Communication method and device

The communication method and apparatus provide operator management of IoT terminals by assigning and storing operator identification codes, addressing the lack of management in existing systems and enabling effective control and authentication of these devices.

JP2025532156AActive Publication Date: 2025-09-29HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025517515
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-09
Filing Date
2023-09-11
Publication Date
2025-09-29
Estimated Expiration
2043-09-11

AI Technical Summary

Technical Problem

Current systems lack a method for operators to manage passive Internet of Things (IoT) terminals, such as tags, after they are purchased by companies, as these terminals rely on external stimuli for communication and do not have integrated management capabilities.

Method used

A communication method and apparatus that enables operator management of terminal devices by assigning and storing operator identification codes, including PLMN identifiers and EPCs, using core network devices to facilitate authentication and management of IoT terminals.

Benefits of technology

Enables effective operator management of IoT terminals by allowing identification and authentication, enhancing control and management capabilities over these devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025532156000001_ABST
    Figure 2025532156000001_ABST
Patent Text Reader

Abstract

The present application relates to the field of communication technologies and provides a communication method and apparatus, so that an operator manages a terminal device. A core network device receives first information from a requestor, where the first information indicates the first terminal; the core network device obtains an operator identification code assigned to the first terminal by the operator device; and the core network device sends second information to the first terminal, where the second information instructs the first terminal to store the operator identification code. After the operator identification code is stored in the terminal, the operator can manage the terminal based on the operator identification code.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims priority to Chinese Patent Application No. 202211230880.2, entitled "Communication Method and Apparatus," filed with the State Intellectual Property Office of China on September 30, 2022, the entire contents of which are incorporated herein by reference. This application claims priority to Chinese Patent Application No. 202211585353.3, entitled "Communication Method and Apparatus," filed with the State Intellectual Property Office of China on December 9, 2022, the entire contents of which are incorporated herein by reference.

[0002] TECHNICAL FIELD Embodiments of the present application relate to the field of communication technologies, and more particularly to communication methods and devices. [Background technology]

[0003] With the development of technology, passive Internet of Things has the prospect of large-scale application and deployment. However, passive Internet of Things terminals (e.g., tags) have simple functions and need to rely on external stimuli to transmit information to the outside. The stimuli are generally from card readers / writers. Referring to the resources of wireless communication systems, the functions of the reader / writer can be integrated into access network devices, and tags are stimulated by using wireless air interface technology.

[0004] Currently, after a company purchases tags from a tag manufacturer, the company (e.g., an application function) can jointly manage the purchased tags. In a possible implementation scenario, the company can approve an operator to jointly manage the tags purchased by the company. However, currently, there is no solution for an operator to manage tags. Summary of the Invention

[0005] The embodiments of the present application provide a communication method and apparatus for operator management of terminal devices.

[0006] According to a first aspect, there is provided a communication method. The method may be executed by a core network device or may be a component, such as a chip or a processor, used in the core network device. The following describes an example in which the method is executed by the core network device. First, the core network device receives first information from a requestor, where the first information indicates a first terminal. Next, the core network device obtains an operator identification code assigned to the first terminal by an operator device. Next, the core network device sends second information to the first terminal, where the second information indicates the first terminal to store the operator identification code.

[0007] After the operator identification code is stored in the terminal, the operator can manage the terminal based on the operator identification code.

[0008] In a possible implementation, the operator identification code comprises a public land mobile network (PLMN) identifier.

[0009] In a possible implementation, the operator identification code further includes one or more of: a first electronic product code (EPC), an enterprise code assigned to the first terminal, and a unique identification code of the first terminal in the operator device that is mapped from the first electronic product code EPC, where the first EPC is assigned by the operator device or the first EPC is from the requestor. Since the operator identification code includes this information, the operator identification code can replace the function of the EPC.

[0010] In a possible implementation, the second information further includes first location information for storing the operator identification code, and the storage location of the operator identification code can be flexibly indicated by using the second information.

[0011] In a possible implementation, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned to the first terminal by an operator device or the first EPC is from the requestor.

[0012] In a possible implementation, the second information further includes second location information for storing the first EPC. The storage location of the EPC can be flexibly indicated by using the second information.

[0013] In a possible implementation, after receiving the first information from the requestor, the core network device may further obtain a key corresponding to the first terminal, wherein the second information further instructs the first terminal to store the corresponding first key.

[0014] In a possible implementation, if the first information includes a key assigned to the first terminal, the core network device may obtain a key corresponding to the first terminal based on the first information.

[0015] In a possible implementation, the core network device assigns a key to the first terminal.

[0016] In a possible implementation, the core network device obtains a key corresponding to the first terminal from the operator device.

[0017] In a possible implementation, the core network devices include a first core network device and a second core network device. The first core network device obtains a key corresponding to the first terminal and transmits the key to the second core network device. The second core network device is configured to communicate with the access network device and the terminal. For example, the second core network device transmits second information to the first terminal. For example, the first core network device is a UDM and the second core network device is a TMF. The UDM checks whether a key corresponding to the first terminal is stored locally. If a key corresponding to the first terminal is stored locally, the UDM may directly transmit the key corresponding to the first terminal to the TMF. If the key is not stored locally, the UDM requests information about a key-storing network element (such as address information) from the NRF. The UDM receives the information about the key-storing network element transmitted by the NRF. The network element is, for example, a UDR or an AUSF. The UDM requests a key corresponding to the first terminal from the key-storing network element based on the information about the network element. After obtaining the key corresponding to the first terminal, the UDM sends the key corresponding to the first terminal to the TMF. Further, optionally, before the UDM obtains the key corresponding to the first terminal, the TMF sends instruction information to the UDM for obtaining the key of the first terminal. After receiving the instruction information for obtaining the key of the first terminal, the UDM sends the obtained information about the key corresponding to the first terminal to the TMF. If there is no corresponding key information on the UDM, the UDM obtains the key corresponding to the first terminal based on the instruction information and sends the key corresponding to the first terminal to the TMF.

[0018] In a possible implementation, the core network devices include a first core network device and a second core network device. The second core network device obtains a key corresponding to the first terminal. The second core network device is configured to communicate with the access network device and the terminal. For example, the second core network device sends second information to the first terminal. For example, the first core network device is a UDM and the second core network device is a TMF. The UDM recognizes information about key storage network elements through the NRF and sends the information about the key storage network elements to the TMF. Then, the TMF obtains keys corresponding to one or more terminals from the key storage network elements (including the first terminal) based on the information about the key storage network elements. Further optionally, before the UDM recognizes the information about the key storage network elements through the NRF, the TMF sends instruction information to the UDM to obtain a key for the first terminal or obtains the information about the key storage network elements. After the UDM receives instruction information for obtaining a key for the first terminal or obtains information about a key storage network element, the UDM recognizes the information about the key storage network element through the NRF and sends the information about the key storage network element to the TMF.

[0019] In a possible implementation, the core network device is a TMF, and the TMF learns information about a key storage network element through the NRF. The network element is, for example, a UDM, a UDR, or an AUSF. Then, the TMF obtains keys corresponding to one or more terminals from the key storage network element (including the first terminal) based on the information about the key storage network element.

[0020] In a possible implementation, the second information further includes third location information for storing the first key.

[0021] In a possible implementation, the first information includes one or more of: a tag identifier (TID) type of the first terminal, a default electronic product code (EPC) of the first terminal, and information about a requestor, where the requestor manages the first terminal. The first terminal can be matched by using the information, and naturally, another terminal can be matched.

[0022] In a possible implementation, before sending the second information to the first terminal, the core network device may further send third information to the access network device, where the third information instructs the access network device to search for the first terminal; then the core network device receives a default electronic product code EPC from the first terminal.

[0023] In a possible implementation, the third information includes one or both of a tag identifier TID type of the first terminal and a default electronic product code EPC of the first terminal, and the first terminal can be matched by using this information, and naturally, another terminal can be matched.

[0024] According to a second aspect, a communication method is provided. The method may be executed by a core network device or may be a component, such as a chip or a processor, used in the core network device. The following describes an example in which the method is executed by the core network device. First, the core network device receives fourth information from a requestor, where the fourth information indicates a first terminal; then sends fifth information to an access network device, where the fifth information indicates searching for the first terminal; then receives a first EPC assigned to the first terminal; and requests to obtain an operator identification code assigned to the first terminal based on the first EPC. Next, the core network device receives the operator identification code assigned to the first terminal, and triggers authentication between the first terminal and the operator device based on the operator identification code.

[0025] The capability of the first terminal is to report the EPC by default. After accessing the access network device (e.g., successful random access), the first terminal may actively transmit the first EPC assigned to the first terminal. After obtaining the first EPC of the first terminal, the core network device may request the operator identification code assigned to the first terminal based on the first EPC of the first terminal. Furthermore, authentication is performed on the terminal based on the operator identification code so that the operator manages the terminal.

[0026] According to a third aspect, there is provided a communication method. The method may be executed by a core network device or may be a component, such as a chip or a processor, used in the core network device. The following will use an example in which the method is executed by the core network device. First, the core network device receives fourth information from a requestor, where the fourth information indicates a first terminal; then, the core network device sends fifth information to an access network device, where the fifth information indicates a request to search for the first terminal and to obtain an operator identification code assigned to the first terminal; then, the core network device receives the operator identification code assigned to the first terminal; and further, the core network device triggers the first terminal to perform authentication with the operator device based on the operator identification code.

[0027] The capability of the first terminal is to report the EPC by default. After accessing the access network device (e.g., successful random access), the first terminal may actively transmit the first EPC assigned to the first terminal. In the process of searching for the first terminal, the access network device instructs the first terminal to transmit the operator identification code assigned to the first terminal. In this way, after accessing the access network device (e.g., successful random access), the first terminal may transmit the operator identification code assigned to the first terminal. Furthermore, authentication is performed on the terminal based on the operator identification code so that the operator manages the terminal.

[0028] According to a fourth aspect, there is provided a communication method. The method may be executed by a core network device or may be a component, such as a chip or a processor, used in the core network device. The following describes an example in which the method is executed by the core network device. First, the core network device receives fourth information from a requestor, where the fourth information indicates a first terminal; then, the core network device sends fifth information to an access network device, where the fifth information indicates searching for the first terminal. Next, the core network device receives an operator identification code assigned to the first terminal. Next, the core network device triggers the first terminal to perform authentication with the operator device based on the operator identification code.

[0029] The capability of the first terminal is to report the operator identification code by default. After accessing the access network device (e.g., successfully random accessing), the first terminal can actively transmit the operator identification code assigned to the first terminal. Furthermore, authentication is performed for the terminal based on the operator identification code so that the operator manages the terminal.

[0030] The following possible implementations are applicable to the second, third and fourth aspects.

[0031] In a possible implementation, the fourth information includes information about a requestor, and the requestor manages the first terminal; before the core network device sends the fifth information to the access network device, the core network device determines a public land mobile network identifier (PLMN ID) assigned to the first terminal based on the information about the requestor, where the fifth information includes the assigned PLMN ID. The PLMN ID is used to match the terminal to be searched.

[0032] In a possible implementation, before sending the fifth information to the access network device, the core network device determines an enterprise identifier assigned to the first terminal based on the information about the requestor, where the fifth information further includes the assigned enterprise identifier. The PLMN ID and the enterprise identifier are used to match the terminal to be searched.

[0033] The company identifier is a company code assigned to the first terminal; or the company identifier is a service identifier in the CompanyPrefix in the Electronic Product Code EPC memory bank of the first terminal.

[0034] In a possible implementation, the fourth information includes one or more of: a first electronic product code EPC of the first terminal, a TID type of the first terminal, and information about a requestor, where the requestor manages the first terminal. The fifth information includes one or more of: a first electronic product code EPC of the first terminal, an operator identification code associated with the first electronic product code EPC of the first terminal, and a TID type of the first terminal. The information is used to match a terminal to be searched.

[0035] In a possible implementation, before triggering authentication between the first terminal and the operator device based on the operator identification code, the core network device may further determine, based on the operator identification code and the subscription information of the first terminal, that the operator needs to perform authentication on the operator identification code. It is first determined that the operator needs to perform authentication on the operator identification code, and then the authentication is performed, so that signaling exchanges caused by invalid authentication can be avoided.

