Communication method, passive Internet of Things equipment, communication device and storage medium
By providing a communication method within the 3GPP framework to receive and process messages containing device identification information and operation type information, and employing secure bearers and key protection, the operational problems of passive IoT devices are solved, the boundaries and application scenarios of the IoT are expanded, and communication security is improved.
Patent Information
- Application Number
- CN202411059024.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-02
- Publication Date
- 2026-02-03
AI Technical Summary
The lack of existing technologies provides operational solutions for passive IoT devices (AIoT devices) within the 3GPP framework, which limits the expansion of the boundaries and application scenarios of the Internet of Things.
A communication method is provided that enables operation of passive IoT devices by receiving and processing messages containing device identification information and operation type information, and employs a secure bearer and key protection mechanism to ensure the security and effectiveness of communication.
Operations on AIoT devices were implemented within the 3GPP framework, expanding the boundaries and application scenarios of the Internet of Things and improving the security and reliability of communication.
Smart Images

Figure CN121462991A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and in particular to a communication method, a passive Internet of Things (IoT) device, a communication apparatus, and a storage medium. Background Technology
[0002] Passive Internet of Things (IoT) is a highly simplified IoT technology with significant advantages such as high transmission speed, low power consumption, small size, and low cost, making it widely applicable across various industries. Utilizing the 3rd Generation Partnership Project (3GPP) to operate passive IoT devices (AIoT devices) will provide trillions of new connections for 5G networks and significantly expand the boundaries and application scenarios of IoT. However, there is still no clear solution on how to operate AIoT devices within the 3GPP framework. Summary of the Invention
[0003] This application provides a communication method, a passive IoT device, a communication apparatus, and a storage medium to address the problem of how to operate AIoT devices within the 3GPP framework.
[0004] In a first aspect, this application provides a communication method applied to a passive Internet of Things (IoT) device, comprising: The system receives a first device operation request message sent by a first entity. The first device operation request message includes device identification information and operation type information. The first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system. Based on the device identification information, determine the operation corresponding to the operation type information and send the first device operation response message to the first entity.
[0005] In some embodiments, the first device operation request message and the first device operation response message include an operation identifier, which is used to identify an operation instruction initiated by the first entity.
[0006] In some embodiments, the first device operation request message includes a first security bearer, which includes at least one of the following: device identification information protected by security, operation type information, and first security information.
[0007] In some embodiments, the first device operation response message includes a second security bearer, which contains security-protected response information and / or second security information.
[0008] In some embodiments, the first security information and the second security information each include one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0009] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0010] In some embodiments, the first device operation response message includes one or more of the following response information: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0011] In some embodiments, the first device operation request message and the first device operation response message further include message type information.
[0012] In some embodiments, the method further includes: A device identification protection key is generated using a dedicated key from a passive IoT device to protect the device's identity.
[0013] Secondly, this application also provides a communication method applied to a secure entity, comprising: Generate a first security bearer, which contains the following information protected by security: device identification information, operation type information, and first security information; A second device operation request message is sent to a second entity, the second device operation request message containing a first security bearer; wherein the second entity includes a reading device based on a base station or terminal, a passive IoT device, or a core network function entity.
[0014] In some embodiments, the second device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0015] In some embodiments, generating a first secure bearer includes: Receive a third device operation request message sent by a third entity. The third device operation request message contains device identification information and operation type information. The third entity may include a core network functional entity or an application system. The first security bearer is generated based on the third device operation request message.
[0016] In some embodiments, the third device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0017] In some embodiments, the method further includes: Receive a second device operation response message sent by a second entity. The second device operation response message contains a second security bearer and an operation identifier. The second security bearer contains the following information that is protected by security: response information and second security information. Decrypt and / or verify the integrity of the second security bearer to obtain response information.
[0018] In some embodiments, the method further includes: Send a third device operation response message to a third entity. The third device operation response message contains response information and operation identifier.
[0019] In some embodiments, the first security information and / or the second security information includes one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0020] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0021] In some embodiments, the response information includes one or more of the following: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0022] In some embodiments, the method further includes: Send a session key request message to the authentication entity. The session key request message contains the device identifier of the passive IoT device. The system receives the session key corresponding to the device identifier sent by the authentication entity and uses the session key to protect the information in the first security bearer.
[0023] In some embodiments, the method further includes: The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Security policy information; Key identification information; Safety parameters.
[0024] In some embodiments, sending a third device operation response message includes: Send a device identification authentication request message to the authentication entity. The device identification authentication request message contains the device identification of the passive IoT device or the device identification of the device that is protected by security. Based on the device identification authentication result sent by the authentication entity, a third device operation response message is sent.
[0025] In some embodiments, the method further includes: Send a device authentication vector request message to the authentication entity. The device authentication vector request message contains the device identifier of the passive IoT device. The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Equipment certification parameters; Second authentication response.
[0026] Thirdly, this application also provides a communication method applied to passive Internet of Things (IoT) devices, comprising: Receive a first device operation request message sent by a network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters. If the device identifier of the passive IoT device matches the device identifier information, the session key is determined based on the key identifier information and / or key derivation parameters. The first device operation request message is decoded and / or its integrity is verified based on the session key. Based on the decoding result and / or verification result, the operation corresponding to the operation type information is determined, and the first device operation response message is sent to the network device.
[0027] In some embodiments, the first security information further includes a first one-time value (Nonce); Decrypting and / or verifying the integrity of the first device operation request message based on the session key, including: The first device operation request message is decrypted and / or its integrity is verified based on the session key and the first nonce.
[0028] In some embodiments, before sending a first device operation response message to the network device, the method further includes: Generate a second nonce, and generate a first response message protection key based on the session key and the second nonce; The first device operation response message is securely protected based on the first response message protection key.
[0029] In some embodiments, the method further includes: A device identifier protection key is generated based on a dedicated key and a second nonce for passive IoT devices; The device identifier carried in the first device operation response message is securely protected based on the device identifier protection key.
[0030] In some embodiments, the first device operation response message includes second security information, which includes a second Nonce and / or key information for indicating that the device identifies the protection key.
[0031] In some embodiments, the method further includes: Receive device authentication request messages sent by network devices. The device authentication request messages include device identification information, operation type information indicating the authentication operation, and device authentication parameters. If the device identifier of the passive IoT device matches the device identifier information, the method further includes: verifying the device authentication parameters and sending a device authentication response message to the network device.
[0032] In some embodiments, before sending a device authentication response message to the network device, the method further includes: Generate a third nonce, and generate a second response message protection key based on the device authentication key and the third nonce; The device authentication response message is securely protected using the second response message protection key.
[0033] In some embodiments, the method further includes: The first authentication response is generated based on the protection key and device authentication parameters of the second response message.
[0034] In some embodiments, the device authentication response message includes one or more of the following: a third nonce, a first authentication response, and capability information of the passive IoT device.
[0035] Fourthly, this application also provides a passive Internet of Things (IoT) device, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: The system receives a first device operation request message sent by a first entity. The first device operation request message includes device identification information and operation type information. The first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system. Based on the device identification information, determine the operation corresponding to the operation type information and send the first device operation response message to the first entity.
[0036] In some embodiments, the first device operation request message and the first device operation response message include an operation identifier, which is used to identify an operation instruction initiated by the first entity.
[0037] In some embodiments, the first device operation request message includes a first security bearer, which includes at least one of the following: device identification information protected by security, operation type information, and first security information.
[0038] In some embodiments, the first device operation response message includes a second security bearer, which contains security-protected response information and / or second security information.
[0039] In some embodiments, the first security information and the second security information each include one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0040] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0041] In some embodiments, the first device operation response message includes one or more of the following response information: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0042] In some embodiments, the first device operation request message and the first device operation response message further include message type information.
[0043] In some embodiments, the operation further includes: A device identification protection key is generated using a dedicated key from a passive IoT device to protect the device's identity.
[0044] Fifthly, this application also provides a security entity, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: Generate a first security bearer, which contains the following information protected by security: device identification information, operation type information, and first security information; A second device operation request message is sent to a second entity, the second device operation request message containing a first security bearer; wherein the second entity includes a reading device based on a base station or terminal, a passive IoT device, or a core network function entity.
[0045] In some embodiments, the second device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0046] In some embodiments, generating a first secure bearer includes: Receive a third device operation request message sent by a third entity. The third device operation request message contains device identification information and operation type information. The third entity may include a core network functional entity or an application system. The first security bearer is generated based on the third device operation request message.
[0047] In some embodiments, the third device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0048] In some embodiments, the operation further includes: Receive a second device operation response message sent by a second entity. The second device operation response message contains a second security bearer and an operation identifier. The second security bearer contains the following information that is protected by security: response information and second security information. Decrypt and / or verify the integrity of the second security bearer to obtain response information.
[0049] In some embodiments, the operation further includes: Send a third device operation response message to a third entity. The third device operation response message contains response information and operation identifier.
[0050] In some embodiments, the first security information and / or the second security information includes one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0051] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0052] In some embodiments, the response information includes one or more of the following: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0053] In some embodiments, the operation further includes: Send a session key request message to the authentication entity. The session key request message contains the device identifier of the passive IoT device. The system receives the session key corresponding to the device identifier sent by the authentication entity and uses the session key to protect the information in the first security bearer.
[0054] In some embodiments, the operation further includes: The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Security policy information; Key identification information; Safety parameters.
[0055] In some embodiments, sending a third device operation response message includes: Send a device identification authentication request message to the authentication entity. The device identification authentication request message contains the device identification of the passive IoT device or the device identification of the device that is protected by security. Based on the device identification authentication result sent by the authentication entity, a third device operation response message is sent.
[0056] In some embodiments, the operation further includes: Send a device authentication vector request message to the authentication entity. The device authentication vector request message contains the device identifier of the passive IoT device. The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Equipment certification parameters; Second authentication response.
[0057] Sixthly, this application also provides a passive Internet of Things (IoT) device, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: Receive a first device operation request message sent by a network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters. If the device identifier of the passive IoT device matches the device identifier information, the session key is determined based on the key identifier information and / or key derivation parameters. The first device operation request message is decoded and / or its integrity is verified based on the session key. Based on the decoding result and / or verification result, the operation corresponding to the operation type information is determined, and the first device operation response message is sent to the network device.
