Communication method, communication device and communication system

By receiving instruction information to determine whether to generate a key, the power consumption and complexity issues of existing A-IoT devices are resolved, and a highly efficient and energy-saving solution for security protection is achieved.

CN121509993APending Publication Date: 2026-02-10HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411097627.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-09
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing secure activation solutions are difficult to apply in environment-based Internet of Things (A-IoT) scenarios where terminal devices have limited capabilities, resulting in increased power consumption, design complexity, and storage latency.

Method used

The system determines whether to generate a key by receiving instruction information, and generates keys only in scenarios requiring security protection, reducing the overhead of computing and storing security parameters.

Benefits of technology

This reduces the device's additional power consumption and design complexity, saving computing and storage resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509993A_ABST
    Figure CN121509993A_ABST
Patent Text Reader

Abstract

Provided are a communication method and a communication device, the communication method comprising: receiving first indication information, the first indication information being used for indicating a service type of communication between a first device and a second device and / or for indicating execution of a security operation, the service type comprising at least one first service, and the service type comprising at least one second service; the first service comprises a flow of completing data transmission based on the security operation, and the security operation comprises encryption protection and / or integrity protection; and generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device. According to the technical scheme, the additional power consumption and the design complexity of the equipment can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and more specifically, to a communication method, communication device, and communication system. Background Technology

[0002] In one possible implementation, security activation / security mode control (SMC) can be used to activate secure interaction of information between the terminal and network sides, comprising two parts: non-access stratum (NAS) SMC and access stratum (AS) SMC. For example, the security activation / SMC process primarily completes the negotiation between the terminal and network sides regarding the security algorithm used, and generates the keys required for the corresponding security algorithm based on KASME or KeNB. For instance, in the 5G NR security activation scheme, by adding many layers of "intermediate" keys between the network and terminal sides, security complexity is increased, ensuring secure communication. For example, "intermediate" keys may include KAUSF, KSEAF, KAMF, KgNB, signaling plane encryption key KRRCenc, and integrity protection key KRRCint, etc.

[0003] However, the aforementioned security activation schemes are quite complex. For example, they require generating, updating, or storing a large number of keys, and the security activation interaction process is numerous and complex. Therefore, current security activation schemes are difficult to apply to scenarios with limited terminal device capabilities, such as A-IoT technologies. Otherwise, they would impose additional power consumption, design complexity, and significant data storage latency on terminal devices with limited capabilities. Summary of the Invention

[0004] This application provides a communication method and a communication device that can reduce the additional power consumption and design complexity of the device.

[0005] In a first aspect, embodiments of this application provide a communication method, which can be executed by a first device such as an electronic tag device or an A-IoT terminal device, or by a module in the first device such as a chip system or circuit, or by a logic node, logic module or software that can implement all or part of the functions of the first device. This application does not limit the scope of the method.

[0006] The method includes: receiving first indication information, the first indication information being used to indicate the service type of communication between the first device and the second device and / or to indicate the execution of a security operation, the service type including at least one first service, the first service including a process of completing data transmission based on the security operation, the security operation including encryption protection and / or integrity protection; generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

[0007] In the above technical solution, the first device generates the first key only when it receives a first instruction message, in scenarios where the first device is instructed to generate the first key. In scenarios where no security protection is required, the first device does not receive any security protection instruction and therefore does not generate the first key, thus saving the first device the overhead of calculating and storing security parameters such as the first key.

[0008] Optionally, the aforementioned data transmission process may include uplink data transmission or downlink data transmission between the first device and the second device. When the data transmission between the first device and the second device includes a third device acting as an intermediate node, it may also include uplink data transmission or downlink data transmission between the first device and the third device.

[0009] Optionally, security measures may also include protection against replay attacks or tampering.

[0010] Optionally, in other embodiments of this application, the first device may receive second indication information, which is used to indicate that no security operation is performed and / or to indicate that the service type of communication between the first device and the second device does not include the first service, that is, the service of communication between the first device and the second device does not include the process of completing data transmission based on the security operation. Therefore, the first device can, according to the second indication information, not perform the security operation. Not performing the security operation may include at least one of the following processes: discarding or releasing security parameters, not generating a session key or other security key for data transmission, not encrypting (all or part) of the data transmission, and not performing integrity protection on (all or part) of the data transmission.

[0011] Optionally, the communication service types between the first device and the second device include, but are not limited to: inventory service, command service, read service, write service, lock service, positioning service, proximity determination service, sensor service, kill or disable service, and device count service. The first service can be one or more of the read, write, lock, and kill or disable services, which have higher security requirements.

[0012] Alternatively, the first instruction information may also instruct the execution of a safety operation through information such as the security level.

[0013] In some implementations, receiving the first indication information includes: receiving a first message, the first message being used to page, select, or trigger at least one device, the at least one device including the first device, and the first message including the first indication information.

[0014] The first message can be a paging message, which may include a paging message or a select signaling. The paging message can be used to indicate that the tag is connected to the reader, or it can be used to trigger / instruct the tag to send uplink data, or to trigger / instruct / request the tag to perform any of the following services or processes: paging service, inventory service, command service (such as read, write, deactivate, lock, etc.), positioning service, and sensing service.

[0015] In some implementations, generating the first key includes: generating the first key after receiving the first message; or, receiving a second message indicating that the first device has successfully connected to the third device; and generating the first key.

[0016] In the above technical solution, generating the first key after receiving the second message can reduce the temporary storage time of the first key, thereby reducing the storage overhead of the first device.

[0017] In some implementations, receiving the first indication information includes: sending first uplink data, the first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information; and receiving first downlink data, the first downlink data including the first indication information.

[0018] In some implementations, the method further includes: receiving a first parameter for security protection of the first identification information; and sending first uplink data, the first uplink data including the first identification information after security protection.

[0019] In some implementations, the method further includes: after generating the first key, releasing the first key after a first storage time; or receiving a third message or a fourth message, the third message indicating or triggering the next access opportunity for the first device, the fourth message indicating the release of stored security parameters and / or keys; and releasing the first key.

[0020] Optionally, releasing the first key may mean that the first device stops saving information related to the first key, or flushes the information / cache / memory related to the first key, or discards information related to the first key.

[0021] Optionally, the third message can be a query message or a queryRep message. Furthermore, in some other embodiments of this application, the third message, such as a query message or a queryRep message, can also indicate whether the key is released, for example, through a MAC CE, MAC header, or other AS layer fields.

[0022] In the above technical solution, by releasing the first key, the overhead of storing the first key and other security parameters in the first device is saved.

[0023] In some implementations, when the first key is released after a first storage time, the method further includes: determining the first storage time based on the capability information of the first device; or receiving fourth indication information, the fourth indication information being used to indicate the first storage time.

[0024] In some implementations, the method further includes receiving a fifth indication message, which instructs the first device to extend the storage time of the first key.

[0025] Optionally, the fifth indication information may carry a temporary identifier (such as an access stratum identity (AS ID)), which is used by the second device to schedule the first device multiple times. This fifth indication information may instruct the first device to save the first key after receiving the aforementioned temporary identifier, and the saving time may be specified by the second device.

[0026] In some implementations, before generating the first key, the method further includes sending a request message for the first device to request a delay in generating the first key.

[0027] In some implementations, the method further includes: receiving an acknowledgment message for the request message, the acknowledgment message indicating that the first device is allowed to delay generating the first key; after a first time period, receiving a reconnection instruction message or a rescheduling instruction message, the reconnection instruction message indicating that the first device reconnects to the third device, and the rescheduling instruction message indicating that the third device reschedules the first device.

[0028] In some implementations, the method further includes: receiving a negative response message for the request message, the negative response indicating that the first device is not allowed to delay generating the first key; and receiving a sixth indication message, the sixth indication message indicating that the first device should reconnect to the third device after a second time period or after the next paging.

[0029] Optionally, the next paging attempt can be determined by the identification information carried in the paging message. For example, the identification information can indicate whether the paging message is a retransmission of the paging message (or the current service, without initiating a new service) or a newly transmitted paging message (initiating a new service). As another example, the next paging attempt can also be identified or associated with the service triggered by the current paging message by a service identifier (or it can also be called a session identifier, task identifier, etc.; this application does not limit the identifier name). For example, a service identifier of 0 indicates that it is the current service and no new service has been initiated. When the tag receives a paging message carrying a service identifier of 1, it determines it to be a new paging attempt or the next paging attempt.

[0030] In some implementations, the first key is used for cryptographic protection and / or integrity protection.

[0031] In some implementations, the first device generates a first key by: receiving a second parameter, the second parameter being a parameter generated by the second device for key generation; and generating the first key based on the second parameter and a third parameter, the third parameter being a parameter generated by the first device for key generation.

[0032] In some implementations, the first device is an environmental Internet of Things (A-IoT) device.

[0033] Secondly, embodiments of this application provide a communication method, which can be executed by a second device such as a core network device, or by a module in the second device such as a chip system or circuit, or by a logic node, logic module or software that can implement all or part of the functions of the second device. This application does not limit this.

[0034] The method includes: sending first indication information, the first indication information being used to indicate the service type of communication between the first device and the second device and / or to indicate the execution of a security operation, the service type including at least one first service, the first service including a process of completing data transmission based on the security operation, the security operation including encryption protection and / or integrity protection; generating a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

[0035] In the above technical solution, the first device generates the first key only when it receives a first instruction message, in scenarios where the first device is instructed to generate the first key. In scenarios where no security protection is required, the first device does not receive any security protection instruction and therefore does not generate the first key, thus saving the first device the overhead of calculating and storing security parameters such as the first key.

[0036] Optionally, the second device can be a core network device, an access network device such as a base station or a terminal device, or a server (third party) such as an IoT server.

[0037] In some implementations, the method further includes: sending third indication information, the third indication information being used to indicate the time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and receiving the third parameter through a first transport block, wherein the time-frequency resources of the first transport block include the time-frequency resources of the third parameter.

[0038] In some implementations, the method further includes sending a seventh indication message, which instructs a third device to send a cached second parameter to the first device, the second parameter being a parameter generated by the second device for key generation.

[0039] In some implementations, sending the first indication information includes: sending a first message, the first message being used to page, select, or trigger at least one device, the at least one device including the first device, and the first message including the first indication information.

[0040] In some implementations, sending the first indication information includes: receiving first uplink data, the first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information; and sending first downlink data, the first downlink data including the first indication information.

[0041] In some implementations, the method further includes: sending a first parameter for security protection of the first identification information of the first device; and receiving first uplink data, the first uplink data including the first identification information after security protection.

[0042] In some implementations, the method further includes sending a fourth indication message, which indicates the first storage time.

[0043] In some implementations, the method further includes sending a fifth indication message, which instructs the first device to extend the storage time of the first key.

[0044] In some implementations, before generating the first key, the method further includes receiving a request message for the first device to request a delay in generating the first key.

[0045] In some implementations, the method further includes sending an acknowledgment message to the request message, the acknowledgment message indicating that the first device is allowed to delay generating the first key.

[0046] In some implementations, the method further includes: sending a negative response message for the request message, the negative response indicating that the first device is not allowed to delay generating the first key; and sending a sixth indication message, the sixth indication message indicating that the first device should reconnect to the third device after a second time period or after receiving the next paging message.

[0047] The explanations and beneficial effects of the communication method provided in the second aspect can be found in the communication method described in the first aspect, and will not be repeated here.

[0048] Thirdly, embodiments of this application provide a communication method, which can be executed by a third device such as a network device, a terminal device, or a reader / writer, or by a module in the third device such as a chip system or circuit, or by a logic node, logic module, or software that can implement all or part of the functions of the third device. This application does not limit this.

[0049] The method includes: receiving third indication information, the third indication information being used to indicate the time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and transmitting the third parameter through a first transport block, wherein the time-frequency resources of the first transport block include the time-frequency resources of the third parameter.

[0050] In some implementations, the method further includes: receiving seventh indication information, the seventh indication information being used to instruct a third device to send a cached second parameter to the first device, the second parameter being a parameter generated by the second device for key generation; and sending the cached second parameter to the first device.

[0051] Fourthly, a communication device is provided. The device includes: a transceiver unit configured to: receive first indication information, the first indication information being used to indicate a service type for communication between a first device and a second device and / or to indicate the execution of a security operation, the service type including at least one first service, the first service including a process for completing data transmission based on the security operation, the security operation including encryption protection and / or integrity protection; and a processing unit configured to: generate a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

[0052] In some implementations, the transceiver unit is specifically used to: receive a first message, the first message being used to page, select, or trigger at least one device, the at least one device including the first device, and the first message including the first indication information.

[0053] In some implementations, the processing unit is specifically used to: generate the first key after receiving the first message; or, receive a second message indicating that the first device has successfully connected to the third device; and generate the first key.

[0054] In some implementations, the processing unit is specifically configured to: send first uplink data, the first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information; and receive first downlink data, the first downlink data including the first indication information.

[0055] In some implementations, the transceiver unit is further configured to: receive a first parameter, the first parameter being used for security protection of the first identification information of the first device; and send first uplink data, the first uplink data including the first identification information after security protection.

[0056] In some implementations, the processing unit is further configured to: release the first key after a first storage period following the generation of the first key; or, the transceiver unit is further configured to receive a third message or a fourth message, the third message being used to indicate or trigger the next access opportunity of the first device, and the fourth message being used to indicate the release of stored security parameters and / or keys; the processing unit is further configured to release the first key.

[0057] In some implementations, when the first key is released after a first storage time, the processing unit is further configured to: determine the first storage time based on the capability information of the first device; or, the transceiver unit is further configured to: receive fourth indication information, the fourth indication information being used to indicate the first storage time.

[0058] In some implementations, the transceiver unit is further configured to: receive a fifth indication message, which instructs the first device to extend the storage time of the first key.

[0059] In some implementations, before the processing unit generates the first key, the transceiver unit is further configured to: the method further includes: sending a request message for the first device to request a delay in generating the first key.

[0060] In some implementations, the transceiver unit is further configured to: receive an acknowledgment message for the request message, the acknowledgment message indicating that the first device is allowed to delay generating the first key; and after a first time period, receive a reconnection instruction message or a rescheduling instruction message, the reconnection instruction message indicating that the first device reconnects to the third device, and the rescheduling instruction message indicating that the third device reschedules the first device.