[0036] According to a fifth aspect, there is provided a communication method. The method may be executed by a first terminal or may be a component, such as a chip or a processor, used by the first terminal. The following describes an example in which the method is executed by the first terminal. First, the first terminal receives second information from a core network device, where the second information instructs the first terminal to store an operator identification code, and the operator identification code is assigned to the first terminal by the operator device. Then, the first terminal stores the operator identification code.

[0037] In a possible implementation, the second information further includes first location information for storing the operator identification code; and the first terminal stores the operator identification code in a first storage location corresponding to the first location information.

[0038] In a possible implementation, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by an operator device or the first EPC is from a requestor; the first terminal may further store the first EPC.

[0039] In a possible implementation, the second information further includes second location information for storing the first EPC; and the first terminal stores the first EPC in a second memory location corresponding to the second location information.

[0040] In a possible implementation, the second information may further instruct the first terminal to store a first key corresponding to the first terminal, and the first terminal may further store the first key.

[0041] In a possible implementation, the second information further includes third location information for storing the first key, and the first terminal stores the first key in a third memory location corresponding to the third location information.

[0042] In a possible implementation, before the first terminal receives the second information from the second core network device, the first terminal accesses the access network device; and sends the first terminal's default electronic product code EPC to the second core network device through the access network device.

[0043] According to a sixth aspect, there is provided a communication device. The device has a function of implementing any one of the above aspects and possible implementations of the above aspects. The function may be implemented by using hardware, or may be implemented by hardware by executing corresponding software. The hardware or software includes one or more functional modules corresponding to the above function.

[0044] According to a seventh aspect, there is provided a communications device. The device comprises a processor and, optionally, further comprises a memory. The processor is coupled to the memory. The memory is configured to store a computer program or instructions. The processor is configured to execute a part or all of the computer program or instructions in the memory; when executing a part or all of the computer program or instructions, the processor is configured to implement functions in a method according to any one of the above aspects and possible implementations of the above aspects.

[0045] In a possible implementation, the device may further include a transceiver configured to transmit a signal to be processed by the processor or to receive a signal input to the processor, and the transceiver may perform the transmitting or receiving operation in any one of the aspects and possible implementations of the aspect.

[0046] According to an eighth aspect, the present application provides a chip system. The chip system includes one or more processors (which may also be referred to as processing circuits). The processors are electrically coupled to a memory (which may also be referred to as a storage medium). The memory may or may not be located within the chip system. The memory is configured to store computer programs or instructions. The processor is configured to execute a portion or all of the computer programs or instructions in the memory; when executing a portion or all of the computer programs or instructions, the processor is configured to implement functions in a method according to any one of the above aspects and possible implementations of the above aspects.

[0047] In a possible implementation, the chip system may further include an input / output interface (which may also be referred to as a communication interface). The input / output interface is configured to output a signal processed by the processor or to receive a signal input to the processor. The input / output interface may perform a transmitting operation or a receiving operation in any one of the aspects and possible implementations of the aspect. Specifically, the output interface performs a transmitting operation, and the input interface performs a receiving operation.

[0048] In possible implementations, a chip system may include a chip, or may include a chip and other discrete devices.

[0049] According to a ninth aspect, a computer-readable storage medium is provided, configured to store a computer program, the computer program including instructions for implementing functions in any one of the aspects and possible implementations of the aspects.

[0050] Alternatively, a computer-readable storage medium is provided, configured to store a computer program, which, when executed by a computer, may enable the computer to perform the method according to any one of the above aspects and possible implementations of the above aspects.

[0051] According to a tenth aspect, there is provided a computer program product, comprising computer program code, which, when executed by a computer, enables the computer to perform a method according to any one of the above aspects and possible implementations of the above aspects.

[0052] According to an eleventh aspect, there is provided a communication system, comprising: a core network device that performs the method according to any one of the first aspect and possible implementations thereof; and a first terminal that performs the method according to any one of the first aspect and possible implementations thereof. Optionally, the communication system further comprises a requestor that communicates with the core network device.

[0053] According to a twelfth aspect, there is provided a communication system, comprising: a core network device configured to perform the method according to the second aspect and any one of the possible implementations of the second aspect; and a first terminal configured to communicate with the core network device. Optionally, the communication system further comprises a requestor configured to communicate with the core network device.

[0054] According to a thirteenth aspect, there is provided a communication system, the system comprising: a core network device configured to perform the method according to the third aspect and any one of possible implementations of the third aspect; and a first terminal configured to communicate with the core network device. Optionally, the communication system further comprises a requestor configured to communicate with the core network device.

[0055] According to a fourteenth aspect, there is provided a communication system, comprising: a core network device configured to perform the method according to the fourth aspect and any one of the possible implementations of the fourth aspect; and a first terminal configured to communicate with the core network device. Optionally, the communication system further comprises a requestor configured to communicate with the core network device.

[0056] For the technical effects of the sixth to fourteenth aspects, please refer to the descriptions of the first to fifth aspects. Repeated parts will not be described again. [Brief explanation of the drawings]

[0057] [Figure 1] Figure 1a is a diagram of the structure of a communication system according to an embodiment of the present application, and Figure 1b is a diagram of the structure of another communication system according to an embodiment of the present application. [Figure 2] FIG. 1 is a diagram of a memory bank format of a tag in the prior art. [Figure 3] 1 is a flowchart of a communication according to an embodiment of the present application; [Figure 4] 1 is a flowchart of a communication for storing an operator identification code in a first terminal according to an embodiment of the present application; [Figure 5] 1 is a flowchart of a communication for an operator to manage a terminal according to an embodiment of the present application; [Figure 6] 1 is a flowchart of a communication for an operator to manage a terminal according to an embodiment of the present application; [Figure 7] 1 is a flowchart of a communication for an operator to manage a terminal according to an embodiment of the present application; [Figure 8] 4 is a schematic flowchart of a network performing authentication on a terminal according to an embodiment of the present application; [Figure 9] 4 is a schematic flowchart of a terminal performing authentication to a network according to an embodiment of the present application; [Figure 10] 1 is a flowchart of communication in a case of corporate mismatch according to an embodiment of the present application. [Figure 11] 1 is a flowchart of communication in a case of corporate mismatch according to an embodiment of the present application. [Figure 12] 1 is a diagram of the structure of a communication device according to an embodiment of the present application; [Figure 13] 1 is a diagram of the structure of a communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0058] The communication methods provided herein may be applied to various communication systems, such as the Internet of Things (IoT), passive Internet of Things (P-IoT; or ambient IoT, A-IoT), semi-passive Internet of Things (Semi-active IoT), semi-active Internet of Things (Semi-active IoT), active Internet of Things (Active IoT), narrowband Internet of Things (NB-IoT), long term evolution (LTE) systems, fifth generation (5G) communication systems, hybrid architectures of LTE and 5G, or new communication systems emerging in 6G or future communication developments. Alternatively, the communication system may be a machine-to-machine (M2M) network, a machine type communication (MTC) network, or another network.

[0059] 1a is a diagram of a possible communication system applicable to embodiments of the present application, the communication system comprising a terminal device, an access network device, a core network device and a requestor.

[0060] The requestor may perform an operation on a terminal device (e.g., a tag), including, but not limited to, obtaining information about the terminal device, an inventory operation (also called a stocktaking operation), a read operation, a write operation, an disable operation, a kill operation, and the like. The requestor sends an operation command through a core network device. In a possible implementation, the core network device instructs an access network device to initiate random access to the terminal device. After the terminal device successfully executes the random access, the access network device sends or forwards information about the operation that needs to be executed to the terminal device. In another possible implementation, the core network device instructs a second terminal device to initiate random access to a first terminal device. After the terminal device successfully executes the random access, the second terminal device sends or forwards information about the operation that needs to be executed to the first terminal device.

[0061] The terminal device obtains or transmits corresponding information based on the received information about the operation. For example, when the operation is an inventory operation, the terminal device transmits the identification information of the terminal device; when the operation is a read operation, the terminal device transmits the data information stored in the memory bank of the terminal device; or when the operation is a write operation, the terminal device stores the data information that needs to be written in the memory bank of the terminal device.

[0062] The access network device transmits the information from the terminal device to the core network device, which then transmits the information to the requestor.

[0063] The terminal device may be a terminal device in Internet of Things technology, including, but not limited to, a passive terminal device, a semi-passive terminal device, a semi-active terminal device, an active terminal device, a low power consumption terminal device, a zero power consumption terminal device, a passive terminal device, an active terminal device, and the like.

[0064] A terminal device may also be referred to as user equipment (UE), terminal, access terminal, subscriber unit, subscriber station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent, or user equipment. Terminal devices may be widely used in various scenarios, such as the Internet of Things (IoT), device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable devices, smart transportation, and smart cities. The terminal device may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication capabilities, a computing device, another processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a 5G network, a terminal device in a future evolved public land mobile network (PLMN) or non-terrestrial network (NTN), or the like.Alternatively, the terminal device may be an end device, a logical entity, a smart device, or the like, for example, a terminal device such as a mobile phone or a smart terminal, a communication device such as a server, a gateway, a base station, or a controller, or an Internet of Things (IoT) device such as a tag (e.g., a passive tag, an active tag, or a semi-active tag), a sensor, an electricity meter, or a water meter. Alternatively, the terminal device may be an unmanned aerial vehicle (UAV) with communication capabilities. When the terminal device is a passive terminal, a semi-passive terminal, a semi-active terminal, an active terminal, or a tag, the terminal device may receive or transmit data by acquiring energy. Energy acquisition methods include, but are not limited to, electromagnetic waves, solar energy, light energy, wind energy, water energy, thermal energy, kinetic energy, and the like. The energy acquisition method of the passive terminal, semi-passive terminal, semi-active terminal, active terminal, or tag is not limited in this application. In addition, the tag in this application may be in the form of a tag or any terminal.

[0065] The access network device is configured to connect terminal devices to a wireless network. The access network device may be a base station, a pole site, an indoor base station (e.g., a Lampsite), a home base station (e.g., a home NB), a micro base station, an integrated access and backhaul (IAB) node, a mobile base station, a radio access network, a radio access network device, an evolved NodeB (eNodeB) in an LTE system or an LTE-Advanced (LTE-A) system, a next generation NodeB (gNB) in a 5G communication system, a transmission / reception point (TRP), a baseband unit (BBU), a Wi-Fi® access point (AP), a base station in a future mobile communication system, an access node in a Wi-Fi® system, or the like. Alternatively, the access network device may be a module or unit implementing some functions of a base station, such as a central unit (CU) or a distributed unit (DU). The specific technology and the specific device configuration used by the access network device are not limited in the embodiments of the present application. For example, in a network structure, the access network device may be a CU node, a DU node, or an access network device including a CU node and a DU node. Specifically, the CU node is configured to support protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP).The DU node is configured to support a radio link control (RLC) layer protocol, a medium access control (MAC) layer protocol, and a physical layer protocol. Alternatively, the access network device may be a device with reader functionality.

[0066] A requestor may be understood as a device that sends an operation command, such as a third-party device, a server, a P-IoT server, an application server (AS), an application function (AF), a Passive Internet of Things Application Function (P-IoT AF), an Internet of Things Application Function (IoT AF), or another device that sends an operation command. A requestor may correspond to a specific type of user. A specific type of user may include, but is not limited to, an enterprise, a tenant, a third party, or a company. A requestor corresponding to a specific type of user may be understood as the requestor belonging to and being managed by a specific type of user.

[0067] The core network devices may include one or more of the following network elements:

[0068] An access management network element (which may also be referred to as an access management network element, a mobility management network element, or an access and mobility management network element) is a network element for a control plane provided by an operator network, and is responsible for access control and mobility management for terminal devices to access the operator network, including functions such as mobility status management, temporary user identification number allocation, and user authentication. In a 5G communication system, the access management network element may be an access and mobility management function (AMF) network element. In future communication systems, the access management network element may still be an AMF network element or may have another name, which is not limited in this application.

[0069] The session management network element is mainly responsible for session management in a mobile network, such as session establishment, modification, and release. Specific functions include, for example, allocating an IP address to a user and selecting a user plane network element that provides packet forwarding functionality. In a 5G communication system, the session management network element may be a session management function (SMF) network element. In future communication systems, the session management network element may still be an SMF network element or may have another name. This is not a limitation in this application.