[0058] In some embodiments, the first security information further includes a first one-time value (Nonce); Decrypting and / or verifying the integrity of the first device operation request message based on the session key, including: The first device operation request message is decrypted and / or its integrity is verified based on the session key and the first nonce.
[0059] In some embodiments, before sending the first device operation response message to the network device, the operation further includes: Generate a second nonce, and generate a first response message protection key based on the session key and the second nonce; The first device operation response message is securely protected based on the first response message protection key.
[0060] In some embodiments, the operation further includes: A device identifier protection key is generated based on a dedicated key and a second nonce for passive IoT devices; The device identifier carried in the first device operation response message is securely protected based on the device identifier protection key.
[0061] In some embodiments, the first device operation response message includes second security information, which includes a second Nonce and / or key information for indicating that the device identifies the protection key.
[0062] In some embodiments, the operation further includes: Receive device authentication request messages sent by network devices. The device authentication request messages include device identification information, operation type information indicating the authentication operation, and device authentication parameters. If the device identifier of the passive IoT device matches the device identifier information, the operation also includes: verifying the device authentication parameters and sending a device authentication response message to the network device.
[0063] In some embodiments, the operation further includes, before sending a device authentication response message to the network device: Generate a third nonce, and generate a second response message protection key based on the device authentication key and the third nonce; The device authentication response message is securely protected using the second response message protection key.
[0064] In some embodiments, the operation further includes: The first authentication response is generated based on the protection key and device authentication parameters of the second response message.
[0065] In some embodiments, the device authentication response message includes one or more of the following: a third nonce, a first authentication response, and capability information of the passive IoT device.
[0066] In a seventh aspect, this application also provides a communication device, comprising: The first receiving unit is configured to receive a first device operation request message sent by a first entity. The first device operation request message includes device identification information and operation type information. The first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system. The execution unit is used to determine the operation corresponding to the operation type information based on the device identification information, and send the first device operation response message to the first entity.
[0067] In some embodiments, the first device operation request message and the first device operation response message include an operation identifier, which is used to identify an operation instruction initiated by the first entity.
[0068] In some embodiments, the first device operation request message includes a first security bearer, which includes at least one of the following: device identification information protected by security, operation type information, and first security information.
[0069] In some embodiments, the first device operation response message includes a second security bearer, which contains security-protected response information and / or second security information.
[0070] In some embodiments, the first security information and the second security information each include one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0071] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0072] In some embodiments, the first device operation response message includes one or more of the following response information: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0073] In some embodiments, the first device operation request message and the first device operation response message further include message type information.
[0074] In some embodiments, the device further includes: The first generation unit is used to generate a protection key for protecting the device identifier using a dedicated key of a passive IoT device.
[0075] Eighthly, this application also provides a communication device, comprising: The second generation unit is used to generate a first security bearer, which includes the following information protected by security: device identification information, operation type information, and first security information; The first sending unit is used to send a second device operation request message to the second entity. The second device operation request message contains a first security bearer. The second entity includes a reading device based on a base station or terminal, a passive Internet of Things device, or a core network function entity.
[0076] In some embodiments, the second device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0077] In some embodiments, generating a first secure bearer includes: Receive a third device operation request message sent by a third entity. The third device operation request message contains device identification information and operation type information. The third entity may include a core network functional entity or an application system. The first security bearer is generated based on the third device operation request message.
[0078] In some embodiments, the third device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0079] In some embodiments, the device further includes: The second receiving unit is used to receive a second device operation response message sent by the second entity. The second device operation response message includes a second security bearer and an operation identifier. The second security bearer includes the following information that is protected by security: response information and second security information. The acquisition unit is used to decrypt and / or verify the integrity of the second security bearer and acquire response information.
[0080] In some embodiments, the device further includes: The second sending unit is used to send a third device operation response message to the third entity. The third device operation response message contains response information and operation identifier.
[0081] In some embodiments, the first security information and / or the second security information includes one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0082] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0083] In some embodiments, the response information includes one or more of the following: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0084] In some embodiments, the device further includes: The third sending unit is used to send a session key request message to the authentication entity. The session key request message contains the device identifier of the passive IoT device. The third receiving unit is used to receive the session key corresponding to the device identifier sent by the authentication entity, and to perform security protection on the information in the first security bearer based on the session key.
[0085] In some embodiments, the third receiving unit is further configured to: The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Security policy information; Key identification information; Safety parameters.
[0086] In some embodiments, sending a third device operation response message includes: Send a device identification authentication request message to the authentication entity. The device identification authentication request message contains the device identification of the passive IoT device or the device identification of the device that is protected by security. Based on the device identification authentication result sent by the authentication entity, a third device operation response message is sent.
[0087] In some embodiments, the device further includes: The fourth sending unit is used to send a device authentication vector request message to the authentication entity. The device authentication vector request message contains the device identifier of the passive IoT device. The fourth receiving unit is used to receive one or more of the following information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Equipment certification parameters; Second authentication response.
[0088] Ninthly, this application also provides a communication device, comprising: The fifth receiving unit is used to receive a first device operation request message sent by the network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters. The first processing unit is used to determine the session key based on the key identification information and / or key derivation parameters when it is determined that the device identifier of the passive Internet of Things device matches the device identifier information. The second processing unit is used to decode and / or verify the integrity of the first device operation request message based on the session key, determine the operation corresponding to the operation type information to be performed based on the decoding result and / or verification result, and send the first device operation response message to the network device.
[0089] In some embodiments, the first security information further includes a first one-time value (Nonce); Decrypting and / or verifying the integrity of the first device operation request message based on the session key, including: The first device operation request message is decrypted and / or its integrity is verified based on the session key and the first nonce.
[0090] In some embodiments, the second processing unit is further configured to: Generate a second nonce, and generate a first response message protection key based on the session key and the second nonce; The first device operation response message is securely protected based on the first response message protection key.
[0091] In some embodiments, the second processing unit is further configured to: A device identifier protection key is generated based on a dedicated key and a second nonce for passive IoT devices; The device identifier carried in the first device operation response message is securely protected based on the device identifier protection key.
[0092] In some embodiments, the first device operation response message includes second security information, which includes a second Nonce and / or key information for indicating that the device identifies the protection key.
[0093] In some embodiments, the device further includes: The sixth receiving unit is used to receive a device authentication request message sent by a network device. The device authentication request message includes device identification information, operation type information indicating the authentication operation, and device authentication parameters. The third processing unit is used to verify the device authentication parameters and send a device authentication response message to the network device when it is determined that the device identifier of the passive IoT device matches the device identifier information.
[0094] In some embodiments, the third processing unit is further configured to: Generate a third nonce, and generate a second response message protection key based on the device authentication key and the third nonce; The device authentication response message is securely protected using the second response message protection key.
[0095] In some embodiments, the third processing unit is further configured to: The first authentication response is generated based on the protection key and device authentication parameters of the second response message.
[0096] In some embodiments, the device authentication response message includes one or more of the following: a third nonce, a first authentication response, and capability information of the passive IoT device.
[0097] In a tenth aspect, this application also provides a non-transient readable storage medium storing a program for causing a processor to execute the communication method described in the first aspect, or the communication method described in the second aspect, or the communication method described in the third aspect.
[0098] Eleventhly, this application also provides a communication device, wherein the communication device stores a program for causing the communication device to perform the communication method described in the first aspect, or the communication method described in the second aspect, or the communication method described in the third aspect.
[0099] In a twelfth aspect, this application also provides a processor-readable storage medium storing a program for causing a processor to perform the communication method described in the first aspect, or the communication method described in the second aspect, or the communication method described in the third aspect.
[0100] In a thirteenth aspect, this application also provides a chip product, wherein the chip product stores a program for causing the chip product to perform the communication method described in the first aspect, or the communication method described in the second aspect, or the communication method described in the third aspect.
[0101] The communication method, passive IoT device, communication apparatus, and storage medium provided in this application enable the AIoT device to receive a first device operation request message sent by a reading device, core network functional entity, or application system based on a base station or terminal. After performing the corresponding operation based on the device identification information and operation type information carried in the first device operation request message, the device returns a first device operation response message, thereby realizing the operation of the AIoT device under the 3GPP framework, which is beneficial to expanding the boundaries and application scenarios of the Internet of Things. Attached Figure Description
[0102] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0103] Figure 1 This is one of the flowcharts illustrating the communication method provided in the embodiments of this application.
[0104] Figure 2 This is an example diagram of an AIoT architecture based on a 5G system provided in an embodiment of this application.
[0105] Figure 3 This is a second flowchart illustrating the communication method provided in an embodiment of this application.
[0106] Figure 4 This is the third flowchart illustrating the communication method provided in the embodiments of this application.
[0107] Figure 5 Example 1 flowchart provided for embodiments of this application.
[0108] Figure 6 Example 2 flowchart provided for embodiments of this application.
[0109] Figure 7 Example 3 flowchart provided for embodiments of this application.
[0110] Figure 8 Example 4 flowchart provided for embodiments of this application.
[0111] Figure 9 Example 5 flowchart provided for embodiments of this application.
[0112] Figure 10 Example 6 flowchart provided for embodiments of this application.
[0113] Figure 11 This is a schematic diagram of the structure of a passive Internet of Things (IoT) device provided in an embodiment of this application.
[0114] Figure 12 A schematic diagram of the structure of the security entity provided in the embodiments of this application.
[0115] Figure 13 This is one of the structural schematic diagrams of the communication device provided in the embodiments of this application.
[0116] Figure 14 This is a second schematic diagram of the communication device provided in the embodiments of this application.
[0117] Figure 15 This is the third schematic diagram of the communication device provided in the embodiments of this application. Detailed Implementation
[0118] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0119] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0120] In the embodiments of this application, the terms "first," "second," etc., are used to distinguish similar objects, and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, and the number of objects is not limited; for example, the first object can be one or more.
[0121] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0122] Figure 1 This is one of the flowcharts illustrating a communication method provided in an embodiment of this application. This method is applied to passive Internet of Things (IoT) devices, such as... Figure 1 As shown, the method includes the following steps 101 and 102.
[0123] Step 101: Receive a first device operation request message sent by a first entity. The first device operation request message includes device identification information and operation type information. The first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system.
