically, after receiving the second network registration request, the AMF / MME will perform encrypted calculations on the connected device identifier in the second network registration request based on the second key information in the security key information, to obtain the second encrypted data corresponding to the connected device identifier. To increase real-time performance during the encryption calculation, timestamp information can be added to the computation process.

[0069] Subsequently, the first encrypted data obtained from the encrypted calculation by the connected device is compared with the second encrypted data obtained from the AMF / MME encrypted calculation. If the first encrypted data and the second encrypted data match, the security of the connected device information is taken as the security verification result, indicating that the connected device information is secure, has not been tampered with, and can be accessed by the network. If the first encrypted data and the second encrypted data do not match, the tampering of the connected device information is taken as the security verification result, indicating that the connected device information poses a security risk and cannot be accessed by the network.

[0070] Next, proceed to step S150.

[0071] S150, send security verification information to the network-connected device, the security verification information including the security verification result.

[0072] Specifically, after obtaining the security verification result of the connected device identifier, the AMF / MME will send security verification information to the connected device as a response to the second network registration request. This security verification information includes at least the security verification result.

[0073] If the security verification result indicates that the network device information is secure, the network device will initiate a session establishment request to the AMF / MME and enter a normal session; if the security verification result indicates that the network device information has been tampered with, the network device will be unable to access the network and will not need to initiate a session establishment request.

[0074] In this embodiment, by responding to a first network registration request from a connected device, security key information is obtained, and the first key information from the security key information is sent to the connected device. Then, a second network registration request from the connected device is received. The second network registration request includes a connected device identifier and its corresponding first encrypted data. The first encrypted data is obtained by encrypting the connected device identifier based on the first key information. Then, based on the second key information in the security key information, second encrypted data of the connected device identifier is obtained. Finally, based on the first and second encrypted data, a security verification result of the connected device identifier is obtained, and security verification information, including the security verification result, is sent to the connected device. This method effectively verifies the authenticity of the connected device information during network access, improving the security and reliability of network access for connected devices and meeting the stringent requirements for task authorization and security management in actual business scenarios.

[0075] Based on the above embodiments, the following will further describe in detail the step of "responding to the first network registration request of the connected device and obtaining security key information" and related steps.

[0076] It is easy to understand that after receiving the first network registration request from the connected device, the AMF / MME first performs access contract authentication on the connected device based on the IMSI in the connected device identifier, that is, verifies the legitimacy of the connected device identifier. Only when the access contract authentication is successful will the AMF / MME send a user subscription configuration request to the second network element to obtain the security key information of the connected device identifier.

[0077] Specifically, provided that the access subscription authentication is successful, the AMF / MME will send user subscription configuration information to the second network element. The user subscription configuration information includes at least the device ID, IMEI, IMSI, and MSISDM identifiers.

[0078] After receiving the user's subscription configuration information, the second network element begins to acquire the security key information of the network-connected device identifier. It then sends the acquired security key information back to the AMF / MME as a response to the user subscription configuration information sent by the AMF / MME. Thus, the AMF / MME can receive the security key information sent back by the second network element. The specific method by which the second network element acquires the security key information will be explained in the following embodiments.

[0079] Based on the above embodiments, the following will further describe in detail some post-processing operations for obtaining security verification results from AMF / MME.

[0080] If the first encrypted data and the second encrypted data match, the security of the network device information is taken as the security verification result. The following steps also include: reporting the first encrypted data / second encrypted data to the second network element, which stores security key information and the first encrypted data / second encrypted data.

[0081] Specifically, if the first encrypted data matches the second encrypted data, it indicates that the connected device information is secure and has not been tampered with. Under this premise, the AMF / MME will send user subscription update information to the second network element. The user subscription update information includes at least the encrypted connected device information, i.e., the first encrypted data or the second encrypted data, so that the second network element can store the first encrypted data or the second encrypted data locally for subsequent initial authentication.

[0082] If the first encrypted data and the second encrypted data are inconsistent, it indicates that the network device information has been tampered with. Under this premise, the AMF / MME will not transfer the first encrypted data or the second encrypted data to the second network element for storage.