[0070] The user plane network element is responsible for forwarding and receiving user data in a terminal device. The user plane network element may receive user data from a data network and transmit the user data to a terminal device through an access network device. The user plane network element may also receive user data from a terminal device through an access network device and forward the user data to a data network. The transmission resources and scheduling functions in the user plane network element serving the terminal device are managed and controlled by the SMF network element. In a 5G communication system, the user plane network element may be a user plane function (UPF) network element. In future communication systems, the user plane network element may still be a UPF network element or may have another name. This is not a limitation in this application.

[0071] The data management network element is configured for generating authentication credentials, user identification processing (e.g., storing and managing persistent user identifiers), access control, subscription data management, and the like. In a 5G communication system, the data management network element may be a unified data management (UDM) network element. In future communication systems, the unified data management may still be a UDM network element or may have another name. This is not a limitation in this application.

[0072] The policy control network element is mainly responsible for providing a unified policy framework for managing network behavior, supporting providing policy rules to control layer network functions, and obtaining user subscription information for policy decisions. In a 4G communication system, the policy control network element may be a policy and charging rules function (PCRF) network element. In a 5G communication system, the policy control network element may be a policy control function (PCF) network element. In future communication systems, the policy control network element may still be a PCF network element or may have another name, which is not limited in this application.

[0073] The network repository network element may be configured to provide network element discovery functionality and provide network element information corresponding to a network element type based on a request from another network element. The NRF also provides network element management services, such as network element registration, update, and de-update, and network element status subscription and push. In a 5G communication system, the network repository network element may be a network repository function (NRF) network element. In future communication systems, the network repository network element may still be an NRF network element or may have another name. This is not a limitation in this application.

[0074] A network opening network element is a control plane network element provided by an operator. The network opening network element may be configured to securely open the external interface of an operator network to a third party and securely open services and capabilities provided by 3rd Generation Partnership Project (3GPP) network function devices and the like. When a session management network element needs to communicate with a third-party network element, the network opening network element may be used as a relay for communication between the session management network element and the third-party network element. When the network opening network element serves as a relay, the network opening network element may translate the identity of a subscriber and the identity of a third-party network element. For example, when the network opening network element sends a subscriber's subscription permanent identifier (SUPI) from the operator network to a third party, the SUPI may be translated into an external identity (ID) corresponding to the SUPI. Conversely, when sending an external ID (a third-party network element ID) to the operator network, the network opening network element may translate the external ID into a SUPI. In a 5G communication system, the network exposure function network element may be a network exposure function (NEF) network element. In future communication systems, the network exposure function network element may still be an NEF network element or may have another name, which is not limited in this application.

[0075] The network slice selection network element may be configured to select an appropriate network slice for a terminal service. In a 5G communication system, the network slice selection network element may be a network slice selection function (NSSF) network element. In future communication systems, the network slice selection function network element may still be an NSSF network element or may have another name. This is not limited in the present application.

[0076] The network data analysis network element may collect data from each network function (NF), such as a policy control network element, a session management network element, a user plane network element, an access management network element, and an application function network element (through a network capability opening function network element), and perform analysis and prediction. In a 5G communication system, the network data analysis network element may be a network data analytics function (NWDAF). In future communication systems, the network opening function network element may still be an NWDAF network element or may have another name. This is not limited in the present application.

[0077] The unified data repository network element is responsible for storing structured data information, including subscription information, policy information, and network or service data defined in a standard format. In a 5G communication system, the unified data repository network element may be a unified data repository (UDR). In future communication systems, the network opening function network element may still be a UDR network element or may have another name. This is not limited in this application.

[0078] An authentication server function (AUSF) is a functional entity that is used by the network to perform authentication on the UE and to verify whether the UE can be trusted, and that can support access service authentication defined in the 3GPP framework and authentication of non-3GPP access networks.

[0079] The network slice-specific and standalone non-public network authentication and authorization function (NSSAAF) is mainly configured to connect to an external authentication, authorization, and accounting (AAA) server and convert between a service-based interface (SBI) and an AAA interface. It is an intermediate network element connecting an internal network element of a 3GPP network and an external AAA server. For example, a correspondence between the address information of the AAA server and the domain information is pre-configured in the NSAAF. After the NSSAAF receives the domain information, the NSAAF may determine the AAA server based on the address information of the AAA server and then send the received message to the AAA server. In another example, the NSSAAF may request the address information of the AAA server from a domain name server (DNS) based on the domain information, obtain the address information of the AAA server from the DNS server, and then send the received message to the AAA server. The NSSAAF may further be configured to support accessing a standalone non-public network using credentials from a credentials holder (CH) using an AAA server, or using credentials from a default credentials server (DCS) using an AAA server. If the certificate holder or default credentials server is from a third party, the NSSAAF may communicate with the AAA server through an AAA proxy.

[0080] A tag management function (TMF) network element, which may also be referred to as an Internet of Things management function (IMF) network element or an Internet of Things device management function (IDMF) network element, may implement one or more of the following functions: (1) identify an instruction sent by a requestor and perform an operation on an Internet of Things terminal according to the instruction sent by the requestor; (2) instruct an access network device or a terminal device to perform a random access procedure for an Internet of Things terminal; (3) obtain data for an Internet of Things terminal, where the data sent by the Internet of Things terminal may be filtered or collected; (4) send data from the Internet of Things terminal to a requestor; (5) connect to one or more requestors and perform data routing; and (6) perform a security authentication procedure for an Internet of Things terminal, where the security procedure may be performed based on context information, policy information, or subscription data corresponding to the requestor or the Internet of Things terminal. The TMF network element may be an independent network element and deployed independently; or it may be part of the functionality of an existing network element and deployed together with the existing network element, for example, the TMF and the AMF or UPF are deployed together.

[0081] It may be understood that the above network elements or functions may be network elements in a hardware device, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). A network element may also be referred to as a "device," an "entity," or the like. One or more services may be obtained through the division into the above network elements or functions. Furthermore, services may arise that exist independently of a network function. In this application, an instance of a function, an instance of a service included in a function, or an instance of a service that exists independently of a network function may be referred to as a service instance.

[0082] It should be understood that Figure 1a is just an example of an applicable network architecture, and an actually applied network architecture may include more or fewer network elements than those shown in Figure 1a. In the embodiments of the present application, the names of the network elements used above may be changed, although the functions of the network elements may remain the same in future communication systems.

[0083] Figure 1b is a diagram of the structure of a communication system applicable to this application. The Tag Management Function (TMF) has a direct connection interface with the UDM, the access network device, the NEF, or the AF for message exchange. The dashed boxes and dashed lines represent optional network elements or optional connections.

[0084] In order to facilitate understanding of the embodiments of the present application, the following describes some terms in the embodiments of the present application to help those skilled in the art have a better understanding.

[0085] (1) Figure 2 shows the format of the memory banks of a tag in the prior art. The memory banks include a reserved memory bank, an electronic product code (EPC) memory bank, a tag identifier (TID) memory bank, and a user memory bank. Each memory bank is described below.

[0086] The reserved memory bank is used to store one or more passwords required for the functionality of the kill and / or access commands.

[0087] The EPC memory bank identifies the EPC to which the tag is attached, including the StoredCRC, StoredPC, EPC, and extended XPC. The EPC uniquely identifies the object. From the perspective of higher layer applications, the EPC is in uniform resource identifier (URI) format and is stored in the tag as binary code. The URI format includes urn:epc:id:scheme:component1.component2.... Different EPC schemes are named using the scheme. The specific form of component1, component2, and the rest of the EPC stored in the EPC scheme depends on the EPC scheme used. The EPC also contains control information, which is used by the card reader to control the card reading procedure.

[0088] Several EPC schemes are defined in the existing EPC tag data standard (TDS), and the URI formats for different schemes are different, for example:

[0089] When the scheme is SGTIN, the corresponding URI format is: urn:epc:id:sgtin:CompanyPrefix.ItemRefAndIndicator.SerialNumber.

[0090] When the scheme is SGLN, the corresponding URI format is: urn:epc:id:sgln:CompanyPrefix.LocationReference.Extension.

[0091] The TID memory bank stores tag and vendor specific data such as the tag manufacturer unique identifier, tag type identifier and tag capabilities.

[0092] The user memory bank is an optional expansion area that allows for the storage of user-specific data.

[0093] (2) An inventory operation may also be referred to as a stocktaking operation. This operation may be performed to obtain identification information of a terminal by using commands such as a query command or an acknowledgment command. The identification information of the terminal may be, for example, an electronic product code (EPC) and a tag identifier (TID).

[0094] (3) A read operation may be to read data in a memory bank of a terminal. For example, the data in the memory bank may include identification information (e.g., an electronic product code EPC and a tag identifier TID), content stored in a reserved bank, or content stored in a user memory bank.

[0095] (4) The Kill operation can disable a terminal, i.e., a disabled terminal cannot operate.

[0096] (5) The lock operation can lock information about the terminal to prevent read or write operations to the tag. Alternatively, the lock operation can lock a memory bank to prevent or enable read or write operations to the memory bank.

[0097] (6) A block write operation may enable a reader / writer to perform a multi-byte write operation to a terminal's memory bank (e.g., a reserved bank, an EPC memory bank, a TID memory bank, or a user memory bank) by using a single command.

[0098] (7) A block erase operation may enable a reader / writer to perform a multi-byte erase operation on a memory bank of a terminal (e.g., a reserved bank, an EPC memory bank, a TID memory bank, or a user memory bank).

[0099] (8) The access operation allows a terminal with a non-zero access password to change from an open state to a secured state.

[0100] (9) A write operation may be performed on a memory bank of the terminal. For example, identification information (e.g., EPC or TID) in the memory bank may be written or rewritten. Alternatively, a write or rewrite operation may be performed on data in a reserved bank or a user memory bank.

[0101] In the present application, "at least one" means one or more, and "multiple" means two or more. The term "and / or" describes a relationship between related objects and indicates that three relationships may exist. For example, A and / or B may represent the following cases: only A is present, both A and B are present, and only B is present, where A and B may be singular or plural. The character " / " generally indicates an "or" relationship between related objects. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of one item or multiple items. For example, "at least one of items a, b, or c" may refer to a, b, c, a and b, a and c, b and c, or a, b, and c, where a, b, and c may be singular or plural.

[0102] Additionally, unless otherwise specified, ordinal numbers such as "first" and "second" referred to in the embodiments of the present application are used to distinguish between multiple objects and are not intended to limit the size, content, order, chronological order, priority, importance, or the like of the multiple objects. For example, first information and second information are simply used to distinguish between different information and do not indicate different content, priority, importance, or the like of the two pieces of information.

[0103] Currently, a requestor (which can be understood as a company or a third party) can jointly manage tags. For example, the requestor performs authentication on the tag by using the Electronic Product Code EPC on the tag. In a possible implementation scenario, an operator jointly manages tags. Currently, there is no solution for an operator to manage tags. This application provides a solution for an operator to manage tags.

[0104] The following describes the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application.

[0105] In current technology, before delivery of a terminal (e.g., a tag), a default EPC is already stored in an EPC memory bank. It can be understood that the default EPC is stored by the terminal manufacturer. The default EPC of multiple terminals manufactured by a manufacturer is usually the same. After purchasing a terminal from the manufacturer, a requestor (the requestor can be understood as a company or a third party) can perform a procedure to store (save can be understood as printing or writing) an EPC (the EPC is an EPC for terminal management, not a default EPC, and it can be understood that the EPC is usually assigned to the terminal by the requestor) in the EPC memory bank of the terminal to overwrite the default EPC stored in the EPC memory bank. Thereafter, the requestor can manage terminals together by using the EPC assigned to the terminal by the requestor. The requestor assigns different EPCs to different terminals. The assigned EPC can uniquely identify the terminal.

[0106] In an embodiment of the present application, an operator may purchase a terminal from a manufacturer or a terminal company, and the operator assigns an operator identification code to the terminal. The operator identification code may uniquely identify the operator, and the operator may assign different operator identification codes to different terminals. The operator identification code may uniquely identify the terminal. After the terminal stores (storing may be understood as printing or writing) the operator identification code assigned by the operator, the operator may manage the terminal by using the operator identification code. For example, management includes: performing network access identification by using the operator identification code, performing security authentication for the terminal, and the like.

[0107] It may be understood that the EPC stored in the EPC memory bank in a terminal purchased by an operator may be a default EPC stored by the manufacturer of the terminal (in other words, the requestor has not performed a procedure to store in the terminal the EPC assigned by the requestor to the terminal), or may be an EPC assigned to the terminal by the requestor (in other words, the requestor has performed a procedure to store in the terminal the EPC assigned to the terminal by the requestor).

