Communication method and device, and storage medium

CN121844600APending Publication Date: 2026-04-10BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-08
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Due to limited resources, existing security mechanisms for environmental IoT devices cannot effectively ensure the confidentiality, integrity, and anti-replay of information, and frequent authentication processes waste energy and signaling resources.

Method used

By storing a first key in an environmental IoT device, the information can be securely protected, ensuring the security of information transmission.

Benefits of technology

It improves the security of information transmission between environmental IoT devices and network elements, and reduces energy consumption and waste of signaling resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121844600A_ABST
    Figure CN121844600A_ABST
Patent Text Reader

Abstract

The invention relates to a communication method, equipment and a storage medium. The method comprises: receiving a first request sent by a first network element, the first request being used for requesting a first device to execute a first operation; and a first message is sent to the first network element, the first message is subjected to security protection through a first key, and the first key is stored in the first device. Namely, the first device can perform security protection on the first message through the stored first key, so that the security of the information transmitted between the first device and the first network element is higher, and the system performance is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, device and storage medium. BACKGROUND

[0002] An ambient power-enabled IoT device is an IoT device without a battery or with only limited energy storage capability (i.e. using a capacitor).

[0003] SUMMARY

[0004] Embodiments of the present disclosure provide a communication method, device and storage medium.

[0005] According to a first aspect of embodiments of the present disclosure, a communication method is provided, performed by a first device, and the method comprises:

[0006] receiving a first request sent by a first network element, the first request being used to request the first device to perform a first operation;

[0007] sending a first message to the first network element, the first message being security protected by a first key, the first key being stored in the first device.

[0008] According to a second aspect of embodiments of the present disclosure, a communication method is provided, performed by a first network element, and the method comprises:

[0009] receiving a second request sent by a second network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation;

[0010] sending the first request to the first device;

[0011] receiving a first message sent by the first device, the first message being security protected by a first key, the first key being stored in the first device.

[0012] According to a third aspect of embodiments of the present disclosure, a communication method is provided, performed by a third network element, and the method comprises:

[0013] receive a fifth request sent by the first network element, the fifth request being used to obtain device data, the device data being used to obtain a second key, the second key being used for security protection of a second request received by the first network element and / or security processing of a first message received by the first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, the first key being stored in the first device;

[0014] send the device data to the first network element.

[0015] According to a fourth aspect of an embodiment of the present disclosure, a communication method is provided, the method being performed by a second network element, and the method comprises:

[0016] send a second request to a first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation.

[0017] According to a fifth aspect of an embodiment of the present disclosure, a first device is provided, comprising:

[0018] a transceiver module, configured to receive a first request sent by a first network element, the first request being used to request the first device to perform a first operation;

[0019] the transceiver module is further configured to send a first message to the first network element, the first message being security protected by a first key, the first key being stored in the first device.

[0020] According to a sixth aspect of an embodiment of the present disclosure, a first network element is provided, comprising:

[0021] a transceiver module, configured to receive a second request sent by a second network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation;

[0022] the transceiver module is further configured to send the first request to the first device.

[0023] the transceiver module is further configured to receive a first message sent by the first device, the first message being security protected by a first key, the first key being stored in the first device.

[0024] According to a seventh aspect of an embodiment of the present disclosure, a third network element is provided, comprising:

[0025] The transceiver module is configured to receive a fifth request sent by the first network element, the fifth request being used to obtain device data, the device data being used to obtain a second key, the second key being used for security protection of a received second request and / or security processing of a received first message by the first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, and the first key being stored in the first device;

[0026] The transceiver module is further configured to send the device data to the first network element.

[0027] According to an eighth aspect of embodiments of the present disclosure, a second network element is provided, comprising:

[0028] The transceiver module is configured to send a second request to a first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation.

[0029] According to a ninth aspect of embodiments of the present disclosure, a core network device is provided, comprising:

[0030] One or more processors; wherein the communication device can be used to execute the optional implementation manners of the second aspect or the third aspect or the fourth aspect.

[0031] According to a tenth aspect of embodiments of the present disclosure, a communication system is provided, comprising a first device and a core network device, wherein the first device is configured to execute the method described in the optional implementation manners of the first aspect, and the core network device is configured to execute the method described in the optional implementation manners of the second aspect or the third aspect or the fourth aspect.

[0032] According to an eleventh aspect of embodiments of the present disclosure, a storage medium is provided, the storage medium storing instructions, when the instructions run on a communication device, causing the communication device to execute the method described in the first aspect or the second aspect or the third aspect or the optional implementation manners of the fourth aspect.

[0033] The technical scheme provided by the embodiments of the present disclosure can produce the following beneficial effects: receiving a first request sent by a first network element, the first request being used to request the first device to perform a first operation; and sending a first message to the first network element, the first message being security protected by a first key, and the first key being stored in the first device. That is, the first device can security protect the first message by the stored first key, so that the security of the information transmitted between the first device and the first network element is higher, thereby improving the system performance.

[0034] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical schemes in the embodiments of the present disclosure, the following describes the drawings required for the embodiment description. The following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0036] FIG. 1A is a schematic architecture diagram of a communication system according to an embodiment of the present disclosure.

[0037] FIG. 1B is a schematic diagram of a topology structure according to an embodiment of the present disclosure.

[0038] FIG. 1C is a schematic diagram of a topology structure according to an embodiment of the present disclosure.

[0039] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.

[0040] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.

[0041] FIG. 2C is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.

[0042] FIG. 3A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0043] FIG. 3B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0044] FIG. 4A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0045] FIG. 4B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0046] FIG. 4C is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0047] FIG. 4D is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0048] FIG. 5A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0049] FIG. 5B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0050] FIG. 5C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0051] FIG. 6A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0052] FIG. 6B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0053] FIG. 6C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure.

[0054] FIG. 7A is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure.

[0055] FIG. 7B is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure.

[0056] FIG. 7C is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure.

[0057] FIG. 8A is a structural diagram of a first device according to an embodiment of the present disclosure.

[0058] FIG. 8B is a structural diagram of a first network element according to an embodiment of the present disclosure.

[0059] FIG. 8C is a structural diagram of a third network element according to an embodiment of the present disclosure.

[0060] FIG. 8D is a structural diagram of a second network element according to an embodiment of the present disclosure.

[0061] FIG. 9A is a structural diagram of a communication device according to an embodiment of the present disclosure.

[0062] FIG. 9B is a structural diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0063] The embodiments of the present disclosure provide a communication method, device and storage medium.

[0064] In a first aspect, the embodiments of the present disclosure provide a communication method, performed by a first device, including:

[0065] Receive a first request sent by a first network element, the first request being used to request the first device to perform a first operation;

[0066] A first message is sent to the first network element. The first message is protected by a first key, and the first key is stored in the first device.

[0067] In the above embodiments, the first device can use the stored first key to protect the security of the first message, thereby improving the security of the information transmitted between the first device and the first network element and thus improving system performance.

[0068] In conjunction with some embodiments of the first aspect, in some embodiments, the first message is protected by a first key, including:

[0069] Some or all of the messages in the first message are protected by the first key. The first message includes at least one of the following: device identifier and first data.

[0070] In the above embodiments, the first device can protect the device identifier or the first data in the first message, or it can protect the entire first message.

[0071] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0072] The first request is verified and / or securely processed using the first key.

[0073] In the above embodiments, when the first request is protected by security, the first device can verify and / or process the first request securely.

[0074] In conjunction with some embodiments of the first aspect, in some embodiments, the security protection includes encryption and / or integrity protection.

[0075] In conjunction with some embodiments of the first aspect, in some embodiments, storing the first key in the first device includes at least one of the following:

[0076] The first key is stored in the Universal Integrated Circuit Card (UICC);

[0077] The first key is stored in the non-volatile memory of the first device.

[0078] In the above embodiments, the storage method of the first key may be different for different first devices.

[0079] Secondly, this disclosure provides a communication method executed by a first network element, the method comprising:

[0080] receiving a second request sent by a second network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation;

[0081] sending the first request to the first device;

[0082] receiving a first message sent by the first device, the first message being security protected by a first key, the first key being stored in the first device.

[0083] With reference to some embodiments of the second aspect, in some embodiments, the second request comprises at least one of the following: a device identifier, a service identifier, a group identifier, area information, an inventory request, a command request.

[0084] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises:

[0085] sending, according to the second request, a third request to a third network element, the third request being used to obtain device data, the device data comprising data corresponding to the first device or data corresponding to a group of devices;

[0086] receiving the device data sent by the third network element;

[0087] obtaining a second key based on the device data;

[0088] security protecting the second request by the second key to obtain the first request.

[0089] In the above embodiments, the first network element can obtain device data from the third network element, obtain a second key based on the device data, and security protect the second request sent by the second network element by the second key to obtain the first request.

[0090] With reference to some embodiments of the second aspect, in some embodiments, the security protecting the second request by the second key comprises:

[0091] security protecting part of information or all information in the second request by the second key, the second request comprising at least one of the following: a device identifier, first information.

[0092] In the above embodiments, the first network element can security protect the device identifier in the second request, can security protect the first information in the second request, or can security protect the entire second request.

[0093] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises:

[0094] According to the first message, a fourth request is sent to a third network element, the fourth request being used to acquire device data, the device data including data corresponding to the first device;

[0095] The device data sent by the third network element is received;

[0096] The second key is acquired based on the device data.

[0097] In the above embodiment, after the first network element receives the first message sent by the first device, the device data can be acquired from the third network element, and the second key is acquired based on the device data.

[0098] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:

[0099] The first message is verified through the second key;

[0100] It is determined that the first message is verified, and the first message is processed securely to obtain a second message.

[0101] In the above embodiment, the first network element can verify and securely process the first message through the second key.

[0102] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:

[0103] The second message is sent to the second network element.

[0104] In combination with some embodiments of the second aspect, in some embodiments, the second request includes the area information, and the method further includes:

[0105] It is determined that the area information corresponds to a public land mobile network (PLMN).

[0106] In the above embodiment, in the case where the second request includes the area information, the area information can be mapped to the PLMN.

[0107] In combination with some embodiments of the second aspect, in some embodiments, the security protection includes encryption and / or integrity protection.

[0108] In combination with some embodiments of the second aspect, in some embodiments, the first key is stored in the first device in at least one of the following manners:

[0109] The first key is stored in a universal integrated circuit card (UICC);

[0110] The first key is stored in a non-volatile memory of the first device.

[0111] In a third aspect, the embodiments of the present disclosure provide a communication method, executed by a third network element, the method comprising:

[0112] receiving a fifth request sent by a first network element, the fifth request being used to obtain device data, the device data being used to obtain a second key, the second key being used for security protection of a second request received by the first network element and / or security processing of a first message received by the first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, the first key being stored in the first device;

[0113] sending the device data to the first network element.

[0114] In some embodiments of the third aspect, the device data comprises at least one of the following:

[0115] the fifth request is a third request, and the device data comprises data corresponding to the first device or data corresponding to a group of devices;

[0116] the fifth request is a fourth request, and the device data comprises data corresponding to the first device.

[0117] In the above embodiments, the third network element can send different device data to the first network element according to different requests.

[0118] In some embodiments of the third aspect, the method further comprises:

[0119] receiving a third message sent by a second network element, the third message being used to instruct the third network element to perform data processing;

[0120] performing data processing according to the third message, the data processing comprising at least one of the following: creating device data, updating device data, and deleting device data.

[0121] In the above embodiments, the third network element can perform different data processing on the device data.

[0122] In some embodiments of the third aspect, the security protection comprises encryption and / or integrity protection.

[0123] In some embodiments of the third aspect, the first key being stored in the first device comprises at least one of the following:

[0124] The first key is stored in a universal integrated circuit card (UICC).

[0125] The first key is stored in a non-volatile memory of the first device.

[0126] In a fourth aspect, embodiments of the present disclosure provide a communication method, performed by a second network element, the method comprising:

[0127] sending, to a first network element, a second request, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation.