[0061] In some implementations, the transceiver unit is further configured to: receive a negative response message for the request message, the negative response indicating that the first device is not allowed to delay generating the first key; and receive a sixth indication message, the sixth indication message indicating that the first device should reconnect to the third device after a second time period or after receiving the next paging message.

[0062] In some implementations, the processing unit is specifically configured to: receive a second parameter, which is a parameter generated by the second device for key generation; and generate the first key based on the second parameter and a third parameter, where the third parameter is a parameter generated by the first device for key generation.

[0063] In some implementations, the device is an environmental Internet of Things (A-IoT) device.

[0064] In one implementation, the communication device is a first device. When the communication device is a first device, the transceiver unit can be a transceiver or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0065] In another implementation, the communication device is a chip, chip system, or circuit used in the first device. When the communication device is a chip, chip system, or circuit used in the device, the transceiver unit may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip, chip system, or circuit; the processing unit may be at least one processor, processing circuit, or logic circuit.

[0066] The explanation of the communication device provided in the fourth aspect and its beneficial effects can be found in the communication method shown in the first aspect, and will not be repeated here.

[0067] Fifthly, a communication apparatus is provided. The apparatus includes: a transceiver unit configured to: transmit first indication information, the first indication information being used to indicate a service type for communication between a first device and a second device and / or to indicate the execution of a security operation, the service type including at least one first service, the first service including a process for completing data transmission based on the security operation, the security operation including encryption protection and / or integrity protection; and a processing unit configured to: generate a first key according to the first indication information, the first key being used for security protection of communication between the first device and the second device.

[0068] In some implementations, the transceiver unit is further configured to: send third indication information, the third indication information being used to indicate the time-frequency resource size of a third parameter, the third parameter being a parameter generated by the first device for key generation; and receive the third parameter through a first transmission block, wherein the time-frequency resources of the first transmission block include the time-frequency resources of the third parameter.

[0069] In some implementations, the transceiver unit is further configured to: send a seventh indication message, which instructs a third device to send a cached second parameter to the first device, the second parameter being a parameter generated by the second device for key generation.

[0070] In some implementations, the transceiver unit is specifically used to: send a first message, the first message being used to page, select, or trigger at least one device, the at least one device including the first device, and the first message including the first indication information.

[0071] In some implementations, the transceiver unit is specifically used to: receive first uplink data, the first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information; and send first downlink data, the first downlink data including the first indication information.

[0072] In some implementations, the transceiver unit is further configured to: send a first parameter for security protection of the first identification information of the first device; and receive first uplink data, the first uplink data including the first identification information after security protection.

[0073] In some implementations, the transceiver unit is further configured to: send a fourth indication message, which indicates the first storage time.

[0074] In some implementations, the transceiver unit is further configured to: send a fifth indication message, which instructs the first device to extend the storage time of the first key.

[0075] In some implementations, before the processing unit generates the first key, the transceiver unit is further configured to: receive a request message for the first device to request a delay in generating the first key.

[0076] In some implementations, the transceiver unit is further configured to: send an acknowledgment message for the request message, the acknowledgment message indicating that the first device is allowed to delay generating the first key.

[0077] In some implementations, the transceiver unit is further configured to: send a negative response message for the request message, the negative response indicating that the first device is not allowed to delay generating the first key; and send a sixth indication message, the sixth indication message indicating that the first device should reconnect to the third device after a second time period or after receiving the next paging message.

[0078] In one implementation, the communication device is a second device. When the communication device is a second device, the transceiver unit can be a transceiver or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0079] In another implementation, the communication device is a chip, chip system, or circuit used in a second device. When the communication device is a chip, chip system, or circuit used in a device, the transceiver unit can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip, chip system, or circuit; the processing unit can be at least one processor, processing circuit, or logic circuit.

[0080] The explanation of the communication device provided in the fifth aspect and its beneficial effects can be found in the communication method shown in the second aspect, and will not be repeated here.

[0081] A sixth aspect provides a communication apparatus. The apparatus includes: a transceiver unit configured to: receive third indication information, the third indication information being used to indicate the size of time-frequency resources of a third parameter, the third parameter being a parameter generated by the first device for key generation; and transmit the third parameter through a first transmission block, wherein the time-frequency resources of the first transmission block include the time-frequency resources of the third parameter.

[0082] In some implementations, the transceiver unit is further configured to: receive a seventh indication message, the seventh indication message being used to instruct a third device to send a cached second parameter to the first device, the second parameter being a parameter generated by the second device for key generation; and send the cached second parameter to the first device.

[0083] In one implementation, the communication device is a third device. When the communication device is a third device, the transceiver unit can be a transceiver or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0084] In another implementation, the communication device is a chip, chip system, or circuit used in a third device. When the communication device is a chip, chip system, or circuit used in a device, the transceiver unit can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip, chip system, or circuit; the processing unit can be at least one processor, processing circuit, or logic.

[0085] The explanation of the communication device provided in the sixth aspect and its beneficial effects can be found in the communication method shown in the third aspect, and will not be repeated here.

[0086] A seventh aspect provides a communication apparatus, the apparatus comprising: a memory for storing a program; and at least one processor for executing the computer program or instructions stored in the memory to perform the method provided by the first aspect or any of the above-described implementations of the first aspect, or to perform the method provided by the second aspect or any of the above-described implementations of the second aspect, or to perform the method provided by the third aspect or any of the above-described implementations of the third aspect.

[0087] In one implementation, the communication device is a device (such as a first device, a second device, or a third device).

[0088] In another implementation, the device is a chip, chip system, or circuit used in a device (such as a first device, a second device, or a third device).

[0089] Eighthly, this application provides a processor for performing the methods provided in the above aspects.

[0090] Unless otherwise specified, or if it does not contradict its actual function or internal logic in the relevant description, the transmission and acquisition / reception operations involved in the processor can be understood as processor output and reception, input and other operations, or as transmission and reception operations performed by radio frequency circuits and antennas. This application does not limit them in this regard.

[0091] A ninth aspect provides a computer-readable storage medium storing program code for execution by a device, the program code including instructions for performing the method provided by the first aspect or any of the above-described implementations of the first aspect, or including instructions for performing the method provided by the second aspect or any of the above-described implementations of the second aspect, or including instructions for performing the method provided by the third aspect or any of the above-described implementations of the third aspect.

[0092] In a tenth aspect, a computer program product comprising instructions is provided, which, when run on a computer, causes the computer to perform the method provided by the first aspect or any of the above-described implementations of the first aspect, or causes the computer to perform the method provided by the second aspect or any of the above-described implementations of the second aspect, or causes the computer to perform the method provided by the third aspect or any of the above-described implementations of the third aspect.

[0093] Eleventhly, a chip system is provided, the chip system including a processor and a communication interface, the processor reads instructions stored in a memory through the communication interface, executes the method provided by the first aspect or any of the above-described implementations of the first aspect, or executes the method provided by the second aspect or any of the above-described implementations of the second aspect, or executes the method provided by the third aspect or any of the above-described implementations of the third aspect.

[0094] Optionally, as one implementation, the chip system further includes a memory storing computer programs or instructions. The processor is used to execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the processor is used to execute the method provided by the first aspect or any of the above-described implementations of the first aspect, or to execute the method provided by the second aspect or any of the above-described implementations of the second aspect, or to execute the method provided by the third aspect or any of the above-described implementations of the third aspect.

[0095] In a twelfth aspect, a communication system is provided, comprising at least one communication device as described in the fourth aspect above, at least one notification device as described in the fifth aspect above, and at least one notification device as described in the sixth aspect above.

[0096] For a description of the beneficial effects of aspects seven through twelfth, please refer to the descriptions of aspects one through three. Attached Figure Description

[0097] Figure 1 This is a schematic diagram of a communication system provided in an embodiment of this application.

[0098] Figure 2This is a schematic block diagram of another communication system provided in the embodiments of this application.

[0099] Figure 3 This is a schematic block diagram of another communication system provided in the embodiments of this application.

[0100] Figure 4 This is a schematic diagram of the network element function division and protocol layer structure of an open radio access network (O-RAN) system provided in an embodiment of this application.

[0101] Figure 5 This is a schematic diagram of the architecture of another O-RAN system provided in the embodiments of this application.

[0102] Figure 6 This is a schematic flowchart of an inventory operation provided in an embodiment of this application.

[0103] Figure 7 This is a schematic diagram of the architecture of an A-IoT technology provided in an embodiment of this application.

[0104] Figure 8 This is a schematic flowchart of a communication method provided in an embodiment of this application.

[0105] Figure 9 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0106] Figure 10 This is a schematic diagram of a key generation process provided in an embodiment of this application.

[0107] Figure 11 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0108] Figure 12 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0109] Figure 13 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0110] Figure 14 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0111] Figure 15 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0112] Figure 16 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0113] Figure 17 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0114] Figure 18 This is a schematic flowchart illustrating another communication method provided in the embodiments of this application.

[0115] Figure 19 This is a schematic structural block diagram of a communication device provided in an embodiment of this application.

[0116] Figure 20 This is a schematic structural block diagram of another communication device provided in the embodiments of this application.

[0117] Figure 21 This is a schematic structural block diagram of another communication device provided in the embodiments of this application.

[0118] Figure 22 This is a schematic diagram of a chip system provided in an embodiment of this application. Detailed Implementation

[0119] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0120] First, with reference to the accompanying drawings, the communication system and network architecture applicable to the embodiments of this application will be described.

[0121] The technical solutions of this application embodiment can be applied to various communication systems, including but not limited to: Long Term Evolution (LTE) systems, NR systems, and other fifth-generation (5G) communication systems. th This includes various mobile communication systems such as 5G, narrowband Internet of Things (NB-IoT), enhanced machine-type communication (eMTC), enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLLC), satellite communication systems, LTE-machine-to-machine (LTE-M) systems, and other systems that evolve after 5G, such as future mobile communication systems.

[0122] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0123] Figure 1 This is a schematic diagram of a communication system 100. (For example...) Figure 1As shown, the communication system 100 includes a wireless access network 110 and a core network 120. Optionally, the communication system 100 may also include an Internet 130. The wireless access network 110 may include at least one network device (such as...). Figure 1 111a and 111b in the above), may also include at least one terminal device (such as Figure 1 (112a-112j in the original text). The terminal device connects to the network device wirelessly. The network device connects to the core network 120 wirelessly or via a wired connection. The core network 120 may include one or more core network devices. These core network devices and network devices can be independent physical devices, or they can integrate the functions of the core network devices and the logical functions of the network devices onto the same physical device. Alternatively, a single physical device can integrate some core network device functions and some network device functions. Terminal devices and network devices can be interconnected via wired or wireless means. Wireless communication between terminal devices, between network devices, and between terminal devices and network devices can occur through air interface resources. For example, air interface resources may include at least one of time-domain resources, frequency-domain resources, code resources, and spatial resources. Figure 1 This is just an illustration; the communication system 100 may also include other network devices, such as wireless repeaters and wireless backhaul devices. Figure 1 It is not shown in the middle.

[0124] Network devices are sometimes also referred to as access network devices or access network nodes. It is understood that the names of devices with network device functions may differ in systems employing different wireless access technologies. For ease of description, the embodiments of this application collectively refer to devices providing wireless communication access functions to terminal devices as base stations. In the embodiments of this application, network devices include, but are not limited to: various forms of macro base stations (such as...) Figure 1 111a), micro base stations or indoor stations (such as Figure 1The types of base stations include 111b), pico base stations, small base stations, balloon base stations, relay stations, and access points. Among them, pico base stations can be referred to as small base stations. Network equipment may include evolved node B (eNB or eNodeB) in LTE, radio controllers in cloud radioaccess network (CRAN) scenarios, network equipment in future evolved public land mobile networks (PLMNs), access points (APs), radio relay nodes, radio backhaul nodes, transmission points (TPs) or transmission reception points (TRPs) in wireless fidelity (WiFi) systems, etc. It may also include next-generation NodeB (gNB) or transmission points (TRPs or TPs) in 5G systems, one or a group of antenna panels (including multiple antenna panels) of base stations in 5G systems, network nodes constituting gNBs or transmission points, such as baseband units (BBUs) or distributed units (DUs), and network equipment, servers, wearable devices, or vehicle-mounted devices in future mobile communication systems and other networks that evolve after 5G. Network equipment can also be modules or units that perform some of the functions of a base station; for example, it can be a central unit (CU) or a unit (DU). Furthermore, network equipment can be understood as a collective term for all equipment on the network side (including sites); for example, multiple sites can be collectively referred to as network equipment. A site refers to a transmission node located in a specific physical location. In other words, network equipment conceptually includes sites.

[0125] In this embodiment, the means for implementing the function of the network device can be the network device itself, or it can be a means that enables the network device to implement the function, such as a chip system or a chip, which can be installed in the network device. The chip system can be composed of chips, or it can include chips and other discrete components.

[0126] In another possible scenario, multiple network devices collaborate to assist the terminal in achieving wireless access, with each network device performing a portion of the base station's functions. For example, network devices can be CUs, DUs, CUs (control plane, CP), CUs (user plane, UP), or radio units (RUs). CUs and DUs can be configured separately or included in the same network element, such as a BBU. RUs can be included in radio equipment or radio units, such as remote radio units (RRUs), active antenna units (AAUs), or remote radio heads (RRHs).

[0127] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an O-RAN system, CU can also be called O-CU (Open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software modules and hardware modules. The embodiments of this application do not limit the specific technology or specific device form used in the network device.