[0124] Specifically, this application proposes a solution for operating passive Internet of Things (AIoT) devices (or simply devices) based on 3GPP technology. For ease of understanding, the various embodiments of this application are combined with... Figure 2 An example AIoT architecture diagram based on a 5G system is provided for illustration. Given the limited capabilities of AIoT devices, 3GPP Ambient IoT can employ a simplified architecture and protocols, including security architecture and protocols.
[0125] In some embodiments, the passive IoT device can be a passive IoT tag. The passive tag can be a passive radio frequency identification (RFID) tag.
[0126] A reading device based on a base station or terminal can be simply referred to as a reader. In this application, the reader can be a base station (i.e., a base station acting as an AIoT Reader) or a terminal (i.e., a terminal acting as an AIoT Reader) capable of operating AIoT devices. The reader can also be referred to as an operating entity. In some embodiments, the operating entity is responsible for discovering AIoT devices and performing specific interactive operations with the AIoT devices.
[0127] Core network functional entities may include the Access and Mobility Management Function (AMF), the standalone AIoT Management Function (AIoTMF), or other core network elements. Core network functional entities can interact with application systems through the external service interfaces of the 3GPP system.
[0128] The application system refers to the application system of AIoT devices, which can be an application function (AF).
[0129] The authentication entity can also be referred to as the authorization entity, authentication / authorization entity, or contract entity. In some embodiments, the authentication entity may be, for example, a Unified Data Management (UDM), which is responsible for generating the contract information of AIoT devices and providing the relevant information to the application system or AIoT devices.
[0130] Device identification information (or Device ID info) is used to identify the identification information of the AIoT device to be operated (such as device identifier, temporary device identifier, device group identifier, etc.) or the identifier mask used for device identifier filtering.
[0131] In some embodiments, the device identification information consists of two basic fields (identifier type and identifier value) and one auxiliary field (mask value): Identifier type: Indicates the type of identifier, such as the value of the identifier field: device identifier (ID), temporary device identifier (temporary ID), group identifier (group ID), ID mask, etc.
[0132] ID value: The value of the identifier of the category indicated by the identifier type.
[0133] Mask value: The value of the mask when the identifier type is indicated as an identifier mask.
[0134] Operation type information (or Operation) is used to indicate operation instructions, such as Inventory, Command, Reader, Write, Disable, Authentication, or other AIoT operation instructions.
[0135] In some embodiments, the first device operation request message may be sent by the application system (or sent through the core network functional entity and / or reader / writer) to the AIoT device.
[0136] In some embodiments, the first device operation request message may be sent to the AIoT device by a core network functional entity (or via a reader / writer). The core network functional entity may send the first device operation request message to the AIoT device based on a device operation request sent by the application system.
[0137] In some embodiments, the first device operation request message may be sent from the reader to the AIoT device. The reader may send the first device operation request message to the AIoT device based on a device operation request sent by the application system or core network functional entity.
[0138] In some embodiments, the first device operation request message further includes a message payload, which may include one or more of the following information: (1) Data area information (or data area info).
[0139] This data area information is used to indicate the data area for which the operation is requested, such as the storage area to be read or written.
[0140] (2) Data identification information.
[0141] The data identification information is a description or identification information of the data for which the requested operation is performed, such as a description or identification information of the content to be read or written.
[0142] (3) Information related to reading and writing content.
[0143] For example, for a read operation, the value of this information is empty or auxiliary information related to the read operation; for a write operation, the value of this information is the specific content to be written.
[0144] (4) Equipment certification parameters.
[0145] The device authentication parameter refers to the parameters provided by the network to AIoT devices that are related to device authentication. AIoT devices can use these parameters to authenticate the network or to calculate the authentication response so that the network can authenticate the device.
[0146] In some embodiments, the device authentication parameter is a Challenge, which is a data structure sent to the device. Depending on the device's capabilities, it can perform two functions: (1) the device can parse the Challenge and perform password-based verification to authenticate the network; (2) it can calculate the entire Challenge or a part of it to generate a response RES* that needs to be returned to the network for network authentication.
[0147] Step 102: Based on the device identification information, determine the operation corresponding to the operation type information and send the first device operation response message to the first entity.
[0148] Specifically, after receiving the first device operation request message, the AIoT device determines whether its own device identifier matches the device identifier information carried in the first device operation request message. If it is determined that the device identifier of the passive IoT device matches the device identifier information, the device performs the corresponding operation according to the operation type information, such as inventory, read, write or deactivate, and returns the first device operation response message.
[0149] In some embodiments, the first device operation response message includes one or more of the following response information: (1) Device identification of passive Internet of Things devices.
[0150] For example, for inventory operations, AIoT devices can return a device ID.
[0151] (2) Capability information of passive IoT devices.
[0152] For example, for inventory operations, AIoT devices can return device identification and capability information.
[0153] (3) The return content of the read operation.
[0154] For example, for a read operation, an AIoT device can return the content read.
[0155] (4) Write the result of the operation.
[0156] For example, for a write operation, an AIoT device can return the result of the write operation, such as "write successful".
[0157] (5) First authentication response.
[0158] For example, for authentication operations, AIoT devices can perform calculations based on device authentication parameters to generate a first authentication response, which is the result returned by the device authentication calculation.
[0159] In some embodiments, the first device operation request message and the first device operation response message further include message type information, which is used to indicate whether the message carrying the message type information is a device operation request message or a device operation response message.
[0160] For example, for a device operation request message, the message type information indicates that this message is an AIoT device operation request message. The message receiver determines that this message was sent by the AIoT system based on the message type information carried in the message. For a device operation response message, the message type information indicates that this message is an AIoT device operation response message. The message receiver determines that this message was sent by the AIoT device based on the message type information carried in the message.
[0161] The communication method provided in this application embodiment allows an AIoT device to receive a first device operation request message sent by a reading device, core network functional entity, or application system based on a base station or terminal. After performing the corresponding operation based on the device identification information and operation type information carried in the first device operation request message, the device returns a first device operation response message. This enables the operation of AIoT devices under the 3GPP framework, which is beneficial for expanding the boundaries and application scenarios of the Internet of Things.
[0162] In some embodiments, the first device operation request message and the first device operation response message include an operation identifier, which is used to identify an operation instruction initiated by the first entity.
[0163] Specifically, operations on AIoT devices can be session-based or session-free. In the case where operations on AIoT devices are not session-based, considering the large number of AIoT devices, this embodiment proposes to uniquely identify an operation instruction initiated by the application system or the first entity by carrying an operation identifier in the device operation request message and the device operation response message. The operation identifier can also be called a message identifier or message ID.
[0164] For example, for an operation command initiated by an application system, an operation identifier can be set. This operation identifier is carried in every device operation request message corresponding to the operation command up to the AIoT device. The AIoT device carries the operation identifier in the device operation response message, and the operation identifier is carried in every device operation response message corresponding to the operation command up to the application system.
[0165] In some embodiments, the operation identifier included in the first device operation request message and the first device operation response message may be an original operation identifier set by the application system, or it may be an identifier within the 3GPP system converted from the original operation identifier (for example, after receiving the original operation identifier sent by the application system, the core network functional entity converts the original operation identifier into an identifier within the 3GPP system). It should be noted that the operation identifiers described in this application can all be original operation identifiers set by the application system, or they can be identifiers within the 3GPP system converted from the original operation identifier.
[0166] Operation identifiers are used to indicate the request and response messages corresponding to a specific operation command, enabling the network side to correctly process messages gathered from the reader. For example, when executing the Inventory command, read and write operations on AIoT devices can begin before Inventory is fully executed, improving system efficiency.
[0167] In some embodiments, the first device operation request message further includes first security information.
[0168] In some embodiments, the first device operation request message includes a first security bearer, which includes at least one of the following: device identification information protected by security, operation type information, and first security information.
[0169] Specifically, for the operation process of an AIoT device with security capabilities, the first device operation request message sent by the first entity to the AIoT device may include a first security bearer, which includes at least one of the following: device identification information protected by security, operation type information, and first security information.
[0170] The secure bearer described in this application refers to a message body that is securely protected. In this application, security protection includes confidentiality protection and / or integrity protection.
[0171] In this application, providing security protection for device operation request messages or device operation response messages can be understood as providing security protection for the security bearer in the message, and decrypting (or decoding) and / or verifying the integrity of device operation request messages or device operation response messages can be understood as decrypting and / or verifying the integrity of the security bearer in the message.
[0172] In some embodiments, the first security information includes one or more of the following: (1) Security policy information.
[0173] Security policy information describes what security mechanisms are used to ensure message security; for example, it can be a combination of various security policies related to confidentiality and integrity. This security policy information can be a security policy identifier.
[0174] (2) Security algorithm information.
[0175] Security algorithm information describes which security algorithm is used to implement the security mechanism described in the security policy, such as the Advanced Encryption Standard (AES) algorithm, the Triple Data Encryption Standard (3DES) algorithm, or an algorithm that implements integrity protection. This security algorithm information can be a security algorithm identifier.
[0176] (3) Key identification information (or Key ID info).
[0177] This key identification information is used to indicate the key identifier from which the session key is derived. For example, if the device identification information is insufficient to describe all the required key information, the session key can be determined based on this key identification information.
[0178] (4) Safety parameters.
[0179] These security parameters include parameters used for session key derivation (or key derivation parameters) and parameters used in secure message computations. For example, security parameters include one-time values Nonce1 generated by the security entity and Nonce2 generated by the device. These parameters can participate in key protection and / or secure message computations (such as hash operations and / or encryption operations) to protect the information that needs to be protected in the message. These parameters can also be included in the message to make each message different.
[0180] For example, an AIoT device can derive a session key based on the key identification information and / or key derivation parameter in the first security information, and then derive the key actually used for message security protection based on the session key and the one-time value Nonce in the first security information, and then decrypt and verify the message.
[0181] (5) Message Integration Code (MIC).
[0182] This MIC is used for message integrity protection. In some embodiments, message integrity protection can be implemented using session keys.
[0183] In some embodiments, the first secure payload also includes one or more of the following information that are securely protected: data area information, data identification information, information related to the read / write content, and device authentication parameters. That is, the message payload in the first device operation request message described above is securely protected.
[0184] In some embodiments, the first security bearer also includes one or more of the following information that are protected by security: operation identifier and message type information.
[0185] In some embodiments, the first device operation request message includes a first security bearer and one or more of the following: operation identifier and message type information.