[0108] The operator identity code includes a public land mobile network identifier (PLMN ID), which may be a combination of a mobile country code (MCC) and a mobile network code (MNC). Based on this, optionally, the operator identity code further includes an enterprise level identity code or an EPC level identity code. For example, the operator identity code may further include one or more of the following: an EPC for terminal management (which may uniquely identify the terminal), an enterprise code assigned to the terminal (the enterprise code may be replaced by an application code or a service code), and a unique identity code of the terminal in the operator device mapped from the EPC for terminal management. The EPC for terminal management is assigned by the operator device or assigned by the requestor. The service code assigned by the operator device may be considered as an enterprise level identity code. The EPC for terminal management may be considered as an EPC level identifier. The unique identity code of the terminal in the operator device mapped from the EPC for terminal management may be considered as an EPC level identity code.

[0109] Generally, one company has multiple departments, and different departments manage different terminals. The same company code can be assigned to terminals in the same department, and different company codes can be assigned to terminals in different departments. In this way, by using the department as a unit, a differentiated inventory can be performed on the terminals. Of course, the same company code can also be assigned to terminals managed by the company, so that a complete inventory of the company can be performed. The company code can uniquely identify the company or the department of the company.

[0110] In another scenario, for example, different terminals may provide different services, such as gas service, water bill service, transportation service, electric vehicle service, and automobile service. The same identification code (e.g., referred to as an application code or service code) may be assigned to terminals that provide the same service, and different identification codes (e.g., referred to as application codes or service codes) may be assigned to terminals that provide different services. In this manner, a differentiated inventory may be performed for terminals by using service as a unit.

[0111] It can be understood that the company code, application code, and service code can uniquely identify the type of terminal. The definition of "type" can be flexible. For example, a company is a type, a department or departments of a company are a type, a service is a type, and multiple services are types. The names of the company code, application code, and service code should not limit the scenario.

[0112] The differences between the default EPC and the EPC for terminal management include: the default EPC is an EPC that is stored before the terminal is delivered and is stored by the terminal manufacturer; the EPC for terminal management is assigned to the terminal by an operator device or a requestor after the terminal is delivered; and the EPC for terminal management can uniquely identify the terminal. In current technology, only the requestor assigns the EPC for terminal management to the terminal. In this application, it is proposed that the operator device or the requestor can assign the EPC for terminal management to the terminal.

[0113] The operator identification code may be stored in any one of the following memory banks of the terminal: reserved memory bank, EPC memory bank, TID memory bank and user memory bank.

[0114] In a specific manner, the operator identification code is stored in the EPC memory bank of the terminal. For the format of the operator identification code, please refer to the Subscription Persistent Identifier SUPI format or SUPI-like format.

[0115] For example, the current international mobile subscriber identity (IMSI) based SUPI format, i.e. network access identifier (NAI), is as follows: <imsi>@ims.mnc <mnc>.mcc <mcc>.3gppnetwork.org.

[0116] Referring to the SUPI format, the format of the operator identification code is: <epc>.3gppnetwork.org or <epc>.mnc <mnc>.mcc <mcc>.3gppnetwork.org.

[0117] Specifically, the following storage formats may be included:

[0118] Format 1: The EPC is extended and a new EPC scheme is added, which is defined as follows: The new EPC scheme includes MNC and MCC, and optionally further includes a company level identification code or an EPC level identification code.

[0119] Based on the description in Figure 2, in the current technology, when the scheme is SGTIN, the corresponding URI format is: urn:epc:id:sgtin:CompanyPrefix.ItemRefAndIndicator.SerialNumber.

[0120] In an example, the format of the URI corresponding to the new EPC scheme added in an embodiment of the present application is as follows: urn:epc:id:PLMN: PLMN ID.CompanyPrefix.ItemRefAndIndicator.SerialNumber.

[0121] Format 2: The EPC schemes are different in different application scenarios. Each EPC scheme is extended. It is defined as follows: the extended EPC scheme includes MNC and MCC, and optionally further includes a company-level identification code or an EPC-level identification code. The extended EPC scheme is similar to the URI format described above, which corresponds to a new EPC scheme added in an embodiment of the present application.

[0122] The operator identification code is stored in the terminal's EPC memory bank, and the EPC cannot be completely occupied. For flexible allocation, the EPC encoding space needs to be reserved for the enterprise. Therefore, the operator identification code can be considered to include an enterprise-level identification code (e.g., an enterprise code assigned to the terminal), and the enterprise-level identification code is used for password verification for enterprise network access.

[0123] In another particular scheme, the operator identification code is written to a non-EPC memory bank, for example, a reserved memory bank, a TID memory bank, a user memory bank, or another memory bank expanded in the terminal.

[0124] The format of the operator identification code may be an extended SUPI-like format based on a serialized TID (TID), where the extended SUPI-like format based on a STID is as follows: <stid>.mnc <mnc>.mcc <mcc>.3gppnetwork.org. The STID may uniquely identify the tag.

[0125] The operator identification code is written to a non-EPC memory bank and does not occupy an EPC memory bank. An enterprise can customize EPC memory bank allocation for different application scenarios in the enterprise, such as object type classification of different parts. The EPC memory bank can be used for verifying network access of the EPC for terminal management, and the like. When authentication is required, the operator can perform authentication based on the operator identification code, where authentication can also be understood as STID-based authentication, and the enterprise can perform authentication based on the EPC in the EPC memory bank.

[0126] Figure 3 is a flowchart of communication for storing an operator identification code in a first terminal. The requestor may be the requestor in Figure 1a, such as a third-party device, a server, a P-IoT server, an application server AS, an application function AF, a passive Internet of Things application function (P-IoT AF), or an Internet of Things application function (IoT AF). The core network device may be the core network device in Figure 1a, such as an AMF, a UDM, a TMF, an AUSF, an NSSAAF, an SMF, a UPF, a PCF, an NEF, or a UDR. The core network device may communicate with the requestor directly or may communicate with the requestor through another core network device. The first terminal may be the terminal device in Figure 1a. The operator device may be a device having one or more of the following functions: assigning an operator identification code to a terminal, performing authentication for a terminal, assigning an EPC for terminal management to a terminal, assigning keys to a terminal, and the like. The operator device may be a device deployed in the core network, such as an AMF, a UDM, a TMF, an AUSF, an NSSAAF, a PCF, or a UDR. Alternatively, the operator device, such as an AAA server, may not be deployed in the core network.

[0127] For ease of distinction, the core network device communicating with the requestor is referred to as the first core network device, and the core network device communicating with the terminal / access network device is referred to as the second core network device. The first core network device and the second core network device may be the same core network device or different core network devices. In Figure 3, an example will be described in which the first core network device and the second core network device are integrated. The first core network device and the second core network device are collectively referred to as core network devices. Alternatively, in Figure 3, an example will be described in which the first core network device and the second core network device are the same, and the first core network device and the second core network device are simply referred to as core network devices.

[0128] Step 301: A requestor sends first information to a core network device, where the first information indicates a first terminal.

[0129] In response, the core network device receives the first information from the requestor.

[0130] The first terminal is the terminal to which an operator identification code needs to be assigned (or printed, stored, or written). The operator identification code may uniquely identify an operator, or it may uniquely identify a terminal.

[0131] It may be understood that in addition to indicating the first terminal, the first information may also indicate another terminal. In a particular example, the first information indicates that a corresponding operator identification code is assigned to one or more terminals (including the first terminal). In an example, the value of a bit at one or more specific positions in the plurality of bits occupied by the first information indicates that the operator identification code is assigned to the terminal or that the operator identification code is not assigned to the terminal. For example, when the value of the bit at a specific position is 0, it indicates that the operator identification code is assigned to the terminal; or when the value of the bit at a specific position is 1, it indicates that the operator identification code is not assigned to the terminal. The meanings represented by the bit values ​​are merely examples and should not constitute limitations on the solution.

[0132] The core network device may determine, based on the first information, one or more terminals to which an operator identification code needs to be assigned, where the one or more terminals to which the operator identification code needs to be assigned include the first terminal. A default EPC may be stored in the EPC memory bank of the one or more terminals indicated by the first information to which the operator identification code needs to be assigned, or the EPC memory bank may be empty, in other words, no default EPC is stored.

[0133] The process of assigning operator identification codes to all terminals is similar, and in the example of Figure 3, we will only use the example where the operator identification code is assigned to the first terminal for explanation.

[0134] The first information may indicate the first terminal in one or more of the following ways:

[0135] For example, the first information includes a default EPC range, and the default EPC range includes a default EPC of the first terminal. The first information can be understood as an EPC range to which an operator identification code allocation is subscribed or approved and is sent by a requestor to a core network device. The core network device determines, based on the default EPC range, that an operator identification code needs to be assigned to a terminal that belongs to the default EPC range.

[0136] For example, the first information includes one or more default EPCs, and the one or more default EPCs include the default EPC of the first terminal. The first information can be understood as one or more default EPCs to which operator identification code allocation is subscribed or approved and which are sent by a requestor to a core network device. The core network device determines, based on the one or more default EPCs, that operator identification codes need to be allocated to terminals that belong to the one or more default EPCs.

[0137] For example, the first information includes one or more target TID types, and the TID of the first terminal belongs to the target TID types. The first information can be understood as one or more target TID types for which operator identification code allocation is subscribed or approved and which are sent by a requestor to a core network device. The core network device determines, based on the one or more target TID types, that operator identification codes need to be assigned to terminals whose TID types belong to the one or more target TID types.

[0138] For example, the first information may include information about a requestor, and the information about the requestor may indicate a default EPC range or one or more default EPCs corresponding to (or managed by) the requestor. The default EPC range or one or more default EPCs corresponding to (or managed by) the requestor may include a default EPC of the first terminal. Based on the information about the requestor, the core network device may determine that an operator identification code needs to be assigned to a terminal whose default EPC belongs to the default EPC range or one or more default EPCs corresponding to (or managed by) the requestor.

[0139] The information about the requestor may include one or more of the following: an AF identifier (AF identifier or AF identity, AF ID), a service identifier (service ID), an application identifier (APP ID), address information of the AF, port information of the AF, address information of the application server AS, and port information of the application server AS. The address of the AF or AS is, for example, an internet protocol address (IP), a medium access control (MAC) address, or an IPv6 prefix. The port of the AF or AS is, for example, a transmission control protocol (TCP) port or a user datagram protocol (UDP) port.

[0140] A default EPC range or one or more default EPCs corresponding to (or managed by) the requestor may be stored or configured on the core network device, or may be stored or configured on another core network device. The core network device may send information about the requestor to the other core network device, and the other core network device may obtain a default EPC range or one or more default EPCs corresponding to (or managed by) the requestor based on the information about the requestor and send the default EPC range or one or more default EPCs to the core network device. For example, the other core network device may include a core network device such as a UDM, UDR, AUSF, NEF, PCF, SMF, TMF, or NSSAAF.

[0141] In conclusion, the first information can be recognized to include one or more of the following: a tag identifier TID type of the first terminal, a default electronic product code EPC of the first terminal, and information about the requestor. The core network device can determine the first terminal, and naturally, can also determine other terminals, based on the information included in the first information.

[0142] Optionally, based on the indication of the first terminal, the first information may further include a service range. For example, the service range includes target area information A, where the target area information A indicates an area corresponding to one or more terminals to which an operator identification code needs to be assigned. For example, the target area information A may be a geographic location, a city location, or 3GPP location information (such as a tracking area (TA) list or a cell list) corresponding to one or more terminals to which an operator identification code needs to be assigned. The service range is used to query an access network device.

[0143] Optionally, the requestor may further request the core network device to assign (or print, save, or write) an EPC for terminal management to the terminal. For example, the first information instructs that the corresponding EPC for terminal management be assigned to one or more terminals (including the first terminal). In an example, the value of a bit at one or more specific positions in the multiple bits occupied by the first information indicates that the EPC is assigned to the terminal or that the EPC is not assigned to the terminal. For example, when the value of the bit at a specific position is 0, it indicates that the EPC is assigned to the terminal; or when the value of the bit at a specific position is 1, it indicates that the EPC is not assigned to the terminal. The meanings represented by the bit values ​​are merely examples and should not constitute limitations on the solution.