[0128] Terminal equipment can be a device that provides voice and / or data connectivity to users; it can also be a device with wireless connectivity. Terminal equipment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on ships); and it can also be deployed in the air (such as on airplanes, balloons, and satellites). Terminal equipment can also be referred to as user equipment (UE), access terminal, terminal, subscriber unit, user station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, wireless network equipment, user agent, or user device. In this application embodiment, terminal devices include, but are not limited to: cellular phones, mobile phones, wireless data cards, wireless modems, tablets, laptop computers, notebook computers, handheld computers, mobile internet devices (MIDs), computers with wireless transceiver capabilities, cordless phones, session initiation protocol (SIP) phones, smartphones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handsets with wireless communication capabilities, computing devices or other devices connected to wireless modems, in-vehicle devices (e.g., cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), wearable devices (e.g., smartwatches, smart bracelets, pedometers, smart glasses, etc.), satellite terminals, terminal devices in the Internet of Things or the Internet of Vehicles, as well as any form of terminal in future networks, relay user equipment, or terminals in future evolved PLMNs, etc.Terminal devices can also be virtual reality (VR) devices, augmented reality (AR) devices, smart point-of-sale (POS) machines, customer-premises equipment (CPE), light user equipment (UE), reduced capability user equipment (RedCapUE), machine-type communication (MTC) terminals, terminal devices in industrial control, terminal devices in self-driving, terminal devices in remote medical care, terminal devices in smart grids, wireless terminals in transportation safety, terminal devices in smart cities, terminal devices in smart homes, tactile terminal devices, smart home devices (e.g., refrigerators, televisions, air conditioners, electricity meters, etc.), smart robots, robotic arms, workshop equipment, wireless terminals in self-driving, or flying devices (e.g., smart robots, hot air balloons, drones, airplanes), etc. The terminal device can also be a vehicle device, such as a transport vehicle with wireless communication capabilities, a communication module, a complete vehicle device, an on-board module, an on-board chip, an on-board unit (OBU), or a telematics box (T-BOX). The terminal device can also be other devices with terminal functions; for example, it can be a device that acts as a terminal in device-to-device (D2D) communication. This application does not limit the scope of the embodiments.

[0129] In this application embodiment, the device for implementing the functions of the terminal device can be the terminal device itself, or it can be any device capable of supporting the terminal device in implementing those functions, such as a chip or chip system. This device can be installed in the terminal device. The chip system can consist of chips or include chips and other discrete components. In the technical solutions of this application embodiment, the device for implementing the functions of the terminal device is exemplified by the terminal device itself. The terminal device can also be called a terminal. The following description may use a UE (User Equipment) as an example to illustrate the technical solutions provided in this application embodiment.

[0130] The roles of base stations and terminals can be relative, for example, Figure 1The helicopter or drone 112i can be configured as a mobile base station. For terminals 112j that access the wireless access network 110 via 112i, terminal 112i is a base station; however, for base station 111a, 112i is a terminal, meaning that 111a and 112i communicate via a wireless air interface protocol. Of course, 111a and 112i can also communicate via a base station-to-base station interface protocol; in this case, relative to 111a, 112i is also a base station. Therefore, both base stations and terminals can be collectively referred to as communication devices. Figure 1 111a and 111b in the diagram can be referred to as communication devices with base station functionality. Figure 1 The 112a-112j in the text can be referred to as communication devices with terminal functions.

[0131] Network devices and terminal devices can communicate via wireless links. The transmission link from a network device to a terminal device can be called a downlink (DL) or downlink channel, used for transmitting downlink signals. The transmission link from a terminal device to a network device can be called an uplink (UL) or uplink channel, used for transmitting uplink signals. The transmission link from a terminal device to a terminal device can be called a sidelink (SL) or sidelink channel. In this application embodiment, multiple network devices can send information to multiple different terminal devices and receive information from multiple different terminal devices; multiple network devices can also send information to the same terminal device and receive information from the same terminal device, and this application is not limited in this respect.

[0132] Optionally, in this embodiment of the application, if the network device is a reader and the terminal device is an electronic tag device, the "uplink" between the reader and the electronic tag device can be referred to as "DR" or "D2R", and "uplink signaling" can be replaced with "D2R signaling"; the "downlink" between the reader and the electronic tag device can be referred to as "RD" or "R2D", and "downlink signaling" can be replaced with "R2D signaling".

[0133] The communication between different devices involved in the embodiments of this application can refer to direct communication between different devices (i.e., without the need for relaying or forwarding by other devices), or communication between different devices through other devices (i.e., requiring relaying or forwarding by other devices), or communication between functional units within a device and other devices through another functional unit. Information may undergo necessary processing between the source and destination ends, such as format changes, digital-to-analog conversion, amplification, or filtering, but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood in a similar way, and will not be elaborated further here.

[0134] Figure 2 This is a schematic block diagram of another communication system. Figure 2 Take the communication between terminal devices and network devices as an example.

[0135] like Figure 2 As shown, terminal device 210 may include processor 211, memory 212, and transceiver 213. Exemplarily, transceiver 213 may include transmitter 2131, receiver 2132, and antenna 2133. Network device 220 may include processor 221, memory 222, and transceiver 223. Exemplarily, transceiver 223 may include transmitter 2231, receiver 2232, and antenna 2233. Receiver 2132 can be used to receive information from network device 220 via antenna 2133, and transmitter 2131 can be used to send information to network device 220 via antenna 2133. Transmitter 2231 can be used to send information to terminal device 210 via antenna 2233, and receiver 2232 can be used to receive information from terminal device 210 via antenna 2233.

[0136] The network device in this application embodiment may include a chip within the network device. For example, the network device may include a processor 221, a memory 222, and a transceiver 223. The terminal device in this application embodiment may include a chip within the terminal device. For example, the terminal device may include a processor 211, a memory 212, and a transceiver 213.

[0137] Figure 3 This is a schematic block diagram of yet another communication system. Figure 3 An O-RAN system is illustrated. The O-RAN system in this application may include... Figure 3 Other components besides those shown may also include only those shown. Figure 3 Some components in.

[0138] See Figure 3 The network device can communicate with the core network device via the backhaul link 310 and with the terminal device via the air interface. For example, the BBU in the network device can communicate with the core network device via the backhaul link 310. The RU in the network device can communicate with at least one terminal device via the air interface. The BBU can communicate with at least one RU via the fronthaul link 330. The BBU and RU may or may not be co-located. For example, the BBU may include at least one CU and at least one DU. The CU and DU can communicate with each other via at least one midhaul link 320.

[0139] Figure 4This is a schematic diagram of the network element function division and protocol layer structure of an O-RAN system. The O-RAN system in this embodiment can adopt... Figure 4 The diagram shows some or all of the methods for dividing network element functions and protocol layers; other methods may also be used.

[0140] In some examples, the CU can be used as a logical node to carry the RRC layer, Service Data Adaptation Protocol (SDAP) layer, Packet Data Convergence Protocol (PDCP) layer, and other control functions of access network devices. Exemplarily, the CU can connect to network nodes such as the core network through interfaces, which may include interfaces such as E2 interfaces. Optionally, the CU may have some of the core network's functions.

[0141] For example, the CU (e.g., the PDCP layer or a layer higher than PDCP) connects to the DU (e.g., the radio link control (RLC) layer or a layer lower than RLC) through interfaces, such as the F1 interface. In some examples, the aforementioned interface (e.g., the F1 interface) can provide CP and UP functions, such as interface management, system information management, UE context management, and RRC message transmission. The F1 interface can employ the F1 application protocol (F1AP).

[0142] In some examples, the CU can be split into CU-CP and CU-UP.

[0143] The CU-CP can be used as a logical node to carry the RRC layer and the control plane part of PDCP (PDCP-C) layer, implementing the control plane functions of the CU. The CU-CP can interact with network elements in the core network used to implement control plane functions. For example, network elements in the core network used to implement control plane functions can be access and mobility function (AMF) network elements, such as the access and mobility management function (AMF) in a 5G system. For example, the AMF network element can be used to handle mobility management in the mobile network, such as terminal device location updates, terminal device registration with the network, and terminal device handover.

[0144] CU-UP can be used as a logical node to carry the SDAP layer and the user plane part of PDCP (PDCP-U) layer, implementing the user plane functions of the CU. CU-UP can interact with network elements in the core network used to implement user plane functions. For example, in a 5G system, the user plane function (UPF) network element can be used to handle data forwarding and reception in terminal equipment.

[0145] The above CU or DU configurations are merely examples; the functions of the CU or DU can be configured as needed. For instance, the CU or DU can be configured to have more protocol layer functions, or to have only some protocol layer processing functions. For example, some RLC layer functions and protocol layer functions above the RLC layer can be placed in the CU, while the remaining RLC layer functions and protocol layer functions below the RLC layer can be placed in the DU. Furthermore, the functions of the CU or DU can be divided according to service type or other system requirements, such as by latency. Functions that require low latency can be placed in the DU, while functions that do not require low latency can be placed in the CU.

[0146] In some examples, a DU can be used as a logical node to carry the RLC layer, medium access control (MAC) layer, higher physical layer (Higher PHY) layer, and other functions. In some examples, a DU can control at least one RU. For example, a DU can connect to an RU through interfaces, which may be fronthaul interfaces. In some examples, the Higher PHY layer may include PHY layer processing functions such as forward error correction (FEC) encoding, decoding, scrambling, modulation, or demodulation.

[0147] In some examples, the RU can be used as a logical node to carry both lower physical layer (PHY) and radio frequency (RF) chain processing. In some examples, the RU can be a 3rd Generation Partnership Project (3GPP) node. rdEntities with TRP, RRH, or other similar functions in the Generation Partnership Project (3GPP). In some examples, the Low PHY layer includes PHY processing functions such as Fast Fourier Transform (FFT), Inverse Fast Fourier Transform (IFFT), digital beamforming, or filtering. The RU can communicate with one or more UEs via a radio link.

[0148] DU and RU may or may not be co-located. For example, DU and RU can exchange control plane and user plane information via a fronthaul link through a lower-layer split control / user / synchronization-plane (LLS-C / U / S) interface. For instance, the O-RAN CUS plane in DU can communicate with the O-RAN CUS plane in RU via the LLS-C / U / S interface. Exemplarily, LLS-C / U / S may include an LLS-control (C) interface and an LLS-user (U) interface providing CP and UP, respectively. In some examples, CP may refer to real-time control between DU and RU. DU and RU can exchange management information via the LLS-management (M) interface of the fronthaul link; the M plane may refer to non-real-time management operations between DU and RU. For example, the O-RAN M plane in DU can communicate with the O-RAN M plane in RU via the LLS-M interface. As another example, the O-RAN M plane in DU or RU can communicate with the management system via the LLS-M interface.

[0149] DUs and RUs can collaborate to implement the functions of the PHY layer. For example, a DU can be connected to one or more RUs. The functions of DUs and RUs can be configured in various ways depending on the design. For example, a DU can be configured to implement baseband functions, and an RU can be configured to implement mid-RF functions. Another example is that a DU can be configured to implement higher-level functions (e.g., high PHY) in the PHY layer, and an RU can be configured to implement lower-level functions (e.g., low PHY), or implement both lower-level and RF functions (e.g., RF chain). Higher-level functions in the physical layer can include a portion of the physical layer's functions that are closer to the MAC layer, while lower-level functions in the physical layer can include another portion of the physical layer's functions that are closer to the mid-RF side.

[0150] Figure 5This is a schematic diagram of an application framework involving a RAN intelligent controller (RIC) under an O-RAN architecture. As shown in the figure, the communication system includes an RIC module, which includes a near-real-time RIC (near-RT RIC) and a non-real-time RIC (non-RT RIC).

[0151] In some examples, near real-time RICs can be used for model training and inference. For instance, they can be used to train artificial intelligence (AI) models and then use those AI models for inference. A near real-time RIC can obtain network-side information from RAN nodes (e.g., CUs, CU-CPs, CU-UPs, DUs, and / or RUs), and / or terminal-side information from terminal devices. This information can serve as training data or inference data for the AI ​​model. Optionally, the near real-time RIC can deliver inference results to RAN nodes and / or terminals. Optionally, inference results can also be exchanged between CUs and DUs, and / or between DUs and RUs. For example, the near real-time RIC delivers inference results to a DU, which then forwards them to an RU.

[0152] In some examples, non-real-time RICs are used for model training and inference. For instance, they can be used to train an AI model and then use that model for inference. Non-real-time RICs can obtain network-side information from RAN nodes (e.g., CUs, CU-CPs, CU-UPs, DUs, and / or RUs), and / or terminal-side information from terminal devices. This information can serve as training data or inference data for the AI ​​model, and the inference results can be delivered to the RAN nodes and / or the terminals. Optionally, inference results can be exchanged between CUs and DUs, and / or between DUs and RUs; for example, a non-real-time RIC delivers the inference result to a DU, which then forwards it to an RU.

[0153] In some examples, near real-time RICs and non-real-time RICs can also be configured as separate network elements. Optionally, near real-time RICs and non-real-time RICs can also be part of other devices. For example, near real-time RICs can be set in RAN nodes (e.g., CUs or DUs), while non-real-time RICs can be set in OAMs, cloud servers, core network devices, or other network devices.

[0154] In a communication system, network elements are connected via interfaces (e.g., NG, Xn) or air interfaces. These network element nodes, such as core network equipment, access network nodes (RAN nodes), terminals, or one or more devices in the OAM (Operational Access Management) system, may contain one or more AI modules. An access network node may be a single RAN node or may include multiple RAN nodes, for example, CU and DU. The CU and / or DU may also contain one or more AI modules. Optionally, a CU may be further divided into CU-CP and CU-UP. One or more AI models are configured in the CU-CP and / or CU-UP.

[0155] The aforementioned AI modules are used to implement corresponding AI functions. AI modules deployed in different network elements can be the same or different. Depending on the parameter configuration, the AI ​​module can implement different functions. The AI ​​module model can be configured based on one or more of the following parameters: structural parameters (e.g., at least one of the following: number of neural network layers, neural network width, inter-layer connections, neuron weights, neuron activation function, or bias in the activation function), input parameters (e.g., type and / or dimension of input parameters), or output parameters (e.g., type and / or dimension of output parameters). The bias in the activation function can also be referred to as the neural network bias.

[0156] An AI module can have one or more models. A model can infer an output, which includes one or more parameters. The learning, training, or inference processes of different models can be deployed on different nodes or devices, or they can be deployed on the same node or device.

[0157] The communication systems described above that are applicable to this application are merely illustrative examples, and the communication systems applicable to this application are not limited to these. They will be uniformly described here and will not be repeated below.

[0158] Before introducing the embodiments, the terminology involved in this application will be described in detail.