[0186] The following example illustrates the processing procedure of an AIoT device after receiving a first device operation request message: 1. Check message type: Is it a device operation request message? If yes, continue with the following operations; otherwise, terminate the operation.
[0187] 2. Match device identification information: Based on the device identification type and value carried in the message, as well as the possible mask value, determine whether this device meets the requirements of this operation request. If it does, continue with the following operations; otherwise, terminate the operation.
[0188] 3. Message security processing (i.e., decryption and / or integrity verification): Based on the security policy in the message, determine whether decryption and / or integrity verification need to be performed; if message security processing is required, determine the session key to be used based on the device identifier and / or key identifier information, and then use the session key, the security parameters carried in the message, the local security parameters, etc. to derive the key for this message security processing; then use the obtained or derived key to decrypt the ciphertext in the message and verify the integrity of the message.
[0189] 4. Perform the corresponding operation based on the operation type information and the content of the payload field in the message.
[0190] In some embodiments, the first device operation response message includes second security information.
[0191] In some embodiments, the first device operation response message includes a second security bearer, which contains security-protected response information and / or second security information.
[0192] Specifically, for the operation process of an AIoT device with security capabilities, the first device operation response message returned by the AIoT device may include a second security bearer, which contains response information protected by security and / or second security information.
[0193] In some embodiments, the second security information includes one or more of the following: (1) Security policy information.
[0194] Security policy information describes what security mechanisms are used to ensure message security; for example, it can be a combination of various security policies related to confidentiality and integrity. This security policy information can be a security policy identifier.
[0195] (2) Security algorithm information.
[0196] Security algorithm information describes which security algorithm is used to implement the security mechanism described by the security policy, such as AES, 3DES, or an algorithm for integrity protection. This security algorithm information can be a security algorithm identifier.
[0197] (3) Key identification information (or Key ID info).
[0198] This key identification information is used to indicate the key identifier for exporting the session key. For example, if the device identification information is insufficient to describe all the key information required to export the session key, this key identification information can be included in the second security information.
[0199] (4) Safety parameters.
[0200] These security parameters include parameters used for session key derivation (or key derivation parameters) and parameters used in secure message computations. For example, security parameters include one-time values Nonce1 generated by the security entity and Nonce2 generated by the device. These parameters can participate in key protection and / or secure message computations (such as hash operations and / or encryption operations) to protect the information that needs to be protected in the message. These parameters can also be included in the message to make each message different.
[0201] For example, the message receiver can derive the session key based on the key identification information and / or Keyderivation parameter in the second security information, and then derive the key actually used for message security protection based on the session key and the one-time value Nonce in the second security information, and then decrypt and verify the message.
[0202] The second security information carries a one-time value Nonce generated by the AIoT device. This one-time value Nonce can be used for two purposes: one is to make the information responded by the device different each time; the other is that the one-time value Nonce is involved in the derivation of the key that actually provides confidentiality and / or integrity protection for the message, so that the key actually used for message security protection is different each time.
[0203] (5) Message Integrity Protection Code (MIC).
[0204] This MIC is used for message integrity protection. In some embodiments, message integrity protection can be implemented using session keys.
[0205] In some embodiments, the second security bearer also includes one or more of the following information that are protected by security: operation identifier and message type information.
[0206] In some embodiments, the first device operation response message includes a second security bearer and one or more of the following information: operation identifier, message type information.
[0207] In some embodiments, the method further includes: generating a device identifier protection key for protecting the device identifier using a dedicated key of the passive IoT device.
[0208] Specifically, if security protection is required for the device identifier of the AIoT device in the response information, one implementation method is to use a message protection key for protection, and another implementation method is to use the specific key of the AIoT device to generate a protection key (which can be called the device identifier protection key) for protecting the device identifier, and use the device identifier protection key to protect the device identifier.
[0209] For example, an AIoT device can derive a device identification protection key using the device's private key and security parameters (Nonce and / or Key derivation parameter) from the first security information. This private key can be carried in the response information or indicated by default.
[0210] The following example illustrates a process for generating a first device operation response message on the AIoT device side, for example: 1. Construct the plaintext message of the first device operation response message, including: Set message type: Set to device operation response message.
[0211] Set operation identifier: Set to the same value as the device operation request message.
[0212] Constructing a message security domain (i.e., second security information): The security policy can be set to no security policy, or a combination of various security policies for confidentiality and integrity protection. When the device identifier is insufficient to determine the key used for message security protection, auxiliary key identification information can be carried in the message. Based on the selection of the security algorithm, the content of the security parameter field is set, such as a one-time value Nonce generated by the AIoT device that can participate in key derivation or message security computation. The derivation of the key used for message security protection can be based on security parameters (such as Nonce or other values) in the first device operation request message and / or locally generated security parameters (such as local Nonce or other values).
[0213] Obtain or export keys used for message security protection. Keys used for message security protection can be divided into confidentiality protection keys and integrity protection keys.
[0214] Determine the message bearer (i.e., the response information).
[0215] 2. Construct a security message for the first device operation response message, including: If the security policy is set to integrity protection, a message integrity protection code (MIC) is generated for the plaintext message using the message integrity protection key and appended to the message.
[0216] If the security policy is set to confidentiality protection, the part of the message that needs to be encrypted is encrypted using the message confidentiality protection key, such as the MIC value in the message bearer field and the message security field.
[0217] Figure 3 This is a second flowchart illustrating the communication method provided in this application embodiment. This method is applied to a secure entity, such as... Figure 3 As shown, the method includes the following steps 301 and 302.
[0218] Step 301: Generate a first security bearer. The first security bearer contains the following information that is protected by security: device identification information, operation type information, and first security information.
[0219] Step 302: Send a second device operation request message to the second entity. The second device operation request message contains a first security bearer. The second entity includes a reading device based on a base station or terminal, a passive IoT device, or a core network function entity.
[0220] Specifically, for the operation of AIoT devices with security capabilities, a security entity is introduced. In this application, the functions of the security entity can be implemented by a reader, a core network functional entity, or an application system. The security entity can provide security-related functions such as authenticating AIoT devices, secure processing of communication with AIoT devices, and secure communication between AIoT devices and the 3GPP network.
[0221] For example, when the application system implements the functions of the security entity, the application system initiates a device operation request and generates a first security bearer. The application system then sends the first security bearer in a second device operation request message to the second entity (such as the core network function entity).
[0222] For example, when the core network functional entity implements the functions of the security entity, the application system initiates a device operation request. The application system sends the device operation request message to the core network functional entity. The core network functional entity generates a first security bearer based on the device operation request message sent by the application system, and then sends the first security bearer in a second device operation request message to the second entity (such as a reader or AIoT device).
[0223] For example, when the reader implements the function of the security entity, the application system initiates a device operation request. The application system sends the device operation request message to the core network functional entity. The core network functional entity sends a device operation request message to the reader based on the device operation request message sent by the application system. The reader generates a first security bearer based on the device operation request message sent by the core network functional entity, and then sends the first security bearer to the AIoT device in a second device operation request message.
[0224] For example, when the function of a security entity is implemented by a reader / writer, the application system initiates a device operation request. The application system sends the device operation request message to the reader / writer. The reader / writer generates a first security bearer based on the device operation request message sent by the application system, and then sends the first security bearer to the AIoT device in a second device operation request message.
[0225] The device identification information, operation type information, and primary security information are consistent with the description above and will not be repeated here. Among them, the device identification information and operation type information can be set by the security entity (for example, the security entity is the application system that initiated the device operation request), or they can be carried in the device operation request message received by the security entity from other entities.
[0226] It is understandable that when the second entity is an AIoT device, the second device operation request message is the same as the first device operation request message.
[0227] In some embodiments, the second device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0228] In some embodiments, the second device operation request message also includes message type information.
[0229] In some embodiments, the first security bearer further includes one or more of the following information that are protected by security: data area information, data identification information, information related to the read / write content, and device authentication parameters.
[0230] In some embodiments, the first security bearer also includes one or more of the following information that are protected by security: operation identifier and message type information.
[0231] In some embodiments, the second device operation request message includes a first security bearer and one or more of the following information: operation identifier, message type information.
[0232] In some embodiments, generating a first secure bearer includes: Receive a third device operation request message sent by a third entity. The third device operation request message contains device identification information and operation type information. The third entity may include a core network functional entity or an application system. The first security bearer is generated based on the third device operation request message.
[0233] For example, when the core network functional entity implements the function of the security entity, the core network functional entity (security entity) receives a third device operation request message sent by the application system (third entity). The third device operation request message contains device identification information and operation type information. The core network functional entity generates a first security bearer based on the third device operation request message, and then sends the first security bearer to the second entity (such as a reader or AIoT device) in a second device operation request message.
[0234] For example, when the reader implements the function of the security entity, the reader (security entity) receives a third device operation request message sent by the core network function entity (third entity). The third device operation request message contains device identification information and operation type information. The reader generates a first security bearer based on the third device operation request message, and then sends the first security bearer to the AIoT device in a second device operation request message.
[0235] For example, when the function of a security entity is implemented by a reader, the reader (security entity) receives a third device operation request message sent by the application system (third entity). The third device operation request message contains device identification information and operation type information. The reader generates a first security bearer based on the third device operation request message, and then sends the first security bearer to the AIoT device in a second device operation request message.
[0236] In some embodiments, the third device operation request message further includes an operation identifier, which identifies an operation command initiated by the application system. The operation identifier included in the second device operation request message may be the same as the operation identifier included in the third device operation request message, or the operation identifier included in the second device operation request message may be an internal 3GPP system identifier converted from the original operation identifier included in the third device operation request message.
[0237] In some embodiments, the third device operation request message also includes message type information.
[0238] In some embodiments, the third device operation request message further includes a message payload, which may include one or more of the following information: data area information, data identification information, information related to the read / write content, and device authentication parameters.
[0239] The communication method provided in this application introduces a security entity to generate a first security bearer and includes the first security bearer in a device operation request message and sends it to a reader, AIoT device, or core network functional entity. The first security bearer includes device identification information and operation type information that are protected by security, thereby enabling the operation process of AIoT devices with security capabilities under the 3GPP framework and ensuring communication security during the operation of AIoT devices.
[0240] The following example illustrates a process for generating a second device operation request message on the security entity side, for example: 1. Set message type: Set to device operation request message.