[0128] In some embodiments of the fourth aspect, the method further comprises:

[0129] receiving a second message sent by the first network element, the second message being a message obtained by performing security processing on a first message, the first message being a response message sent by the first device according to the first request, the first message being security-protected by a first key, and the first key being stored in the first device.

[0130] In the above embodiments, the second network element can manage device data stored in the third network element.

[0131] In some embodiments of the fourth aspect, the security protection comprises encryption and / or integrity protection.

[0132] In some embodiments of the fourth aspect, the first key being stored in the first device comprises at least one of the following:

[0133] The first key is stored in a universal integrated circuit card (UICC).

[0134] The first key is stored in a non-volatile memory of the first device.

[0135] In some embodiments of the fourth aspect, the method further comprises:

[0136] sending, to a third network element, a third message, the third message being used to instruct the third network element to perform data processing, the data processing comprising at least one of the following: creating device data, updating device data, and deleting device data.

[0137] In a fifth aspect, embodiments of the present disclosure provide a first device, which can comprise at least one of a transceiver module and a processing module; wherein the first device can be configured to perform the optional implementation manners of the first aspect.

[0138] In a sixth aspect, an embodiment of the present disclosure provides a first network element, which can include at least one of a transceiver module, a processing module; wherein the first network element can be configured to perform the optional implementation manners of the second aspect.

[0139] In a seventh aspect, an embodiment of the present disclosure provides a third network element, which can include at least one of a transceiver module, a processing module; wherein the third network element can be configured to perform the optional implementation manners of the third aspect.

[0140] In an eighth aspect, an embodiment of the present disclosure provides a second network element, which can include at least one of a transceiver module, a processing module; wherein the second network element can be configured to perform the optional implementation manners of the fourth aspect.

[0141] In a ninth aspect, an embodiment of the present disclosure provides a first device, which can include one or more processors; wherein the first device can be configured to perform the optional implementation manners of the first aspect.

[0142] In a tenth aspect, an embodiment of the present disclosure provides a first network element, which can include one or more processors; wherein the first network element can be configured to perform the optional implementation manners of the second aspect.

[0143] In an eleventh aspect, an embodiment of the present disclosure provides a third network element, which can include one or more processors; wherein the third network element can be configured to perform the optional implementation manners of the third aspect.

[0144] In a twelfth aspect, an embodiment of the present disclosure provides a second network element, which can include one or more processors; wherein the second network element can be configured to perform the optional implementation manners of the fourth aspect.

[0145] In a thirteenth aspect, an embodiment of the present disclosure provides a core network device, which can include one or more processors; wherein the core network device can be configured to perform the optional implementation manners of the second aspect or the third aspect or the fourth aspect.

[0146] In a fourteenth aspect, an embodiment of the present disclosure provides a communication system, which can include a first device and a core network device; wherein the first device is configured to perform the method described in the optional implementation manners of the first aspect, and the core network device is configured to perform the method described in the optional implementation manners of the second aspect or the third aspect or the fourth aspect.

[0147] In a fifteenth aspect, the embodiments of the present disclosure provide a storage medium, which stores instructions, when the instructions are executed on a communication device, cause the communication device to perform the method described in the optional implementation manner of the first aspect or the second aspect or the third aspect or the fourth aspect.

[0148] In a sixteenth aspect, the embodiments of the present disclosure provide a program product, which, when executed by a communication device, causes the communication device to perform the method described in the optional implementation manner of the first aspect or the second aspect or the third aspect or the fourth aspect.

[0149] In a seventeenth aspect, the embodiments of the present disclosure provide a computer program, when executed on a computer, causes the computer to perform the method described in the optional implementation manner of the first aspect or the second aspect or the third aspect or the fourth aspect.

[0150] In an eighteenth aspect, the embodiments of the present disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the method described in the optional implementation manner of the first aspect or the second aspect or the third aspect or the fourth aspect.

[0151] It can be understood that the first device, the first network element, the second network element, the third network element, the core network device, the communication device, the communication system, the storage medium, the program product, the computer program, the chip or the chip system can be used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved are referred to the beneficial effects in the corresponding method, which will not be described here.

[0152] The embodiments of the present disclosure propose a communication method, device and storage medium. In some embodiments, the terms of information transmission method, information processing method and communication method can be replaced with each other; the terms of information transmission device, information processing device, communication device and communication equipment can be replaced with each other; the terms of information transmission system and communication system can be replaced with each other.

[0153] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or parts or all of the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.

[0154] In the embodiments of the present disclosure, the terms and / or descriptions among the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0155] The terms used in the embodiments of the present disclosure are only for the purpose of describing particular embodiments and are not used as limitations of the present disclosure.

[0156] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "one kind", "the", "the above", "the", "the above", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.

[0157] In some embodiments, "plurality" can refer to two or more.

[0158] In some embodiments, the terms "at least one of", "one or more of", "a plurality of", "multiple" and the like can be replaced with each other.

[0159] In some embodiments, the writing manner of "at least one of A, B", "A and / or B", "A in one case and B in another case", "A in response to one case and B in response to another case" and the like can include the following technical solutions according to the case: A is executed in some embodiments (A is executed regardless of B); B is executed in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected to be executed); A and B are executed in some embodiments (A and B are executed). When there are more branches of A, B, C and the like, it is similar to the above.

[0160] In some embodiments, the writing manner of "A or B" and the like can include the following technical solutions according to the case: A is executed in some embodiments (A is executed regardless of B); B is executed in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected to be executed). When there are more branches of A, B, C and the like, it is similar to the above.

[0161] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" modified thereby are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different. For example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.

[0162] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0163] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0164] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0165] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0166] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0167] In some embodiments, the terms "Access Network Device (AN Device)", "Radio Access Network Device (RAN Device)", "Base Station (BS)", "Radio Base Station", "Fixed Station", "Node", "Access Point", "Transmission Point (TP)", "Reception Point (RP)", "Transmission / Reception Point (TRP)", "Panel", "Antenna Panel", "Antenna Array", "Cell", "Macro Cell", "Small Cell", "Femto Cell", "Pico Cell", "Sector", "Cell Group", "Serving Cell", "Carrier", "Component Carrier", "Bandwidth Part (BWP)" and the like can be replaced with each other.

[0168] In some embodiments, the terms "terminal," "terminal device," "user equipment" (UE), "user terminal," "mobile station" (MS), "mobile terminal" (MT), subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, and the like can be used interchangeably.

[0169] In some embodiments, an access network device, a core network device, or a network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between an access network device, a core network device, or a network device and a terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), or the like). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, an uplink channel, a downlink channel, and the like can be replaced with a side channel or a direct connection channel, and an uplink, a downlink, and the like can be replaced with a side link or a direct connection link.

[0170] In some embodiments, a terminal can be replaced with an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.

[0171] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.

[0172] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0173] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0174] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1A, the communication system 100 can include a first device 101, a core network device 102.

[0175] In some embodiments, the first device 101 can be an ambient Internet of Things device, or any other Internet of Things device.

[0176] In some embodiments, the core network device 102 can be one device including a first network element 1021, a second network element 1022, a third network element 1023, a network exposure function (NEF), etc., or can be multiple devices or device groups including all or part of the first network element 1021, the second network element 1022, the third network element 1023, the NEF, etc. respectively. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a 6G core network (6GCN), a next generation core (NGC), etc.

[0177] In some embodiments, the terms “network element”, “function”, “unit”, “entity”, “device”, “apparatus”, “element”, “node”, etc. can be replaced with each other.

[0178] In some embodiments, the first network element 1021 is a network element with the function of managing ambient Internet of Things services, for example, an ambient Internet of Things function (AIoTF), or a network element with the function of managing access and mobility, for example, an access and mobility management function (AMF), the name is not limited to this, and it can also be other network elements that implement similar functions.

[0179] In some embodiments, the second network element 1022 is a network element capable of triggering an Internet of Things service, for example, is an Application Function (AF), a Network Function (NF), the name is not limited thereto, and it can also be other network elements that implement similar functions.

[0180] In some embodiments, the third network element 1023 is a network element with a data storage function, for example, is a Unified Data Management (UDM), a Unified Data Repository (UDR), the name is not limited thereto, and it can also be other network elements that implement similar functions.

[0181] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed in the embodiments of the present disclosure are also applicable to similar technical problems.

[0182] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subject, but are not limited thereto. The subjects shown in FIG. 1A are examples, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than FIG. 1A. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is an example, each subject can not be connected or can be connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0183] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).

[0184] In some embodiments of the present disclosure, an environmental energy-driven IoT device is an IoT device that either has no battery or has limited energy storage capability (i.e., uses a capacitor), and energy is provided by collecting radio waves, light, motion, heat, or by any other available power source. Applications of environmental IoT include making supply chains more efficient and sustainable, preventing counterfeiting, and providing the required data for advanced transportation and smart cities.

[0185] According to the study of TR 38.848 [1], the topology connection of environmental IoT networks and devices can be divided into two categories: topology structure 1 and topology structure 2. FIG. IB is a schematic diagram illustrating a topology structure according to an embodiment of the present disclosure. As shown in FIG. IB, in topology structure 1, the environmental IoT device directly communicates with the base station in both directions. The communication between the base station and the environmental IoT device includes environmental IoT data and / or signaling. This topology structure includes the case that the base station transmitting signals to the environmental IoT device can be different from the base station receiving signals from the environmental IoT device.

[0186] FIG. 1C is a schematic diagram illustrating a topology structure according to an embodiment of the present disclosure. As shown in FIG. 1C, in topology structure 2, the environmental IoT device communicates with an intermediate node located between the device and the base station in both directions. In this topology structure, the intermediate node can be a repeater with environmental IoT function, an Integrated Access and Backhaul (IAB) node, a UE, a repeater, etc. The intermediate node transmits information between the base station and the environmental IoT device.

[0187] In some embodiments, based on the above topology structure, the 5GC / application server can perform inventory services or send commands (e.g., read, write) to the environmental IoT device, and the environmental IoT device can report sensing data to the 5GC / application server. From a security perspective, all transmitted information should be protected by security. Otherwise, an attacker can intercept or tamper with this information, causing interruption or misleading the decision-making process.

[0188] However, due to the limited capabilities of environmental IoT devices, the existing security mechanisms defined for UEs cannot be applied. For example, for devices deployed by third parties, the environmental IoT device cannot be identified by the 5G core network, and the root key cannot be shared between the device and the 5G core network to establish secure communication. For devices deployed by operators, the environmental IoT device does not have the resources to support mutual authentication and secure communication by reusing existing mechanisms.

[0189] Therefore, how to ensure the confidentiality, integrity and / or anti-replay of information between the core network function and the non-Universal Integrated Circuit Card (UICC) device for the inventory / command procedure controlled by the core network becomes a technical problem to be solved urgently.

[0190] In some embodiments, it is assumed that the corresponding subscription information of the Internet of Things device is stored in the UDM. However, for the non-UICC device, the corresponding subscription information cannot be stored and managed by the UDM.

[0191] In some embodiments, it is assumed that the core network can authenticate the environmental Internet of Things device in the inventory process and derive a session key to protect the subsequent command process. However, due to the limited resources of the environmental Internet of Things device, the multi-level key hierarchy increases the energy consumption. In addition, the frequently performed authentication process wastes the energy and signaling resources of the device.

[0192] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. The method can be performed by the communication system described above. As shown in FIG. 2A, the method can include:

[0193] In step S2101, the second network element sends a second request to the first network element.

[0194] In some embodiments, the first network element can receive the second request. For example, the first network element can receive the second request sent by the second network element. For another example, the first network element can also receive the second request sent by other entities.

[0195] In some embodiments, the second network element can include at least one of the following: AF, NF.

[0196] In some embodiments, the first network element can include at least one of the following: AIoTF, AMF.

[0197] In some embodiments, the second request can be used to request the first network element to send a first request to the first device.