[0159] 1. Passive Radio Frequency Identification (RFID):

[0160] RFID is a type of automatic identification technology. RFID uses radio frequency (RF) for non-contact, two-way data communication and reads and writes data to recording media (electronic tags or RFID cards) to achieve target identification and data exchange. The primary application of RFID is identity verification, but it can also be used for data reading and writing. For example, RFID can be applied in logistics and warehousing, such as inventory and tracking of goods, monitoring the environment and cargo status during the transportation of high-value goods (such as vaccines), and in industrial manufacturing, such as environmental and equipment status monitoring.

[0161] A complete RFID system consists of three parts: a reader, electronic tags, and a data management system. The reader is the device that reads information from the electronic tags or writes information to the electronic tags. Depending on the structure and technology used, the reader can be a read / write device and serves as the information control and processing center of the RFID system. When the RFID system is working, the reader emits radio frequency energy to create an electromagnetic field within a designated area; the size of this area depends on the transmission power. Electronic tags within the reader's coverage area are triggered, sending the data stored within them or modifying the data stored according to the reader's instructions. They can also communicate with a computer network through an interface.

[0162] For ease of description, the electronic tag device will be referred to as "tag" in the following text.

[0163] Tags can consist of transceiver antennas, AC / DC circuits, demodulation circuits, logic control circuits, memory, and modulation circuits. Tag functionality is simple; they generally require activation from a reader to transmit information. That is, the tag converts the wireless signal emitted by the reader into energy, which powers itself. Tags support power consumption in the microwatt or hundreds of microwatts range and cannot support complex designs. RFID can be classified into three categories based on its tag power supply method: passive RFID, active RFID, and semi-active RFID.

[0164] In passive RFID, the tag receives microwave signals from the RFID reader and briefly powers itself using energy from an electromagnetic induction coil, thus completing the information exchange. Because the power supply system is eliminated, passive RFID products can be as small as centimeters or even smaller, and they are simple in structure, low in cost, have a low failure rate, and a long lifespan. However, the effective identification distance of passive RFID is usually short, and it is generally used for short-range contact identification. Passive RFID mainly operates in lower frequency bands such as 125kHz and 13.56MKHz.

[0165] Active RFID is powered by an external power source and actively sends signals to the RFID reader. It is relatively large in size but boasts a long transmission distance and high transmission speed. Active RFID primarily operates in higher frequency bands such as 800MHz, 2.45GHz, and 5.8GHz, and has the ability to simultaneously identify multiple tags.

[0166] Semi-active RFID, also known as low-frequency activation triggering technology, typically operates in a dormant state, supplying power only to the data storage portion of the tag. This results in lower power consumption and longer operation times. When the tag enters the reader's range, the reader first uses a low-frequency signal for precise positioning, then uses a high-frequency signal for rapid data transmission.

[0167] Optionally, the reader / writer can adopt a separate architecture, for example, consisting of a transceiver unit and an assistance unit. There are forward and reverse links between the reader / writer and the tag, and forward uplink and forward downlink between the transceiver unit and the assistance unit. The assistance unit is responsible for sending excitation signals to the tag via the forward link. Upon receiving the excitation signal, the tag responds by sending a reflected signal to the transceiver unit via the reverse link. The transceiver unit is responsible for generating RFID-related signaling and sending it to the assistance unit, which then forwards it on the forward link to achieve communication.

[0168] If RFID is applied to mobile communication systems, such as the aforementioned 5G system, then the base station can act as a reader / writer, and the terminal device can act as a tag. Furthermore, the fronthaul link between the transceiver unit and the assisting unit can employ 5G New Radio (NR) transmission technology. That is, when the transceiver unit generates RFID-related signaling, it transmits it to the assisting unit via 5G NR technology, and the assisting unit then forwards the signaling on the fronthaul link.

[0169] The card reader performs basic storage / access operations on the tags, such as reading, writing, accessing, and killing, according to the instructions of the application server. Figure 6 This is a schematic diagram of a basic RFID inventory process provided in an embodiment of this application. Wherein, as... Figure 6 As shown, the basic inventory process for RFID includes the following steps:

[0170] S610, the reader sends a select signal to the tag. Correspondingly, the electronic tag device receives the select signal from the reader.

[0171] The select signaling is used to select one tag or a group of tags. Specifically, the reader uses the select signaling to cause tags that meet and / or do not meet the selection criteria to set the status of a specific session in the inventory flag.

[0172] For example, the inventory flag can have four independent sessions: session 0 (S0), session 1 (S1), session 2 (S2), and session 3 (S3). Each session can be in state A or state B. Specifically, the select signaling also carries the fields of inventory session, action, and mask. The select signaling selects a tag and sets the corresponding flag. Assuming the inventorySession selects session S0 and action = 0, if the mask matches, the tag sets the flag of S0 to A, i.e., performs the initial flag setting.

[0173] Each flag corresponds to a session, and `inventorySession` specifies which session's flag should be set. The `action` parameter specifies how to set the flag; for example, `action = 1` or `action = 0`. When a tag receives a `select` signal, if the mask matches, it will set the flag corresponding to the session to A (action = 1) or B (action = 0). The `mask` is used to filter which tags are selected. For example, if a tag stores a complete 96-bit identifier, the `mask` can indicate that tags with the first 16 bits being 111…111 are selected. If the `mask` matches, the tag can further set its flag based on the `action` parameter and then listen for subsequent query commands.

[0174] Optionally, the above select signaling can also be paging signaling, used to page one or a group of tags.

[0175] In S620, the reader sends a query message to the tag. Correspondingly, the tag receives the query message from the reader. This query message can also be referred to as a query command.

[0176] The Query message carries the value of parameter Q, session, and inventory flag. Assuming session is S0 and inventory flag is A, when the tag's session matches the flag, a value between 0 and 2Q-1 is randomly generated based on parameter Q as the initial value of the counter. The tag determines whether to immediately send a random number (RN) to the reader based on the value of this counter. For example, when counter = 0, the tag will send an RN to the reader (e.g., RN(16), where RN(16) is a 16-bit random number). When counter is not 0, the tag does not send an RN to the reader. If the reader does not receive an RN from the tag within a certain period, it will send a QueryRep message to the tag.

[0177] Specifically, there are two scenarios for the subsequent execution steps: scenario 1 and scenario 2.

[0178] Case 1: Counter = 0, specifically including S621.

[0179] S621, the tag sends a random number to the reader. Correspondingly, the reader receives the random number from the tag.

[0180] The random number (RN) can be a 16-bit random number or an 8-bit random number; this application does not limit this.

[0181] Case 2: Counter is an integer greater than or equal to 1, specifically including S622 and S623.

[0182] S622, the reader sends a QueryRep message to the tag. Correspondingly, the tag receives a QueryRep message from the reader. The QueryRep message can also be referred to as a QueryRep command.

[0183] The QueryRep message may be empty, meaning it may omit the value of parameter Q, session, and disk flag. The number of times the QueryRep message is sent is determined by the value of counter. Specifically, each time the tag receives a QueryRep message, counter = counter - 1. This continues until the value of counter reaches 0, at which point the tag sends an RN to the reader.

[0184] More specifically, the tag can calculate the available time slot range [0, 2Q-1] based on the value of the random parameter Q, and the tag can randomly select a value from [0, 2Q-1] and assign it to the counter. Each time the tag receives a QueryRep message, the counter's count is decremented by 1. When the counter's count is 0, S623 can be executed.

[0185] For example, each QueryRep message corresponds to the start or end of an access time slot. That is, each time a tag receives a QueryRep message, it signifies the end of the previous time slot and the start of the next time slot.

[0186] S623, the tag sends a random number to the reader. Correspondingly, the reader receives the random number from the tag.

[0187] When the counter count is 0, the tag sends a random number in its randomly selected access time slot.

[0188] In S630, the reader sends an acknowledged (ACK) message to the tag. Correspondingly, the tag receives the ACK message from the reader.

[0189] When a reader receives the aforementioned RN from a tag, if there is no collision (i.e., the reader receives only one RN from a tag), it will send an ACK message to the reader. This ACK message includes the received RN, indicating that the tag contention has been successfully resolved.

[0190] S640, the tag sends uplink data to the reader.

[0191] The upstream data can be the electronic product code (EPC).

[0192] S650, the reader sends a QueryRep message to the tag again. Correspondingly, the tag receives the QueryRep message from the reader.

[0193] S660, the tag will reverse the state of the disk storage flag.

[0194] After a tag receives a QueryRep message, indicating successful data transmission, it can reverse the state of the disk entry flag. For example, the state of session 0 can be set from state A to state B. Reversing the disk entry flag prevents tags that have already been disked from being disked again, because tags with flag A in subsequent Query messages and flag B will not respond to the Query command.

[0195] The QueryRep message can be used to trigger tags that have not yet successfully connected to the reader. Specifically, the count value of tags whose counter value is not 0 is decremented by 1 until the counter value is 0. Then, S623 to S660 are repeated until all tags have successfully connected to the reader.

[0196] 2. Ambient Internet of Things (A-IoT):

[0197] With the development of communication technology, in order to significantly reduce the power consumption and complexity of IoT devices, the 3rd Generation Partnership Project (3GPP) defined Ambient Internet of Things (A-IoT) technology. A-IoT technology refers to IoT terminals where network nodes do not require an external power source, but instead use ambient energy for power. Building upon RFID, A-IoT further extends to passive interconnection using communication technologies such as Wi-Fi, Bluetooth, UWB, LoRa, and 5G. The ultra-low power consumption and ultra-low complexity A-IoT technology defined by the 3GPP plenary meeting can be understood as an extension of RFID within 3GPP. While A-IoT and RFID share some principles, such as similar inventory management processes, 3GPP introduces more value-added scenarios.

[0198] The A-IoT architecture in A-IoT technology includes network devices and A-IoT terminal devices; in other words, an A-IoT-based communication system includes network devices and A-IoT terminal devices. In this case, as described earlier with RFID, both readers and tags can be implemented based on cellular network infrastructure. In other words, both readers and tags can be devices within a cellular network. For example, the functionality of a reader can be implemented by network devices such as base stations, or it can be implemented by a terminal device. Tags can be implemented by A-IoT terminals within a cellular network, such as ultra-low power, ultra-low complexity IoT terminals. Non-contact data communication can occur between network devices and A-IoT terminal devices, allowing network devices to read information from A-IoT terminal devices and / or write information that needs to be stored into A-IoT terminal devices. In terms of application scope, A-IoT technology can be applied to scenarios such as logistics, warehousing, industrial manufacturing, identity recognition, or environmental monitoring.

[0199] In A-IoT technology, readers and tags can interact with each other through one or more services. These services can include, but are not limited to, inventory, command, read, write, lock, positioning, proximity determination, sensor, kill or disable, and device count. Among these, inventory, read, proximity determination, sensor, and positioning (e.g., when only positioning sequences are sent) may have lower security requirements; while write, lock, and kill / disable services have higher security requirements, meaning these services require the aforementioned keys for security protection. If the reader and tag are attacked while processing a write operation, it may result in incorrect information being written to the tag's storage / memory. Similarly, if the reader and tag are attacked while processing lock or kill / disable operations, the tag may become inoperable.

[0200] It is worth noting that "service" can also be replaced with "task," "session," "request," "transaction," "process," "procedure," or other similar terms. This application does not impose any restrictions on the name of the service; for example, the first service can also be called the first task, and the inventory service can also be called an inventory task, inventory request, inventory process, or inventory transaction, etc.

[0201] For example, such as Figure 6 As shown, the inventory service utilizes a reader (which can be a base station / terminal) to access tags (A-IoT terminal devices) within its coverage area. Successfully connected tags need to send their unique identifier (identifiable by the network, such as the EPC in RFID) to the reader. The positioning service involves the reader (which can be a base station / terminal) using positioning signals to locate the tag (A-IoT terminal device). The sensing service involves the tag (A-IoT terminal device) reporting sensing data to the reader (which can be a base station / terminal), such as temperature data. The write process involves the reader (which can be a base station / terminal) sending a downlink command and data, instructing the tag (A-IoT terminal device) to write the data into the memory area. The locking process involves the reader (which can be a base station / terminal) sending a downlink command to lock the tag (A-IoT terminal device) at a specified address in the memory area, making the contents of that memory area unchangeable and / or unreadable.

[0202] As mentioned above, communication between different devices can refer to direct communication between the devices (i.e., without the need for other devices to relay or forward the communication) or communication between the devices through other devices (i.e., requiring other devices to relay or forward the communication). For example, Figure 7 A schematic diagram of an A-IoT network architecture provided in an embodiment of this application is shown. For example, as Figure 7 As shown in (a), A-IoT terminal devices (i.e., tags) communicate directly and bidirectionally with network devices such as base stations (i.e., readers). Communication between network devices and A-IoT terminal devices includes A-IoT data and / or signaling. Figure 7 The topology shown in (a) includes network devices that send data and / or signaling to A-IoT terminal devices and network devices that receive data and / or signaling from A-IoT terminal devices; that is, there is uplink / downlink data or signaling transmission / reception between the network devices and the A-IoT terminal devices. For example, such as... Figure 7 As shown in (b), A-IoT terminal devices and network devices communicate bidirectionally through intermediate nodes. In this topology, the intermediate node can be a repeater, IAB node, UE, etc., and it transmits A-IoT data and / or signaling between the A-IoT terminal devices and network devices. For example, ... Figure 7 As shown in (c), the A-IoT terminal device sends data / signaling to the network device and receives data / signaling from the auxiliary node; or, the A-IoT terminal device receives data / signaling from the network device and sends data / signaling to the auxiliary node. In this topology, the auxiliary node can be a repeater, IAB, UE, etc. For example, such as... Figure 7 As shown in (d), the A-IoT terminal device communicates bidirectionally with other terminal devices. The communication between the A-IoT terminal device and other terminal devices includes A-IoT data and / or signaling.

[0203] For example, terminal devices in A-IoT can be divided into three categories: device A, device B, and device C.

[0204] 1) Device A (similar to a passive A-IoT terminal): It has no energy storage or some low capacitor energy storage, cannot generate independent signals, and uses backscatter to transmit signals.