[0241] 2. Set Operation Identifier: Generate an operation identifier that can uniquely identify this operation instruction.
[0242] 3. Construct device identification information, including: The identifier type is set based on the type of device identifier carried in this message, which can be: device ID, temporary device ID, group identifier, or device identifier with mask.
[0243] Set the identifier value of the specific device identifier carried in the message; when the identifier type is a masked device identifier, set the mask value.
[0244] 4. Construct the message security domain (i.e., the first security information): The security policy can be set to no security policy, or a combination of various security policies for confidentiality and integrity protection. When the device identifier is insufficient to determine the key used for message security protection, auxiliary key identification information can be carried in the message. Based on the selection of the message security algorithm, set the content of the security parameter field, such as a one-time value (Nonce) that can participate in key derivation or message security calculation. Obtain or derive the key used for message security protection, which can be divided into confidentiality protection keys and integrity protection keys.
[0245] 5. Set operation commands: These can be Inventory, Reader, Write, Disable, or other AIoT operation commands.
[0246] 6. Determine the message carrier, including: the data area information or data identification information to be read or written; the content to be written; and auxiliary information related to the read operation.
[0247] 7. Construct security messages: If the security policy is set to integrity protection, a message integrity protection code (MIC) is generated for the plaintext message using the message integrity protection key, and the generated MIC is appended to the message.
[0248] If the security policy is set to confidentiality protection, the part of the message that needs to be encrypted is encrypted using the message confidentiality protection key, such as the MIC value in the message bearer field and the message security field.
[0249] In some embodiments, the method further includes: Receive a second device operation response message sent by a second entity. The second device operation response message contains a second security bearer and an operation identifier. The second security bearer contains the following information that is protected by security: response information and second security information. Decrypt and / or verify the integrity of the second security bearer to obtain response information.
[0250] Specifically, after the security entity sends a second device operation request message to the second entity, the first security bearer is finally sent to the AIoT device. The AIoT device performs the corresponding operation based on the information in the first security bearer and sends a first device operation response message. The first device operation response message contains the second security bearer. The second security bearer is finally sent to the security entity. The security entity can decrypt and / or verify the integrity of the second security bearer to obtain the response information contained in the second security bearer.
[0251] The response information and the second security information are consistent with the previous description and will not be repeated here.
[0252] If the second device operation request message contains an operation identifier, the second device operation response message also contains the same operation identifier.
[0253] An example of a security entity decrypting and / or verifying the integrity of a second security bearer is as follows: The security entity can derive a session key based on the key identification information and / or key derivation parameter in the second security information, then derive the key actually used for message security protection based on the session key and the one-time value Nonce in the second security information, and then decrypt and verify the message.
[0254] The following example illustrates the processing procedure after a security entity receives an operation response message from a second device. 1. Check message type: Is it a device operation response message? If yes, continue with the following operations; otherwise, terminate the operation.
[0255] 2. Match Operation Identifier: Check if it is a response message to a previously broadcast device operation request. If yes, continue with the following operations; otherwise, terminate the operation.
[0256] 3. Message security processing: Based on the security policy in the message, determine whether decryption and / or integrity verification need to be performed; if message security processing is required, determine the session key to be used based on the device identifier and / or key identifier information, and then use the session key, the security parameters carried in the message, the local security parameters, etc. to derive the key for this message security processing; then use the obtained or derived key to decrypt the ciphertext in the message and verify the integrity of the message.
[0257] 4. If the security verification passes, retrieve the content of the fields carried in the message (i.e., the response information).
[0258] In some embodiments, the method further includes: sending a third device operation response message to a third entity, the third device operation response message containing response information and an operation identifier.
[0259] For example, if the security entity is not an application system, after obtaining the response information by decrypting and / or verifying the integrity of the second security bearer, the security entity can send a third device operation response message to the third entity, thus sending the response information to the third entity.
[0260] If the third device operation request message contains an operation identifier, the third device operation response message also contains the same operation identifier.
[0261] In some embodiments, sending a third device operation response message includes: Send a device identification authentication request message to the authentication entity. The device identification authentication request message contains the device identification of the passive IoT device or the device identification of the device that is protected by security. Based on the device identification authentication result sent by the authentication entity, a third device operation response message is sent.
[0262] For example, in a device inventory operation, after obtaining the response information, the security entity receives the device identifier returned by the AIoT device. The security entity can then send a device identifier authentication request message to the authentication entity. This message carries either the device identifier of the AIoT device or a securely protected device identifier returned by the AIoT device. The authentication entity checks the subscription information of the AIoT device to determine if the device identifier carried in the device identifier authentication request message is genuine. It then returns the check result (i.e., the device identifier authentication result) to the security entity. If the device identifier authentication result shows that the device identifier in the response information is genuine, the security entity sends a third device operation response message to the third entity.
[0263] If the device identifier carried in the device identifier authentication request message is protected by confidentiality, the device identifier authentication request message may also carry information such as key identifier information, security parameters, and device-specific key used for key derivation in the second security information, so that the authentication entity can derive the key and decrypt it to obtain the device identifier.
[0264] In some embodiments, the device identification authentication result includes the authenticated device identification and the device's capability information.
[0265] In some embodiments, the method further includes: Send a session key request message to the authentication entity. The session key request message contains the device identifier of the passive IoT device. The system receives the session key corresponding to the device identifier sent by the authentication entity and uses the session key to protect the information in the first security bearer.
[0266] Specifically, a security entity can request a session key from an authentication entity to secure the first security bearer. The session key request message carries the device identifier of the AIoT device.
[0267] For example, after a security entity determines that it is initiating a device operation request or receives a third device operation request message from a third entity, it can send a session key request message to the authentication entity to request a session key. The authentication entity queries the applicable session key based on the device identifier carried in the session key request message and returns it to the security entity. After receiving the session key, the security entity can use the session key to protect the information in the first security bearer.
[0268] In some embodiments, the security entity may also generate a one-time value Nonce, use the session key and the one-time value Nonce to generate a key that is actually used to securely protect the information in the first security bearer, and include the one-time value Nonce in the first security bearer and send it to the AIoT device.
[0269] In some embodiments, the method further includes: The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Security policy information; Key identification information; Safety parameters.
[0270] Specifically, the authentication entity can also return one or more of the following information corresponding to the device identifier to the security entity based on the session key request message: device identifier information, security policy information, key identifier information, and security parameters. The security entity can include this one or more of the information in the first security bearer and send it to the AIoT device. This one or more of the information is consistent with the device identifier information, security policy information, key identifier information, and security parameter descriptions contained in the first security bearer, and will not be repeated here.
[0271] In some embodiments, the method further includes: Send a device authentication vector request message to the authentication entity. The device authentication vector request message contains the device identifier of the passive IoT device. The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Equipment certification parameters; Second authentication response.
[0272] Specifically, after a security entity determines that it has initiated a device operation request or received a third device operation request message from a third entity, it can send a device authentication vector request message to the authentication entity to request relevant information for device authentication in order to perform the device authentication operation. The device authentication vector request message carries the device identifier of the AIoT device.
[0273] The authentication entity queries the device's subscription information based on the device identifier carried in the device authentication vector request message, and then returns one or more of the following information to the security entity: the device identifier, device authentication parameters, and the second authentication response. The security entity can include the device identifier and device authentication parameters in the first security bearer and send them to the AIoT device. The device identifier and device authentication parameters are consistent with the description above and will not be repeated here.
[0274] The second authentication response is provided by the authentication entity to the security entity for comparison with the first authentication response returned by the AIoT device in order to authenticate the device's information.
[0275] In some embodiments, the device authentication parameter is a Challenge, which is a data structure sent to the device. Depending on the device's capabilities, it can perform two functions: (1) the device can parse the Challenge and perform password-based verification to authenticate the network; (2) the device can calculate the Challenge as a whole or a part thereof to generate a response RES* that needs to be returned to the network for network authentication. This RES* is the first authentication response. The second authentication response provided by the authentication entity to the security entity is denoted as RES. After the security entity obtains RES* from the response information, it compares RES* with RES. If RES* is the same as RES, the device authentication is successful.
[0276] Figure 4 This is a third flowchart illustrating the communication method provided in this application embodiment. The method is applied to a network device (e.g., a reading device based on a base station or terminal), such as... Figure 4 As shown, the method includes the following steps 401, 402 and 403.
[0277] Step 401: Receive a first device operation request message sent by the network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters.
[0278] Step 402: If the device identifier of the passive IoT device matches the device identifier information, determine the session key based on the key identifier information and / or key derivation parameters.
[0279] Step 403: Decode and / or verify the integrity of the first device operation request message based on the session key; determine the operation corresponding to the operation type information based on the decoding result and / or verification result; and send the first device operation response message to the network device.
[0280] In some embodiments, the first security information further includes a first one-time value (Nonce); Decrypting and / or verifying the integrity of the first device operation request message based on the session key, including: The first device operation request message is decrypted and / or its integrity is verified based on the session key and the first nonce.
[0281] In some embodiments, before sending a first device operation response message to the network device, the method further includes: Generate a second nonce, and generate a first response message protection key based on the session key and the second nonce; The first device operation response message is securely protected based on the first response message protection key.
[0282] In some embodiments, the method further includes: A device identifier protection key is generated based on a dedicated key and a second nonce for passive IoT devices; The device identifier carried in the first device operation response message is securely protected based on the device identifier protection key.
[0283] In some embodiments, the first device operation response message includes second security information, which includes a second Nonce and / or key information for indicating that the device identifies the protection key.
[0284] In some embodiments, the method further includes: Receive device authentication request messages sent by network devices. The device authentication request messages include device identification information, operation type information indicating the authentication operation, and device authentication parameters. If the device identifier of the passive IoT device matches the device identifier information, the method further includes: verifying the device authentication parameters and sending a device authentication response message to the network device.
[0285] In some embodiments, before sending a device authentication response message to the network device, the method further includes: Generate a third nonce, and generate a second response message protection key based on the device authentication key and the third nonce; The device authentication response message is securely protected using the second response message protection key.
[0286] In some embodiments, the method further includes: The first authentication response is generated based on the protection key and device authentication parameters of the second response message.
[0287] In some embodiments, the device authentication response message includes one or more of the following: a third nonce, a first authentication response, and capability information of the passive IoT device.