[0198] In some embodiments, the second request can include at least one of the following: device identifier, service identifier, group identifier, area information, inventory request, command request.

[0199] For example, the second request can include the device identifier, the area information and the inventory request; for another example, the second request can include the device identifier and the inventory request; for yet another example, the second request can include the device identifier, the area information and the command request; for yet another example, the second request can include the device identifier and the command request.

[0200] In some embodiments, the device identity can be an identity of an Ambient Internet of Things (AIoT) device.

[0201] In some embodiments, the service identity can be used to indicate a service requested by the second network element, and different service identities can correspond to different services.

[0202] In some embodiments, the group identity can be an identity of a group of AIoT devices.

[0203] In some embodiments, the group of AIoT devices can be AIoT devices located in the same PLMN, or AIoT devices deployed by the same third party.

[0204] In some embodiments, the area information can be used to indicate an area for which the second network element requests to provide a service.

[0205] In some embodiments, the second request can be used to inventory the first device, or can be used to issue a command to the first device, such as reading data in the first device or writing data into the first device.

[0206] In some embodiments, the device identity can also be referred to as a “device ID”, and the service identity can also be referred to as a “service ID”.

[0207] In some embodiments, the name of the second request is not limited, and can be, for example, “AIoT service request”, “AIoT service indication information”, “information reporting indication”, etc.

[0208] In step S2102, the first network element sends a third request to the UDR according to the second request.

[0209] In some embodiments, the UDR can receive the third request. For example, the UDR can receive the third request sent by the first network element. For another example, the UDR can also receive the third request sent by another entity.

[0210] In some embodiments, the third request can be sent by invoking Nudr_DM_query.

[0211] In some embodiments, after the first network element receives the second request sent by the second network element, the first network element can send the third request to the third network element according to the second request.

[0212] For example, if the second request includes a device identity, the first network element can send the third request to the third network element according to the device identity. For another example, if the second request includes a group identity, the first network element can send the third request to the third network element according to the group identity. For yet another example, if the second request includes a service identity, the first network element can send the third request to the third network element according to the service identity.

[0213] In some embodiments, if the second request comprises area information, the first network element can determine a PLMN corresponding to the area information.

[0214] It should be understood that after the first network element determines the PLMN corresponding to the area information, the first network element can map the area information to the PLMN or to a PLMN ID. According to the mapped PLMN ID, the first network element can send a third request to the UDR located in the PLMN network to obtain device data.

[0215] In some embodiments, the UDR can also be other network elements with data storage functions.

[0216] Step S2103: The UDR sends device data to the first network element.

[0217] In some embodiments, the first network element can receive device data. For example, the first network element can receive device data sent by the UDR. For another example, the first network element can also receive device data sent by other entities.

[0218] In some embodiments, the second network element can store device data of the AIoT device as part of application data in the UDR. For another example, the second network element can also store device data of the AIoT device as part of application data in other network elements.

[0219] In some embodiments, the structure of the device data of the AIoT device stored in the UDR is shown in any one of Tables 1-3.

[0220] Table 1

[0221] Table 2

[0222] Table 3

[0223] In some embodiments, the second network element can determine a target UDR according to the location of the deployed AIoT device, and can determine the first network element according to the location of the deployed AIoT device.

[0224] In some embodiments, the UDR and the first network element belong to the same PLMN.

[0225] In some embodiments, the device data can comprise data corresponding to a first device or data corresponding to a group of devices.

[0226] In some embodiments, the UDR can send the device data to the first network element according to the third request.

[0227] For example, if the third request includes the device identifier of the first device, the device data can include data corresponding to the first device. For another example, if the third request includes the group identifier, the device data can include data corresponding to a group of devices.

[0228] In some embodiments, the device data can include a root key and / or a derived key.

[0229] For example, the UDR can obtain the derived key by running a hash function or a KDF, and send the derived key to the first network element. For example, the UDR can input the device identifier and the root key into the KDF to obtain the derived key.

[0230] It should be noted that for a group of AIoT devices, the UDR can obtain a derived key corresponding to each AIoT device.

[0231] In step S2104, the first network element obtains a second key based on the device data.

[0232] In some embodiments, the second key can include a root key and / or a derived key.

[0233] In some embodiments, if the device data includes a root key and / or a derived key, the first network element can obtain the second key from the device data.

[0234] In some embodiments, if the device data includes data of a group of devices, the first network element can obtain a derived key corresponding to each device.

[0235] In some embodiments, if the device data includes a root key and does not include a derived key, the first network element can obtain a derived key according to the root key and the device identifier.

[0236] In some embodiments, the first network element can receive the root key of the first device or the group to which the first device belongs sent by the UDR, and determine the derived key according to the root key.

[0237] For example, the first network element can receive the root key of the AIoT device or the group to which the AIoT device belongs sent by the UDR. The first network element obtains the derived key by running a hash function or a KDF. For example, the first network element can input the device identifier and the root key into the KDF to obtain the derived key.

[0238] In step S2105, the first network element performs security protection on the second request by using the second key to obtain a first request.

[0239] In some embodiments, the first request can be the second request after security protection.

[0240] In some embodiments, the first request can be used to request the first device to perform a first operation.

[0241] For example, if the first request is an inventory request, the first operation can be sending a device identification of the first device; if the first request is a command request, the first operation can be an operation performed according to the command request, for example, reading data or writing data.

[0242] In some embodiments, the first network element security protects the second request includes:

[0243] The second key is used to security protect part of information or all information in the second request, and the second request includes at least one of the following: device identification, first information.

[0244] In some embodiments, if the second request includes a device identification, the device identification in the second request can be security protected by the second key.

[0245] In some embodiments, if the second request includes first information, the first information in the second request can be security protected by the second key.

[0246] In some embodiments, the entire second request can be security protected by the second key.

[0247] In some embodiments, security protection can include encryption and / or integrity protection.

[0248] In some embodiments, if the second request includes an inventory request, and the inventory request includes a device identification, the first network element can encrypt and / or integrity protect the device identification in the inventory request by the second key to obtain the first request.

[0249] In some embodiments, if the second request includes a command request, the first network element can encrypt and / or integrity protect first information contained in the command request by the second key to obtain the first request.

[0250] In some embodiments, the first network element can encrypt and / or integrity protect the entire second request by the second key to obtain the first request.

[0251] In some embodiments, if the second request includes an inventory request, and the inventory request does not include a device identification, the first network element can not encrypt and / or integrity protect the inventory request.

[0252] It should be noted that if the second request comprises the inventory request and the inventory request is not security protected, the first network element can send the second request to the first device, i.e., send the second request as the first request directly to the first device.

[0253] At step S2106, the first network element sends the first request to the first device.

[0254] In some embodiments, the first device can receive the first request. For example, the first device can receive the first request sent by the first network element. For another example, the first device can also receive the first request sent by other entity.

[0255] In some embodiments, the first network element can send the first request to the reader, and the reader can send the first request to the first device after receiving the first request.

[0256] In some embodiments, the reader can be a UE or a gNB.

[0257] At step S2107, the first device verifies and / or security processes the first request by using the first key.

[0258] In some embodiments, the first key can be stored in the first device.

[0259] For example, the first key can be stored in the non-volatile memory in the device, and can also be stored in the register in the device.

[0260] In some embodiments, the first key can comprise a root key and / or a derived key.

[0261] For example, the first key is a root key, and the key can be pre-configured on the AIoT device.

[0262] For example, the first key is a derived key, and once the derived key is determined, the AIoT device stores the derived key in the memory.

[0263] In some embodiments, the first key stored in the first device can comprise at least one of the following:

[0264] The first key is stored in the UICC;

[0265] The first key is stored in the non-volatile memory of the first device.

[0266] In some embodiments, if the first device is a UICC device, the first key is stored in the UICC.

[0267] In some embodiments, if the first device is a non-UICC device, the first key is stored in the non-volatile memory of the first device.

[0268] In some embodiments, the AIoT device can be deployed and owned by a third party.

[0269] In some embodiments, the third party can pre-configure a root key in the AIoT device for establishing secure communication of the AIoT service.

[0270] In some embodiments, for the AIoT device deployed and owned by the third party, the subscription information corresponding to the device is not stored in the core network network element (e.g., UDM).

[0271] In some embodiments, after the first device receives the first request sent by the first network element, if the first request is a request for security protection, the first device can verify the integrity of the first request by using the first key. If the first request passes the integrity verification, the first device can perform security processing by using the first key.

[0272] In some embodiments, the security processing can be decryption processing.

[0273] In some embodiments, after the first device receives the first request sent by the first network element, the first device can directly perform decryption processing on the first request.

[0274] In some embodiments, after the first device obtains the decrypted first request, the first device can determine a first message according to the first request, the first message being a response message corresponding to the first request.

[0275] In some embodiments, the first request can be an inventory request for the device, or a command request for the device.

[0276] It should be noted that if the first request is not protected by security, the first device can not perform verification and / or security processing on the first request, i.e., step S2107 can be omitted.

[0277] It should also be noted that the specific methods of integrity verification and security processing can refer to existing protocols, which will not be described here.

[0278] Step S2108, the first device sends the first message to the first network element.

[0279] In some embodiments, the first network element can receive the first message. For example, the first network element can receive the first message sent by the first device. For another example, the first network element can also receive the first message sent by other entities.

[0280] In some embodiments, the first message can be protected by security by using the first key.

[0281] In some embodiments, the first message is protected by security by using the first key includes:

[0282] Part or all of the first message is security protected by the first key, the first message comprising at least one of: device identity, first data.

[0283] In some embodiments, if the first message comprises device identity, the device identity in the first message is security protected by the first key.

[0284] In some embodiments, if the first message comprises first data, the first data in the first message is security protected by the first key.

[0285] In some embodiments, the whole first message can be security protected by the first key.

[0286] In some embodiments, the first request comprises an inventory request, and the first message can comprise device identity of the first device.

[0287] In some embodiments, the first request comprises a command request, and the first message can comprise the first data, which can be response data corresponding to the command request.

[0288] In some embodiments, security protection can comprise encryption and / or integrity protection.

[0289] In some embodiments, the first device can send the first message by a reader, and the reader can send the first message to the first network element after receiving the first message.

[0290] Step S2109, the first network element verifies the first message by the second key.

[0291] In some embodiments, after receiving the first message, the first network element can perform integrity verification on the first message by the second key.

[0292] It should be noted that the specific method of integrity verification can refer to existing protocols, which will not be described here.

[0293] Step S2110, the first network element determines that the first message passes verification, and performs security processing on the first message to obtain a second message.

[0294] In some embodiments, security processing can be decryption processing.

[0295] In some embodiments, if the first message passes integrity verification, the first network element can perform decryption processing on the first message by the second key to obtain the second message.

[0296] It should be noted that the specific method of decryption processing can refer to the existing protocol, which will not be repeated here.

[0297] Step S2111, the first network element sends a second message to the second network element.

[0298] In some embodiments, the second network element can receive the second message. For example, the second network element can receive the second message sent by the first network element. For another example, the second network element can also receive the second message sent by other entities.

[0299] Step S2112, the second network element sends a third message to the UDR.

[0300] In some embodiments, the third message can be used to instruct the UDR to perform data processing.

[0301] In some embodiments, the data processing can include at least one of the following: creating device data, updating device data, and deleting device data.

[0302] In some embodiments, the third message can contain device identification, device data, service identification, supported algorithms, and other data.

[0303] In some embodiments, the second network element determines the PLMN ID according to the location where the AIoT device is deployed, and then sends the third message to the UDR located in the PLMN.

[0304] Step S2113, the UDR performs data processing according to the third message.

[0305] In some embodiments, the UDR can create device data according to the third message.

[0306] In some embodiments, the UDR can update device data according to the third message.

[0307] In some embodiments, the UDR can delete device data according to the third message.