[0083] It should be noted that the second network element not only stores the first or second encrypted data, but also the security key information of the network device identifier, which can be called when the same network device identifier performs a second security verification of the device information.

[0084] In other words, when performing a second security verification of device information using the same network device identifier, the second encrypted data can be obtained directly by calling the encrypted data stored locally on the second network element, without needing to perform a second encryption calculation at the AMF / MME. Of course, this is only applicable if the security key information is within its validity period.

[0085] Based on the above embodiments, the following will further describe in detail some post-processing operations for the security key information obtained by the AMF / MME.

[0086] Responding to the first network registration request from the connected device, obtaining security key information, and then triggering a key update mechanism if the key validity period in the security key information meets the near-expiration condition.

[0087] Specifically, after obtaining the security key information, the AMF / MME can determine whether the first and second key information are still valid based on the key validity period in the security key information. If they are within the validity period, it means that the key validity period does not meet the near-expiration condition, and no additional processing is performed in this case; if they are outside the validity period, it means that the key validity period meets the near-expiration condition, and in this case, the key update mechanism is triggered.

[0088] The key update mechanism is triggered. Specifically, the AMF / MME sends a security key information update request to the second network element. The second network element responds to the received security key information update request, begins to acquire new security key information, and feeds back the newly acquired security key information to the AMF / MME, thereby updating the security key information and preventing the security key information from becoming outdated.

[0089] The above describes a method for verifying the information security of connected devices applied to AMF / MME. Accordingly, this application also proposes a method for verifying the information security of connected devices applied to a second network element.

[0090] Specifically, Figure 2 This paper illustrates a flowchart of a network-connected device information security verification method applied to core network function authentication network elements, as provided in an embodiment of this application.

[0091] like Figure 2 As shown, the method includes: S210, receiving a user subscription configuration request from a first network element, the user subscription configuration request including at least a network-connected device identifier; S220, responding to the user subscription configuration request and obtaining security key information of the network-connected device identifier; S230, sending the security key information to the first network element.

[0092] It should be noted that the network device information security verification method provided in this embodiment is applied to the second network element, which is the core network function authentication network element (Unified Data Management, UDM), hereinafter referred to as UDM.

[0093] The following will provide a detailed description of steps S210-S230 and related steps.

[0094] S210, receive a user subscription configuration request from the first network element, wherein the user subscription configuration request includes at least the network device identifier.

[0095] It's easy to understand that after receiving the first network registration request from the connected device, the AMF / MME performs access contract authentication. If the access contract authentication is successful, it sends a user subscription configuration request to the UDM. The user subscription configuration request includes at least the connected device identifiers such as Device ID, IMEI, IMSI, and MSISDM. Thus, the UDM can receive the user subscription configuration request from the AMF / MME.

[0096] Next, proceed to step S220.

[0097] S220, in response to the user subscription configuration request, obtain the security key information of the network device identifier.

[0098] Specifically, after receiving a user's subscription configuration request, UDM will first perform an initial authentication determination on the network device identifier in the user's subscription configuration request. Only when the network device identifier is initially authenticated will the external acquisition of security key information be triggered.

[0099] The initial authentication determination is based on whether the UDM stores encrypted data corresponding to the connected device identifier (i.e., the first encrypted data or the second encrypted data in the above embodiment). Specifically, a query is performed in the database based on the Device ID in the connected device identifier. If it is determined that the UDM stores encrypted data corresponding to the connected device identifier, then the connected device identifier is considered for initial authentication; if it is determined that the UDM does not store encrypted data corresponding to the connected device identifier, then the connected device identifier is considered for non-initial authentication.

[0100] If the network-connected device identifier is for initial authentication, the UDM obtains the security key information of the network-connected device identifier by requesting externally, including: 1) The UDM sends a security key request message to the data storage network element (USS) or traffic management network element (UTM) through the Network Open Element (NEF), and receives the security key information returned by the data storage network element or traffic management network element; 2) The UDM sends a security key request message to the Authentication, Authorization and Accounting Network Element (AAA), and receives the security key information returned by the Authentication, Authorization and Accounting Network Element.