[0288] In some embodiments, the first device operation request message and the first device operation response message include an operation identifier.
[0289] In some embodiments, the device authentication request message and the device authentication response message include an operation identifier.
[0290] In some embodiments, the first device operation request message may further include one or more of the following message bearers (which may be security-protected message bearers): data area information; data identification information; information related to the read / write content; and device authentication parameters.
[0291] In some embodiments, the first device operation response message may further include one or more of the following message bearers (which may be security-protected message bearers): the device identifier of the passive IoT device; the capability information of the passive IoT device; the return content of the read operation; the result of the write operation; and the first authentication response.
[0292] The methods provided in the various embodiments of this application are based on the same technical concept, so the implementation of each method can be referred to each other, and repeated parts will not be described again.
[0293] The methods provided in the above embodiments of this application are illustrated by specific examples below.
[0294] Example 1: Figure 5 Example 1 flowchart provided for embodiments of this application, such as Figure 5 As shown in Example 1, the functions of the security entity are implemented by core network elements. The main interaction flow of Example 1 includes: Step 1-1: The AF sends a device operation request to the core network (5GC). The device operation request includes: message type, operation identifier, device identifier information, operation type information and message payload.
[0295] Steps 1-2: The core network constructs a security message (first security bearer) and then sends a device operation request to the reader. The device operation request includes: operation control information that the reader may need (such as the number of AIoT devices that may be involved in the operation command, which the reader can use to optimize the allocation of air interface resources), command type (such as the command type can be used to distinguish between Inventory and Command operations so that the reader can execute Inventory operations), message type, operation identifier, and first security bearer.
[0296] Steps 1-3: The reader sends a device operation request to the AIoT device. The device operation request includes: message type, operation identifier, and first security bearer.
[0297] Steps 1-4: The AIoT device responds to the device operation request by sending a device operation response, which includes: message type, operation identifier, and second security bearer.
[0298] Steps 1-5: The reader determines whether the message response is valid based on the message type and operation identifier; if valid, it returns a device operation response to 5GC, which includes: message type, operation identifier, and second security bearer.
[0299] Steps 1-6: 5GC decrypts and verifies the received second security bearer, and then returns a device operation response to AF, which includes: message type, operation identifier, and message bearer.
[0300] Example 2: Figure 6 Example 2 flowchart provided for embodiments of this application, such as Figure 6 As shown in Example 2, the reader / writer implements the functionality of the security entity. The main interaction flow in Example 2 includes: Step 2-1: The AF sends a device operation request to the core network (5GC). The device operation request includes: message type, operation identifier, device identifier information, operation type information and message payload.
[0301] Step 2-2: The core network sends a device operation request to the reader. The device operation request includes: operation control information that the reader may need (such as the number of AIoT devices that may be involved in the operation command, which the reader can use to optimize the allocation of air interface resources), command type (such as the command type can be used to distinguish between Inventory and Command operations so that the reader can execute Inventory operations), message type, operation identifier, operation type information, and message payload.
[0302] Steps 2-3: The reader constructs a security message (first security bearer) and then sends a device operation request to the AIoT device. The device operation request includes: message type, operation identifier and first security bearer.
[0303] Steps 2-4: The AIoT device responds to the device operation request by sending a device operation response, which includes: message type, operation identifier, and second security bearer.
[0304] Steps 2-5: The reader determines whether the message response is valid based on the message type and operation identifier. If valid, it decrypts and verifies the received second security bearer. Then, it returns a device operation response to 5GC, which includes the message type, operation identifier, and message bearer.
[0305] Steps 2-6: 5GC returns a device operation response to AF, which includes: message type, operation identifier, and message payload.
[0306] Example 3: Figure 7 Example 3 flowchart provided for embodiments of this application, such as Figure 7 As shown in Example 3, the security entity functionality is implemented by the application layer. The main interaction flow in Example 3 includes: Step 3-1: The AF sends a device operation request to the core network (5GC). The device operation request includes: message type, operation identifier, operation type information and first security bearer.
[0307] Step 3-2: The core network sends a device operation request to the reader. The device operation request includes: operation control information that the reader may need (such as the number of AIoT devices that may be involved in the operation command, which the reader can use to optimize the allocation of air interface resources), command type (such as the command type can be used to distinguish between Inventory and Command operations so that the reader can execute Inventory operations), message type, operation identifier, and first security bearer.
[0308] Step 3-3: The reader sends a device operation request to the AIoT device. The device operation request includes: message type, operation identifier and first security bearer.
[0309] Steps 3-4: The AIoT device responds to the device operation request by sending a device operation response, which includes: message type, operation identifier, and second security bearer.
[0310] Steps 3-5: The reader determines whether the message response is valid based on the message type and operation identifier. If valid, it returns a device operation response to 5GC, which includes: message type, operation identifier, and second security bearer.
[0311] Steps 3-6: 5GC returns a device operation response to AF, which includes: message type, operation identifier, and second security bearer.
[0312] Example 4: Figure 8 Example 4 flowchart provided for embodiments of this application, such as Figure 8 As shown in Example 4, the reader implements the functions of the security entity, and the reader interacts directly with the application system. The main interaction flow in Example 4 includes: Step 4-1: AF sends a device operation request to the reader / writer. The device operation request includes: message type, operation identifier, device identifier information, operation type information, and message payload.
[0313] Step 4-2: The reader constructs a security message (first security bearer) and then sends a device operation request to the AIoT device. The device operation request includes: message type, operation identifier and first security bearer.
[0314] Step 4-3: The AIoT device responds to the device operation request by sending a device operation response, which includes: message type, operation identifier, and second security bearer.
[0315] Step 4-4: The reader determines whether the message response is valid based on the message type and operation identifier. If valid, it returns a device operation response to the AF, which includes the message type, operation identifier, and message payload.
[0316] Example 5: Figure 9 Example 5 flowchart provided for embodiments of this application, such as Figure 9 As shown in Example 5, the core network elements implement the security entity function, and the operation type is Inventory operation. The main interaction flow of Example 5 includes: Step 5-1: The AF sends a device operation request to the security entity. This device operation request includes: Message ID: Message identifier (also known as operation identifier), used as a unique identifier for operation instructions between the AF and the core network.
[0317] Device ID info: Device identification information, used for this device query. It can be a specific device identifier, a device group identifier, or a device identifier mask used to filter device identifiers, etc.
[0318] Operation: Operation type information; in this example, it is set to Inventory.
[0319] Payload: Message carrier. Here, it contains parameters related to equipment inventory provided to the core network. It can be used to carry additional query filtering conditions, such as querying only the information of a given device in a certain device group.
[0320] Step 5-2: If it is not necessary to protect certain information in the Inventory directive, skip steps 5-2 and 5-3. The security entity sends a session key request to the authentication entity (i.e., the entity that holds the device subscription information, or the authorization entity, authentication or authorization entity, etc.). This session key request includes: Device ID info.
[0321] Step 5-3: The authentication entity queries the applicable session key for protecting the message based on the Device ID info and returns the following information to the security entity: 'Device ID info' (optional): A unique device identifier for the device ID info used for the session between the device and the network (to protect user privacy information), such as a temporary device identifier or a group temporary identifier.
[0322] Security policy: Specifies the security policies used for messages, such as confidentiality protection and / or integrity protection.
[0323] Session key: A session key used to protect messages.
[0324] Key ID Info (optional): Indicates key identification information used by the device to export the session key.
[0325] Key derivation parameter: The device can derive the session key using the key indicated by the Key ID Info and this parameter.
[0326] Step 5-4: The security entity sends an inventory request to the device. This inventory request includes: Message ID: This can be a message identifier generated by the authentication entity to identify this operation, or the Message ID provided by AF can be used directly.
[0327] Device ID info'.
[0328] Operation: Set to Inventory operation.
[0329] Key ID Info (optional).
[0330] Key derivation parameter.
[0331] For steps 5-5 to 5-7, there are two processing methods as follows.
[0332] Method 1: Step 5-5: The device checks the Device ID info; if it matches, it derives the session key using the key specified in the Key ID Info and the Key derivation parameter. A one-time value, Nonce, is generated, which can be used for two purposes: (1) to ensure the device response information is different each time; (2) to participate in the derivation of the key that actually provides confidentiality and / or integrity protection for the message, with the key used for message protection being different each time. The generated message protection key is used to protect the sent message (i.e., the device inventory response), which includes: Message ID: Its value is the same as that in the device inventory request.
[0333] Nonce.
[0334] Secured Device ID info: The device identifier of this device that is securely protected. This value can be encrypted if confidentiality protection (privacy protection) is provided.
[0335] Device capability (optional): This describes the device's capabilities, including its AIoT capabilities and / or security capabilities.
[0336] MIC (optional): Message Integrity Protection Code.
[0337] Steps 5-6: The security entity uses the session key and the nonce to derive the key for the actual protection message (device inventory response), then decrypts and verifies the message. It then sends a device identification authentication request to the authentication entity, which includes Device ID info.
[0338] Steps 5-7: The authentication entity checks the device's contract information, determines whether the device identifier included in the device identifier authentication request is genuine, and returns the device identifier authentication result to the security entity.
[0339] Method 2 (The difference from Method 1 is that the device uses its unique private key to protect the device identifier, so authentication entity processing is required): Step 5-5: The device checks the Device ID info; if it matches, the session key is derived using the key specified in the Key ID Info and the Key derivation parameter. A one-time value, Nonce, is generated. This value can be used for two purposes: (1) to make the information in the device response different each time; (2) to participate in the derivation of the key that actually provides confidentiality and / or integrity protection for the message, and the key used for message protection is different each time. The device identification protection key is derived using the device's private key (which may be indicated by the Key Info in the device inventory response, or by default), Nonce, Key derivation parameter, etc. The message protection key is derived using the key specified in the device inventory request, Nonce, Key derivation parameter, etc., and the generated message protection key is used to protect the sent message (i.e., the device inventory response), which includes: Message ID: Its value is the same as that in the device inventory request.
[0340] Key Info (Optional): Key information used by the device to protect the device identifier.
[0341] Nonce.
[0342] Secured Device ID info: The device identifier of this device that is securely protected. This value can be encrypted if confidentiality protection (privacy protection) is provided.
[0343] Device capability (optional): This describes the device's capabilities, including its AIoT capabilities and / or security capabilities.