[0308] With the above method, the first network element can protect the second request by the second key obtained from the UDR, and the first device can protect the first message by the stored first key, so that the security of the information transmitted between the first device and the first network element is higher, thereby improving the system performance.

[0309] The method related to the embodiments of the present disclosure can include at least one of the steps S2101-S2113. For example, the step S2101 can be implemented as an independent embodiment, the step S2102 can be implemented as an independent embodiment, the step S2104 can be implemented as an independent embodiment, the step S2105 can be implemented as an independent embodiment, the step S2106 can be implemented as an independent embodiment, the step S2107 can be implemented as an independent embodiment, the step S2108 can be implemented as an independent embodiment, the step S2109 can be implemented as an independent embodiment, the step S2110 can be implemented as an independent embodiment, the step S2111 can be implemented as an independent embodiment, the step S2112 can be implemented as an independent embodiment, the step S2102+the step S2103 can be implemented as an independent embodiment, the step S2104+the step S2105 can be implemented as an independent embodiment, the step S2105+the step S2106 can be implemented as an independent embodiment, the step S2112+the step S2113 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0310] In some embodiments, any two steps among the steps S2101-S2113 can be exchanged in order or executed simultaneously. For example, the step S2112 can be exchanged in order or executed simultaneously with any one of the steps S2101-S2111.

[0311] In some embodiments, the steps S2101-S2113 are optional, and one or more of the steps can be omitted or replaced in different embodiments. For example, the step S2112 and the step S2113 can be omitted.

[0312] In some embodiments, other optional implementations described before or after the description corresponding to FIG. 2A can be referred to.

[0313] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. The method can be performed by the communication system described above. As shown in FIG. 2B, the method can include:

[0314] The step S2201, the second network element sends a second request to the first network element.

[0315] In some embodiments, the first network element can receive the second request. For example, the first network element can receive the second request sent by the second network element. For another example, the first network element can also receive the second request sent by another entity.

[0316] In some embodiments, the second network element can include at least one of the following: an AF, an NF.

[0317] In some embodiments, the first network element can include at least one of the following: an AIoT function (AIoT F), an access and mobility function (AMF).

[0318] In some embodiments, the second request can be used to request the first network element to send the first request to the first device.

[0319] In some embodiments, the second request can include at least one of the following: area information, an inventory request.

[0320] In some embodiments, the area information can be used to indicate an area in which the second network element requests to provide services.

[0321] In some embodiments, the name of the second request is not limited, for example, it can be "AIoT service request", "AIoT service indication information", "information reporting indication", etc.

[0322] In some embodiments, the second request can be used to request the first network element to send the first request to the first device.

[0323] In some embodiments, the second request can be used to request an inventory of devices in an area corresponding to the area information.

[0324] In some embodiments, the first request can be used to request the first device to perform a first operation.

[0325] For example, if the first request is an inventory request, the first operation can be sending a device identifier of the first device.

[0326] Step S2202, the first network element sends a first request to the first device.

[0327] In some embodiments, after the first network element receives the second request sent by the second network element, the first network element sends the first request to the first device according to the second request, that is, the first request sent by the first network element to the first device is not protected by security.

[0328] In some embodiments, the first device can be an AIoT device.

[0329] In some embodiments, the first request can be an inventory request for a device.

[0330] Step S2203, the first device sends a first message to the first network element.

[0331] In some embodiments, the first message can be protected by security through a first key.

[0332] In some embodiments, the first message is protected by security through the first key, including:

[0333] Part or all of the first message is security protected by the first key, and the first message can comprise a device identity.

[0334] In some embodiments, the first request comprises an inventory request, and the first message can comprise a device identity of the first device.

[0335] In some embodiments, the device identity in the first message can be security protected by the first key.

[0336] In some embodiments, the entire first message can be security protected by the first key.

[0337] In some embodiments, the security protection can comprise integrity protection.

[0338] For example, the first device can integrity protect the device identity in the first message by the first key.

[0339] In some embodiments, the first device can integrity protect the entire first message.

[0340] In some embodiments, the first key can be pre-configured in the environment IoT device by an operator. For example, the first key can be stored in the first device.

[0341] For example, the first key is stored in a non-volatile memory in the device, and can also be stored in a register in the device.

[0342] In some embodiments, the first key can comprise a root key and / or a derived key.

[0343] For example, the first key is a root key, and the key can be pre-configured on the AIoT device.

[0344] For example, the first key is a derived key, and once the derived key is determined, the AIoT device stores it in a memory.

[0345] In some embodiments, the first key stored in the first device can comprise at least one of:

[0346] The first key is stored in a UICC;

[0347] The first key is stored in a non-volatile memory of the first device.

[0348] In some embodiments, if the first device is a UICC device, the first key is stored in the UICC.

[0349] In some embodiments, if the first device is a non-UICC device, the first key is stored in a non-volatile memory of the first device.

[0350] In some embodiments, the AIoT device can be deployed and owned by an operator.

[0351] In some embodiments, the operator can pre-configure a root key in the AIoT device for establishing secure communication of the AIoT service.

[0352] In some embodiments, for the AIoT device deployed and owned by the operator, subscription information corresponding to the device can be stored in a core network network element (e.g., UDM).

[0353] Step S2204, the first network element sends a fourth request to the UDM according to the first message.

[0354] In some embodiments, the fourth request can be used to request to obtain device data.

[0355] In some embodiments, after the first network element receives the first message sent by the first device, the fourth request can be sent to the UDM according to the device identifier in the first message.

[0356] In some embodiments, the fourth request can include the device identifier of the first device.

[0357] Step S2205, the UDM sends device data to the first network element.

[0358] In some embodiments, the subscription information stored in the UDM can include the device data.

[0359] In some embodiments, the structure of the device data of the AIoT device stored in the UDM is shown in Table 4.

[0360] Table 4

[0361] In some embodiments, the device data can include data corresponding to the first device.

[0362] In some embodiments, after the UDM receives the fourth request sent by the first network element, the data corresponding to the first device can be sent to the first network element according to the device identifier in the fourth request.

[0363] In some embodiments, the device data can include a second key.

[0364] In some embodiments, the second key can include a root key and / or a derived key, and the derived key can be a derived key corresponding to the first device.

[0365] For example, the UDM can obtain the derived key by running a hash function or a KDF, and send the derived key to the first network element. For example, the UDM can input the device identity of the first device and the root key into the KDF to obtain the derived key corresponding to the first device.

[0366] In step S2206, the first network element obtains the second key based on the device data.

[0367] In some embodiments, the second key can include a root key and / or a derived key.

[0368] In some embodiments, if the device data includes a root key and / or a derived key, the first network element can obtain the second key from the device data.

[0369] In some embodiments, if the device data includes a root key and does not include a derived key, the first network element can obtain the derived key corresponding to the first device according to the root key and the device identity of the first device.

[0370] In some embodiments, the first network element can receive the root key sent by the UDM and determine the derived key according to the root key.

[0371] For example, the first network element can receive the root key sent by the UDM. The first network element obtains the derived key by running a hash function or a KDF. For example, the first network element can input the device identity of the first device and the root key into the KDF to obtain the derived key.

[0372] In step S2207, the first network element verifies the first message by using the second key.

[0373] The optional implementation of step S2207 can refer to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be described here.

[0374] In step S2208, the first network element determines that the first message is verified, performs security processing on the first message to obtain a second message.

[0375] The optional implementation of step S2208 can refer to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be described here.

[0376] In step S2209, the first network element sends the second message to the second network element.

[0377] The optional implementation of step S2209 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be described here.

[0378] By using the method, the first device can perform security protection on the first message by using the stored first key, so that the security of the information transmitted between the first device and the first network element is higher, thereby improving the system performance.

[0379] The method related to the embodiments of the present disclosure can include at least one of the steps S2201-S2209. For example, the step S2201 can be implemented as an independent embodiment, the step S2202 can be implemented as an independent embodiment, the step S2203 can be implemented as an independent embodiment, the step S2204 can be implemented as an independent embodiment, the step S2205 can be implemented as an independent embodiment, the step S2206 can be implemented as an independent embodiment, the step S2207 can be implemented as an independent embodiment, the step S2208 can be implemented as an independent embodiment, the step S2209 can be implemented as an independent embodiment, the step S2201+the step S2202 can be implemented as an independent embodiment, the step S2202+the step S2203 can be implemented as an independent embodiment, the step S2204+the step S2205 can be implemented as an independent embodiment, the step S2207+the step S2208 can be implemented as an independent embodiment, but not limited thereto.

[0380] In some embodiments, the order between any two of the steps S2201-S2209 can be exchanged or executed simultaneously.

[0381] In some embodiments, the steps S2201-S2209 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0382] FIG. 2C is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. The method can be performed by the communication system described above. As shown in FIG. 2C, the method can include:

[0383] The step S2301, the second network element sends a second request to the first network element.

[0384] In some embodiments, the first network element can receive the second request. For example, the first network element can receive the second request sent by the second network element. For another example, the first network element can also receive the second request sent by another entity.

[0385] In some embodiments, the second network element can include at least one of the following: an AF, an NF.

[0386] In some embodiments, the first network element can include at least one of the following: an AIoT F, an AMF.

[0387] In some embodiments, the second request can be used to request the first network element to send a first request to the first device.

[0388] In some embodiments, the second request can comprise at least one of the following: device identity, group identity, inventory request, command request.

[0389] For example, the second request can comprise device identity and inventory request; for another example, the second request can comprise device identity and command request; for another example, the second request can comprise group identity and inventory request; for another example, the second request can comprise group identity and command request.

[0390] In some embodiments, the device identity can be the identity of an AIoT device.

[0391] In some embodiments, the group identity can be the identity of a group of AIoT devices.

[0392] In some embodiments, the group of AIoT devices can be AIoT devices located in the same PLMN, or AIoT devices deployed by the same third party.

[0393] In some embodiments, the second request can be used to inventory the first device, or can be used to issue a command to the first device, such as reading data in the first device or writing data into the first device.

[0394] In some embodiments, the device identity can also be referred to as "device ID", and the group identity can also be referred to as "group ID".

[0395] In some embodiments, the name of the second request is not limited, for example, it can be "AIoT service request", "AIoT service indication information", "information reporting indication", etc.

[0396] Step S2302, the first network element sends a fourth request to the UDM according to the second request.

[0397] In some embodiments, the fourth request can be used to request to obtain device data.

[0398] In some embodiments, after the first network element receives the first message sent by the first device, the fourth request can be sent to the UDM according to the device identity and / or group identity in the first message.

[0399] In some embodiments, the fourth request can comprise the device identity of the first device or the group identity of a group of devices.

[0400] For example, if the fourth request comprises the device identity, the first network element can send the fourth request to the third network element according to the device identity. For another example, if the fourth request comprises the group identity, the first network element can send the fourth request to the third network element according to the group identity.

[0401] In some embodiments, the UDM can also be other network elements with data storage functions.

[0402] At step S2303, the UDM sends device data to the first network element.

[0403] In some embodiments, the device data can include data corresponding to the first device or data corresponding to a group of devices.

[0404] In some embodiments, the UDM can send the device data to the first network element according to the fourth request.

[0405] For example, if the fourth request includes the device identifier of the first device, the device data can include data corresponding to the first device. For another example, if the fourth request includes the group identifier, the device data can include data corresponding to a group of devices.

[0406] In some embodiments, the device data can include the root key and / or the derived key.

[0407] For example, the UDM can input the device identifier and the root key into the KDF to obtain the derived key, and send the derived key to the first network element.

[0408] It should be noted that for a group of AIoT devices, the UDM can obtain the derived key corresponding to each AIoT device.

[0409] At step S2304, the first network element obtains the second key based on the device data.

[0410] In some embodiments, the second key can include the root key and / or the derived key.

[0411] In some embodiments, if the device data includes the root key and / or the derived key, the first network element can obtain the second key from the device data.

[0412] In some embodiments, if the device data includes data of a group of devices, the first network element can obtain the derived key corresponding to each device.