[0101] In other words, both USS / UTM and AAA support issuing security key information for connected device identification. The security key information includes at least one key pair: a first key and a second key. Furthermore, the security key information may also include key validity period and connected device identification validity information. The key validity period triggers the security key information update mechanism, and the connected device identification validity information specifically includes the validity of the Device ID.

[0102] If the network-connected device is identified as not being authenticated for the first time, the UDM will directly access its own stored security key information.

[0103] It should be noted that, under USS / UTM authorization, UDM can also configure the security key information of the connected device identifier locally. In this case, UDM only needs to request USS / UTM to confirm the validity of the connected device identifier (such as Device ID).

[0104] In addition, after obtaining the security key information, UDM will store the security key information locally for use during secondary security verification of the same network device identifier.

[0105] Next, proceed to step S230.

[0106] S230, send security key information to the first network element.

[0107] After obtaining the security key information, the UDM will send the security key information back to the AMF / MME so that the AMF / MME can perform security verification on the network device identifier.

[0108] It should be noted that, in addition to the first key information, the second key information, the key validity period, and the validity information of the connected device identifier, the security key information in this step can also include encrypted data of the connected device identifier if the UDM stores encrypted data of the connected device identifier. This allows the AMF / MME to directly perform verification and comparison based on the encrypted data of the connected device identifier.

[0109] In this embodiment, by receiving a user subscription configuration request from the AMF / MME (which includes at least the network-connected device identifier), and responding to the request, obtaining the security key information of the network-connected device identifier, and sending the security key information to the AMF / MME for security verification of the network-connected device identifier. This method effectively verifies the authenticity of the device information during the network access process, improving the security and reliability of network access for network-connected devices, and meeting the stringent requirements for task authorization and security management in real-world business scenarios.

[0110] Based on the above embodiments, it further includes: receiving encrypted data reported by AMF / MME, and storing the security key information and the encrypted data together.

[0111] It is easy to understand that during the security verification of the connected device identifier by the AMF / MME, the first encrypted data and the second encrypted data of the connected device identifier are involved. If the security verification of the connected device identifier passes, the AMF / MME will report the first encrypted data or the second encrypted data to the UDM. The UDM will store the security key information together with the first encrypted data or the second encrypted data locally for retrieval when needed.

[0112] The above describes a method for verifying the information security of connected devices applied to AMF / MME and a method for verifying the information security of connected devices applied to UDM. Accordingly, this application also proposes a method for verifying the information security of connected devices applied to connected devices.

[0113] Specifically, Figure 3 A flowchart illustrating the network device information security verification method for network devices provided in this application embodiment is shown.

[0114] like Figure 3 As shown, the method includes: S310, receiving first key information sent by a first network element; S320, performing encryption calculation on the network-connected device identifier according to the first key information to obtain first encrypted data; S330, sending a network registration request to the first network element; the network registration request includes the network-connected device identifier and the first encrypted data of the network-connected device identifier, the first encrypted data being used for security verification of the network-connected device identifier. The following will describe steps S310-S330 and related steps in detail.

[0115] S310 receives the first key information sent by the first network element.

[0116] It is easy to understand that when a connected device first accesses or reconnects to a mobile communication network, it will send a first network registration request to the AMF / MME. The first network registration request carries a reporting code number, including the connected device's Device ID, IMEI, IMSI, and MSISDM, which is the connected device identifier.

[0117] After receiving the first network registration request, the AMF / MME obtains the security key information. The security key information includes at least one key pair: a first key and a second key. Additionally, the security key information may include key validity period and network device identification validity information. The key validity period triggers the security key information update mechanism, and the network device identification validity information specifically includes the validity of the Device ID.

[0118] The AMF / MME will send the first key information obtained from the security key information to the connected device as a response to the first network registration request.

[0119] Further, proceed with steps S320-S330.

[0120] S320, based on the first key information, perform encryption calculation on the network device identifier to obtain the first encrypted data.

[0121] S330, a network registration request is sent to the first network element; the network registration request includes the network device identifier and first encrypted data of the network device identifier, the first encrypted data being used for security verification of the network device identifier.

[0122] Specifically, after receiving the first key information, the connected device will perform an encryption calculation on the connected device identifier based on the first key information to obtain the first encrypted data corresponding to the connected device identifier. To increase real-time performance during the encryption calculation, timestamp information can be added to the computation process.