[0205] 2) Device B (similar to a semi-passive A-IoT terminal): It has energy storage, such as capacitor energy storage, but cannot generate signals independently; it uses backscattering to transmit signals. The stored energy can amplify the reflected signal. Optionally, device B stores energy through a battery.

[0206] 3) Device C (similar to an active A-IoT terminal): It has energy storage, can generate signals independently, and has active radio frequency (RF) components for transmission.

[0207] The 3GPP meeting further defined the following three categories of A-IoT devices: device 1, device 2a, and device 2b. Device A can be equivalent to device 1, device B can be equivalent to device 2a, and device C can be equivalent to device 2b. This application does not impose any restrictions on the names of these three categories of A-IoT devices.

[0208] 1) Device 1: Peak power consumption is approximately 1μW, with energy storage function, and initial sampling frequency offset (SFO) reaches 10. X At parts per million (ppm), it cannot amplify downlink (DL) or uplink (UL) signals. It requires an external carrier signal for backscatter communication to enable uplink transmission.

[0209] 2) Device 2a: Peak power consumption less than or equal to several hundred μW, with energy storage function, and initial sampling frequency offset up to 10. X ppm can amplify DL and / or UL signals. An external carrier signal is required for backscatter communication in order to perform uplink transmission.

[0210] 3) Device 2b: Peak power consumption less than or equal to several hundred μW, with energy storage function, and initial sampling frequency offset of 10. X ppm, capable of DL and / or UL signal amplification. The device can perform uplink transmission without relying on an externally provided carrier.

[0211] Taking device A / device 1 (or device B / device 2) as an example, the power consumption is approximately in the 1 microwatt (μW) range, resulting in very low power consumption and limited storage capacity. Furthermore, due to the short duration of capacitor charge (less than 1 second) and low sensitivity, the inability to distinguish between charging energy and valid signal energy, signal transmission and reception during RF charging is not possible, and charging time can reach several seconds or even tens of seconds. The charging-operating mode of this type of device is: charge until the capacitor is fully charged, then begin transmitting and receiving messages. Additionally, the extremely low power consumption and cost of this type of device, coupled with its extremely low storage capacity, necessitates additional design costs and power consumption for storing extra information; therefore, information storage in this type of device requires strict consideration. Information temporarily stored in registers is lost after the power is depleted.

[0212] 3. Security Activation / Security Mode Control (SMC)

[0213] Currently, Security Activation / SMC can be used to activate secure interaction of information between the terminal and network sides, including two parts: Non-Access Stratum (NAS) SMC and Access Stratum (AS) SMC. For example, the Security Activation / SMC process mainly completes the negotiation of the security algorithm used by the terminal and network sides, and generates the key required for the corresponding security algorithm based on KASME or KeNB. For example, in the 5G NR security activation scheme, by adding many layers of "intermediate" keys between the network and terminal sides, the security complexity is increased, ensuring the security of communication. For example, "intermediate" keys may include KAUSF, KSEAF, KAMF, KgNB, signaling plane encryption key KRRCenc, and integrity protection key KRRCint, etc.

[0214] However, as described in the aforementioned security activation schemes, terminal devices need to generate, update, or store a large number of keys, which leads to significant additional storage overhead. The security activation process is complex, requiring multiple interactions to complete, thus introducing substantial latency to the terminal device. For example, in A-IoT technology, A-IoT devices have low power consumption and low complexity, making current security activation schemes unsuitable for A-IoT terminal devices. This would result in additional power consumption, greater design complexity, and significant inventory latency (for instance, significantly impacting inventory efficiency in scenarios with a large number of A-IoT terminal devices, and high latency also increases energy consumption). Similarly, current security activation schemes are also difficult to apply to scenarios with weaker terminal device capabilities. For ease of description, the following section uses the A-IoT scenario as an example of a scenario with weaker terminal device capabilities.

[0215] Furthermore, when a tag receives a paging message from a reader, it is unaware of the specific type of service between itself and the reader. That is, the tag is unaware whether it includes services requiring security protection, such as write, lock, and deactivation. Consequently, currently, regardless of whether the scenario involves only inventory management, includes inventory management and other services not requiring security protection, or includes both inventory management and services requiring security protection, the tag will deduce / save / send security keys and related parameters (tens to hundreds of bits).

[0216] In the two scenarios mentioned earlier (i.e., scenarios with only inventory management and scenarios with inventory management and other services that do not require security protection), the security key is additional stored information. Excessive temporary storage of these additional security parameters may cause the tag's power consumption to fail to meet low-power requirements, and the increased register capacity will also lead to a larger additional chip area and power consumption overhead. The calculation and derivation of the security key and security parameters will also introduce additional power consumption and latency. The additional latency will affect inventory management efficiency, especially in scenarios with a large number of tags (e.g., 1000 tags serially connected to the reader). The additional latency may also cause the tag's own power to be insufficient to sustain successful connection to the reader, resulting in service failure.

[0217] To address the aforementioned issues, this application proposes a communication method 800 that can save on the computation and storage overhead of parameters such as security keys. Figure 8 A flowchart of the communication method 800 is shown, wherein, as Figure 8 As shown, the communication method 800 may include steps S810, S820 and S830.

[0218] S810: The second device sends the first instruction information.

[0219] Correspondingly, the first device receives the first indication information. Specifically, the first indication information is used to indicate the service type of communication between the first device and the second device and / or to indicate the execution of a security operation. The service type includes at least one first service, which includes a process for completing data transmission based on the security operation.

[0220] In the embodiments of this application, performing security operations may be a process or operation involving encryption protection and / or integrity protection. The purpose is to encrypt and / or protect the integrity of uplink and downlink data between the reader and the tag to prevent attacks by attackers. Furthermore, performing security operations may also include other security protection operations such as preventing replay attacks or preventing tampering.

[0221] In the embodiments of this application, the process of completing data transmission based on secure operations can be a portion of the data transmission process in the first service, which is a process where secure operations are to be performed during service processing. In other words, this portion of the data transmission process requires the execution of secure operations, such as security protection based on a key, in order to achieve uplink or downlink transmission. For example, when the first service is a write service, the process of the tag receiving the data to be written from the reader requires security protection based on a security key; otherwise, it will cause the tag to write incorrect information. This process is the aforementioned process of completing data transmission based on secure operations.

[0222] Optionally, the aforementioned data transmission based on secure operation may include uplink or downlink data transmission between the first device and the second device. When the data transmission between the first device and the second device includes a third device acting as an intermediate node, it may also include uplink or downlink data transmission between the first device and the third device, or it may include uplink or downlink data transmission between the third device and the second device.

[0223] For example, when the first device is a tag, the third device is a reader, and the second device is a core network device, the data transmission between the tag and the core network can include uplink and downlink data transmission between the tag and the core network device, or uplink and downlink data transmission between the tag and the reader, or uplink and downlink data transmission between the reader and the core network device.

[0224] Optionally, in other cases of embodiments of this application, the second device may send a second indication message. This second indication message is used to indicate that no security operation should be performed and / or to indicate that the service type of communication between the first device and the second device does not include the first service. That is, the service of communication between the first device and the second device does not include the process of data transmission based on the security operation, or only includes the process of data transmission that does not require data transmission based on the security operation. Correspondingly, after receiving the second indication message in this case, the first device may not perform any security operation.

[0225] For example, not performing security operations may include at least one of the following processes: discarding or releasing security parameters, not generating security keys such as session keys for data transmission, not encrypting (all or part) of the data transmission, and not performing integrity protection on (all or part) of the data transmission.

[0226] For example, as mentioned above, the types of services communicated between the first device and the second device include, but are not limited to: inventory services, command services, read services, write services, lock services, positioning services, proximity determination services, sensor services, kill or disable services, and device count services. The first service can be one or more of the read, write, lock, and kill or disable services, which have higher security requirements.

[0227] Those skilled in the art should understand that data transmission or signaling interaction between the first and second devices requires the passage of a third device. For example, the third device may directly forward messages from the first or second device. Alternatively, the third device may process the received message content (such as a NAS PDU or MAC SDU) before sending it, for instance, by adding access layer / air interface headers (such as MAC headers, physical layer frame headers such as preamble, CRC, etc.), or by performing physical layer processing such as scrambling or modulation. Furthermore, the third device may determine the instruction information to send to the first device based on the instruction information sent by the second device (this instruction information may differ from the instruction information sent by the second device).

[0228] For simplicity, the accompanying figures below omit some signaling steps that require forwarding through a third device. For example, the first indication information needs to be forwarded through a third device, but this forwarding step is omitted in the figures for simplicity. The interaction process between the first and third devices, as well as the interaction process between the third and second devices, can be found in [reference needed]. Figure 7 The descriptions shown are not repeated here. For ease of description, the following text will use direct interaction between devices (i.e., no intermediate nodes) as an example to introduce the technical solution of this application.

[0229] Furthermore, the communication method 800 can be executed by the first device, the second device, and the third device, or by modules such as chip systems or circuits in the first device, the second device, and the third device, or by logic nodes, logic modules, or software capable of implementing all or part of the functions of the first device, the second device, and the third device. This application does not limit this.

[0230] In the embodiments of this application, the first device may be the aforementioned tag (or A-IoT terminal device); the second device may be the aforementioned core network device, or an access network device such as a base station or terminal device, or the second device may be a server (third party) such as an IoT server; the third device may be a network device, a terminal device, or a reader / writer.

[0231] Optionally, the first device may receive a paging message from a third device, the paging message including the first indication information. Correspondingly, the second device may send a service request message to the third device, the service request message including the first indication information. Optionally, in some other embodiments of this application, the first device may receive first downlink data from a second device, the first downlink data including the first indication information. This part will be described in detail below with reference to embodiments, and will not be repeated here.

[0232] Optionally, in other cases of embodiments of this application, the first indication information may also be determined by indication information received by the third device from the second device. For example, the second device, such as a core network device, indicates to the third device that the service type between the first and second devices includes a first service and / or the execution of a security operation. The third device then generates the first indication information according to the second device's indication and sends it to the first device via a paging message or first downlink data. Here, the interface between the second and third devices (e.g., NG-AP or XX-AP) is different from the interface between the first and third devices. Therefore, the format of the message received by the third device from the second device may differ from the format of the message received by the first device from the third device, meaning the content of the indication information may differ. Furthermore, the third device can generate the first indication information based on other indication information sent by the second device.

[0233] Optionally, in other cases of embodiments of this application, the first indication information may also be determined and generated by the third device itself, and sent to the first device through the aforementioned paging message or first downlink data.

[0234] Optionally, the aforementioned paging message may include a paging message or Figure 6 The select signaling shown is used to page, select, or trigger one or more devices. Access trigger messages include Query messages or QueryRep messages, which will be described below.

[0235] Optionally, the Paging message can be used to indicate that a tag is accessing a reader. For example, when the reader is a base station / access network device, the Paging message can be used to indicate that the tag is accessing the network; when the reader is a terminal device, the Paging message can be used to indicate that the tag is accessing a terminal. Optionally, the reader can access the network through a terminal.

[0236] Optionally, Paging messages can also be used to trigger / instruct tags to send uplink data, or to trigger / instruct / request tags to perform any of the following services or processes: paging service, inventory service, command service (such as read, write, deactivate, lock, etc.), location service, and sensing service.

[0237] Optionally, a Paging message can also be called an (initial) trigger message. Paging messages can be triggered by A-IoT sensing core network nodes (such as AMF, or ambient IoT management function (A-IoT MF), ambient IoT function (AIoTF), etc.). For example, an A-IoT sensing core network node sends a service request message or a paging message to an A-IoT access network node, and the A-IoT access network node sends a Paging message based on the service request message or paging message. The service requested in the service request message can be a service related to the application scenario, such as at least one of the following: inventory service, command service, positioning service, sensing service, proximity determination, read service, write service, deactivation service, locking service, or security service (such as authentication, authorization, registration, etc.), or it can be a newly defined service type in the future; the specific naming is not limited.

[0238] Optionally, the Paging message can also be called a storage trigger / instruction / request message or a command trigger / instruction / request message. For example, a storage trigger / instruction / request message is used to trigger / instruct / request the tag to be stored, and a command trigger / instruction / request message is used to trigger / instruct / request the first device to perform a command.

[0239] Optionally, the paging message may include identification information for selecting / filtering communication devices, such as device ID, mask, group identifier, temporary identifier, permanent identifier (e.g., not lost due to battery level below a threshold / depletion), temporary identifier (e.g., only lasts for a period of time and may be lost due to battery level below a threshold / depletion), access stratum (AS) ID, etc.

[0240] For example, the aforementioned paging message, service request message, or first downlink data may include a first field. The value of this first field is used to indicate the service type of communication between the first device and the second device and / or to indicate the execution of a security operation. For example, the first field may be 1 bit, where a value of 0 indicates that no security operation is performed (e.g., security OFF), and a value of 1 indicates that a security operation is performed (e.g., security ON). As another example, the first field may be a service identification information field, that is, the value of this service identification information field is used to indicate the service type of communication between the first device and the second device. For example, the aforementioned service identification field values ​​of 0 to 3 correspond to the aforementioned inventory service, positioning service, sensing service, and command service (requiring security protection). In the embodiments of this application, the value of the service identification field may include 3 (and may also include values ​​corresponding to other services), that is, the communication between the first device and the second device includes a command service with a security protection process.

[0241] Optionally, the first indication information can also indicate the execution of a security operation through information such as security level. For example, a high security level in communication between the first and second devices can correspond to executing a security operation (e.g., security ON), while a low security level can correspond to not executing a security operation (e.g., security OFF). In other words, the second device can configure or indicate whether to execute a security operation based on the different security levels of communication between the first and second devices, with the first indication information corresponding to a higher security level. Furthermore, different types of first devices (such as the different types of tags mentioned earlier) can correspond to different security levels. For instance, a low-capability first device (such as device 1 or device A mentioned above) may default to not performing a security operation (such as generating a key for encryption and / or integrity protection) or not perform a security operation after receiving an indication such as security OFF, while a high-capability first device (such as device 2b or device C mentioned above) may default to performing a security operation.