[0144] When an EPC needs to be assigned to a terminal, in an example, the requestor instructs the core network device to assign an EPC for terminal management to each of one or more terminals (including the first terminal) indicated by the first information. For example, the first information may further include an EPC range for terminal management, or an EPC range corresponding to each type, so that the core network device stores the EPC for terminal management in the corresponding terminal. An enterprise may define terminal types and EPC ranges for different purposes and send them to an operator for printing. In another example, the requestor does not instruct the core network device to assign an EPC for terminal management corresponding to each of one or more terminals (including the first terminal) indicated by the first information, but the operator assigns an EPC code to one or more terminals indicated by the first information.

[0145] Optionally, the requestor may further request the core network device to assign (or print, save, or write) the key to the terminal. The key is used for security authentication between the terminal and the core network device or the requestor. In an example, the value of a bit at one or more specific positions in the plurality of bits occupied by the first information indicates that the key is assigned to the terminal or that the key is not assigned to the terminal. For example, when the value of the bit at a specific position is 0, it indicates that the key is assigned to the terminal; or when the value of the bit at a specific position is 1, it indicates that the key is not assigned to the terminal. The meanings represented by the bit values ​​are merely examples and should not constitute limitations on the solution.

[0146] When a key needs to be assigned to a terminal, in an optional example, the requestor indicates to the core network device a key corresponding to each of one or more terminals (including the first terminal) indicated by the first information. For example, the first information further indicates a key corresponding to each of the one or more terminals. In possible examples, the one or more terminals indicated by the first information share one or more keys; the one or more terminals indicated by the first information each correspond to different keys; or terminals of the same type among the one or more terminals indicated by the first information share one or more keys, and terminals of different types correspond to different keys.

[0147] In another optional example, when a key needs to be assigned to a terminal, the requestor does not instruct the core network device on a key corresponding to each of the one or more terminals (including the first terminal) indicated by the first information, and the core network device assigns the corresponding key to the one or more terminals (including the first terminal) indicated by the first information; or the core network device obtains from the operator device a key corresponding to each of the one or more terminals (including the first terminal) indicated by the first information.

[0148] In an example in which the requestor does not indicate to the core network device keys corresponding to each of one or more terminals (including the first terminal) indicated by the first information, the requestor may indicate key requirements to the core network device, and the core network device may assign keys to the terminals based on the key requirements. In a possible implementation, the first information further indicates key requirements. The key requirements may indicate that one or more terminals indicated by the first information share one or more keys, and that the one or more terminals indicated by the first information correspond to different keys, or that terminals of the same type among the one or more terminals indicated by the first information share one or more keys, and that terminals of different types correspond to different keys.

[0149] For example, the first information indicates key requirements by using a package service identifier or a security level service identifier, for example, package service identifier A or security level service identifier A corresponds to the case where terminals correspond to different keys, package service identifier B or security level service identifier B corresponds to the case where all terminals share one or more keys, package service identifier C or security level service identifier C corresponds to the case where terminals of the same type share one or more keys, and terminals of different types correspond to different keys.

[0150] In an example, the value of a bit at one or more specific positions in the plurality of bits occupied by the first information indicates key requirements. For example, when the bit values ​​at two specific positions are 00, it indicates that the terminals correspond to different keys, or indicates package service identifier A or security level service identifier A; when the bit values ​​at two specific positions are 11, it indicates that all terminals share one or more keys, or indicates package service identifier B or security level service identifier B; or when the bit values ​​at two specific positions are 01, it indicates that terminals of the same type share one or more keys, and terminals of different types correspond to different keys, or indicates package service identifier C or security level service identifier C. The meanings represented by the bit values ​​are merely examples and should not constitute limitations on the solution.

[0151] In another example, the key requirements may alternatively be determined by an operator device or a core network device and need not be determined by the requestor. In addition, the operator may further determine the security policy of the terminal, for example, whether authentication is required or not, whether the authentication scheme is one-way or two-way authentication, whether message encryption and / or integrity protection is supported or not, etc.

[0152] Step 302: The core network device obtains an operator identification code assigned to the first terminal by the operator device.

[0153] When the first information indicates that an operator identification code is to be assigned to one or more terminals (including the first terminal), the core network device may determine, based on the first information, one or more terminals (including the first terminal) to which the operator identification code needs to be assigned, and obtain the operator identification code assigned to the one or more terminals by the operator device. The operator device may assign different operator identification codes to different terminals, and the operator identification code may uniquely identify the terminal.

[0154] The operator device and the core network device may be the same device or different devices. If the operator device and the core network device are the same device, the process by the core network device of obtaining the operator identification code assigned to one or more terminals by the operator device includes: the core network device assigning the operator identification code to one or more terminals, or the core network device selecting corresponding operator identification codes for one or more terminals from pre-stored operator identification codes. If the operator device and the core network device are not the same device, the process by the core network device of obtaining the operator identification code assigned to one or more terminals by the operator device includes: the core network device receiving the operator identification code of one or more terminals from the operator device.

[0155] When the first information instructs the core network device to allocate an EPC for terminal management to one or more terminals (including the first terminal), the requestor does not instruct the core network device to allocate an EPC for terminal management corresponding to each of the one or more terminals (including the first terminal) indicated by the first information, and the core network device may further obtain the EPC for terminal management allocated by the operator device to the one or more terminals (including the first terminal).

[0156] The operator device and the core network device may be the same device or different devices. If the operator device and the core network device are the same device, the process of the core network device acquiring the EPC for terminal management assigned to one or more terminals by the operator device includes: the core network device assigning the EPC for terminal management to one or more terminals; or the core network device selecting, for one or more terminals, corresponding EPC for terminal management from pre-stored EPCs for terminal management. If the operator device and the core network device are not the same device, the process of the core network device acquiring the EPC for terminal management assigned to one or more terminals by the operator device includes: the core network device receiving, from the operator device, the EPC for terminal management for one or more terminals.

[0157] When the first information indicates that a key is to be assigned to one or more terminals (including the first terminal) and the requestor does not indicate to the core network device a key corresponding to each of the one or more terminals (including the first terminal) indicated by the first information, the core network device may further obtain keys assigned to the one or more terminals (including the first terminal) by the operator device. Optionally, when the first information further indicates key requirements, the core network device obtains keys assigned to the one or more terminals (including the first terminal) by the operator device based on the key requirements.

[0158] The operator device and the core network device may be the same device or different devices. If the operator device and the core network device are the same device, the process by which the core network device obtains the keys assigned by the operator device to one or more terminals includes: the core network device assigning keys to one or more terminals, or the core network device selecting corresponding keys from pre-stored keys for one or more terminals. If the operator device and the core network device are not the same device, the process by which the core network device obtains the keys assigned by the operator device to one or more terminals includes: the core network device receiving keys of one or more terminals from the operator device.

[0159] Step 303: The core network device sends second information to the first terminal, where the second information instructs the first terminal to store the operator identification code.

[0160] In response, the first terminal receives second information from the core network device.

[0161] The second information instructs the first terminal to store an operator identification code. For example, the second information includes an operator identification code assigned to the first terminal. For example, the second information is a write command.

[0162] In a possible implementation, the operator identification code is stored in a default storage location in the terminal, and the core network device does not need to instruct the terminal about the storage location of the operator identification code, thereby reducing signaling overhead.

[0163] Therefore, in another possible implementation, the core network device may instruct the terminal to store the operator identification code. For example, based on the second information instructing the first terminal to store the operator identification code, the second information may further include first location information for storing the operator identification code. For example, the first location information may indicate a memory bank, such as an EPC memory bank, a reserved memory bank, a TID memory bank, or a user memory bank. The storage locations for storing operator identification codes instructed by the core network device to multiple terminals by the core network device may be the same; or the storage locations for storing operator identification codes instructed by the core network device to terminals of the same type by the core network device may be the same, and the storage locations for storing operator identification codes instructed by the core network device to terminals of different types by the core network device may be different. In a specific implementation, designs may be performed based on different requirements. This is not limited in the present application.

[0164] When the procedure for storing the operator identification code in the terminal is performed, the EPC memory bank of the terminal stores a default EPC stored by the manufacturer of the terminal, or does not store a default EPC (in other words, the requestor has not performed a procedure for storing an EPC assigned to the terminal by the requestor in the terminal). In this case, in the procedure for storing the operator identification code in the terminal, an EPC for terminal management may also be stored in the terminal, and a procedure for storing an EPC for terminal management in the terminal does not need to be performed separately, resulting in reduced signaling exchanges. In a possible implementation, based on the second information instructing the first terminal to store the operator identification code, optionally, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC may be assigned to the first terminal by an operator device or the first EPC is from the requestor. The first EPC is an EPC for terminal management that is assigned to the first terminal by an operator device or a requestor, and the first EPC uniquely identifies the first terminal.

[0165] In a possible implementation, the EPC for terminal management is stored in a default storage location in the terminal, and the core network device does not need to instruct the terminal on the storage location of the EPC, thereby reducing signaling overhead.

[0166] Therefore, in another possible implementation, the core network device may instruct the terminal to store the EPC for terminal management. For example, based on the second information instructing the first terminal to store the first EPC, the second information may further include second location information for storing the first EPC. For example, the second location information may indicate a memory bank, such as an EPC memory bank. The storage locations for storing the EPC instructed by the core network device to multiple terminals by the core network device may be the same; or, the storage locations for storing the EPC instructed by the core network device to the same type of terminals by the core network device may be the same, and the storage locations for storing the EPC instructed by the core network device to different types of terminals by the core network device may be different. In a specific implementation, designs may be performed based on different requirements. This is not limited in the present application.

[0167] Based on the second information instructing the first terminal to store the operator identification code, optionally in a possible implementation, the second information further instructs the first terminal to store a key, for example, the second information includes a key assigned to the first terminal.

[0168] In a possible implementation, the key is stored in a default storage location in the terminal, and the core network device does not need to instruct the terminal about the storage location of the key, thereby reducing signaling overhead.

[0169] In another possible implementation, the core network device may instruct the terminal to store the key. For example, based on the second information instructing the first terminal to store the key, the second information may further include third location information for storing the key. For example, the third location information may indicate a memory bank, such as an EPC memory bank, a reserved memory bank, a TID memory bank, or a user memory bank. The storage locations for storing keys instructed by the core network device to multiple terminals by the core network device may be the same; or the storage locations for storing keys instructed by the core network device to terminals of the same type by the core network device may be the same, and the storage locations for storing keys instructed by the core network device to terminals of different types by the core network device may be different. In a specific implementation, designs may be performed based on different requirements. This is not limited in the present application.

[0170] Step 304: The first terminal stores the operator identification code.

[0171] When the first terminal stores the operator identification code, for example, the first terminal stores the operator identification code in a default storage location; or in another example, the second information includes first location information for storing the operator identification code assigned to the first terminal, and the first terminal stores the operator identification code assigned to the first terminal in a first storage location corresponding to the first location information. In a possible example, the storage location corresponding to the first location information may include a storage location of an EPC in a terminal in the prior art. In this way, the operator identification code may be stored in the storage location of the EPC, and the operator identification code may replace the function of the EPC, and the EPC does not need to be stored in the terminal. If a default EPC is stored in the storage location of the EPC, the operator identification code may overwrite the default EPC.

[0172] When the second information further instructs the first terminal to store a first EPC corresponding to the first terminal, the first terminal may further store the first EPC. The first EPC may be assigned by an operator device or a requestor. The first EPC may overwrite a default EPC.

[0173] When the first terminal stores the first EPC, for example, the first terminal stores the first EPC in a default storage location; or, in another example, the second information includes second location information for storing the first EPC, and the first terminal stores the first EPC in a second storage location corresponding to the second location information. For example, the second location information indicates an EPC memory bank. If the default EPC is stored in the EPC storage location, the first EPC may overwrite the default EPC.

[0174] In the above process, the operator identification code assigned to the terminal by the operator device is stored in the terminal, and the operator can manage the terminal based on the operator identification code. Optionally, the terminal further stores an EPC for terminal management assigned to the terminal by the operator device or the requestor, and the operator device or the requestor can manage the terminal based on the EPC for terminal management.

[0175] When the second information further instructs the first terminal to store a key corresponding to the first terminal, the first terminal may further store the key. The key may be assigned to the first terminal by the operator device or the requestor. When the first terminal stores the key, for example, the first terminal stores the key in a default storage location; or, in another example, the second information includes third location information for storing the key assigned to the first terminal, and the first terminal stores the key assigned to the first terminal in a third storage location corresponding to the third location information. The terminal stores the key assigned to the terminal by the operator device or the requestor, and the operator device or the requestor may perform authentication with the terminal based on the key.