[0123] Then, the connected device will package the connected device identifier and its corresponding first encrypted data into a network registration request (similar to the second network registration request in the above embodiment, hereinafter referred to as the second network registration request), and send them together to the AMF / MME.

[0124] Next, after receiving the second network registration request, the AMF / MME will perform encryption calculation on the network device identifier in the second network registration request based on the second key information in the security key information to obtain the second encrypted data corresponding to the network device identifier. Then, it will compare the first encrypted data obtained by the encryption calculation of the network device with the second encrypted data obtained by the encryption calculation of the AMF / MME to obtain the security verification result.

[0125] Finally, the AMF / MME will package the security verification result of the connected device identifier into the security verification information and forward it to the connected device. The connected device can then receive the security verification information forwarded by the AMF / MME and determine subsequent operation steps based on this information, such as initiating a new session establishment request.

[0126] In this embodiment, by receiving the first key information sent by the AMF / MME and performing encrypted calculations on the network-connected device identifier based on the first key information to obtain first encrypted data, a network registration request is then sent to the AMF / MME. The network registration request includes the network-connected device identifier and the first encrypted data of the network-connected device identifier. The first encrypted data is used for security verification of the network-connected device identifier. This method improves the security and reliability of network access for network-connected devices by effectively verifying the authenticity of their device information during network access, meeting the stringent requirements for task authorization and security management in actual business scenarios.

[0127] Based on the above embodiments, the following will further describe in detail some post-processing operations for the networked device to obtain the first key information.

[0128] Receive the first key information sent by AMF / MME, and then trigger the key update mechanism if the key validity period of the first key information meets the near-expiration condition.

[0129] Specifically, when the AMF / MME sends the first key information to the connected device, it also sends the corresponding key validity period. The connected device will determine whether the first key information is still valid based on the key validity period. If it is within the validity period, it means the key validity period does not meet the near-expiration condition, and no additional processing is performed in this case; if it is outside the validity period, it means the key validity period meets the near-expiration condition, and the key update mechanism is triggered in this case.

[0130] The key update mechanism is triggered. Specifically, the connected device sends a security key information update request to the AMF / MME. The AMF / MME responds to the received security key information update request, begins to acquire new security key information, and feeds back the newly acquired security key information to the connected device, thereby updating the security key information and preventing the security key information from becoming outdated.

[0131] Based on the above embodiments, the following will further describe in detail some post-processing operations for obtaining security verification results by network-connected devices.

[0132] Specifically, after obtaining the first encrypted data by encrypting the network device identifier based on the first key information, the network device will also transmit the network device identifier, the first key information, and the first encrypted data to the network device hardware system for local storage to ensure the binding relationship between the local hardware information and the network device identifier.

[0133] Based on the network-connected device information security verification method described in the above embodiments, taking a network-connected unmanned aerial vehicle (UAV) as the network-connected device and an AMF as the first network element as an example. Figure 4 This paper illustrates the overall flowchart of the network device information security verification method provided in the embodiments of this application.

[0134] like Figure 4 As shown, the network device information security verification method provided in this application embodiment includes steps 1-13.

[0135] Step 1: The connected drone attaches and sends the first network registration request to the AMF.

[0136] Step 2: If the access contract authentication is successful, AMF sends a user contract configuration request to UDM.

[0137] Step 3a: If the connected drone is being authenticated for the first time, the UDM initiates a security key request to the USS / UTM; or, Step 3b: If the connected drone is being authenticated for the first time, the UDM initiates a security key request to the AAA.

[0138] Step 4a: USS / UTM returns security key information to UDM; or, Step 4b: AAA returns security key information to UDM. Steps 3a and 4a correspond to each other, and steps 3b and 4b correspond to each other. "a" and "b" represent two parallel methods for obtaining security key information; either one can be chosen.

[0139] Step 5: UDM sends security key information to AMF.

[0140] Step 6: AMF sends the first key information to the connected drone.

[0141] Step 7: The connected drone performs encryption calculation on the identification information of the connected drone based on the first key information to obtain the first encrypted data, and saves it locally.