[0242] Optionally, when the first indication information is used to instruct the execution of a safety operation, based on Figure 5 In the O-RAN architecture, the second device can dynamically configure the first indication information based on the RIC (such as using its AI model). That is, it can dynamically configure the indication of whether a security operation needs to be activated based on the RIC. The RIC can be any network element in the core network. In this case, the second device can determine whether a security operation needs to be performed based on the prior information of the first device and indicate the result to the CU in the third device. In other words, the process includes an additional step where the RIC provides prior information to the CU.

[0243] For example, if prior information or historical data indicates that the first device is an A-IoT terminal device in a closed warehouse and the closed warehouse does not support secure operation, the RIC can instruct the CU not to perform a secure operation. As another example, if prior information or historical data indicates that the first device is a low-cost device with low security requirements, the RIC can instruct the CU not to perform a secure operation. Yet another example, if prior information or historical data indicates that the first device has high security requirements, the RIC can instruct the CU to perform a secure operation, that is, instruct the CU to provide the first indication information.

[0244] Optionally, when the second device needs to interact with multiple devices (including the first device), the second device can perform inventory checks or trigger business processes on different devices in batches, based on the security level of the different devices, whether security operations are required, or the business type. For example, the second device can first perform inventory checks or trigger business processes on A-IoT devices with high security levels (or those requiring security operations, or whose business type includes the first business).

[0245] Optionally, as described above for inventory management, the first device needs to report its identification information to the second device. When the identification information of the first device needs to be encrypted or protected for privacy, the first device can receive a first parameter from the second device to protect the privacy of its identification information. The first parameter is a parameter generated by the second device for protecting the privacy of the identification information. The following embodiments will describe this process in detail, and will not be repeated here.

[0246] S820: The first device generates a first key based on the first instruction information.

[0247] Correspondingly, in step S830, the second device generates the first key based on the first instruction information. That is, as mentioned above regarding... Figure 8 As described above, the first key is a key generated in alignment between the first device and the second device. For example, it can be a key generated based on one or more of the same parameters, and the generation algorithm (such as an encryption algorithm like a hash algorithm, an integrity protection algorithm, etc.) is also the same. Specifically, the first key is used for security protection of communication between the first device and the second device, such as the encryption protection and / or integrity protection described above.

[0248] Furthermore, after generating the first key, both the first and second devices can save it. This saved first key can not only be used for security protection of communication between the first and second devices in the current access opportunity, but can also be used multiple times by the second device; that is, the first key can have a relatively long storage time for repeated use by the second device. The first device can also release the first key after a certain period of storage to save storage space. Alternatively, the storage time of the first key can be specified by the second device. The scheme for saving the first key will be described in detail below.

[0249] It should be understood that the first instruction information is used to instruct the first device to generate the first key, rather than the generation parameters or input parameters of the first key. In other words, the first instruction information can trigger the first device to generate the first key. The following will describe the generation process of the first key, that is, the generation of the first key based on multiple key generation parameters.

[0250] It is worth noting that the first key can also be used for other security protections such as anti-tampering in communication between the first device and the second device. This application does not limit the type of security protection. The following embodiments will use encryption protection and integrity protection as examples for description.

[0251] Optionally, in other cases of embodiments of this application, if the first device receives a second indication message indicating that no security operation should be performed and / or indicating that the service type of communication between the first device and the second device does not include the first service, that is, the service of communication between the first device and the second device does not include the process of completing data transmission based on the security operation, then the first device may not perform any security operation. Not performing a security operation may include at least one of the following processes: discarding or releasing security parameters, not generating a security key such as a session key for data transmission, not encrypting (all or part) of the data transmission, and not performing integrity protection on (all or part) of the data transmission.

[0252] For example, Figure 9 A schematic flowchart illustrating the generation of a first key according to an embodiment of this application is shown. Figure 9As shown in (a), the first device receives the second parameter in step S821, generates the third parameter in step S822 (or the third parameter may be pre-stored by the first device), and sends the third parameter to the second device in step S823. Then, in step S824, the first device generates a first key based on at least the second and third parameters. Correspondingly, the second device generates and sends the second parameter in step S821, receives the third parameter in step S823, and then, in step S830, generates a first key based on at least the second and third parameters. That is, the second parameter is the parameter generated by the second device for key generation, and the third parameter is the parameter generated by the first device for key generation.

[0253] For example, Figure 10 A schematic diagram of a key generation process provided in an embodiment of this application is shown. Wherein, as Figure 10 As shown, corresponding to step S821, the reader carries a random number / prior information / freshness number RAND1 (i.e., the aforementioned second parameter) in the paging message as input parameters for the security algorithm. RAND1 can be updated with each paging to ensure the freshness of subsequent security algorithm input parameters. Corresponding to step S822, after receiving RAND1, the tag needs to temporarily store RAND1 and generate a random number / prior information / freshness number RAND2 (i.e., the aforementioned third parameter) (which can also be pre-stored). Then, at least based on RAND1 and RAND2, RES1 (e.g., a response or a user / device response) is generated.

[0254] Afterwards, the tag can communicate with the reader as follows: Figure 6 The disk storage / access process is shown. That is, the tag and reader connect via... Figure 6The process interaction is shown below. Corresponding to step S823, the tag sends its ID (which can be encrypted using a pre-stored key), RES1 (used by the core network device CN to verify the validity of the message), RAND2 (informing the CN of the prior information generated by the electronic tag device, used for subsequent key generation and verification using RES1), and key id (indicating which key the electronic tag device has pre-stored; the CN can find the key used by the electronic tag device based on the key id, i.e., the pre-stored key mentioned earlier) to the CN via the first uplink data. Furthermore, corresponding to steps S824 and S830, the tag and CN can, based on the aforementioned security parameters, generate (i.e., generate and save consistently) a session key for data encryption protection and a security key for integrity protection, such as a message authentication code for integrity (MAC-I). The input parameters for the session key include at least RAND2, RAND1, and keyid, while the input parameters for MAC-I can be RAND1, RAND2, etc.

[0255] It is worth noting that the session key can also be called the transaction key, group key, service key, etc. Figure 10 The security keys and security parameters shown are merely examples. The security keys in this application embodiment can also be parameters with similar functions as session keys or MAC-I. This application does not limit the names of the keys such as MAC-I, session keys, or security parameters such as RAND and RES used.

[0256] Finally, as Figure 8 As shown, the uplink and downlink data exchanged between the tag and the core network device (CN) can be securely protected using the aforementioned Sessionkey and MAC-I. Furthermore, corresponding to step S650, the reader sends a QueryRep message to the tag again. Accordingly, after receiving the QueryRep message from the reader, the tag indicates successful data transmission and can then reverse the state of the disk storage flag.

[0257] Optionally, Figure 10 RAND1 can also be used for privacy protection of the tag's ID; that is, RAND1 can also serve as the first parameter for privacy protection of the identification information of the first device. Thus, in Figure 10 In the first uplink data shown, the tag sends the encrypted or privacy-protected ID to the CN.

[0258] like Figure 9As shown in (a), in step S823, the first device needs to send a third parameter to the second device through the third device; that is, the third device needs to schedule the third parameter (the second parameter can be included in the aforementioned paging message and service request message). Therefore, optionally, as... Figure 9 As shown in (b) of this application, in an embodiment of this application, if the third device does not know the resource size of the scheduling third parameter, the second device can send third indication information to the third device through step S910. This third indication information is used to indicate the resource size when scheduling the third parameter. Furthermore, the third device can send the third parameter to the second device through the first transmission block in step S920 based on this third indication information. The first transmission block includes the scheduling resources for the third parameter. Optionally, in some other embodiments of this application, if the third device knows the scheduling resource size of the third parameter, then... Figure 9 Step S910 may be omitted from the process shown in (b).

[0259] Figure 11 A schematic diagram illustrating the timing of the generation of the first key provided in an embodiment of this application is shown. Optionally, as... Figure 11 As shown in (a), if the first indication information is included in the paging message and the paging message includes the aforementioned second parameter, the first device can generate the first key immediately after receiving the paging message. Optionally, the first device can also generate the first key after sending the paging message. Figure 11 The first key is generated before the first uplink data shown in (a) (e.g., reading data or command response). Optionally, as shown... Figure 11 As shown in (b) of this application, in some other embodiments, the first device may generate the first key only after successfully connecting to the third device, such as upon receiving the msg2 message indicating successful connection to the third device. This reduces the temporary storage time of the first key, thereby reducing the storage overhead of the first device.

[0260] Optionally, if the aforementioned msg2 message indicates that the contention has been successfully resolved, the first device generates the first key. At this time, Figure 11 The msg2 shown can be associated with msg1. For example, msg2 contains the same identification information as msg1 (in whole or in part), or the identification information contained in msg2 can be generated based on the information in msg1 through calculation. For example, msg2 is obtained by hashing the identification information (such as device ID) in msg1.

[0261] also, Figure 11The msg1 shown can also be called RN, random access ID, or random ID. msg1 is used for contention resolution, or to distinguish different UEs during random access / contention resolution. Figure 11 The msg2 shown can also be called ACK, or Access ID response, or access response, or Contention Resolution Identity (UE / device Contention Resolution Identity). Msg2 is used to indicate whether contention resolution was successful, and ACK is used to associate the device by carrying the contention resolution identity.

[0262] Optionally, if the first device and the second device need to use the first key again later, the first device and the second device will generate and continuously store the first key until the first device and the second device no longer need to use it, and then release the first key. If the first device and the second device only use the first key a few times, such as only completing one secure uplink or downlink transmission operation based on the first key, the first device and the second device can release the first key after using it. Similarly, for the security parameters used to generate the first key, such as the second parameter and the third parameter, if the first device and the second device only use them a few times, they can release them after use. If they need to be used multiple times, or if multiple data transmissions require the aforementioned security parameters, the first device and the second device can generate and store the aforementioned security parameters for a period of time until the aforementioned security parameters are no longer needed, and then release them.

[0263] For example, when the first key is used a limited number of times by the first device and the second device mentioned above, after the first key is generated, the first device can release the generated first key after a specific storage time or through signaling interaction, thereby reducing the storage time of the first key and thus reducing storage overhead. For example, releasing the first key can be achieved by the first device not continuing to save the relevant information of the first key, or by flushing the relevant information / cache / memory of the first key, or by discarding the information related to the first key. Figure 12 This illustration shows a schematic diagram of a first device releasing a first key according to an embodiment of this application.

[0264] For example, the first device can release the first key after a first storage time. For instance, the duration of the first storage time can be determined based on the device capability information of the first device; that is, the stronger the capability of the first device, the longer the first storage time, and vice versa. As another example, the duration of the first storage time can also be related to the type of service between the first and second devices. For example, if the first and second devices have many or high-priority services requiring security protection, the duration of the first storage time can be longer. Furthermore, the second device can indicate the first storage time to the first device, such as... Figure 12 As shown in option 1, the second device sends a fourth indication message (which may be included in the paging message) to the first device through step S815. The fourth indication message indicates the first storage time.

[0265] As another example, the first device may release the first key after receiving specific signaling. For example, such as... Figure 12 As shown in option 2, in step S840, after receiving the third message, the first device releases the first key in step S860. This third message can be used to indicate or trigger the first device's next access opportunity, such as... Figure 6 The query message or queryRep message shown. Furthermore, in some other embodiments of this application, a third message such as a query message or queryRep message may also indicate whether to release the key, for example, through MAC CE or MAC header or other AS layer fields. For example, as... Figure 12 As shown in option 3, in step S850, after receiving the fourth message, the first device releases the first key through step S860. The fourth message can be used to instruct the first device to release the stored security parameters and / or keys.

[0266] Optionally, the Query message can also be called an Access round indication / trigger message, which is used to indicate / trigger at least one access opportunity, such as directly or indirectly indicating the total number of access opportunities, or to trigger the first access opportunity, or to trigger a new round of access, or to trigger the first device that failed to access / data transmission to re-access.

[0267] Optionally, the QueryRep message can also be called an access occasion indication / trigger message, which is used to indicate / trigger the next access occasion. It can also be understood as indicating / associating with the boundary (start or end) of an access occasion.

[0268] The aforementioned access opportunities can also be described as access timing, access time slots, etc. Each access opportunity may allow the first device to send access (request), and / or contention resolution, and / or data transmission, etc.

[0269] Optionally, corresponding to the situation mentioned above where the first device and the second device need to use the key multiple times, such as when there are periodic triggered services between the first device and the second device or services that require repeated use of the security key, the second device can instruct the first device to extend the storage time of the first key to continuously store the first key for a period of time. That is, the first key can be continuously stored for a period of time. Figure 13 This illustration shows a schematic flowchart of an embodiment of the present application for extending the storage time of a first key. For example, when the first key needs to be used multiple times between a first device and a second device, such as... Figure 13 As shown, after the first device and the second device generate the first key, the second device can send a fifth instruction message in step S870 to instruct the first device to extend the storage time of the first key, or to specify the extended storage time as T1. Then, the first device releases the first key after time T1 has elapsed.

[0270] Optionally, if the second device schedules the first device across time slots based on the AS ID, the second device may extend the storage time of the first key through the aforementioned fifth indication information, or may instruct the first device to release the first key only when it receives a signaling carrying a temporary identifier.

[0271] For example, after the first device completes its service, if the second device needs to schedule the first device again later, it can directly schedule the first device using a temporary identifier (such as an access stratum identity (AS ID)). If the second device does not want to reallocate or generate security parameters later, it can reuse the currently generated security parameters for encryption / integrity protection of uplink and downlink messages when scheduling the first device later. Therefore, in this case, when the first device receives the aforementioned temporary identifier such as the AS ID, it can save the existing security parameters for a period of time, which can be indicated by the second device. For example, the indicated saving time can cover the time of scheduling the first device. If the second device may schedule the first device again in 10 seconds, the second device can instruct the first device to release the security parameters after >10 seconds.

[0272] Optionally, in some other embodiments of this application, the first device may request a delay in performing a security operation, such as delaying the generation of the first key. For example, if the first device's battery power is insufficient to generate the first key, it may request a delay in generating the first key. In this case, after receiving the request from the first device, the second device may reply whether it agrees to the first device's delay request.