[0413] In some embodiments, if the device data includes the root key and does not include the derived key, the first network element can obtain the derived key according to the root key and the device identifier.

[0414] In some embodiments, the first network element can receive the root key of the first device or the group to which the first device belongs sent by the UDM, and determine the derived key according to the root key.

[0415] For example, the first network element can receive the root key of the AIoT device or the group to which the AIoT device belongs sent by the UDM. The first network element obtains the derived key by running a hash function or a KDF. For example, the first network element can input the device identifier and the root key into the KDF to obtain the derived key.

[0416] In step S2305, the first network element performs security protection on the second request by using the second key to obtain the first request.

[0417] The optional implementation of step S2305 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0418] In step S2306, the first network element sends the first request to the first device.

[0419] The optional implementation of step S2306 can refer to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0420] In step S2307, the first device verifies and / or securely processes the first request by using the first key.

[0421] The optional implementation of step S2307 can refer to the optional implementation of step S2107 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0422] In step S2308, the first device sends the first message to the first network element.

[0423] The optional implementation of step S2308 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0424] In step S2309, the first network element verifies the first message by using the second key.

[0425] The optional implementation of step S2309 can refer to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0426] In step S2310, the first network element determines that the first message is verified, securely processes the first message to obtain the second message.

[0427] The optional implementation of step S2310 can refer to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0428] Step S2311, the first network element sends a second message to the second network element.

[0429] The optional implementation of step S2311 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0430] By using the above method, the first network element can protect the second request by the second key obtained from the UDM, and the first device can protect the first message by the stored first key, so that the security of the information transmitted between the first device and the first network element is higher, thereby improving the system performance.

[0431] The method involved in the embodiments of the present disclosure can include at least one of the above steps S2301-S2311. For example, step S2301 can be implemented as an independent embodiment, step S2302 can be implemented as an independent embodiment, step S2304 can be implemented as an independent embodiment, step S2305 can be implemented as an independent embodiment, step S2306 can be implemented as an independent embodiment, step S2307 can be implemented as an independent embodiment, step S2308 can be implemented as an independent embodiment, step S2309 can be implemented as an independent embodiment, step S2310 can be implemented as an independent embodiment, step S2311 can be implemented as an independent embodiment, step S2302+step S2303 can be implemented as an independent embodiment, step S2304+step S2305 can be implemented as an independent embodiment, step S2305+step S2306 can be implemented as an independent embodiment, but not limited thereto.

[0432] In some embodiments, the order of any two steps among steps S2301-S2311 can be exchanged or executed simultaneously.

[0433] In some embodiments, steps S2301-S2311 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0434] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", "chip", and the like can be replaced with each other.

[0435] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by processing oneself, implementing autonomously, and the like.

[0436] In some embodiments, the terms "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other.

[0437] In some embodiments, the terms "certain", "preset", "preset", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced with each other, and "certain A", "preset A", "preset A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, A obtained by setting, configuring, or indicating, and A as certain A, certain A, arbitrary A, or first A, but are not limited thereto.

[0438] FIG. 3A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the present embodiment relates to a communication method, which can be performed by a first device. The method can include:

[0439] Step S3101, receiving a first request.

[0440] The optional implementation of step S3101 can refer to the optional implementation of step S2106 in FIG. 2A, step S2306 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.

[0441] Step S3102, verifying and / or securely processing the first request by the first key.

[0442] The optional implementation of step S3102 can refer to the optional implementation of step S2107 in FIG. 2A, step S2307 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.

[0443] Step S3103, sending the first message.

[0444] The optional implementation of step S3103 can refer to the optional implementation of step S2108 in FIG. 2A, step S2308 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.

[0445] The method related to the embodiments of the present disclosure can include at least one of the above steps S3101 to step S3103. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, step S3103 can be implemented as an independent embodiment, step S3101+step S3102 can be implemented as an independent embodiment, step S3102+step S3103 can be implemented as an independent embodiment, but is not limited thereto.

[0446] In some embodiments, the order between any two of steps S3101 to step S3103 can be exchanged or executed simultaneously.

[0447] In some embodiments, steps S3101 to step S3103 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0448] FIG. 3B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to a communication method, which can be executed by a first device. The method can include:

[0449] Step S3201, receiving a first request.

[0450] The optional implementation of step S3201 can refer to the optional implementation of step S2106 in FIG. 2A, step S2202 in FIG. 2B, step S2306 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which are not described here again.

[0451] Step S3202, sending the first message.

[0452] The optional implementation of step S3202 can refer to the optional implementation of step S2108 in FIG. 2A, step S2203 in FIG. 2B, step S2308 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which are not described here again.

[0453] In some embodiments, the security protection of the first message by the first key comprises:

[0454] Part or all of the first message is security protected by the first key, and the first message comprises at least one of the following: device identity, first data.

[0455] In some embodiments, the method further comprises:

[0456] The first request is verified and / or security processed by the first key.

[0457] In some embodiments, the security protection comprises encryption and / or integrity protection.

[0458] In some embodiments, the first key is stored in the first device by at least one of the following:

[0459] The first key is stored in a UICC;

[0460] The first key is stored in a non-volatile memory of the first device.

[0461] FIG. 4A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4A, the embodiment of the present disclosure relates to a communication method, which can be performed by a first network element. The method can comprise:

[0462] Step S4101, receiving a second request.

[0463] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, which are not described here again.

[0464] Step S4102, sending a third request according to the second request.

[0465] The optional implementation of step S4102 can refer to the optional implementation of step S2102 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, which are not described here again.

[0466] Step S4103, receiving device data.

[0467] The optional implementation of step S4103 can be referred to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0468] Step S4104, obtaining a second key based on the device data.

[0469] The optional implementation of step S4104 can be referred to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0470] Step S4105, performing security protection on the second request by using the second key, to obtain a first request.

[0471] The optional implementation of step S4105 can be referred to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0472] Step S4106, sending the first request.

[0473] The optional implementation of step S4106 can be referred to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0474] Step S4107, receiving a first message.

[0475] The optional implementation of step S4107 can be referred to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0476] Step S4108, verifying the first message by using the second key.

[0477] The optional implementation of step S4108 can be referred to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0478] Step S4109, determining that the first message is verified, performing security processing on the first message, to obtain a second message.

[0479] The optional implementation of step S4109 can be referred to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A. Here, no longer be repeated.

[0480] Step S4110, sending the second message.

[0481] The optional implementation of step S4110 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0482] The method involved in the embodiments of the present disclosure can include at least one of steps S4101-S4110. For example, step S4101 can be implemented as an independent embodiment, step S4102 can be implemented as an independent embodiment, step S4104 can be implemented as an independent embodiment, step S4105 can be implemented as an independent embodiment, step S4106 can be implemented as an independent embodiment, step S4109 can be implemented as an independent embodiment, step S4110 can be implemented as an independent embodiment, step S4102+step S4103 can be implemented as an independent embodiment, step S4104+step S4105 can be implemented as an independent embodiment, step S4105+step S4106 can be implemented as an independent embodiment, but not limited thereto.

[0483] In some embodiments, the order between any two of steps S4101-S4110 can be exchanged or executed simultaneously.

[0484] In some embodiments, steps S4101-S4110 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0485] FIG. 4B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure involve a communication method, which can be executed by a first network element. The method can include:

[0486] Step S4201, receiving a second request.

[0487] The optional implementation of step S4201 can refer to the optional implementation of step S2201 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.

[0488] Step S4202, sending a first request.

[0489] The optional implementation of step S4202 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.

[0490] Step S4203, receiving a first message.

[0491] The optional implementation of step S4203 can be referred to the optional implementation of step S2203 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0492] Step S4204, sending a fourth request according to the first message.

[0493] The optional implementation of step S4204 can be referred to the optional implementation of step S2204 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0494] Step S4205, receiving device data.

[0495] The optional implementation of step S4205 can be referred to the optional implementation of step S2205 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0496] Step S4206, obtaining a second key based on the device data.

[0497] The optional implementation of step S4206 can be referred to the optional implementation of step S2206 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0498] Step S4207, verifying the first message by using the second key.

[0499] The optional implementation of step S4207 can be referred to the optional implementation of step S2207 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0500] Step S4208, determining that the first message is verified, and performing security processing on the first message to obtain a second message.

[0501] The optional implementation of step S4208 can be referred to the optional implementation of step S2208 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0502] Step S4209, sending the second message.

[0503] The optional implementation of step S4209 can be referred to the optional implementation of step S2209 in FIGURE 2B and other associated parts in the embodiments related to FIGURE 2B. Here, it is not described in detail.

[0504] The method related to the embodiments of the present disclosure can include at least one of the steps S4201-S4209. For example, the step S4201 can be implemented as an independent embodiment, the step S4202 can be implemented as an independent embodiment, the step S4203 can be implemented as an independent embodiment, the step S4204 can be implemented as an independent embodiment, the step S4205 can be implemented as an independent embodiment, the step S4206 can be implemented as an independent embodiment, the step S4207 can be implemented as an independent embodiment, the step S4208 can be implemented as an independent embodiment, the step S4209 can be implemented as an independent embodiment, the step S4201+the step S4202 can be implemented as an independent embodiment, the step S4202+the step S4203 can be implemented as an independent embodiment, the step S4204+the step S4205 can be implemented as an independent embodiment, the step S4207+the step S4208 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0505] In some embodiments, the order between any two of the steps S4201-S4209 can be exchanged or performed simultaneously.

[0506] In some embodiments, the steps S4201-S4209 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0507] FIG. 4C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4C, the embodiments of the present disclosure relate to a communication method, which can be performed by a first network element. The method can include:

[0508] Step S4301: receiving a second request.

[0509] The optional implementation of the step S4301 can refer to the optional implementation of the step S2301 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be described here.

[0510] Step S4302: sending a fourth request according to the second request.

[0511] The optional implementation of the step S4302 can refer to the optional implementation of the step S2302 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be described here.

[0512] Step S4303: receiving device data.

[0513] The optional implementation of the step S4303 can refer to the optional implementation of the step S2303 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be described here.

[0514] In step S4304, a second key is obtained based on the device data.

[0515] The optional implementation of step S4304 can refer to the optional implementation of step S2304 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0516] In step S4305, the second request is security-protected by the second key to obtain a first request.

[0517] The optional implementation of step S4305 can refer to the optional implementation of step S2305 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0518] In step S4306, the first request is sent.

[0519] The optional implementation of step S4306 can refer to the optional implementation of step S2306 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0520] In step S4307, the first message is received.

[0521] The optional implementation of step S4307 can refer to the optional implementation of step S2308 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0522] In step S4308, the first message is verified by the second key.

[0523] The optional implementation of step S4308 can refer to the optional implementation of step S2309 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0524] In step S4309, it is determined that the first message is verified, and the first message is security-processed to obtain a second message.

[0525] The optional implementation of step S4309 can refer to the optional implementation of step S2310 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0526] In step S4310, the second message is sent.

[0527] The optional implementation of step S4310 can refer to the optional implementation of step S2311 in FIG. 2C and other associated parts in the embodiments involved in FIG. 2C, which will not be repeated here.

[0528] The method related to the embodiments of the present disclosure can include at least one of the steps S4301-S4310. For example, the step S4301 can be implemented as an independent embodiment, the step S4302 can be implemented as an independent embodiment, the step S4304 can be implemented as an independent embodiment, the step S4305 can be implemented as an independent embodiment, the step S4306 can be implemented as an independent embodiment, the step S4307 can be implemented as an independent embodiment, the step S4308 can be implemented as an independent embodiment, the step S4309 can be implemented as an independent embodiment, the step S4310 can be implemented as an independent embodiment, the step S4302+the step S4303 can be implemented as an independent embodiment, the step S4304+the step S4305 can be implemented as an independent embodiment, the step S4305+the step S4306 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0529] In some embodiments, the order between any two of the steps S4301-S4310 can be exchanged or performed simultaneously.