[0142] Step 8: The connected drone sends a second network registration request to the AMF, including the identification information of the connected drone and the corresponding first encrypted data.

[0143] Step 9: AMF performs a security verification based on the first encrypted data and the second encrypted data to obtain the security verification result.

[0144] Step 10: After confirming the information security of the connected drone, the AMF will report the first encrypted data or the second encrypted data to the UDM.

[0145] Step 11: AMF sends security verification information containing the security verification result to the connected drone and initiates a successful access authentication response.

[0146] Step 12: The connected drone initiates a session establishment request to AMF.

[0147] Step 13: The core network sends a flight service authorization request to the connected drone in accordance with the 3GPP TS 23.256 UUAA-SM procedure.

[0148] In some other embodiments, the example of a connected drone is still taken as an example of a connected device. Figure 5 A logical schematic diagram of the network device information security verification method provided in the embodiments of this application is shown.

[0149] like Figure 5As shown, the basic logic of this application is to ensure that the information of the connected drone (identifier) ​​will not be maliciously tampered with. Therefore, it is required that the relevant information must be stored locally on the connected drone hardware. When the connected drone initiates a network registration request again, the communication module can retrieve the locally stored connected drone identification information from the connected drone hardware to initiate the registration process. At this time, the AMF can determine from the UDM that the current user is not registering for the first time. It can then compare the security key information and encrypted data issued by the UDM to determine that the information reported by the connected drone hardware is consistent with the information issued by the UDM and has not been tampered with.

[0150] Specifically, during initial registration, the UDM does not store security key information and encrypted data locally. It needs to request and obtain security key information externally, store it locally, and then distribute the security key information to the AMF. The AMF distributes a portion of the security key information to the connected drone. The connected drone encrypts its identification information based on the key information and reports the connected drone identification information and encrypted data to the AMF. The AMF encrypts the connected drone identification information locally based on the key information and compares the locally encrypted data with the encrypted data reported by the connected drone to determine whether the connected drone identification information has been tampered with. Furthermore, if the connected drone identification information is secure, the AMF will also report the locally encrypted data to the UDM for storage.

[0151] For subsequent registrations, the UDM locally stores the security key information and corresponding encrypted data of the connected drone's identification information, which can be directly sent to the AMF. The connected drone, in turn, reports its first encrypted data to the AMF. The AMF compares the received and sent information to determine whether the connected drone's identification information has been tampered with.

[0152] Whether it's the local hardware system of a connected drone or a UDM, if it stores security key information and encrypted data, it can be directly accessed, or the encrypted data can be obtained by re-encrypting and calculating based on the security key information. No specific limitations are made here.

[0153] Corresponding to the network-connected device information security verification method applied to the first network element described in the above embodiments, this application also proposes a network-connected device information security verification device applied to the first network element.

[0154] Specifically, Figure 6 A schematic diagram of the structure of the network device information security verification device applied to the first network element provided in an embodiment of this application is shown.

[0155] like Figure 6As shown, the device includes: a first network registration request response module 610, configured to respond to a first network registration request from a connected device, obtain security key information, and send the first key information in the security key information to the connected device; a second network registration request receiving module 620, configured to receive a second network registration request from the connected device; the second network registration request includes a connected device identifier and its corresponding first encrypted data, the first encrypted data being obtained by encrypting the connected device identifier according to the first key information; a connected device identifier encryption module 630, configured to obtain second encrypted data of the connected device identifier according to the second key information in the security key information; a connected device identifier security verification module 640, configured to obtain a security verification result of the connected device identifier according to the first encrypted data and the second encrypted data; and a security verification information response module 650, configured to send security verification information to the connected device, the security verification information including the security verification result.

[0156] In this embodiment, the first network registration request response module 610 responds to the first network registration request of the connected device, obtains security key information, and sends the first key information from the security key information to the connected device; the second network registration request receiving module 620 receives the second network registration request of the connected device; the second network registration request includes the connected device identifier and its corresponding first encrypted data, the first encrypted data being obtained by encrypting the connected device identifier based on the first key information; the connected device identifier encryption module 630 obtains the second encrypted data of the connected device identifier based on the second key information in the security key information; the connected device identifier security verification module 640 obtains the security verification result of the connected device identifier based on the first encrypted data and the second encrypted data; the security verification information response module 650 sends security verification information to the connected device, the security verification information including the security verification result. This device effectively verifies the authenticity of the connected device information during the network access process, improving the security and reliability of the connected device's network access, and meeting the stringent requirements for task authorization and security management in actual business scenarios. Corresponding to the network-connected device information security verification method applied to the second network element described in the above embodiments, this application also proposes a network-connected device information security verification device applied to the second network element.