[0176] When the first core network device and the second core network device are different core network devices, information is exchanged between the first core network device and the second core network device. The first core network device may be, for example, an AMF, UDM, TMF, AUSF, NSSAAF, SMF, UPF, PCF, NEF, or UDR, and the second core network device may be, for example, an AMF, UDM, TMF, AUSF, NSSAAF, SMF, UPF, PCF, NEF, or UDR. It may be understood that the first core network device may communicate directly with the second core network device or may communicate with the second core network device through another core network device. The first core network device may communicate directly with the requestor or may communicate with the requestor through another core network device. The second core network device may communicate directly with the terminal / access network device or may communicate with the terminal / access network device through another core network device.

[0177] Referring to the communication procedure in FIG. 3, the following describes the communication procedure when the first core network device and the second core network device are different core network devices.

[0178] Step 301 may be replaced by the following: a requestor sends first information to a first core network device, and in response, the first core network device receives the first information from the requestor.

[0179] Step 302 may be replaced by the following: the first core network device obtains an operator identification code assigned to the first terminal by the operator device.

[0180] A new step is added before step 303: the first core network device sends first instruction information to the second core network device, where the first instruction information instructs the second core network device to write the corresponding operator identification code to one or more terminals (including the first terminal).

[0181] In response, the second core network device receives first indication information from the first core network device.

[0182] The first instruction may be a request to write an operator identification code into the blank tag.

[0183] Based on the first instruction information instructing to write the corresponding operator identification code to one or more terminals (including the first terminal), further optionally, the first instruction information further includes first location information for storing the operator identification code.

[0184] Based on the first instruction information instructing to write the corresponding operator identification code to one or more terminals (including the first terminal), further optionally, the first instruction information further instructs to write the corresponding EPC for terminal management (the EPC for managing the first terminal is referred to as the first EPC) to one or more terminals (including the first terminal), where the EPC for terminal management (including the first EPC) is assigned to the first terminal by the operator device; or the EPC for terminal management (including the first EPC) is from a requestor. In a specific example, the first instruction information includes an association relationship between the operator identification code and the EPC for terminal management, and the operator identification code and the EPC for terminal management assigned to each terminal may be determined based on the association relationship. The first instruction information may be a request to write the operator identification code and the EPC to a blank tag.

[0185] Based on the first instruction information further instructing to write the corresponding first EPC to one or more terminals (including the first terminal), further optionally, the first instruction information further includes second location information for storing the EPC (including the first EPC) for terminal management.

[0186] Based on the first instruction information instructing to write the corresponding operator identification code to one or more terminals (including the first terminal), further optionally, the first instruction information further instructs to write the corresponding key to one or more terminals (including the first terminal). The key is assigned to the first terminal by the operator device, or the key is from a requestor. In a specific example, the first instruction information includes an association relationship between the operator identification code and the key, and the operator identification code and key assigned to each terminal may be determined based on the association relationship. The first instruction information may be a request to write the operator identification code and the key to a blank tag.

[0187] In an optional example, the first instruction information instructs writing a corresponding operator identification code, an EPC for terminal management, and a key to one or more terminals (including the first terminal). For example, the first instruction information includes an association relationship between the operator identification code, the EPC for terminal management, and the key. The operator identification code, the EPC for terminal management, and the key assigned to each terminal may be determined based on the association relationship. The first instruction information may be a request to write the operator identification code, the EPC for terminal management, and the key to a blank tag.

[0188] When the first information sent by the requestor to the first core network device indicates key requirements and the first instruction information instructs writing the corresponding key to one or more terminals (including the first terminal), further optionally, the first instruction information may further indicate the key requirements.

[0189] For example, the first indication information includes a default EPC range, and the default EPC range includes a default EPC of the first terminal. The second core network device determines, based on the default EPC range, that an operator identification code needs to be assigned to the terminal belonging to the default EPC range.

[0190] For example, the first indication information includes one or more default EPCs, and the one or more default EPCs include a default EPC of the first terminal. The second core network device determines, based on the one or more default EPCs, that operator identification codes need to be assigned to the terminals that belong to the one or more default EPCs.

[0191] For example, the first indication information includes one or more target TID types, and the TID of the first terminal belongs to the target TID types. The second core network device determines, based on the one or more target TID types, that an operator identification code needs to be assigned to the terminal whose TID type belongs to the one or more target TID types.

[0192] In conclusion, the first instruction information can be recognized to include one or both of the following: a tag identifier TID type of the first terminal, and a default electronic product code EPC of the first terminal. The second core network device can determine the first terminal, and naturally, can determine further terminals, based on the information included in the first instruction information.

[0193] Optionally, based on the first instruction information instructing to write corresponding operator identification codes to one or more terminals (including the first terminal), the first instruction information may further include a service range, the service range being used to query the access network device.

[0194] Step 303 may be replaced by: the second core network device sends the second information to the first terminal.

[0195] In response, the first terminal receives second information from the second core network device.

[0196] For specific details of the communication procedure, please refer to the description in Fig. 3. The details will not be described again.

[0197] In an optional example, before the core network device (or the second core network device) sends the second information to the first terminal, the core network device (or the second core network device) first sends third information to the access network device, where the third information instructs to search for one or more terminals (including the first terminal) or to obtain a default EPC for one or more terminals (including the first terminal). Correspondingly, the access network device receives the third information from the core network device (or the second core network device). The access network device searches for one or more terminals (including the first terminal) based on the third information (the terminal search may also be understood as terminal selection or terminal filtering), and a first terminal among the one or more discovered terminals accesses the access network device. After the first terminal accesses the access network device, the first terminal sends the default EPC of the first terminal to the core network device (or the second core network device) through the access network device. In response, the core network device (or the second core network device) receives the default EPC from the first terminal, and further transmits second information to the first terminal.

[0198] The third information may be referred to as an inventory command or an inventory request. The third information may instruct one or more terminals in one or more of the following ways:

[0199] For example, the third information includes a default EPC range, and the default EPC range includes a default EPC of the first terminal. Based on the default EPC range, the access network device determines that the default EPC needs to search for a terminal belonging to the default EPC range, or that the default EPC in the default EPC range needs to be obtained.

[0200] For example, the third information includes one or more default EPCs, and the one or more default EPCs include a default EPC of the first terminal. The access network device determines, based on the one or more default EPCs, that terminals belonging to the one or more default EPCs need to be searched for or that the one or more default EPCs need to be obtained.

[0201] For example, the third information includes one or more target TID types, and the TID of the first terminal belongs to the target TID types. The access network device determines, based on the one or more target TID types, that terminals whose TID types belong to the one or more target TID types need to be searched for, or that default EPCs of terminals whose TID types belong to the one or more target TID types need to be obtained.

[0202] In conclusion, the third information may be recognized to include one or both of the following: a tag identifier TID type of the first terminal, and a default electronic product code EPC of the first terminal. The access network device may determine the first terminal based on the third information, and may also determine another terminal.

[0203] In a possible implementation, the process of the access network device searching for one or more terminals (including the first terminal) based on the third information includes: the access network device transmitting radio frequency information to terminals in the coverage area of ​​the access network device based on the third information to provide stimulus signals to the terminals in the coverage area of ​​the access network device, so that the terminals transmit signals to the access network device; the access network device performing a selection operation on the terminals in the coverage area, and selecting one or more terminals by performing the selection operation; and the access network device sending a query command to the selected one or more terminals (including the first terminal) to search for one or more terminals (including the first terminal).

[0204] In a possible implementation, the process of a first terminal among one or more discovered terminals accessing an access network device includes: one or more terminals initiating a random access procedure after receiving a query command, wherein one terminal (i.e., the first terminal) successfully performs random access, in other words, accesses the access network device.

[0205] In a possible implementation, the random access procedure may be as follows: after receiving a query command, one or more terminals separately send random numbers to the access network device, the access network device can accurately receive the random numbers and accurately feed back the received random numbers to the terminals, and the terminals that send the random numbers determine that the random access is successful.

[0206] Optionally, the query command sent by the access network device to one or more terminals includes TID types of one or more terminals or default EPCs of one or more terminals. After receiving the query command, the one or more terminals may match the TID types in the query command with the TID types of the terminals, or match the default EPC in the query command with the default EPC of the terminals, and after the matching is successful, initiate a random access procedure (e.g., send a random number to the access network device). Of course, the first terminal may also first initiate a random access procedure, and after the random access is successful and before the default EPC of the first terminal is sent to the core network device, the first terminal performs a process of matching the information in the query command with the information of the first terminal, and after the matching is successful, sending the default EPC of the first terminal to the core network device.

[0207] In a possible implementation, the first terminal sending the default EPC of the first terminal to the core network device (or the second core network device) includes: the first terminal sending a request message to the core network device (or the second core network device) through the access network device, where the request message includes the default EPC of the first terminal. The access network device may send the request message transparently. The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0208] Referring to the communication system shown in Fig. 1b, Fig. 4 is a diagram of a specific communication procedure for storing an operator identification code in a first terminal. In the communication procedure, an example is used in which the requestor is an AF, the first core network device is a UDM, and the second core network device is a TMF. The UDM and the AF may communicate with each other directly or through another core network device (e.g., a NEF).

[0209] Step 401: The AF sends first information to the UDM, where the first information indicates one or more terminals, and the one or more terminals includes the first terminal.

[0210] In response, the UDM receives the first information from the AF.

[0211] The AF may send the first information directly to the UDM, or may send the first information to the UDM through another core network device (eg, a NEF).

[0212] For the process of step 401, please refer to the process of step 301. The details will not be described again.

[0213] Step 402: After the AF (which may be understood as a company) pays the operator, the subscription may be considered successful, and the UDM assigns a company code to the AF, where the company code uniquely identifies the AF.

[0214] The company code may be replaced by an application code or a service code.

[0215] Step 403a: The UDM obtains an operator identification code assigned to one or more terminal devices by an operator device.

[0216] After receiving the first information from the AF, the UDM may obtain operator identification codes assigned to one or more terminal devices by the operator device. For example, the UDM may assign corresponding operator identification codes to one or more terminals that need to store the operator identification codes, where different operator identification codes are assigned to different terminals. Naturally, the UDM may obtain operator identification codes corresponding to one or more terminals from the operator device. For a specific process, please refer to the process of the core network device obtaining the operator identification code assigned to the first terminal by the operator device described in step 302.

[0217] When the first information sent by the AF to the UDM in step 401 instructs to allocate an EPC for terminal management to one or more terminals (including the first terminal) and the first information does not include an EPC for terminal management for each of the one or more terminals (including the first terminal), the UDM may further acquire an EPC for terminal management allocated to one or more terminals (including the first terminal) by the operator device. For a specific process, see step 302 in which a core network device acquires an EPC for terminal management allocated to one or more terminals (including the first terminal) by the operator device. Different terminals correspond to different EPCs for terminal management.

[0218] When the first information sent by the AF to the UDM in step 401 instructs to allocate keys to one or more terminals (including the first terminal), and the first information does not include keys corresponding to each of the one or more terminals (including the first terminal), the UDM may further obtain keys allocated to one or more terminals (including the first terminal) by the operator device, and the keys corresponding to different terminals may be different or the same. For a specific process, please refer to step 302 in which the core network device obtains keys allocated to one or more terminals (including the first terminal) by the operator device.

[0219] A particular example will be described by using an example in which the UDM obtains keys corresponding to one or more terminals (including the first terminal).

[0220] The UDM may check whether keys corresponding to one or more terminals are stored locally. If the keys are stored, the UDM may use the keys directly. If the keys are not stored locally, the UDM requests information about the key-storing network element (such as address information) from the NRF. The network element storing the key information registers with the NRF. Thus, the NRF knows the network element storing the key information.

[0221] The NRF sends information about the key-storing network element to the UDM. In response, the UDM receives the information about the key-storing network element sent by the NRF. The network element may be, for example, a UDR or an AUSF.

[0222] The UDM requests keys corresponding to one or more terminals indicated by the first information from a key storage network element based on the information about the network element. For example, the UDM sends a request message to the key storage network element, where the request message is used to request one or more keys. Optionally, the request message may further indicate key requirements, and the key storage network element may assign corresponding keys to one or more terminals based on the key requirements. Optionally, the request message may further indicate a default EPC code range and / or a TID type.