[0344] MIC (optional): Message Integrity Protection Code. Message integrity protection can be implemented using session keys.
[0345] Steps 5-6: The security entity decrypts and verifies the integrity of the message, and then sends a device identifier authentication request to the authentication entity. The device identifier authentication request includes: Key Info.
[0346] Nonce.
[0347] Secured Device ID info.
[0348] Steps 5-7: The authentication entity uses Key Info, Nonce, Key derivation parameter, etc., to derive the key, decrypt the device identifier, determine whether the device identifier is genuine, and return the device identifier authentication result to the security entity. The device identifier authentication response includes: Device ID information.
[0349] Device capability (optional).
[0350] Steps 5-8: The security entity returns to the AF: Message ID.
[0351] Device ID list.
[0352] In this example, the security entity and the authentication entity can be combined into one.
[0353] Example 6: Figure 10 Example 6 flowchart provided for embodiments of this application, such as Figure 10 As shown in Example 6, the core network elements implement the functions of the security entity, and the operation type is Command operation. The main interaction flow of Example 6 includes: Step 6-1: The AF sends a device operation request to the security entity. This device operation request includes: Message ID: Message identifier (also known as operation identifier), used as a unique identifier for operation instructions between the AF and the core network.
[0354] Device ID info: Device identification information, used for this device query. It can be a specific device ID, a device group ID, or a device ID mask used to filter device IDs.
[0355] Operation: Operation type information; in this example, it is set to device command.
[0356] Payload: Message carrier, here it is the information sent to the device that is transparent to the core network in relation to the Command.
[0357] Step 6-2: The security entity sends a device authentication vector request to the authentication entity (i.e., the signing entity that has the device subscription information, or the authorization entity, authentication or authorization entity, etc.). The device authentication vector request includes: Device ID info.
[0358] Step 6-3: The authentication entity queries the device subscription information based on the Device ID info and returns the following information to the security entity: 'Device ID info' (optional): A unique device identifier used for the device's session with the network (to protect user privacy information), such as a temporary device identifier.
[0359] Challenge: Device authentication parameters, the data structure sent to the device. Based on the different capabilities of the device, it can achieve two functions: (1) The device can parse the Challenge and perform password-based verification to authenticate the network; (2) Calculate the whole or part of the Challenge to generate a response RES* that needs to be returned to the network for network authentication.
[0360] RES: Authentication Response. This response is provided to the security entity for comparison with the RES* returned by the device in order to authenticate the device.
[0361] Step 6-4: The security entity sends a device authentication request to the device. The device authentication request includes: Message ID: This can be a message identifier generated by the authentication entity to identify this operation, or the Message ID provided by AF can be used directly.
[0362] Device ID info or Device ID info'.
[0363] Operation: Set to Authentication operation.
[0364] Challenge.
[0365] Step 6-5: The device checks the Device ID Info; if it matches, it verifies the Challenge (if it has this function); then it generates a one-time value Nonce; using the device authentication key and the Nonce, it performs a key derivation operation to obtain the key for this specific message processing, and uses this key to operate on the Challenge or a portion of its values, generating an authentication response RES*. The device authentication response sent by the device to the network includes: Message ID: Its value is the same as that in the device authentication request.
[0366] Nonce.
[0367] RES*.
[0368] Device capability (optional): Describes the AIoT device capabilities and / or security capabilities that the device possesses.
[0369] Step 6-6: The security entity compares the received RES* with the local RES. If they are the same, the device authentication is successful.
[0370] Note: The authentication process and the command execution process are actually two separate processes and do not necessarily have to be executed sequentially. The authentication process is already implicitly included in the actual command execution process because the device has the key for secure communication.
[0371] Steps 6-7: To ensure message security, the security entity sends a session key request to the authentication entity. The request includes: Device ID information.
[0372] Device capability (optional).
[0373] Steps 6-8: The authentication entity returns information to the security entity. Device ID info'.
[0374] Security policy: Message security policy.
[0375] Session key: A session key used for message security.
[0376] Key ID Info (optional): Key identifier, used to indicate which key to use to generate the session key when multiple keys are available on the device.
[0377] Key derivation parameter: Parameter used to derive the Session key.
[0378] Steps 6-9: The security entity generates a one-time value, Nonce1, which can be used for two purposes: (1) to derive the actual key used for message security using the Session key and Nonce1; (2) for message uniqueness. The security entity sends a device operation request to the device, which includes: Message ID'.
[0379] Device ID info or Device ID info'.
[0380] Operation: Set as a Command operation.
[0381] Security policy.
[0382] Nonce1.
[0383] Key ID Info (optional).
[0384] Key derivation parameter.
[0385] Secured Payload.
[0386] MIC: Message Integrity Protection Code.
[0387] Steps 6-10: The device checks the Device ID info or Device ID info'. If they match, it determines the master key (which can be determined using Key ID Info) and exports the session key using the Key derivation parameter. It then uses the session key and Nonce1 to verify and decrypt messages. A one-time device value, Nonce2, is generated; the purpose and function of Nonce2 are the same as Nonce1. Finally, the device uses the session key, Nonce1, and Nonce2 to generate a response message protection key and protect the response message. The response message (device operation response) contains: Message ID'.
[0388] Security policy.
[0389] Nonce2.
[0390] Secured Payload.
[0391] MIC.
[0392] Steps 6-11: The security entity uses the Session key, Nonce1, Nonce2, etc., to generate a response message protection key, and uses it to decrypt and verify the response message to obtain the plaintext payload. The security entity returns the payload to the AF through the device operation response, which includes: Message ID.
[0393] Payload.
[0394] In this example, the security entity and the authentication entity can be combined into one.
[0395] Figure 11 This is a schematic diagram of the structure of a passive IoT device provided in an embodiment of this application, such as... Figure 11 As shown, the passive IoT device includes a memory 1120, a transceiver 1110, and a processor 1100; wherein the processor 1100 and the memory 1120 can also be physically arranged separately.
[0396] The memory 1120 is used to store computer programs; the transceiver 1110 is used to send and receive data under the control of the processor 1100.
[0397] Among them, Figure 11 In this application, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1100 and memory represented by memory 1120 together. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be further described herein. The bus interface provides an interface. The transceiver 1110 may be multiple elements, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, and other transmission media.
[0398] The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 can store the data used by the processor 1100 when performing operations.
[0399] The processor 1100 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0400] The processor 1100 executes any of the methods described in the passive IoT device embodiments of this application by calling the computer program stored in the memory 1120 according to the obtained executable instructions.
[0401] Figure 12 A schematic diagram of the structure of the security entity provided in the embodiments of this application, such as Figure 12 As shown, the security entity includes a memory 1220, a transceiver 1210, and a processor 1200; wherein the processor 1200 and the memory 1220 can also be physically arranged separately.
[0402] The memory 1220 is used to store computer programs; the transceiver 1210 is used to send and receive data under the control of the processor 1200.
[0403] Among them, Figure 12 In this application, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1200 and memory represented by memory 1220 together. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be further described herein. The bus interface provides an interface. The transceiver 1210 may be multiple elements, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, and other transmission media.
[0404] The processor 1200 is responsible for managing the bus architecture and general processing, while the memory 1220 can store the data used by the processor 1200 when performing operations.
[0405] The processor 1200 can be a CPU, ASIC, FPGA or CPLD, and the processor can also adopt a multi-core architecture.
[0406] The processor 1200 executes any of the methods described in the security entity side of the embodiments of this application by calling the computer program stored in the memory 1220 according to the obtained executable instructions.
[0407] It should be noted that the passive IoT device and security entity provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail here.
[0408] The communication device provided in the embodiments of this application is described below. The communication device described below can be referred to in correspondence with the communication method described above.
[0409] Figure 13 This is one of the structural schematic diagrams of the communication device provided in the embodiments of this application, such as... Figure 13 As shown, the device includes a first receiving unit 1310 and an execution unit 1320.
[0410] The first receiving unit 1310 is used to receive a first device operation request message sent by a first entity. The first device operation request message includes device identification information and operation type information. The first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system.
[0411] The execution unit 1320 is used to determine the operation corresponding to the operation type information based on the device identification information, and send a first device operation response message to the first entity.
[0412] In some embodiments, the first device operation request message and the first device operation response message include an operation identifier, which is used to identify an operation instruction initiated by the first entity.
[0413] In some embodiments, the first device operation request message includes a first security bearer, which includes at least one of the following: device identification information protected by security, operation type information, and first security information.
[0414] In some embodiments, the first device operation response message includes a second security bearer, which contains security-protected response information and / or second security information.
[0415] In some embodiments, the first security information and the second security information each include one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0416] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0417] In some embodiments, the first device operation response message includes one or more of the following response information: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0418] In some embodiments, the first device operation request message and the first device operation response message further include message type information.
[0419] In some embodiments, the device further includes: The first generation unit is used to generate a protection key for protecting the device identifier using a dedicated key of a passive IoT device.
[0420] Figure 14 This is a second schematic diagram of the communication device provided in the embodiments of this application, as shown below. Figure 14 As shown, the device includes a second generating unit 1410 and a first transmitting unit 1420.
[0421] The second generation unit 1410 is used to generate a first security bearer, which includes the following information protected by security: device identification information, operation type information, and first security information.
[0422] The first sending unit 1420 is used to send a second device operation request message to a second entity. The second device operation request message contains a first security bearer. The second entity includes a reading device based on a base station or terminal, a passive Internet of Things device, or a core network function entity.
[0423] In some embodiments, the second device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0424] In some embodiments, generating a first secure bearer includes: Receive a third device operation request message sent by a third entity. The third device operation request message contains device identification information and operation type information. The third entity may include a core network functional entity or an application system. The first security bearer is generated based on the third device operation request message.
[0425] In some embodiments, the third device operation request message further includes an operation identifier, which is used to identify an operation instruction initiated by the application system.
[0426] In some embodiments, the device further includes: The second receiving unit is used to receive a second device operation response message sent by the second entity. The second device operation response message includes a second security bearer and an operation identifier. The second security bearer includes the following information that is protected by security: response information and second security information. The acquisition unit is used to decrypt and / or verify the integrity of the second security bearer and acquire response information.
[0427] In some embodiments, the device further includes: The second sending unit is used to send a third device operation response message to the third entity. The third device operation response message contains response information and operation identifier.