[0157] Specifically, Figure 7 A schematic diagram of the structure of the network device information security verification device applied to the second network element provided in the embodiment of this application is shown.

[0158] like Figure 7As shown, the device includes: a subscription configuration request receiving module 710, used to receive a user subscription configuration request from a first network element, the user subscription configuration request including at least a network-connected device identifier; a subscription configuration request response module 720, used to respond to the user subscription configuration request and obtain security key information of the network-connected device identifier; and a security key information sending module 730, used to send security key information to the first network element.

[0159] In this embodiment, the subscription configuration request receiving module 710 receives a user subscription configuration request from the first network element, the user subscription configuration request including at least a network-connected device identifier; the subscription configuration request response module 720 responds to the user subscription configuration request and obtains the security key information of the network-connected device identifier; the security key information sending module 730 sends the security key information to the first network element. This device effectively verifies the authenticity of the device information during the network access process of the network-connected device, improving the security and reliability of the network access of the network-connected device and meeting the stringent requirements for task authorization and security management in actual business scenarios.

[0160] Corresponding to the network device information security verification method for network-connected devices described in the above embodiments, this application also proposes a network device information security verification device for network-connected devices.

[0161] Specifically, Figure 8 A schematic diagram of the structure of the network device information security verification device applied to network devices provided in an embodiment of this application is shown.

[0162] like Figure 8As shown, the device includes: a first key information receiving module 810, used to receive first key information sent by a first network element; a network-connected device identifier encryption calculation module 820, used to perform encryption calculation on the network-connected device identifier according to the first key information to obtain first encrypted data; and a network registration request sending module 830, used to send a network registration request to the first network element; the network registration request includes the network-connected device identifier and the first encrypted data of the network-connected device identifier, the first encrypted data being used for security verification of the network-connected device identifier. In this embodiment, the first key information receiving module 810 receives the first key information sent by the first network element; the network-connected device identifier encryption calculation module 820 performs encryption calculation on the network-connected device identifier according to the first key information to obtain first encrypted data; and the network registration request sending module 830 sends a network registration request to the first network element; the network registration request includes the network-connected device identifier and the first encrypted data of the network-connected device identifier, the first encrypted data being used for security verification of the network-connected device identifier. This device effectively verifies the authenticity of device information during the network access process, thereby improving the security and reliability of network access for connected devices and meeting the stringent requirements for task authorization and security management in actual business scenarios.

[0163] Figure 9 This example illustrates the physical structure of a core network access element, such as... Figure 9 As shown, the electronic device may include a processor 910, a communications interface 920, a memory 930, and a communication bus 940. The processor 910, communications interface 920, and memory 930 communicate with each other via the communication bus 940. The processor 910 can call logical instructions from the memory 930 to execute a network-connected device information security verification method applied to the first network element.

[0164] Figure 10 This example illustrates the entity structure of a core network functional authentication element, as shown below. Figure 10 As shown, the electronic device may include a processor 1010, a communications interface 920, a memory 1030, and a communication bus 1040. The processor 1010, communications interface 1020, and memory 1030 communicate with each other via the communication bus 1040. The processor 1010 can call logical instructions from the memory 1030 to execute a network-connected device information security verification method applied to the second network element.

[0165] Figure 11 An example is a schematic diagram of the physical structure of a connected device, such as... Figure 11 As shown, the electronic device may include a processor 1110, a communications interface 1120, a memory 1130, and a communication bus 1140. The processor 1110, communications interface 1120, and memory 1130 communicate with each other via the communication bus 1140. The processor 1110 can call logical instructions from the memory 1130 to execute a network-connected device information security verification method applied to the network-connected device.