[0223] The key storage network element sends keys corresponding to one or more terminals to the UDM, and in response, the UDM receives the keys corresponding to one or more terminals sent by the key storage network element.

[0224] In a particular example, both the operator identification code and the key can be obtained from a key storage network element. For example, the UDM sends a request message to the key storage network element, where the request message is used to request the operator identification code and the key corresponding to one or more terminals. The key storage network element sends the operator identification code and the key corresponding to each of the one or more terminals to the UDM. In response, the UDM receives the operator identification code and the key corresponding to each of the one or more terminals sent by the key storage network element.

[0225] For each terminal indicated by the first information from the AF, the UDM stores a mapping relationship between an operator identification code and a key assigned to the terminal. Further, optionally, for each terminal indicated by the first information from the AF, the UDM stores a mapping relationship between an operator identification code, an EPC for terminal management, and a key assigned to the terminal.

[0226] Step 403: The UDM sends first instruction information to the TMF, where the first instruction information instructs the TMF to write corresponding operator identification codes to one or more terminals (including the first terminal).

[0227] In response, the TMF receives the first indication information from the UDM.

[0228] Further, optionally, the first instruction information further includes first location information for storing an operator identification code.

[0229] Optionally, the first instruction information further instructs writing corresponding EPCs for terminal management to one or more terminals (including the first terminal). Further, optionally, the first instruction information further includes second location information for storing EPCs for terminal management (including the first EPC).

[0230] Optionally, the first instruction information further instructs writing the corresponding key to one or more terminals (including the first terminal). Further, optionally, the first instruction information further includes third location information for storing the key. Further, optionally, the first instruction information further includes requirements for the key.

[0231] For the process of step 403, please refer to the above process of the first core network device sending the first indication information to the second core network device, and the details will not be described again.

[0232] It may be understood that the operator identification code writing procedure may be performed separately for different types of terminals; or the operator identification code writing procedure may be performed simultaneously for multiple types of terminals. The procedure for writing the EPC for terminal management may be performed separately for different types of terminals; or the procedure for writing the EPC for terminal management may be performed simultaneously for multiple types of terminals. The key writing procedure may be performed separately for different types of terminals, or the key writing procedure may be performed simultaneously for multiple types of terminals.

[0233] Step 404: The TMF determines an access network device based on the service range.

[0234] When the first instruction information instructs to write corresponding operator identification codes and EPCs for terminal management to one or more terminals (including the first terminal), the TMF stores the association relationship between the operator identification codes and EPCs for terminal management.

[0235] If the first instruction information instructs to write the corresponding operator identification code and key to one or more terminals (including the first terminal), the TMF stores the association relationship between the operator identification code and the key.

[0236] When the first instruction information instructs to write the corresponding operator identification code, EPC for terminal management, and key to one or more terminals (including the first terminal), the TMF stores the association relationship between the operator identification code, EPC for terminal management, and key.

[0237] Step 405: The TMF sends third information to the access network device determined in step 404, where the third information instructs the access network device to search for one or more terminals (including the first terminal).

[0238] In response, the access network device receives third information from the TMF.

[0239] For the process of step 405, please refer to the above process of the second core network device sending the third information to the access network device, and the details will not be described again.

[0240] Step 406: The access network device searches for one or more terminals (including the first terminal) based on the third information.

[0241] Terminal searching can also be understood as terminal selection or terminal filtering.

[0242] For the process of step 406, please refer to the above process in which the access network device searches for one or more terminals (including the first terminal) based on the third information.

[0243] For example, the access network device transmits radio frequency information to terminals in the coverage area of ​​the access network device based on the third information to provide stimulus signals to the terminals in the coverage area of ​​the access network device, so that the terminals transmit signals to the access network device. The access network device performs a selection operation on the terminals in the coverage area to select one or more terminals by performing the selection operation. Further, the access network device transmits a query command to the selected one or more terminals (including the first terminal) to search for one or more terminals (including the first terminal).

[0244] Optionally, the query command sent by the access network device to the one or more terminals includes TID types of the one or more terminals or default EPCs of the one or more terminals.

[0245] Step 407: A first terminal in the one or more discovered terminals accesses the access network device.

[0246] For the process of step 407, please refer to the above process of the first terminal among one or more discovered terminals accessing the access network device.

[0247] For example, after receiving the query command, one or more terminals initiate a random access procedure, and one terminal (i.e., the first terminal) successfully performs random access, in other words, accesses the access network device.

[0248] Optionally, the query command sent by the access network device to one or more terminals includes TID types of the one or more terminals or default EPCs of the one or more terminals. After receiving the query command, the one or more terminals may match the TID types in the query command with the TID types of the terminals, or match the default EPC in the query command with the default EPC of the terminals, and initiate a random access procedure after the matching is successful.

[0249] After receiving the query command, one or more terminals may match the TID type in the query command with the terminal's TOD type, or match the default EPC in the query command with the terminal's default EPC, and initiate a random access procedure after the matching is successful. Of course, the first terminal may alternatively initiate the random access procedure first. After the random access is successful, before step 408, the first terminal matches the information in the query command with the first terminal's information. After the matching is successful, step 408 is executed.

[0250] Step 408: The first terminal sends a request message to the access network device.

[0251] In response, the access network device receives a request message from the first terminal.

[0252] Optionally, the request message includes a default EPC of the first terminal.

[0253] The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0254] Step 409: The access network device transparently sends the request message to the TMF.

[0255] Step 410: The TMF sends a response message to the first terminal.

[0256] In response, the first terminal receives a response message from the TMF.

[0257] The response message may be a registration acceptance message, an indication information indicating that the first terminal has successfully accessed, an access success message, a response message for successful network access, or a response message for successful network registration, where the name of the response message is not limited in this application.

[0258] For example, the TMF transparently transmits the response message to the first terminal through the access network device.

[0259] Step 411: The TMF sends second information to the first terminal, where the second information instructs the first terminal to store the operator identification code.

[0260] In response, the first terminal receives second information from the core network device.

[0261] Based on the second information instructing the first terminal to store the operator identification code, optionally, the second information further includes first location information for storing the operator identification code.

[0262] Optionally, the second information further instructs the first terminal to store the first EPC. Further, optionally, the second information further includes second location information for storing the first EPC.

[0263] Optionally, the second information further instructs the first terminal to store the key. Further, optionally, the second information further includes third location information for storing the key.

[0264] For the process of step 411, please refer to the process of step 303. The details will not be described again.

[0265] Step 412: The first terminal stores the operator identification code assigned to the first terminal.

[0266] Optionally, the first terminal may further store the first EPC assigned to the first terminal.

[0267] Optionally, the first terminal may further store a key assigned to the first terminal.

[0268] For the process of step 412, please refer to the process of step 304. The details will not be described again.

[0269] Step 413: The first terminal sends a storage success indication to the TMF.

[0270] In response, the TMF receives a storage success indication from the first terminal.

[0271] In certain examples, the indication may indicate successful storage of one or more of the operator identification code, the first EPC, and the key.

[0272] A successful save may be replaced with a successful write, a successful print, a successful inventory, or the like.

[0273] Step 414: The TMF sends instruction information for the next terminal inventory to the access network device.

[0274] In response, the access network device receives indication information about the next terminal inventory from the TMF.

[0275] Inventory may be understood as an operator identification code being written to the terminal (stored in it or printed by it), and optionally further as an EPC and / or keys for terminal management being written to the terminal.

[0276] If not all terminals indicated by the third information are inventoried in step 405, steps 406 to 414 are repeatedly executed; or if all terminals indicated by the third information are inventoried in step 405, step 415 is executed.

[0277] To determine whether all terminals have been inventoried, in a possible implementation, the access network device may consider all terminals to be inventoried when it determines that a preset number of terminals have been inventoried. For example, if there are 2,000 matched terminals in the coverage area of ​​the access network device and the core network device needs to print only 1,000 terminals, the access network device may determine that the inventory is complete after determining that 1,000 terminals have been inventoried. In another possible implementation, the access network device may determine that the inventory is complete if it determines that a terminal does not respond. For example, if the core network device needs to print 1,000 terminals, 1,000 terminals are deployed in the coverage area of ​​the access network device. When it determines that a terminal does not respond, the access network device may determine that 1,000 terminals have been inventoried.

[0278] Step 415: The access network device sends inventory completion indication information to the TMF.

[0279] Inventory completion may be replaced by a successful save, a successful write, a successful print, or the like.

[0280] In a particular example, the instruction information may indicate that one or more of the operator identification code, the EPC for terminal management, and the key have been successfully saved (or successfully written, or successfully printed).

[0281] Step 416: The TMF sends the write completion indication information to the UDM.

[0282] Step 417: The UDM sends the write completion indication information to the AF.

[0283] In a particular example, the instruction information may indicate that one or more of an operator identification code, an EPC for terminal management, and a key are to be written.

[0284] Write completion may be replaced with write success, inventory completion, subscription success, print success, or the like.

[0285] Optionally, step 417 includes assigning one or more of the following items to one or more (including the first terminal): EPC code (EPC for terminal management, not default EPC) range, operator identification code, and key.

[0286] In a scenario in which a key is written to a terminal, the UDM receives first information from the AF, where the first information instructs to assign a key to one or more terminals (including the first terminal), and when the first information does not include a key corresponding to each of the one or more terminals (including the first terminal), in step 403a of the example in Figure 4, after recognizing a key storage network element through the NRF, the UDM obtains keys corresponding to the one or more terminals (including the first terminal) from the key storage network element and sends the keys corresponding to the one or more terminals to the TMF. In addition, there may be other possible implementations.

[0287] In possible implementation a, the UDM recognizes information about the key storage network element through the NRF and sends the information about the key storage network element to the TMF, and the TMF then obtains keys corresponding to one or more terminals from the key storage network element (including the first terminal) based on the information about the key storage network element.

[0288] In possible implementation b, the UDM indicates that the TMF needs to print keys for one or more terminals. The TMF then learns information about key storage network elements through the NRF. The TMF then obtains keys corresponding to one or more terminals from the key storage network elements (including the first terminal) based on the information about the key storage network elements.

[0289] Referring to implementations a and b described above, the TMF obtains keys corresponding to one or more terminals (including the first terminal) from a key storage network element. In this example, there are multiple implementations.

[0290] In possible implementation c, before the TMF receives the request message from the first terminal (e.g., step 408 and step 409), the TMF obtains keys corresponding to one or more terminals (including the first terminal) from a key storage network element. This method can be understood as keys corresponding to one or more terminals (including the first terminal) being obtained in batches from a key storage network element before any one of the one or more terminals is discovered.

[0291] In possible implementation d, after the TMF receives the request message from the first terminal (e.g., step 408 and step 409), the TMF obtains keys corresponding to one or more terminals (including the first terminal) from a key storage network element. This method can be understood as keys corresponding to one or more terminals (including the first terminal) being obtained in batches from a key storage network element when the first terminal (i.e., the first terminal) among the one or more terminals is discovered.

[0292] In possible implementation d, after the TMF receives the request message from the first terminal (e.g., step 408 and step 409), the TMF obtains the key corresponding to the first terminal from the key storage network element. This method can be understood as when any terminal is discovered, the key corresponding to the terminal is discovered from the key storage network element.

[0293] In the above-described examples in FIG. 4 and other possible implementations a, b, c, and d, an example in which the first core network device is a UDM will be described. In another example, the first core network device may alternatively be a NEF. For other details, please still refer to the description of the example in FIG. 4 and other possible implementations a, b, c, and d. The details will not be described again.

[0294] In addition, to write the three pieces of information, i.e., the operator identification code, the EPC for terminal management, and the key, to one or more terminals, in this embodiment of the present application, the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in one procedure; the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in three procedures; or any two of the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in one procedure, and the remaining one of the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in another procedure.

[0295] After the operator identification code is stored in the terminal, the operator may manage the terminal based on the operator identification code. Optionally, after the EPC for terminal management is stored in the terminal, the operator or the requestor may manage the terminal based on the EPC for terminal management (all EPCs described in the following examples are EPCs used for terminal management, not default EPCs). With reference to Figures 5, 6 and 7, the following describes a process in which an operator manages a terminal. An example will be described in which the first core network device (a core network device communicating with the requestor) and the second core network device (a core network device communicating with the terminal / access network device) are integrated, and the first core network device and the second core network device are collectively referred to as core network devices. Alternatively, an example will be described in which the first core network device and the second core network device are the same, and the first core network device and the second core network device are simply referred to as core network devices.