[0530] In some embodiments, the steps S4301-S4310 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0531] FIG. 4D is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4D, the embodiments of the present disclosure relate to a communication method, which can be performed by a first network element. The method can include:

[0532] Step S4401, receiving a second request.

[0533] Optional implementation of the step S4401 can be referred to optional implementation of the step S2101 in FIG. 2A, the step S2201 in FIG. 2B, the step S2301 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which will not be repeated here.

[0534] Step S4402, sending a first request.

[0535] Optional implementation of the step S4402 can be referred to optional implementation of the step S2106 in FIG. 2A, the step S2202 in FIG. 2B, the step S2306 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which will not be repeated here.

[0536] Step S4403, receiving a first message.

[0537] The optional implementation of step S4403 can refer to the optional implementation of step S2108 in FIG. 2A, step S2203 in FIG. 2B, step S2308 in FIG. 2C, and other associated parts in the embodiments related to FIGS. 2A, 2B, and 2C, which are not described herein again.

[0538] In some embodiments, the second request comprises at least one of the following: a device identifier, a service identifier, a group identifier, area information, an inventory request, a command request.

[0539] In some embodiments, the method further comprises:

[0540] According to the second request, a third request is sent to a third network element, the third request being used to acquire device data, the device data comprising data corresponding to the first device or data corresponding to a group of devices;

[0541] The device data sent by the third network element is received;

[0542] Based on the device data, a second key is acquired;

[0543] The second request is security-protected by the second key, obtaining the first request.

[0544] In some embodiments, the security-protection of the second request by the second key comprises at least one of the following:

[0545] The second request comprises a device identifier, and the device identifier in the second request is security-protected by the second key;

[0546] The second request comprises first information, and the first information in the second request is security-protected by the second key;

[0547] The second request is security-protected by the second key.

[0548] In some embodiments, the method further comprises:

[0549] According to the first message, a fourth request is sent to a third network element, the fourth request being used to acquire device data, the device data comprising data corresponding to the first device;

[0550] The device data sent by the third network element is received;

[0551] Based on the device data, the second key is acquired.

[0552] In some embodiments, the method further comprises:

[0553] verify the first message by the second key;

[0554] determine that the first message is verified, and perform security processing on the first message to obtain a second message.

[0555] In some embodiments, the method further includes:

[0556] sending the second message to the second network element.

[0557] In some embodiments, the second request includes the area information, and the method further includes:

[0558] determining a public land mobile network (PLMN) corresponding to the area information.

[0559] In some embodiments, the security protection includes encryption and / or integrity protection.

[0560] In some embodiments, the storing the first key in the first device includes at least one of:

[0561] the first key is stored in a UICC;

[0562] the first key is stored in a non-volatile memory of the first device.

[0563] FIG. 5A is a flow diagram illustrating a communication method according to embodiments of the present disclosure. As shown in FIG. 5A, embodiments of the present disclosure relate to a communication method, which can be performed by a third network element. The method can include:

[0564] Step S5101, receiving a third request.

[0565] Optional implementation of the step S5101 can refer to optional implementation of the step S2102 in FIG. 2A and other associated parts in the embodiments involved by FIG. 2A, which will not be described here.

[0566] Step S5102, sending device data.

[0567] Optional implementation of the step S5102 can refer to optional implementation of the step S2103 in FIG. 2A and other associated parts in the embodiments involved by FIG. 2A, which will not be described here.

[0568] Step S5103, receiving a third message.

[0569] Optional implementation of the step S5103 can refer to optional implementation of the step S2112 in FIG. 2A and other associated parts in the embodiments involved by FIG. 2A, which will not be described here.

[0570] Step S5104: performing data processing according to the third message.

[0571] The optional implementation of step S5104 can refer to the optional implementation of step S2113 in FIG. 2A, and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0572] The method involved in the embodiments of the present disclosure can include at least one of steps S5101-S5104. For example, step S5101 can be implemented as an independent embodiment, step S5102 can be implemented as an independent embodiment, step S5103 can be implemented as an independent embodiment, step S5104 can be implemented as an independent embodiment, step S5101+step S5102 can be implemented as an independent embodiment, step S5103+step S5104 can be implemented as an independent embodiment, but is not limited thereto.

[0573] In some embodiments, any two steps among steps S5101-S5104 can be exchanged in order or executed simultaneously. For example, step S5103 and step S5101 can be exchanged in order or executed simultaneously.

[0574] In some embodiments, steps S5101-S5104 are optional, and one or more of the steps can be omitted or replaced in different embodiments. For example, step S5103 and step S5104 can be omitted.

[0575] FIG. 5B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5B, the embodiments of the present disclosure involve a communication method, which can be executed by a third network element. The method can include:

[0576] Step S5201: receiving a fourth request.

[0577] The optional implementation of step S5201 can refer to the optional implementation of step S2204 in FIG. 2B, step S2302 in FIG. 2C, and other associated parts in the embodiments involved in FIG. 2B and FIG. 2C, which will not be repeated here.

[0578] Step S5202: sending device data.

[0579] The optional implementation of step S5202 can refer to the optional implementation of step S2205 in FIG. 2B, step S2303 in FIG. 2C, and other associated parts in the embodiments involved in FIG. 2B and FIG. 2C, which will not be repeated here.

[0580] FIG. 5C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5C, the embodiments of the present disclosure relate to a communication method, which can be performed by a third network element. The method can include:

[0581] Step S5301, receiving a fifth request.

[0582] Optional implementation of the step S5301 can refer to the optional implementation of the step S2102 in FIG. 2A, the step S2204 in FIG. 2B, the step S2302 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which will not be repeated here.

[0583] In some embodiments, the fifth request is used to obtain device data.

[0584] In some embodiments, the device data can include at least one of the following:

[0585] The fifth request is the third request, and the device data includes data corresponding to the first device or data corresponding to a group of devices.

[0586] The fifth request is the fourth request, and the device data includes data corresponding to the first device.

[0587] Step S5302, sending the device data.

[0588] Optional implementation of the step S5301 can refer to the optional implementation of the step S2103 in FIG. 2A, the step S2205 in FIG. 2B, the step S2303 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2B and FIG. 2C, which will not be repeated here.

[0589] In some embodiments, if the fifth request received by the third network element is the third request, the third network element can send data corresponding to the first device or data corresponding to a group of devices according to the third request.

[0590] In some embodiments, if the fifth request received by the third network element is the fourth request, the third network element can send data corresponding to the first device according to the fourth request.

[0591] In some embodiments, the method further includes:

[0592] receiving a third message sent by the second network element, the third message being used to instruct the third network element to perform data processing;

[0593] performing data processing according to the third message, the data processing including at least one of the following: creating device data, updating device data, and deleting device data.

[0594] In some embodiments, the security protection comprises encryption and / or integrity protection.

[0595] In some embodiments, storing the first key in the first device comprises at least one of:

[0596] the first key is stored in a UICC;

[0597] the first key is stored in a non-volatile memory of the first device.

[0598] FIG. 6A is a flow diagram illustrating a communication method according to some embodiments of the present disclosure. As shown in FIG. 6A, the embodiments of the present disclosure relate to a communication method, which can be performed by a second network element. The method can comprise:

[0599] Step S6101, sending a second request.

[0600] Optional implementation of step S6101 can refer to optional implementation of step S2101 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be described here.

[0601] Step S6102, receiving a second message.

[0602] Optional implementation of step S6102 can refer to optional implementation of step S2111 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be described here.

[0603] Step S6103, sending a third message.

[0604] Optional implementation of step S6103 can refer to optional implementation of step S2112 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be described here.

[0605] The method related to the embodiments of the present disclosure can comprise at least one of steps S6101-S6103 described above. For example, step S6101 can be implemented as an independent embodiment, step S6102 can be implemented as an independent embodiment, step S6103 can be implemented as an independent embodiment, step S6101+step S6102 can be implemented as an independent embodiment, but not limited thereto.

[0606] In some embodiments, the order of any two of steps S6101-S6103 can be exchanged or executed simultaneously. For example, step S6103 and step S6101 can be exchanged or executed simultaneously.

[0607] In some embodiments, steps S6101-S6103 are optional, and one or more of these steps can be omitted or replaced in different embodiments. For example, step S6103 can be omitted.

[0608] FIG. 6B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6B, the embodiments of the present disclosure relate to a communication method, which can be performed by a second network element. The method can include:

[0609] Step S6201: sending a second request.

[0610] Optional implementation of step S6201 can be referred to optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2B, step S2301 in FIG. 2C, and other associated parts in embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which will not be repeated here.

[0611] Step S6202: receiving a second message.

[0612] Optional implementation of step S6202 can be referred to optional implementation of step S2111 in FIG. 2A, step S2209 in FIG. 2B, step S2311 in FIG. 2C, and other associated parts in embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which will not be repeated here.

[0613] In some embodiments, the above steps are optional steps.

[0614] FIG. 6C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6C, the embodiments of the present disclosure relate to a communication method, which can be performed by a second network element. The method can include:

[0615] Step S6301: sending a second request.

[0616] Optional implementation of step S6301 can be referred to optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2B, step S2301 in FIG. 2C, and other associated parts in embodiments related to FIG. 2A, FIG. 2B, and FIG. 2C, which will not be repeated here.

[0617] In some embodiments, the method further includes:

[0618] receiving a second message sent by the first network element, the second message being a message obtained by performing security processing on the first message, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, and the first key being stored in the first device.

[0619] In some embodiments, the security protection comprises encryption and / or integrity protection.

[0620] In some embodiments, the storing the first key in the first device comprises at least one of:

[0621] the first key is stored in a UICC;

[0622] the first key is stored in a non-volatile memory of the first device.

[0623] In some embodiments, the method further comprises:

[0624] sending a third message to a third network element, the third message being used to instruct the third network element to perform data processing, the data processing comprising at least one of: creating device data, updating device data, deleting device data.

[0625] In some embodiments, the method of the embodiments of the present disclosure can ensure that the information transmitted between the non-UICC device and the core network function is secure.

[0626] In some embodiments, FIG. 7A is an interaction diagram illustrating a communication method according to embodiments of the present disclosure. As shown in FIG. 7A, the embodiments of the present disclosure relate to a communication method, which can be performed by a communication system.

[0627] In some embodiments, the following assumptions can be included:

[0628] The AIoT device is deployed and owned by a third party, and the third party pre-configures a root key in the AIoT device for establishing secure communication of AIoT services;

[0629] For AIoT devices deployed and owned by a third party, no subscription information is stored in the 3GPP core network (e.g., UDM);

[0630] The third party subscribes to an environmental Internet of Things service with the 3GPP network, and the AMF / AIoTF is responsible for processing inventory / command requests sent by the third party;

[0631] Establishing secure communication between the core network and the AIoT device.

[0632] In some embodiments, the AF reuses the existing mechanism to store the information of the owned environmental Internet of Things device as part of the application data in the UDR.

[0633] In some embodiments, the potential structure of the environmental Internet of Things device data stored in the UDR is shown in Tables 1-3.

[0634] It should be noted that the AF determines the target UDR according to the location of the deployed environmental IoT device, and the UDR and the AIoTF / AMF belong to the same PLMN.

[0635] The method can include:

[0636] Step S7101, the application server sends an AIoT service request to the AIoTF / AMF.

[0637] In some embodiments, the AIoT service request can include an AIoT device ID, area information, a service ID, a group ID, and / or an inventory / command request.

[0638] For example, the parameters of the function of sending the AIoT service request can be (device ID / area info, inventory / command).

[0639] Step S7102, if the application server provides area information, the AIoTF / AMF can map the area information to a PLMN ID.

[0640] In some embodiments, if the application server provides area information, the AIoTF / AMF can map the area information to a PLMN ID.

[0641] In some embodiments, according to the AIoT service request, the AIoTF / AMF can obtain a device ID, a PLMN ID, a group ID, and / or a service ID.

[0642] Step S7103, the AIoTF / AMF obtains environmental IoT device data.