[0166] Furthermore, the logical instructions in the aforementioned memories 930 / 1030 / 1130 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0167] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the network device information security verification method provided by the above methods.

[0168] In another aspect, this application also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, is implemented to perform the network device information security verification methods provided by the above methods.

[0169] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0170] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for checking information security of a networked device, applied to a first network element, and characterized in that, The method comprises the following steps: In response to a first network registration request of the network-connected device, security key information is obtained, and first key information in the security key information is sent to the network-connected device; A second network registration request of the network-connected device is received; the second network registration request comprises a network-connected device identifier and corresponding first encrypted data, and the first encrypted data is obtained by encrypting the network-connected device identifier according to the first key information; Second encrypted data of the network-connected device identifier is obtained according to second key information in the security key information; A security check result of the network-connected device identifier is obtained according to the first encrypted data and the second encrypted data; Security check information is sent to the network-connected device, and the security check information comprises the security check result.

2. The network equipment information security verification method of claim 1, wherein, The method comprises the following steps: The first network registration request of the network-connected device is received; A user subscription configuration request is sent to a second network element; Security key information fed back by the second network element is received; The first network registration request and the user subscription configuration request both comprise at least the network-connected device identifier.

3. The network equipment information security verification method of claim 2, wherein, The method further comprises the following steps before the user subscription configuration request is sent to the second network element: The network-connected device is subjected to access subscription authentication; If the access subscription authentication is passed, the user subscription configuration request is sent to the second network element.

4. The network equipment information security verification method of claim 1, wherein, The method further comprises the following steps of obtaining the security check result of the network-connected device identifier according to the first encrypted data and the second encrypted data: If the first encrypted data and the second encrypted data are consistent, the network-connected device information is safe as the security check result; If the first encrypted data and the second encrypted data are inconsistent, the network-connected device information is tampered as the security check result.

5. The network equipment information security verification method of claim 4, wherein, The method further comprises the following steps after the network-connected device information is safe as the security check result if the first encrypted data and the second encrypted data are consistent: The first encrypted data / the second encrypted data is reported to the second network element, and the second network element stores the security key information and the first encrypted data / the second encrypted data.

6. The networked device information security verification method of any one of claims 1-5, wherein, The method further comprises the following steps after the security key information is obtained in response to the first network registration request of the network-connected device: If the key validity period in the security key information meets a deadline condition, a key update mechanism is triggered.

7. A network equipment information security verification method applied to a second network element, characterized in that, The method comprises the following steps: A user subscription configuration request of a first network element is received, and the user subscription configuration request comprises at least a network-connected device identifier; In response to the user subscription configuration request, security key information of the network-connected device identifier is obtained; The security key information is sent to the first network element.

8. The network equipment information security verification method of claim 7, wherein, The method further comprises the following steps before the security key information of the network-connected device identifier is obtained in response to the user subscription configuration request: The network-connected device identifier is subjected to initial authentication determination.

9. The network equipment information security verification method of claim 8, wherein, The method further comprises the following steps of determining the initial authentication of the network-connected device identifier: If it is determined that the network-connected device identifier corresponding encrypted data is stored, the network-connected device identifier is subjected to initial authentication. If it is determined that no encrypted data corresponding to the network device identifier is stored, then the network device identifier is not the first authentication.

10. The network equipment information security verification method of claim 9, wherein, The step of responding to the user subscription configuration request and obtaining the security key information of the network device identifier includes: When the network-connected device identifier is in the case of initial authentication, the security key information of the network-connected device identifier is obtained by requesting an external source. If the network-connected device is identified as not being authenticated for the first time, the stored security key information can be directly retrieved.

11. The network equipment information security verification method of claim 10, wherein, When the network-connected device identifier is undergoing initial authentication, obtaining the security key information of the network-connected device identifier by requesting an external source includes: Send security key request information to data storage network element or traffic management network element through network open network element; Receive security key information returned by the data storage network element or the traffic management network element; The security key information includes first key information, second key information, key validity period, and network device identification validity information.