[0428] In some embodiments, the first security information and / or the second security information includes one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
[0429] In some embodiments, the first security bearer further includes one or more of the following information that is securely protected: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
[0430] In some embodiments, the response information includes one or more of the following: Device identification for passive IoT devices; Capability information of passive IoT devices; The return value of the read operation; Write the result of the operation; First authentication response.
[0431] In some embodiments, the device further includes: The third sending unit is used to send a session key request message to the authentication entity. The session key request message contains the device identifier of the passive IoT device. The third receiving unit is used to receive the session key corresponding to the device identifier sent by the authentication entity, and to perform security protection on the information in the first security bearer based on the session key.
[0432] In some embodiments, the third receiving unit is further configured to: The following one or more pieces of information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Security policy information; Key identification information; Safety parameters.
[0433] In some embodiments, sending a third device operation response message includes: Send a device identification authentication request message to the authentication entity. The device identification authentication request message contains the device identification of the passive IoT device or the device identification of the device that is protected by security. Based on the device identification authentication result sent by the authentication entity, a third device operation response message is sent.
[0434] In some embodiments, the device further includes: The fourth sending unit is used to send a device authentication vector request message to the authentication entity. The device authentication vector request message contains the device identifier of the passive IoT device. The fourth receiving unit is used to receive one or more of the following information corresponding to the device identifier sent by the authentication entity: Equipment identification information; Equipment certification parameters; Second authentication response.
[0435] Figure 15 This is the third schematic diagram of the communication device provided in the embodiments of this application, as shown below. Figure 15 As shown, the device includes a fifth receiving unit 1510, a first processing unit 1520, and a second processing unit 1530.
[0436] The fifth receiving unit 1510 is used to receive a first device operation request message sent by a network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters. The first processing unit 1520 is used to determine a session key based on key identification information and / or key derivation parameters when it is determined that the device identifier of the passive Internet of Things device matches the device identifier information. The second processing unit 1530 is used to decode and / or verify the integrity of the first device operation request message based on the session key, determine the operation corresponding to the operation type information to be performed based on the decoding result and / or verification result, and send the first device operation response message to the network device.
[0437] In some embodiments, the first security information further includes a first one-time value (Nonce); Decrypting and / or verifying the integrity of the first device operation request message based on the session key, including: The first device operation request message is decrypted and / or its integrity is verified based on the session key and the first nonce.
[0438] In some embodiments, the second processing unit is further configured to: Generate a second nonce, and generate a first response message protection key based on the session key and the second nonce; The first device operation response message is securely protected based on the first response message protection key.
[0439] In some embodiments, the second processing unit is further configured to: A device identifier protection key is generated based on a dedicated key and a second nonce for passive IoT devices; The device identifier carried in the first device operation response message is securely protected based on the device identifier protection key.
[0440] In some embodiments, the first device operation response message includes second security information, which includes a second Nonce and / or key information for indicating that the device identifies the protection key.
[0441] In some embodiments, the device further includes: The sixth receiving unit is used to receive a device authentication request message sent by a network device. The device authentication request message includes device identification information, operation type information indicating the authentication operation, and device authentication parameters. The third processing unit is used to verify the device authentication parameters and send a device authentication response message to the network device when it is determined that the device identifier of the passive IoT device matches the device identifier information.
[0442] In some embodiments, the third processing unit is further configured to: Generate a third nonce, and generate a second response message protection key based on the device authentication key and the third nonce; The device authentication response message is securely protected using the second response message protection key.
[0443] In some embodiments, the third processing unit is further configured to: The first authentication response is generated based on the protection key and device authentication parameters of the second response message.
[0444] In some embodiments, the device authentication response message includes one or more of the following: a third nonce, a first authentication response, and capability information of the passive IoT device.
[0445] It should be noted that the communication device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0446] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0447] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0448] On the other hand, embodiments of this application also provide a processor-readable storage medium storing a program for causing a processor to execute the communication methods provided in the above embodiments.
[0449] It should be noted that the processor-readable storage medium provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0450] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).
[0451] The technical solutions provided in this application can be applied to a variety of systems. For example, applicable systems may include Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, and 6G (sixth generation mobile communication technology) systems. These systems may include terminal equipment and network equipment. The systems may also include a core network component, such as an Evolved Packet Core (EPC) or a 5G core network (5GC).
[0452] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0453] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0454] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0455] These processors can execute instructions that can also be loaded onto a computer or other programmable data processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0456] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A communication method, characterized in that, Applications include passive IoT devices, including: The system receives a first device operation request message sent by a first entity, the first device operation request message containing device identification information and operation type information; wherein, the first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system; Based on the device identification information, determine the operation corresponding to the operation type information, and send a first device operation response message to the first entity.
2. The communication method according to claim 1, characterized in that, The first device operation request message and the first device operation response message contain an operation identifier, which is used to identify the operation instruction initiated by the first entity.
3. The communication method according to claim 1 or 2, characterized in that, The first device operation request message includes a first security bearer, which contains at least one of the following: the device identification information protected by security, the operation type information, and first security information.
4. The communication method according to claim 3, characterized in that, The first device operation response message includes a second security bearer, which contains security-protected response information and / or second security information.
5. The communication method according to claim 4, characterized in that, The first security information and the second security information each include one or more of the following: Security policy information; Security algorithm information; Key identification information; Safety parameters; Message integrity protection code.
6. The communication method according to claim 3, characterized in that, The first secure bearer also includes one or more of the following information that are protected by security: Data area information; Data identification information; Information related to the content to be read and written; Equipment certification parameters.
7. The communication method according to claim 1, 2 or 4, characterized in that, The first device operation response message includes one or more of the following response information: The device identifier of the passive IoT device; The capability information of the passive IoT device; The return value of the read operation; Write the result of the operation; First authentication response.
8. The communication method according to claim 1 or 2, characterized in that, The first device operation request message and the first device operation response message also include message type information.
9. The communication method according to claim 7, characterized in that, The method further includes: A device identification protection key is generated using the dedicated key of the passive IoT device to protect the device identifier.
10. A communication method, characterized in that, Applications include passive IoT devices, including: Receive a first device operation request message sent by a network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters. If it is determined that the device identifier of the passive IoT device matches the device identifier information, a session key is determined based on the key identifier information and / or the key derivation parameters. Based on the session key, the first device operation request message is decoded and / or its integrity is verified. Based on the decoding result and / or verification result, the operation corresponding to the operation type information is determined to be executed, and a first device operation response message is sent to the network device.
11. The communication method according to claim 10, characterized in that, The first security information also includes a first one-time value (Nonce); The step of decrypting and / or verifying the integrity of the first device operation request message based on the session key includes: The first device operation request message is decrypted and / or its integrity is verified based on the session key and the first Nonce.
12. The communication method according to claim 10, characterized in that, Before sending the first device operation response message to the network device, the method further includes: Generate a second Nonce, and generate a first response message protection key based on the session key and the second Nonce; The first device operation response message is securely protected based on the protection key of the first response message.
13. The communication method according to claim 12, characterized in that, The method further includes: Based on the dedicated key of the passive IoT device and the second Nonce, a device identification protection key is generated; The device identifier carried in the first device operation response message is securely protected based on the device identifier protection key.
14. The communication method according to claim 12 or 13, characterized in that, The first device operation response message contains second security information, which includes the second Nonce and / or key information used to indicate the device identification protection key.
15. The communication method according to claim 10, characterized in that, The method further includes: The network device receives a device authentication request message, which includes device identification information, operation type information indicating the authentication operation, and device authentication parameters. If the device identifier of the passive IoT device is determined to match the device identifier information, the method further includes: verifying the device authentication parameters and sending a device authentication response message to the network device.
16. The communication method according to claim 15, characterized in that, Before sending a device authentication response message to the network device, the method further includes: Generate a third Nonce, and generate a second response message protection key based on the device authentication key and the third Nonce; The device authentication response message is securely protected based on the second response message protection key.
17. The communication method according to claim 16, characterized in that, The method further includes: A first authentication response is generated based on the protection key of the second response message and the device authentication parameters.
18. The communication method according to claim 16 or 17, characterized in that, The device authentication response message includes one or more of the following: the third Nonce, the first authentication response, and the capability information of the passive IoT device.
19. A passive Internet of Things (IoT) device, characterized in that, Includes memory, transceiver, and processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor. Processor, configured to read the computer program in the memory and perform the following operations: The system receives a first device operation request message sent by a first entity, the first device operation request message containing device identification information and operation type information; wherein, the first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system; Based on the device identification information, determine the operation corresponding to the operation type information, and send a first device operation response message to the first entity.
20. A passive Internet of Things (IoT) device, characterized in that, Includes memory, transceiver, and processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor. Processor, configured to read the computer program in the memory and perform the following operations: Receive a first device operation request message sent by a network device. The first device operation request message includes device identification information, operation type information and first security information. The first security information includes key identification information and / or key derivation parameters. If it is determined that the device identifier of the passive IoT device matches the device identifier information, a session key is determined based on the key identifier information and / or the key derivation parameters. Based on the session key, the first device operation request message is decoded and / or its integrity is verified. Based on the decoding result and / or verification result, the operation corresponding to the operation type information is determined to be executed, and a first device operation response message is sent to the network device.
21. A communication device, characterized in that, include: The first receiving unit is configured to receive a first device operation request message sent by a first entity, wherein the first device operation request message includes device identification information and operation type information; wherein the first entity includes a reading device based on a base station or terminal, a core network functional entity, or an application system; The execution unit is configured to determine, based on the device identification information, the operation corresponding to the operation type information, and send a first device operation response message to the first entity.
22. A communication device, characterized in that, include: The fifth receiving unit is used to receive a first device operation request message sent by a network device. The first device operation request message includes device identification information, operation type information, and first security information. The first security information includes key identification information and / or key derivation parameters. The first processing unit is configured to determine a session key based on the key identification information and / or the key derivation parameters when it is determined that the device identifier of the passive IoT device matches the device identifier information. The second processing unit is configured to decode and / or verify the integrity of the first device operation request message based on the session key, determine the operation corresponding to the operation type information to be executed based on the decoding result and / or verification result, and send a first device operation response message to the network device.
23. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a program for causing the processor to perform the method according to any one of claims 1 to 9, or to perform the method according to any one of claims 10 to 18.