[0643] In some embodiments, the AIoTF / AMF can obtain the corresponding environmental IoT device data by invoking the Nudr_DM_query service operation.

[0644] In some embodiments, the device data can be associated with one environmental IoT device or a group of AIoT devices (e.g., located within the same PLMN, deployed by the same third party, etc.).

[0645] In some embodiments, the UDR can provide a root key to the AIoTF / AMF. Alternatively, the UDR can provide a derived key to the AIoTF / AMF by running a hash function or a key derivation function. For example, using the AIoT device ID and the root key as inputs to the KDF, a derived key is obtained.

[0646] Step S7104, the AIoTF / AMF generates a protected inventory / command request based on the obtained environmental IoT device data.

[0647] In some embodiments, for inventory, the AIoTF / AMF can protect the specific environmental IoT device ID included in the inventory request / page to address privacy concerns and also to ensure the integrity of the inventory request. If the specific environmental IoT device ID is not included in the inventory request / page, the inventory can be sent without further protection.

[0648] In some embodiments, for commands, the AIoTF / AMF can protect the command container or the entire command request.

[0649] In some embodiments, the security protection can include encryption and / or integrity protection.

[0650] In some embodiments, if the obtained data is associated with a group of environmental IoT devices, the AIoTF / AMF can derive a key for each AIoT device and use the derived key to protect the inventory / command. For example, the AIoT device ID and the key are used as inputs to the KDF to obtain the derived key. The group key corresponding to the group of AIoT devices can also be used to protect the inventory / command.

[0651] Step S7105, the AIoTF / AMF sends the protected AIoT service request to the selected reader.

[0652] In some embodiments, the reader can be a UE or a gNB.

[0653] Step S7106, the reader sends the protected inventory / command request to the environmental IoT device.

[0654] Step S7107, the environmental IoT device returns the inventory / command response.

[0655] In some embodiments, the environmental IoT device verifies the integrity of the AIoT service request and / or decrypts the message using the pre-configured root key / derived key.

[0656] In some embodiments, for inventory response, the environmental IoT device can protect part of the device ID or the entire message.

[0657] In some embodiments, for command response, the environmental IoT device can protect the data container or the entire command response.

[0658] In some embodiments, if the verification is passed, the environmental IoT device will return the inventory / command response, which is protected by the root key / derived key.

[0659] Step S7108, the reader forwards the received response message.

[0660] Step S7109, the AIoTF / AMF verifies and decrypts the response message.

[0661] Step S7110, the AIoTF / AMF sends the result to the application server.

[0662] In some embodiments, FIG. 7B is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 7B, the embodiment of the present disclosure relates to a communication method, which can be executed by a communication system.

[0663] In some embodiments, the following assumptions can be included:

[0664] The environmental IoT device is deployed and owned by an operator;

[0665] The operator pre-configures a root key in the environmental IoT device for establishing secure communication between the core network and the environmental IoT device, and for a UICC device, the root key is stored in the UICC, and for a non-UICC device, the root key is stored in the non-volatile memory;

[0666] The identifier of the environmental IoT device is assigned / managed by the operator;

[0667] The corresponding subscription information is stored in the UDM;

[0668] The AIoTF / AMF is responsible for processing the inventory / command request.

[0669] The method can include:

[0670] Step S7201, the application server sends an AIoT service request to the AIoTF / AMF.

[0671] In some embodiments, the AIoT service request includes area information and / or an inventory request.

[0672] Step S7202, the AIoTF / AMF sends the AIoT service request to the selected reader.

[0673] In some embodiments, the inventory request is sent without security protection.

[0674] Step S7203, the reader sends the AIoT service request to the environmental IoT device.

[0675] Step S7204, the environmental IoT device returns an inventory / command response.

[0676] In some embodiments, after receiving the inventory request, the environmental IoT device will reply its identifier in the inventory response.

[0677] In some embodiments, the device identifier or the entire inventory response message can be protected by a pre-configured key / derived key stored in the environmental IoT device.

[0678] Step S7205, the reader forwards the received response message.

[0679] Step S7206, the AIoT F / AMF obtains the subscription information.

[0680] In some embodiments, the AIoT F / AMF can interact with the UDM based on the received response message to obtain the subscription data related to the device identifier.

[0681] In some embodiments, the structure of the subscription information stored in the UDM is shown in Table 4.

[0682] In some embodiments, the subscription information includes environmental IoT device data.

[0683] Step S7207, the AIoT F / AMF verifies and decrypts the response message.

[0684] In some embodiments, the AIoT F / AMF performs security verification by using the key in the subscription information obtained from the UDM.

[0685] Step S7208, the AIoT F / AMF sends the device ID to the application server.

[0686] In some embodiments, if the verification is passed, the AIoT F / AMF returns the device ID to the AF / NF.

[0687] In some embodiments, the protection of the inventory response can only include integrity protection.

[0688] In some embodiments, FIG. 7C is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 7C, the embodiment of the present disclosure relates to a communication method, which can be executed by a communication system.

[0689] In some embodiments, the following assumptions can be included:

[0690] The environmental IoT device is deployed and owned by the operator;

[0691] The operator pre-configures a root key in the environmental IoT device for establishing secure communication between the core network and the environmental IoT device, for a UICC device, the root key is stored in the UICC, and for a non-UICC device, the root key is stored in the non-volatile memory;

[0692] The identifier of the environmental IoT device is assigned / managed by the operator;

[0693] Corresponding subscription information is stored in the UDM;

[0694] The AIoTF / AMF is responsible for handling inventory / command requests.

[0695] The method can include:

[0696] Step S7301, the application server sends an AIoT service request to the AIoTF / AMF.

[0697] In some embodiments, the AIoT service request includes an AIoT device ID, a group ID, and / or an inventory / command request.

[0698] Step S7302, the AIoTF / AMF determines the target AIoT device or group.

[0699] Step S7303, the AIoTF / AMF obtains subscription information.

[0700] In some embodiments, the AIoTF / AMF obtains a root key / derived key from the UDM by providing the device ID / group ID, which is stored in the subscription information of the environmental IoT device.

[0701] Step S7304, the AIoTF / AMF generates a protected inventory / command request

[0702] Step S7305, the AIoTF / AMF sends the protected AIoT service request to the selected reader.

[0703] Step S7306, the reader sends the protected inventory / command request to the environmental IoT device.

[0704] Step S7307, the environmental IoT device returns an inventory / command response.

[0705] In some embodiments, the environmental IoT device verifies the integrity of the AIoT service request and / or decrypts the message using a preconfigured root key / derived key.

[0706] Step S7308, the reader forwards the received response message.

[0707] Step S7309, the AIoTF / AMF verifies and decrypts the response message.

[0708] Step S7310, the AIoTF / AMF sends the result to the application server.

[0709] In some embodiments, the communication method of the present disclosure can include the following embodiments:

[0710] Embodiment 1 (environmental IoT device side),

[0711] The environmental IoT device shall be pre-configured with long term credentials to establish communication.

[0712] The environmental IoT device shall be able to protect inventory / command and send the protected inventory / command to the core network.

[0713] The environmental IoT device shall be able to verify and decrypt the protected inventory / command sent by the core network.

[0714] Embodiment 2 (AIoTF / AMF side),

[0715] The AIoTF / AMF shall be able to fetch the environmental IoT device data from the UDR.

[0716] The AIoTF / AMF shall be able to protect inventory / command and send the protected inventory / command to the environmental IoT device.

[0717] The AIoTF / AMF shall be able to verify and decrypt the protected inventory / command sent by the environmental IoT device.

[0718] The AIoTF / AMF shall be able to derive the root key for each environmental IoT device.

[0719] Embodiment 3 (Application Server side),

[0720] The application server shall be able to create / update / delete the environmental IoT device data stored in the UDR as part of application data.

[0721] Embodiment 4 (UDR / UDM side),

[0722] The UDR shall be able to store the data of the environmental IoT device as part of application data.

[0723] The UDR shall be able to provide the stored data to the AIoTF / AMF upon receiving the Nudr_DM_query request.

[0724] In some embodiments of the present disclosure, a communication system is provided, which can include a first device, a first network element, a second network element, and a third network element, wherein the first device can perform the communication method performed by the first device in the foregoing embodiments of the present disclosure; the first network element can perform the communication method performed by the first network element in the foregoing embodiments of the present disclosure; the second network element can perform the communication method performed by the second network element in the foregoing embodiments of the present disclosure; and the third network element can perform the communication method performed by the third network element in the foregoing embodiments of the present disclosure.

[0725] The embodiments of the present disclosure further provide a device for implementing any of the above methods. For example, a device is provided, which includes units or modules for implementing the steps performed by the first device in any of the above methods. For another example, another device is provided, which includes units or modules for implementing the steps performed by the core network device (e.g., the first network element, the second network element, the third network element, etc.) in any of the above methods.

[0726] It should be understood that the division of units or modules in the above device is only a logical functional division, and all or part of the units or modules can be integrated into one physical entity or physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software. For example, the device includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device. The processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of the hardware circuit. The hardware circuit can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship between the elements in the circuit. For another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and the functions of part or all of the units or modules are implemented by the configuration of the connection relationship between the logical gate circuits through a configuration file, for example, a field programmable gate array (FPGA) which can include a large number of logical gate circuits. All units or modules of the device can be implemented in the form of processor calling software, or all units or modules of the device can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0727] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), or the like.

[0728] FIG. 8A is a structural schematic diagram of a first device according to an embodiment of the present disclosure. As shown in FIG. 8A, the first device 101 can include at least one of a transceiver module 8101, a processing module 8102, and the like. In some embodiments, the transceiver module 8101 is configured to receive a first request sent by a first network element, the first request being used to request the first device to perform a first operation; and the transceiver module 8101 is further configured to send a first message to the first network element, the first message being security protected by a first key, and the first key being stored in the first device. Optionally, the transceiver module 8101 can be configured to perform at least one of the communication steps (for example, steps S2106 and S2108, but not limited to) of the sending and / or receiving performed by the first device 101 in any of the above methods, details of which are not described herein. Optionally, the processing module 8102 can be configured to perform at least one of the other steps (for example, step S2107, but not limited to) performed by the first device 101 in any of the above methods, details of which are not described herein.

[0729] In some embodiments, the transceiving module can include a transmitting module and / or a receiving module, which can be separate or integrated together. Alternatively, the transceiving module can be mutually replaced with a transceiver.

[0730] In some embodiments, the processing module can be one module or include multiple sub-modules. Alternatively, the multiple sub-modules perform all or part of the steps required to be performed by the processing module respectively. Alternatively, the processing module can be mutually replaced with a processor.

[0731] FIG. 8B is a structural schematic diagram of a first network element according to an embodiment of the present disclosure. As shown in FIG. 8B, the first network element 1021 can include at least one of a transceiving module 8201, a processing module 8202, etc. In some embodiments, the transceiving module 8201 is configured to receive a second request sent by a second network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation; the transceiving module 8201 is further configured to send the first request to the first device; and the transceiving module 8201 is further configured to receive a first message sent by the first device, the first message being security-protected by a first key, and the first key being stored in the first device. Alternatively, the transceiving module 8201 can be configured to perform at least one of the communication steps (for example, steps S2101, S2102, and S2103, but not limited to) of sending and / or receiving performed by the first network element 1021 in any of the above methods, details of which are not described herein. Alternatively, the processing module 8202 can be configured to perform at least one of the other steps (for example, steps S2104, S2105, and S2109, but not limited to) performed by the first network element 1021 in any of the above methods, details of which are not described herein.

[0732] In some embodiments, the transceiving module can include a transmitting module and / or a receiving module, which can be separate or integrated together. Alternatively, the transceiving module can be mutually replaced with a transceiver.

[0733] In some embodiments, the processing module can be one module or include multiple sub-modules. Alternatively, the multiple sub-modules perform all or part of the steps required to be performed by the processing module respectively. Alternatively, the processing module can be mutually replaced with a processor.