[0273] Figure 14 This illustration shows a schematic flowchart of a first device delaying the execution of a security operation according to an embodiment of this application. In step S880, the first device sends a request message to a second device, which requests a delay in the execution of a security operation, such as delaying the generation of the first key.

[0274] For example, such as Figure 14 As shown in option 1, if the second device agrees to the first device delaying the execution of the security operation, it can send an acknowledgment message for the request message in step S891. This acknowledgment message indicates that the first device is allowed to delay the execution of the security operation. Furthermore, the first device can perform the security operation, such as generating the first key, after a sleep time T2. T2 can be the maximum service time indicated by the second device, or it can be determined based on the charging time of the first device, or it can be determined based on the capabilities of the third device.

[0275] Optionally, such as Figure 14 As shown, in some other embodiments of this application, after time T2 has elapsed, the first device may send a reconnection indication message to the third device to reconnect to the third device, or the third device may send a rescheduling indication message to the first device to reschedule the first device. For example, the rescheduling indication message may be as follows: Figure 6 When using RN16 or the aforementioned AS ID, the rescheduling instruction message can also carry security parameters for security protection.

[0276] For example, such as Figure 14 As shown in option 2, if the second device disagrees with the first device's delay in performing the security operation, it can send a denial response message for the request message in step S895. This denial response message indicates that the first device is not allowed to delay performing the security operation. At this time, the second device can send a sixth instruction message in step S896 to instruct the first device to reconnect to the third device after a second time period, such as T3, or after the next paging. In other words, the first device will not reconnect to the third device during the T3 time period or before the next paging.

[0277] The next paging request can be determined by the identification information carried in the paging message. For example, this identification information can indicate whether the paging message is a retransmission of the paging message (or the current service, without initiating a new service) or a newly transmitted paging message (initiating a new service). Alternatively, the next paging request can also be identified or associated with the service triggered by the current paging message using a service identifier (or session identifier, task identifier, etc.; this application does not limit the identifier name). For instance, a service identifier of 0 indicates the current service and no new service has been initiated. When the tag receives a paging message carrying a service identifier of 1, it determines it to be a new paging request or the next paging request.

[0278] The reason the second device instructs the first device not to reconnect to the third device is that during random access or data transmission, the first device may experience access failure or data transmission failure, resulting in the current service not being completed. Therefore, it will reselect an access opportunity to reconnect to the third device, for example, the first device may wait for the next query to reselect an access opportunity. However, in the reconnection process of this application embodiment, there is an additional situation where the service fails: the first device does not support security, but the second device does not allow the first device and the second device to perform unsecured operations. If the first device does not support or is temporarily unable to support secure operations, and the second device does not allow the first device without security protection to report its ID or transmit data, then even if the first device reconnects in a subsequent process, the second device will not allow it to transmit data. Therefore, the first device does not need to reconnect and can only wait until the next new service arrives to initiate a new process.

[0279] As mentioned earlier, currently, regardless of whether the first device only performs inventory management, performs inventory management and other operations not requiring security protection, or includes both inventory management and operations requiring security protection, it will deduce, save, and send security keys and related parameters (tens to hundreds of bits), resulting in additional storage overhead. However, in communication method 800, the first device generates the first key only when instructed to do so, i.e., upon receiving a first instruction. In the aforementioned scenarios where no security protection is required, the first device does not receive any security protection instruction and therefore does not generate the first key, thus saving the first device the overhead of calculating and storing the first key and other security parameters.

[0280] The above text combined Figures 8 to 14 This section illustrates the steps of communication method 800. The following text will combine... Figures 15 to 18Specific embodiments of the communication method 800 are described below. Embodiment 1 describes the specific flow of the communication method 800 when the paging message includes first indication information; Embodiment 2 describes the specific flow of the communication method 800 when the first downlink data includes first indication information; and Embodiment 3 describes the specific flow of the first device requesting a delayed execution of a security operation.

[0281] Example 1:

[0282] Figure 15 A flowchart of the communication method 800 provided in Embodiment 1 is shown. Wherein, Figure 15 This example uses a first device as a tag (such as an A-IoT terminal device), a second device as a core network device, and a third device as a reader / writer, such as a base station. Figure 15 In the process shown, the core network equipment knows whether the tag needs security protection, and therefore can directly carry the first indication information through the service request message.

[0283] like Figure 15 As shown in (a), corresponding to step S810 in communication method 800, the core network device sends a service request message to the reader via step S1510. The service request message includes the first indication information. Furthermore, the reader sends a paging message to the tag via step S1515. The paging message includes the first indication information.

[0284] Furthermore, since generating the first key for the tag requires RAND1 (i.e., the second parameter mentioned above), which corresponds to... Figure 9 As shown in step S921, the core network device sends a service request message to the reader in step S1510. This service request message includes the RAND1. Furthermore, the reader sends a paging message to the tag in step S1515. This paging message also includes the RAND1. That is, both steps S910 and S921 can be implemented using steps S1510 and S1515.

[0285] Afterwards, tags can be used as follows: Figure 6 The inventory process shown ultimately sends its ID to the core network device via the first uplink data. Furthermore, since the core network device needs RAND2 (i.e., the aforementioned third parameter) and key id to generate the first key, then... Figure 9 As shown in step S823, the tag can also send RES1, RAND2 and key id to the core network device through the first uplink data.

[0286] Optionally, if the tag's ID requires privacy protection, the tag can also use RAND1 (i.e., the aforementioned first parameter) to encrypt and protect its identification information ID, or in other words, to protect its privacy. Then, the ID sent by the tag to the core network device via the first uplink data is the ID protected by RAND1 privacy.

[0287] Then, corresponding to steps S820 and S830, the tag and core network equipment can generate a session key for encryption protection based at least on the aforementioned RAND1, RAND2, and key id, and can generate a MAC-I for integrity protection based at least on the aforementioned RAND1 and RAND2. Furthermore, as... Figure 15 As shown in (a), uplink and / or downlink data between the tag and the core network device can be encrypted and protected by the aforementioned session key, and integrity can be protected by the aforementioned MAC-I.

[0288] The timing of session key and MAC-I generation can be referenced. Figure 11 The process described is as follows. Specifically, the session key and MAC-I can be generated either after the tag receives the paging message in step S1515, or after successful access, i.e., after receiving the A-IoT msg2 message.

[0289] Optionally, corresponding to Figure 12 As shown in the process, after the tag and the core network device generate the first key, the core network device can instruct the tag to release the first key in order to reduce the tag's temporary storage space.

[0290] For example, corresponding to Figure 12 In step S815, the fourth indication information can also be included in the service request message and the paging message. That is, the core network device can send a service request message to the reader / writer in step S1510, which includes the fourth indication information. Furthermore, the reader / writer sends a paging message to the tag in step S1515, which also includes the fourth indication information. The fourth indication information can be used to indicate the tag's storage time T0; that is, after receiving the fourth indication information, the tag can release the first key in step S1570 after time T0.

[0291] For example, corresponding to Figure 12 As shown in step S840, after the tag receives a duplicate message or duplicate query message in step S1540, it can release the first key in step S1570. In other words, Figure 15 The duplicate query message shown in (a) is... Figure 12 The third message shown. For example, corresponding to... Figure 12 As shown in step S850, after the reader receives the release signaling from the core network device in step S1550, and the tag receives the release signaling from the reader in step S1560, it can release the first key in step S1570. In other words, Figure 15 The release signaling shown in (a) is... Figure 12 The fourth message shown.

[0292] Optionally, corresponding to Figure 13 The illustrated process shows that after the tag and core network device generate the first key, the core network device can instruct the tag to extend the storage time of the first key to cope with periodically triggered services or services that require repeated use of the security key. This corresponds to step S870, as follows... Figure 15 As shown in (a), the reader receives the fifth indication information from the core network device in step S1575, and the tag receives the fifth indication information from the reader in step S1580. This fifth indication information can be used to instruct the first device to extend the storage time of the first key, for example, by extending the storage time to T1. Then, after the tag receives the fifth indication information, after time T1, the tag releases the first key in step S1590.

[0293] Figure 15 Figure (a) shows a flowchart of communication method 800, while Figure 15 (b) shows a flowchart of the opposite scenario of communication method 800, that is, when no security protection is required after the core network equipment and the tag.

[0294] like Figure 15 As shown in (b), the core network device can use the second indication information to instruct that no security operation be performed or that the core network device and the tag do not include services requiring security protection procedures. Furthermore, as shown, the first uplink data may only include the tag's ID, etc. Consequently, the tag and the core network device do not need to generate a first key, or in other words, they do not need to generate any keys for security protection. If there is still uplink or downlink data interaction between the tag and the core network device, this uplink or downlink data also does not require any security parameters or security keys for protection.

[0295] Optionally, if the tag's ID requires privacy protection, the service request message sent by the core network device and the paging message sent by the reader may include not only the second indication information, but also the aforementioned first parameter, such as... Figure 15 RAND1 is shown in (a) in the diagram.

[0296] Will Figure 15Comparing the two scenarios, it can be seen that communication method 800 can enable... Figure 15 In the scenario shown in (b), the tag does not generate a first key. That is, the tag does not need to derive and save the first key, nor does it need to temporarily store the security parameters used to generate the first key. Consequently, the computational and storage costs of the tag can be reduced.

[0297] Example 2:

[0298] Figure 16 A flowchart of the communication method 800 provided in Embodiment 2 is shown. Wherein, Figure 16 This example uses a first device as a tag (such as an A-IoT terminal device), a second device as a core network device, and a third device as a reader / writer, such as a base station. Figure 16 In the illustrated process, during service inventory, the core network equipment is unaware of whether a tag requires security protection. Therefore, the core network equipment needs to determine whether the tag requires security protection based on the identification information (ID) reported by the tag. Consequently, the core network equipment can directly carry the first indication information through the first downlink data.

[0299] like Figure 16 As shown in (a), in step S1605, the core network device determines that the tag needs security protection based on the ID reported by the tag, that is, it determines the first indication information. Furthermore, corresponding to... Figure 8 In step S810, the core network device sends first downlink data through step S1610, which includes the first indication information.

[0300] In addition, corresponding to Figure 9 In step S821, the core network device sends first downlink data via step S1610. This first downlink data includes RAND1 (i.e., the aforementioned second parameter) used to generate the first key. Correspondingly, Figure 10 In step S823, the tag sends second uplink data via step S1615. This second uplink data includes RAND2 (i.e., the aforementioned third parameter) used to generate the first key. Furthermore, the tag and core network equipment can generate a first key, such as a session key and MAC-I, for security protection, based at least on RAND1 and RAND2.

[0301] The steps for releasing the key and extending the key storage time can be referred to the corresponding description in Example 1. These two processes will not be elaborated upon in Example 2.

[0302] In addition, Figure 16In the process shown in (a), if the ID reported by the tag needs to be protected for privacy through the aforementioned RAND1 (i.e., the aforementioned first parameter), then RAND1, as the first parameter, can be carried in... Figure 16 In the service request message and paging message shown, if the ID reported by the tag does not need to be reported, the core network device may not send RAND1, which is used as the first parameter. It is worth noting that RAND1 in the first downlink data is used as the second parameter; therefore, even if the ID does not require privacy protection, RAND1 still needs to be included in the first downlink data. In other words, in Figure 16 In the process shown, RAND1 can be used as both the first and second parameters, and the core network device can send RAND1 twice.

[0303] Optionally, to reduce the temporary storage space of RAND1 as the first parameter, the tag can discard or release RAND1 after sending the first uplink data. Releasing the first key can mean the first device stops storing information related to the first key, or flushes the information / cache / memory related to the first key, or discards the information related to the first key. After receiving RAND1 again via the first downlink data, the tag does not need to temporarily store RAND1 as the second parameter, but can generate the first key based on at least RAND1 and RAND2 while receiving RAND1. In other words, RAND1 as the second parameter is not temporarily stored on the tag side; the tag can directly use the received RAND1 as the second parameter to calculate and derive the first key. This saves temporary storage space on the tag side.

[0304] Figure 16 Figure (a) shows a flowchart of communication method 800, while Figure 16 (b) shows a flowchart of the opposite scenario of communication method 800, that is, when no security protection is required after the core network equipment and the tag.

[0305] like Figure 16 As shown in (b), when the core network device determines the second indication information based on the ID reported by the tag, meaning that no security protection is required between the tag and the core network device, the core network device can skip any procedures. In other words, the core network device and the tag do not need to generate a first key, or any key for security protection. If there is still uplink or downlink data interaction between the tag and the core network device, this uplink or downlink data also does not require any security parameters or security keys for protection.

[0306] Optionally, if the tag's ID requires privacy protection, the service request message sent by the core network device and the paging message sent by the reader may also include the aforementioned first parameter, such as... Figure 16 RAND1 is shown in (a) in the diagram.

[0307] Will Figure 16 Comparing the two scenarios, it can be seen that communication method 800 can enable... Figure 16 In the scenario shown in (b), each tag can indicate whether security protection is needed, or in other words, each tag reports its own ID, allowing the core network equipment to determine whether security operations need to be performed based on the granularity of each tag. Furthermore, the tag does not generate a first key; that is, the tag does not need to derive or store the first key, nor does it need to temporarily store the security parameters used to generate the first key. This reduces the computational and storage costs of the tags.

[0308] exist Figure 16 In the illustrated process, when RAND1 is used for both the first and second parameters, the core network device needs to send RAND1 to the tag twice, that is, through the service request message and the first downlink data. Optionally, in some other embodiments of this application, the reader can cache the RAND1, so the core network device only needs to send an indication message to instruct the reader to send RAND1 to the tag.

[0309] Figure 17 A flowchart of another communication method provided in an embodiment of this application is shown, wherein the reader / writer can buffer the received RAND1 from the core network device. For example... Figure 17 As shown, when the core network device sends RAND1 to the reader via a service request message, the reader can cache RAND1. When the core network device determines, based on the tag's ID, that security protection is required between the two, it can send a seventh indication message to the reader in step S1713. This seventh indication message can be used to indicate that subsequent data requiring security protection is pending transmission, or to instruct the reader to send the cached RAND1 to the tag. Subsequently, the reader can send the cached RAND1 to the tag in step S1715. Figure 17 The other steps can be referred to in the previous description, and will not be repeated in this article.