12. The network equipment information security verification method of claim 10, wherein, When the network-connected device identifier is undergoing initial authentication, obtaining the security key information of the network-connected device identifier by requesting an external source includes: Send a security key request message to the authentication, authorization, and accounting network element; Receive the security key information returned by the authentication, authorization, and billing network element; The security key information includes first key information, second key information, key validity period, and network device identification validity information.

13. The network equipment information security verification method of claim 7, wherein, Also includes: The system receives encrypted data reported by the first network element and stores the security key information and the encrypted data together.

14. A method for checking information security of an Internet of Things device, applied to the Internet of Things device, and characterized in that, include: Receive the first key information sent by the first network element; Based on the first key information, the identifier of the connected device is encrypted to obtain the first encrypted data; A network registration request is sent to the first network element; the network registration request includes the network device identifier and first encrypted data of the network device identifier, the first encrypted data being used for security verification of the network device identifier.

15. The network equipment information security verification method of claim 14, wherein, The process of receiving the first key information sent by the first network element includes, prior to: A first network registration request is sent to the first network element, wherein the first network registration request includes at least the identifier of the network-connected device.

16. The network equipment information security verification method of claim 14, wherein, The step of receiving the first key information sent by the first network element then includes: If the key validity period of the first key information meets the near-expiration condition, the key update mechanism is triggered.

17. The network equipment information security verification method of claim 14, wherein, The step of performing encryption calculations on the network device identifier based on the first key information to obtain first encrypted data includes: The network device identifier, the first key information, and the first encrypted data are transmitted to the network device hardware system for local storage.

18. The network equipment information security verification method of claim 14, wherein, The step of sending a network registration request to the first network element includes: The system receives security verification information sent by the first network element, wherein the security verification information includes the security verification result of the network device identifier.

19. A network connection device information security verification apparatus, applied to a first network element, characterized in that, include: The first network registration request response module is used to respond to the first network registration request of the network-connected device, obtain security key information, and send the first key information in the security key information to the network-connected device; The second network registration request receiving module is configured to receive a second network registration request of the network-connected device; the second network registration request comprises a network-connected device identifier and corresponding first encrypted data, and the first encrypted data is obtained by encrypting the network-connected device identifier according to the first key information; The network-connected device identifier encryption module is configured to obtain second encrypted data of the network-connected device identifier according to the second key information in the security key information; The network-connected device identifier security check module is configured to obtain a security check result of the network-connected device identifier according to the first encrypted data and the second encrypted data; The security check information response module is configured to send security check information to the network-connected device, wherein the security check information comprises the security check result.

20. A network connection device information security verification apparatus, applied to a second network element, characterized in that, The subscription configuration request receiving module is configured to receive a user subscription configuration request of a first network element, wherein the user subscription configuration request at least comprises a network-connected device identifier; The subscription configuration request response module is configured to obtain security key information of the network-connected device identifier in response to the user subscription configuration request; The security key information sending module is configured to send the security key information to the first network element. The first key information receiving module is configured to receive first key information sent by a first network element; 21. A networked device information security verification apparatus, applied to a networked device, characterized in that, The network-connected device identifier encryption calculation module is configured to encrypt the network-connected device identifier according to the first key information to obtain first encrypted data; The network registration request sending module is configured to send a network registration request to the first network element; the network registration request comprises the network-connected device identifier and the first encrypted data of the network-connected device identifier, and the first encrypted data is used for security check of the network-connected device identifier. The processor executes the computer program to implement the network-connected device information security check method in any one of claims 1 to 6. The processor executes the computer program to implement the network-connected device information security check method in any one of claims 7 to 13.

22. A first network element comprising a memory, a processor, and a computer program stored on the memory and running on the processor, wherein, The processor executes the computer program to implement the network-connected device information security check method in any one of claims 14 to 18.

23. A core network function authentication network element comprising a memory, a processor, and a computer program stored on the memory and running on the processor, wherein, The computer program is executed by the processor to implement the network-connected device information security check method in any one of claims 1 to 18. 24.A networked device comprising a memory, a processor, and a computer program stored on the memory and running on the processor, wherein, The computer program is executed by the processor to implement the network-connected device information security check method in any one of claims 1 to 18. 25.A non-transitory computer-readable storage medium having stored thereon a computer program. ​ 26. A computer program product comprising a computer program, characterised in that, ​