[0734] FIG. 8C is a structural schematic diagram of a third network element according to an embodiment of the present disclosure. As shown in FIG. 8C, the third network element 1023 can include at least one of a transceiver module 8301, a processing module 8302, and the like. In some embodiments, the transceiver module 8301 is configured to receive a fifth request sent by a first network element, the fifth request being used to obtain device data, the device data being used to obtain a second key, the second key being used for security protection of a received second request and / or security processing of a received first message by the first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, the first key being stored in the first device; and the transceiver module 8301 is further configured to send the device data to the first network element. Optionally, the transceiver module 8201 can be used to perform at least one of the communication steps (for example, steps S2102 and S2103, but not limited to) of sending and / or receiving performed by the third network element 1023 in any of the above methods, and details are not described herein again. Optionally, the processing module 8202 can be used to perform at least one of the other steps (for example, step S2113, but not limited to) performed by the third network element 1023 in any of the above methods, and details are not described herein again.

[0735] In some embodiments, the transceiver module can include a sending module and / or a receiving module, and the sending module and the receiving module can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.

[0736] In some embodiments, the processing module can be one module, or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module respectively. Optionally, the processing module can be mutually replaced with a processor.

[0737] FIG. 8D is a structural schematic diagram of a second network element according to an embodiment of the present disclosure. As shown in FIG. 8D, the second network element 1022 can include at least one of a transceiver module 8401, a processing module 8402, and the like. In some embodiments, the transceiver module 8401 is configured to send a second request to a first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation. Optionally, the transceiver module 8201 can be used to perform at least one of the sending and / or receiving communication steps (for example, step S2101, step S2112, but not limited to this) performed by the second network element 1022 in any of the above methods, and details are not described herein again. Optionally, the processing module 8202 can be used to perform at least one of the other steps performed by the second network element 1022 in any of the above methods, and details are not described herein again.

[0738] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.

[0739] In some embodiments, the processing module can be a module or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module. Optionally, the processing module can be mutually replaced with a processor.

[0740] FIG. 9A is a structural schematic diagram of a communication device 9100 according to an embodiment of the present disclosure. The communication device 9100 can be a network device (for example, an access network device, a core network device, and the like), a terminal (for example, a first device, and the like), a chip, a chip system, or a processor supporting the implementation of the above method by the core network device, a chip, a chip system, or a processor supporting the implementation of the above method by the terminal, and the like. The communication device 9100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0741] As shown in FIG. 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (for example, a base station, a baseband chip, an Internet of Things device, an Internet of Things device chip, a DU or a CU, and the like), execute programs, and process data of the programs. The communication device 9100 is used to execute any of the above methods.

[0742] In some embodiments, the communication device 9100 further includes one or more memories 9102 for storing instructions. Optionally, all or part of the memories 9102 can also be outside the communication device 9100.

[0743] In some embodiments, the communication device 9100 further includes one or more transceivers 9103. When the communication device 9100 includes one or more transceivers 9103, the transceiver 9103 performs at least one of the communication steps (for example, steps S2101, steps S2102, but not limited to) in the above-described method, and the processor 9101 performs at least one of the other steps (for example, step S2104, but not limited to).

[0744] In some embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced with each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.

[0745] In some embodiments, the communication device 9100 can include one or more interface circuits. Optionally, the interface circuit is connected with the memory 9102, and the interface circuit can be used to receive signals from the memory 9102 or other devices, and can be used to send signals to the memory 9102 or other devices. For example, the interface circuit can read the instructions stored in the memory 9102 and send the instructions to the processor 9101.

[0746] The communication device 9100 described in the above embodiments can be a first device or an Internet of Things device, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited by Figure 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, optionally, the set of ICs can also include storage components for storing data, programs; (3) an ASIC, such as a Modem; (4) a module that can be embedded in other devices; (5) a receiver, an Internet of Things device, a smart Internet of Things device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a first device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0747] Figure 9B is a structural schematic diagram of a chip 9200 according to an embodiment of the present disclosure. For the case where the communication device 9100 can be a chip or a chip system, the structural schematic diagram of the chip 9200 shown in Figure 9B can be referred to, but is not limited thereto.

[0748] The chip 9200 comprises one or more processors 9201, and the chip 9200 is configured to execute any of the above methods.

[0749] In some embodiments, the chip 9200 further comprises one or more interface circuits 9203. Optionally, the interface circuit 9203 is connected with the memory 9202, and the interface circuit 9203 can be configured to receive signals from the memory 9202 or other devices, and the interface circuit 9203 can be configured to send signals to the memory 9202 or other devices. For example, the interface circuit 9203 can read instructions stored in the memory 9202 and send the instructions to the processor 9201.

[0750] In some embodiments, the interface circuit 9203 performs at least one of the communication steps (for example, step S2101, step S2102, but not limited thereto) in the above methods, and the processor 9201 performs at least one of the other steps (for example, step S2104, but not limited thereto).

[0751] In some embodiments, the terms of interface circuit, interface, transceiver pin, transceiver, etc. can be replaced by each other.

[0752] In some embodiments, the chip 9200 further comprises one or more memories 9202 configured to store instructions. Optionally, all or part of the memory 9202 can be outside the chip 9200.

[0753] The embodiments of the present disclosure further propose a storage medium, and the storage medium stores instructions, and the instructions, when executed on the communication device 9100, cause the communication device 9100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer readable storage medium, but is not limited thereto, and it can also be a storage medium readable by other devices. Optionally, the storage medium can be a non-transitory storage medium, but is not limited thereto, and it can also be a transitory storage medium.

[0754] The embodiments of the present disclosure further propose a program product, and the program product, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Optionally, the program product can be a computer program product.

[0755] The embodiments of the present disclosure further propose a computer program, and the computer program, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method characterized by comprising: The method is performed by a first device, and the method comprises: receiving a first request sent by a first network element, the first request being used to request the first device to perform a first operation; sending a first message to the first network element, the first message being security protected by a first key, the first key being stored in the first device.

2. The method of claim 1, wherein, The security protection of the first message by the first key comprises: part of the first message or all of the first message is security protected by the first key, the first message comprising at least one of the following: device identity, first data.

3. The method according to claim 1 or 2, characterized in that, The method further comprises: verifying and / or security processing the first request by the first key.

4. The method according to any one of claims 1 to 3, characterized in that, The security protection comprises encryption and / or integrity protection.

5. The method according to any one of claims 1 to 4, characterized in that, The first key being stored in the first device comprises at least one of the following: the first key is stored in a universal integrated circuit card (UICC); the first key is stored in a non-volatile memory of the first device.

6. A communication method characterized by comprising: The method is performed by a first network element, and the method comprises: receiving a second request sent by a second network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation; sending the first request to the first device; receiving a first message sent by the first device, the first message being security protected by a first key, the first key being stored in the first device.

7. The method of claim 6, wherein, The second request comprises at least one of the following: device identity, service identity, group identity, area information, inventory request, command request.

8. The method according to claim 6 or 7, characterized in that, The method further comprises: according to the second request, sending a third request to a third network element, the third request being used to obtain device data, the device data comprising data corresponding to the first device or data corresponding to a group of devices; receiving the device data sent by the third network element; obtaining a second key based on the device data; security protecting the second request by the second key to obtain the first request.

9. The method of claim 8, wherein, The security protection of the second request by the second key comprises: security protecting part of information or all of information in the second request by the second key, the second request comprising at least one of the following: device identity, first information.

10. The method of claim 6 or 7, wherein, The method further comprises: according to the first message, sending a fourth request to a third network element, the fourth request being used to obtain device data, the device data comprising data corresponding to the first device; receiving the device data sent by the third network element; obtaining a second key based on the device data.

11. The method according to any one of claims 8-10, characterized in that, The method further comprises: verifying the first message by the second key; determining that the first message is verified, and security processing the first message to obtain a second message.

12. The method of claim 11, wherein, The method further comprises: sending the second message to the second network element.

13. The method according to any one of claims 7-12, characterized in that, The second request comprises area information, and the method further comprises: determining a public land mobile network (PLMN) corresponding to the area information.

14. The method according to any one of claims 6-13, characterized in that, The security protection comprises encryption and / or integrity protection.

15. The method according to any one of claims 6-14, characterized in that, The first key is stored in the first device includes at least one of: The first key is stored in a universal integrated circuit card (UICC); The first key is stored in a non-volatile memory of the first device.

16. A method of communication, comprising: The method is performed by a third network element, and the method comprises: receiving a fifth request sent by a first network element, the fifth request being used to obtain device data, the device data being used to obtain a second key, the second key being used for security protection of a received second request and / or security processing of a received first message by the first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, the first key being stored in the first device; sending the device data to the first network element.

17. The method of claim 16, wherein, The device data includes at least one of: The fifth request is a third request, and the device data includes data corresponding to the first device or data corresponding to a group of devices; The fifth request is a fourth request, and the device data includes data corresponding to the first device.

18. The method of claim 16 or 17, wherein, The method further comprises: receiving a third message sent by a second network element, the third message being used to instruct the third network element to perform data processing; performing data processing according to the third message, the data processing including at least one of: creating device data, updating device data, and deleting device data.

19. The method according to any one of claims 16-18, characterized by, The security protection includes encryption and / or integrity protection.

20. The method according to any one of claims 16-19, characterized by, The first key is stored in the first device includes at least one of: The first key is stored in a universal integrated circuit card (UICC); The first key is stored in a non-volatile memory of the first device.

21. A method of communication, comprising: The method is performed by a second network element, and the method comprises: sending a second request to a first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation.

22. The method of claim 21, wherein, The method further comprises: receiving a second message sent by the first network element, the second message being obtained after security processing of a first message, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, the first key being stored in the first device.

23. The method of claim 22, wherein, The security protection includes encryption and / or integrity protection.

24. The method of claim 22 or 23, wherein, The first key is stored in the first device includes at least one of: The first key is stored in a universal integrated circuit card (UICC); The first key is stored in a non-volatile memory of the first device.

25. The method of any one of claims 21-24, wherein, The method further comprises: sending a third message to a third network element, the third message being used to instruct the third network element to perform data processing, the data processing including at least one of: creating device data, updating device data, and deleting device data.

26. A first device, comprising: comprises: a transceiver module, configured to receive a first request sent by a first network element, the first request being used to request the first device to perform a first operation; The transceiver module is further configured to send a first message to the first network element, the first message being security protected by a first key, and the first key being stored in the first device.

27. A first network element, characterized by, Comprising: The transceiver module is configured to receive a second request sent by a second network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation; The transceiver module is further configured to send the first request to the first device; The transceiver module is further configured to receive a first message sent by the first device, the first message being security protected by a first key, and the first key being stored in the first device.

28. A third network element, characterized by Comprising: The transceiver module is configured to receive a fifth request sent by a first network element, the fifth request being used to obtain device data, the device data being used to obtain a second key, the second key being used by the first network element to security protect the received second request and / or to security process the received first message, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation, the first message being a response message sent by the first device according to the first request, the first message being security protected by a first key, and the first key being stored in the first device; The transceiver module is further configured to send the device data to the first network element.

29. A second network element, characterized by Comprising: The transceiver module is configured to send a second request to a first network element, the second request being used to request the first network element to send a first request to a first device, the first request being used to request the first device to perform a first operation.

30. A core network device, comprising: Comprising: One or more processors; The core network device is configured to perform the communication method in any one of claims 6-15 or claims 16-20 or claims 21-25.

31. A communication system, characterized by The communication system comprises a first device and a core network device, wherein the first device is configured to implement the communication method in any one of claims 1-5, and the core network device is configured to implement the communication method in any one of claims 6-15 or claims 16-20 or claims 21-25.

32. A storage medium, the storage medium storing instructions, wherein, The instructions, when executed on a communication device, cause the communication device to perform the communication method in any one of claims 1-5 or claims 6-15 or claims 16-20 or claims 21-25.