[0310] Example 3:

[0311] Figure 18 A flowchart of the communication method 800 provided in Embodiment 3 is shown. Wherein, in Figure 18In the process shown, the tag is unable to support the overhead of subsequent calculations and derivation of security parameters due to insufficient power, and therefore requests the core network equipment to delay the execution of security operations such as generating the first key.

[0312] like Figure 18 As shown, corresponding to Figure 14 In step S880, the tag can send an A-IoT msg1 (RN16) message via step S1881 of option 1, which includes a request message for requesting a delay in performing a security operation. Alternatively, the tag can send an A-IoT msg3 message via step S1885 of option 2, which includes a request message for requesting a delay in performing a security operation.

[0313] Optionally, when the core network device agrees to the tag request, corresponding to Figure 14 In step S891 of option 3, the core network device can send an ACK, i.e., the acknowledgment message in step S891, via step S1891 of option 3. Furthermore, corresponding to... Figure 14 In step S892, the reader can send an AS ID or RN16 to the tag to reactivate it. In other words, the rescheduling message in step S992 can include the aforementioned AS ID or RN16.

[0314] Optionally, when the core network device does not agree to the tag request, corresponding to Figure 14 In step S895 of the protocol, the core network device can send a NACK (negative acknowledgment message) via step S1895 of option 4. Furthermore, corresponding to... Figure 14 In step S995, the core network device sends a sixth indication message through step S1896 to indicate that the tag should not re-access within a certain period of time or before the next paging.

[0315] Finally, the device embodiments of this application will be described.

[0316] To achieve the functions provided in this application, communication devices such as terminal devices or base stations may include hardware structures and / or software modules, implementing the aforementioned functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a particular function is implemented using hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.

[0317] Figure 19This is a schematic block diagram of a communication device 1900 according to an embodiment of this application. The communication device 1900 can be a first device, such as a tag or an A-IoT terminal device, or it can be a second device, such as a core network device. Furthermore, the communication device 1900 can also be a chip or module within a device such as the first or second device, used to implement the methods involved in the above embodiments. The communication device 1900 includes a transceiver unit 1910 and a processing unit 1920. The transceiver unit 1910 will be described exemplarily below.

[0318] The transceiver unit 1910 may include a transmitting unit and a receiving unit. The transmitting unit is used to perform the transmitting action of the communication device, and the receiving unit is used to perform the receiving action of the communication device. For ease of description, the transmitting unit and the receiving unit are combined into one transceiver unit in this embodiment. This will be explained uniformly here and will not be repeated later.

[0319] In some embodiments of this application, the transceiver unit 1910 may also be referred to as a transceiver or transceiver device, etc., and may include an antenna and a radio frequency (RF) circuit. The RF circuit can be used for the conversion between baseband signals and RF signals and for processing RF signals, and the antenna can be used for transmitting and receiving RF signals in the form of electromagnetic waves. The aforementioned RF circuit and the aforementioned antenna can be set up independently of the processor that performs baseband processing, that is, as a separately set module. For example, in a distributed scenario, the RF circuit and the antenna can be arranged in a remote radio unit (RRU) independently of the communication device.

[0320] In some other embodiments of this application, the transceiver unit 1910 may also be implemented as an input / output interface consisting only of input / output circuits.

[0321] When the communication device 1900 is the first device, for example, the transceiver unit 1910 is used to receive first instruction information; the processing unit 1920 can be used to generate a first key according to the first instruction information.

[0322] When the communication device 1900 is a second device, for example, the transceiver unit 1910 is used to send first instruction information; the processing unit 1920 can be used to generate a first key according to the first instruction information.

[0323] The above description is for illustrative purposes only. When the communication device 1900 is the first device or the second device, it will be responsible for executing the methods or steps related to the first device and the second device in the foregoing method embodiments.

[0324] Optionally, the communication device 1900 further includes a storage unit (not shown in the figure) for storing programs or code for performing the aforementioned methods.

[0325] Figure 20 This is a schematic block diagram of a communication device 2000 according to an embodiment of this application. The communication device 2000 includes a processor 2010 and a communication interface 2020, which can be interconnected via a bus 2030. The communication device 2000 may be a first device or a second device, etc., that executes the communication method 800.

[0326] Optionally, the communication device 2000 may also include a memory 2040. The memory 2040 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM), which is used to store related instructions and data.

[0327] Processor 2010 can be one or more central processing units (CPUs). When processor 2010 is a CPU, the CPU can be a single-core CPU or a multi-core CPU.

[0328] The communication interface 2020 may include the aforementioned antenna and radio frequency (RF) circuit. The RF circuit can be used for converting baseband signals to RF signals and processing RF signals, while the antenna can be used for transmitting and receiving RF signals in the form of electromagnetic waves. The aforementioned RF circuit and antenna can be set up independently of the processor that performs baseband processing, that is, as a separately set module. For example, in a distributed scenario, the RF circuit and antenna can be arranged in a remote radio unit (RRU) independently of the communication device.

[0329] When the communication device 2000 is the first device, for example, the communication interface 2020 is used to receive first instruction information; the processor 2010 is used to generate a first key according to the first instruction information.

[0330] When the communication device 2000 is a second device, for example, the communication interface 2020 is used to send first instruction information; the processor 2010 is used to generate a first key according to the first instruction information.

[0331] The above description is for illustrative purposes only. When the communication device 2000 is a first device or a second device, it will be responsible for executing the methods or steps related to the first device or the second device in the foregoing method embodiments.

[0332] The above description is merely exemplary. For details, please refer to the content shown in the above method embodiments. Figure 20 The implementation of each operation can also be referenced accordingly. Figures 8 to 14 The corresponding description of the method embodiments shown.

[0333] Figure 19 and Figure 20 The illustrated device embodiment is used to implement Figures 8 to 14 The content described. Figure 19 and Figure 20 The specific execution steps and methods of the device shown can be found in the content described in the foregoing method embodiments.

[0334] Figure 21 This is a schematic block diagram of a communication device 2100 according to an embodiment of this application. The communication device 2100 is used to implement the functions of a first device or a second device. The communication device 2100 may be a chip in the first device or the second device.

[0335] The communication device 2100 includes an input / output interface 2120 and a processor 2110. The input / output interface 2120 may be an input / output circuit. The processor 2110 may be a signal processor, a chip, or other integrated circuit capable of implementing the method of this application. The input / output interface 2120 is used for inputting or outputting signals or data.

[0336] For example, when the communication device 2100 is the first device, the input / output interface 2120 is used to receive first instruction information, and the processor 2110 is used to generate a first key.

[0337] For example, when the communication device 2100 is a second device, the input / output interface 2120 is used to send first instruction information, and the processor 2110 is used to generate a first key.

[0338] In one possible implementation, the processor 2110 executes instructions stored in memory to implement the functions of the first device or the second device.

[0339] Optionally, the communication device 2100 may also include a memory.

[0340] Optionally, the processor and memory are integrated together.

[0341] Optionally, the memory is located outside the communication device 2100.

[0342] In one possible implementation, the processor 2110 can be a logic circuit, which inputs / outputs messages or signaling through the input / output interface 2120. The logic circuit can be a signal processor, a chip, or other integrated circuit that can implement the methods of the embodiments of this application.

[0343] The above description of the communication device 2100 is merely an exemplary description. The communication device 2100 can be used to execute the methods described in the foregoing embodiments. For details, please refer to the description of the foregoing method embodiments, which will not be repeated here.

[0344] Optionally, the memory is located outside the communication device 2100.

[0345] In one possible implementation, device 2100 can be a chip system 2100.

[0346] Figure 22 This is a schematic diagram of a chip system 2200 provided in an embodiment of this application. The chip system 2200 (or may also be called a processing system) includes logic circuitry 2210 (i.e., processor 2110) and input / output interface 2220.

[0347] The logic circuit 2210 can be a processing circuit in the chip system 2200. The logic circuit 2210 can be coupled to a memory unit, calling instructions from the memory unit, enabling the chip system 2200 to implement the methods and functions of the embodiments of this application. The input / output interface 2220 can be an input / output circuit in the chip system 2200, outputting processed information from the chip system 2200, or inputting data or signaling information to be processed into the chip system 2200 for processing.

[0348] As one approach, the chip system 2200 is used to implement the operations performed by the first device or the second device in the various method embodiments described above.

[0349] For example, input / output interface 2220 is used to implement the sending and / or receiving related operations performed by the first device or the second device in the above method embodiments.

[0350] The above description of the communication device is merely an exemplary description. The communication device can be used to perform the methods described in the foregoing embodiments. For details, please refer to the description of the foregoing method embodiments, which will not be repeated here.

[0351] This application also provides a chip, including a processor, for calling and executing instructions stored in a memory, causing a communication device on which the chip is installed to perform the methods in the examples above.

[0352] This application also provides a chip, including: an input interface, an output interface, and a processor. The input interface, the output interface, and the processor are connected via an internal connection path. The processor is used to execute code in a memory. When the code is executed, the processor is used to perform the methods described in the examples above. Optionally, the chip further includes a memory for storing computer programs or code.

[0353] This application also provides a processor for coupling with a memory for performing the methods and functions involving the first and second devices in any of the above embodiments.

[0354] This application provides a computer program product containing instructions that, when run on a computer, implement the methods of the aforementioned embodiments.

[0355] This application also provides a computer program that, when run on a computer, enables the implementation of the methods described in the foregoing embodiments.

[0356] This application also provides a computer-readable storage medium storing a computer program that, when executed by a computer, implements the methods described in the foregoing embodiments.

[0357] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0358] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0359] In the several embodiments provided in this application, the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0360] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the technical objectives of the embodiments of this application, depending on actual needs.

[0361] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0362] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to the prior art, or parts of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the various method embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0363] The above description is merely a specific embodiment of this application, but the protection scope of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the embodiments of this application should be included within the protection scope of the embodiments of this application. Therefore, the protection scope of this application should be determined by the protection scope of the claims.

Claims

1. A communication method, characterized in that, include: Receive first indication information, the first indication information being used to indicate the service type of communication between the first device and the second device and / or to indicate the execution of a security operation, the service type including at least one first service, the first service including a process of completing data transmission based on the security operation, the security operation including encryption protection and / or integrity protection; Based on the first instruction information, a first key is generated, which is used for security protection of communication between the first device and the second device.

2. The method according to claim 1, characterized in that, The receiving of the first indication information includes: A first message is received, the first message being used to page, select, or trigger at least one device, the at least one device including the first device, and the first message including the first indication information.

3. The method according to claim 2, characterized in that, The generation of the first key includes: After receiving the first message, generate the first key; or, Receive a second message, which indicates that the first device has successfully connected to the third device; Generate the first key.

4. The method according to claim 1, characterized in that, The receiving of the first indication information includes: Send first uplink data, the first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information; Receive first downlink data, the first downlink data including the first indication information.

5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Receive a first parameter, which is used for the security protection of the first identification information of the first device; Send first uplink data, which includes the first identification information after security protection.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: After the first key is generated, and after a first storage period, the first key is released; or, Receive a third message or a fourth message, wherein the third message is used to indicate or trigger the next access opportunity of the first device, and the fourth message is used to indicate the release of stored security parameters and / or keys; Release the first key.

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: The device receives a fifth instruction, which instructs the first device to extend the storage time of the first key.

8. A communication method, characterized in that, include: Send first indication information, the first indication information being used to indicate the service type of communication between the first device and the second device and / or to indicate the execution of a security operation, the service type including at least one first service, the first service including a process of completing data transmission based on the security operation, the security operation including encryption protection and / or integrity protection; Based on the first instruction information, a first key is generated, which is used for security protection of communication between the first device and the second device.

9. The method according to claim 8, characterized in that, The method further includes: Send a third indication message, which is used to indicate the time-frequency resource size of a third parameter, wherein the third parameter is a parameter generated by the first device for key generation; The third parameter is received through the first transmission block, wherein the time-frequency resources of the first transmission block include the time-frequency resources of the third parameter.

10. The method according to claim 8 or 9, characterized in that, The method further includes: Send a seventh instruction message, which instructs the third device to send a cached second parameter to the first device. The second parameter is a parameter generated by the second device for key generation.

11. The method according to any one of claims 8 to 10, characterized in that, The sending of the first instruction information includes: Send a first message, the first message being used to page, select or trigger at least one device, the at least one device including the first device, and the first message including the first indication information.

12. The method according to any one of claims 8 to 11, characterized in that, The sending of the first instruction information includes: Receive first uplink data, the first uplink data including first identification information of the first device, the first identification information being used by the second device to determine the first indication information; Send first downlink data, the first downlink data including the first indication information.

13. The method according to any one of claims 8 to 12, characterized in that, The method further includes: Send a first parameter, which is used for the security protection of the first identification information of the first device; Receive first uplink data, the first uplink data including the first identification information after security protection.

14. The method according to any one of claims 8 to 13, characterized in that, The method further includes: Send a fifth instruction message, which instructs the first device to extend the storage time of the first key.

15. A communication device, characterized in that, The communication device includes a unit for implementing the method as described in any one of claims 1 to 7.

16. A communication device, characterized in that, The communication device includes a unit for implementing the method as described in any one of claims 8 to 14.

17. A communication device, characterized in that, include: A processor configured to be coupled to a memory, read and execute instructions and / or program code in the memory to perform the method as described in any one of claims 1 to 7.

18. A communication device, characterized in that, include: A processor configured to be coupled to memory, read and execute instructions and / or program code in the memory to perform the method as described in any one of claims 8 to 14.

19. A communication system, characterized in that, It includes at least one communication device as described in claim 15 and at least one communication device as described in claim 16.

20. A chip system, characterized in that, include: A logic circuit for coupling with an input / output interface, through which data is transmitted to perform the method as described in any one of claims 1 to 7, or to perform the method as described in any one of claims 8 to 14.

21. A computer-readable medium, characterized in that, The computer-readable medium stores program code that, when executed on a communication device, causes the communication device to perform the method as described in any one of claims 1 to 7, or the method as described in any one of claims 8 to 14.

22. A computer program product, characterized in that, It includes computer program code that, when run, implements the method as described in any one of claims 1 to 7, or implements the method as described in any one of claims 8 to 14.