[0296] 5 is a possible flowchart of communication for an operator to manage a terminal according to an embodiment of the present application. In FIG. 5, the capability of the first terminal is to report an EPC by default. After accessing an access network device (e.g., successful random access), the first terminal may actively transmit the first EPC assigned to the first terminal. After obtaining the first EPC of the first terminal, the core network device may request an operator identification code assigned to the first terminal based on the first EPC of the first terminal.

[0297] Step 501: A requestor sends fourth information to a core network device, where the fourth information indicates one or more terminals (including the first terminal).

[0298] In response, the core network device receives fourth information from the requestor.

[0299] It may be understood that in addition to indicating the first terminal, the fourth information may indicate another terminal. The core network device may determine one or more terminals that need to be managed based on the fourth information, where the one or more terminals that need to be managed include the first terminal. Management may be understood as performing authentication on the terminal based on the operator identification code, and may optionally be further understood as performing an operation on the terminal. The process of managing all terminals is similar. In the example of Figure 5, an example in which only the first terminal is managed will be used for explanation.

[0300] The fourth information may indicate to the first terminal in one or more of the following manners:

[0301] For example, the fourth information includes an EPC range, and the EPC range includes a first EPC of the first terminal. The fourth information can be understood as an EPC range that needs to be managed and is sent by the requestor to the core network device. The core network device determines, based on the EPC range, that the terminal whose EPC belongs to the EPC range needs to be managed.

[0302] For example, the fourth information may include one or more EPCs, and the one or more EPCs may include a first EPC of the first terminal. The fourth information may be understood as one or more EPCs that need to be managed and are indicated to the core network device by the requestor. The core network device determines, based on the one or more EPCs, that the terminals belonging to the one or more EPCs need to be managed.

[0303] For example, the fourth information includes one or more target TID types, and the TID of the first terminal belongs to the target TID types. The fourth information can be understood as one or more target TID types that need to be managed and are indicated to the core network device by the requestor. The core network device determines, based on the one or more target TID types, that the terminals whose TID types belong to the one or more target TID types need to be managed.

[0304] For example, the fourth information includes information about a requestor. The information about the requestor may indicate an EPC range or one or more EPCs corresponding to (or managed by) the requestor. The EPC range or one or more EPCs corresponding to (or managed by) the requestor include a first EPC of a first terminal. Based on the information about the requestor, the core network device may determine terminals belonging to the EPC range or one or more EPCs corresponding to (or managed by) the requestor whose EPCs need to be managed.

[0305] For information about the requestor, please refer to the description of step 301. The details will not be described again.

[0306] The EPC range or one or more EPCs corresponding to (or managed by) the requestor may be stored or configured on the core network device, or may be stored or configured on another core network device. The core network device may send information about the requestor to the other core network device, and the other core network device may obtain the EPC range or one or more EPCs corresponding to (or managed by) the requestor based on the information about the requestor and send the EPC range or one or more EPCs to the core network device. For example, the other core network device may include a core network device such as a UDM, UDR, AUSF, NEF, PCF, SMF, TMF, or NSSAAF.

[0307] In conclusion, it can be recognized that the fourth information includes one or more of the following: a tag identifier TID type of the first terminal, a first electronic product code EPC of the first terminal, and information about the requestor. The core network device can determine the first terminal based on the first information, and naturally can further determine another terminal.

[0308] In a possible implementation, the first information may instruct one or more terminals (including the first terminal) to perform a first operation. The first operation may be an operation of obtaining an identifier of the first terminal (which may also be referred to as an inventory operation, stock check operation, or inventory), a read operation, a write operation, a delete operation, an encryption operation, an access operation, a block write operation, a block erase operation, a kill operation, or the like. For example, the first information includes information about the first operation, and the information about the first operation instructs the first operation. Further, optionally, the first information further includes operation parameters corresponding to the first operation. For example, operation parameters corresponding to a read operation may include a memory bank to be read, a starting byte address of the memory bank to be read, the number of bytes in the memory bank to be read, and the like. Operation parameters corresponding to a write operation may include a write memory bank, a starting byte of the memory bank to be read, and write data. In addition, the operation of obtaining an identifier of the first terminal (which may also be referred to as an inventory operation, stock check operation, or inventory) may not be retained in the first information. For example, when the first information does not include the first operation, it may indicate that the first information is used to obtain an identifier of the first terminal.

[0309] Optionally, based on the indication of the fourth information, the first terminal may further include a service range. For example, the service range includes target area information A, where the target area information A indicates an area corresponding to one or more terminals to which an operator identification code needs to be assigned. For example, the target area information A may be a geographical location, a city / town location, or 3GPP location information (such as a tracking area (TA) list or a cell list) corresponding to one or more terminals to which an operator identification code needs to be assigned. The service range is used to query an access network device.

[0310] Step 502: The core network device sends fifth information to the access network device, where the fifth information instructs to search for one or more terminals (including the first terminal).

[0311] In response, the access network device receives fifth information from the core network device.

[0312] It can be understood that in addition to the instruction to search for the first terminal, the fifth information can further instruct to search for another terminal. The access network device can determine one or more terminals that need to be searched based on the fifth information, where the one or more terminals that need to be searched include the first terminal.

[0313] The fifth information may be referred to as an inventory request or an inventory request. The fifth information may instruct the first terminal in one or more of the following ways:

[0314] For example, the fifth information includes an EPC range, and the EPC range includes the EPC of the first terminal. The access network device determines, based on the EPC range, that the terminal whose EPC belongs to the EPC range needs to be searched.

[0315] For example, the fifth information includes one or more EPCs, and the one or more EPCs include an EPC of the first terminal. The access network device determines, based on the one or more EPCs, that terminals to which the EPC belongs need to be searched.

[0316] For example, the fifth information includes one or more target TID types, and the TID of the first terminal belongs to the target TID types. The access network device determines, based on the one or more target TID types, that terminals whose TID types belong to the one or more target TID types need to be searched for.

[0317] For example, the fifth information includes operator identification codes associated with EPCs for terminal management of one or more terminals (including the operator identification code associated with the first EPC of the first terminal), and the access network device determines, based on the one or more operator identification codes, that terminals whose operator identification codes belong to the one or more operator identification codes need to be searched for.

[0318] For example, when the fourth information includes information about the requestor (the requestor manages one or more terminals (including the first terminal)), the core network device may determine public land mobile network identifiers (PLMN IDs) assigned to one or more terminals (including the first terminal) based on the information about the requestor, and the fifth information includes the PLMN IDs assigned to the one or more terminals (including the first terminal). Further, optionally, the core network device determines enterprise identifiers assigned to one or more terminals (including the first terminal) based on the information about the requestor, where the fifth information further includes the enterprise identifiers assigned to the one or more terminals (including the first terminal). The enterprise identifier is an enterprise code, an application code, or a service code assigned to the first terminal by the operator device (see step 402); or the enterprise identifier is a service identifier in the CompanyPrefix in the EPC memory bank of the one or more terminals (including the first terminal). The enterprise identifier can also be replaced with a service identifier or an application identifier. It can be understood that the enterprise identifier, application identifier, and service identifier can uniquely identify the type of terminal. The definition of "type" can be flexible. For example, an enterprise is a type, a department or departments of an enterprise are a type, a service is a type, and multiple services are types. The names of the enterprise identifier, application identifier, and service identifier should not limit the scenario.

[0319] In a particular example, when the fifth information includes a PLMN ID and an enterprise identifier, the EPC may be optional. When an EPC is not included, the fifth information may be understood to instruct a search for all EPCs managed by the enterprise corresponding to the enterprise identifier. When an EPC is included, the fifth information may be understood to instruct a search for EPCs that match the EPC included in the fifth information and are managed by the enterprise corresponding to the enterprise identifier.

[0320] In conclusion, it can be recognized that the fifth information includes one or more of the following: a tag identifier TID type of the first terminal, a first EPC of the first terminal, an operator identification code associated with the first EPC of the first terminal, a PLMN ID assigned to the first terminal, and an enterprise identifier assigned to the first terminal. The access network device can determine the first terminal based on the fifth information, and of course, can further determine another terminal.

[0321] Step 503: The access network device searches for one or more terminals (including the first terminal) based on the fifth information.

[0322] Terminal searching can also be understood as terminal selection or terminal filtering.

[0323] In a possible implementation, the process of the access network device searching for one or more terminals (including the first terminal) based on the fifth information includes: the access network device transmitting radio frequency information to terminals in a coverage area of ​​the access network device based on the fifth information to provide stimulus signals to the terminals in the coverage area of ​​the access network device, so that the terminals transmit signals to the access network device; the access network device performing a selection operation on the terminals in the coverage area, and selecting one or more terminals by performing the selection operation; and the access network device sending a query command to the selected one or more terminals (including the first terminal) to search for one or more terminals (including the first terminal).

[0324] Optionally, the query command sent by the access network device to the one or more terminals includes one or more of the following: TID types of the one or more terminals, EPCs of the one or more terminals, operator identification codes associated with the EPCs of the one or more terminals, PLMN IDs assigned to the one or more terminals, and enterprise identifiers assigned to the one or more terminals.

[0325] Step 504: A first terminal in the one or more discovered terminals accesses the access network device.

[0326] In a possible implementation, the process of a first terminal among one or more discovered terminals accessing an access network device includes: one or more terminals initiating a random access procedure after receiving a query command, wherein one terminal (i.e., the first terminal) successfully performs random access, in other words, accesses the access network device.

[0327] In a possible implementation, the random access procedure may be as follows: after receiving a query command, one or more terminals separately send random numbers to the access network device, the access network device can accurately receive the random numbers and accurately feed back the received random numbers to the terminals, and the terminals that send the random numbers determine that the random access is successful.

[0328] Optionally, the query command sent by the access network device to the one or more terminals includes one or more of the following: TID types of the one or more terminals, EPCs of the one or more terminals, operator identification codes associated with the EPCs of the one or more terminals, PLMN IDs assigned to the one or more terminals, and enterprise identifiers assigned to the one or more terminals. After receiving the query command, the terminal may match the information in the query command with the information of the terminal. After the matching is successful, the terminal initiates a random access procedure (e.g., sends a random number to the access network device). Of course, the first terminal may alternatively initiate the random access procedure first. After the random access is successful, before step 505, the first terminal matches the information in the query command with the information of the first terminal. After the matching is successful, step 505 is executed.

[0329] Step 505: The first terminal sends a first EPC allocated to the first terminal to the core network device.

[0330] In response, the core network device receives a first EPC assigned to the first terminal.

[0331] When the capability of the first terminal is to report an EPC by default, after accessing an access network device (e.g., successfully completing random access), the first terminal may actively transmit the first EPC assigned to the first terminal to the core network device through the access network device.

[0332] In a possible implementation, the first terminal transmitting the first EPC assigned to the first terminal to the core network device includes: the first terminal transmitting a request message to the core network device through the access network device, where the request message includes the first EPC assigned to the first terminal. The access network device transparently transmits the request message. The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0333] Step 506: Based on the subscription information of the first EPC and the first terminal, the core network device may determine that the operator or requestor needs to perform authentication to the first EPC and then perform step 507.

[0334] If it determines that authentication does not need to be performed for the first EPC, the core network device may not need to perform step 507.

[0335] The subscription information includes information about whether authentication needs to be performed for the EPC.

[0336] Step 506 is an optional step and may not be performed.

[0337] Step 507: The core network device triggers authentication between the first terminal and the operator device or the requestor based on the first EPC. Step 507 is an optional step and may not be performed.

[0338] Step 508: The core network device may determine that the first EPC is associated with the operator identification code, and then perform step 509.

[0339] If the first EPC is not associated with the operator identification code, step 509 may not be performed. For example, in step 404, the TMF stores the association relationship between the operator identification code and the EPC for terminal management.

[0340] Step 508 is an optional step and may not be performed.

[0341] Step 509: The core network device requests the first terminal to obtain an operator identification code assigned to the first terminal based on the first EPC.

[0342] Correspondingly, the first terminal receives a request from the core network device to request the first terminal to obtain an operator identification code assigned to the first terminal based on the first EPC.

[0343] In a possible implementation, the core network device sends a request to the first terminal to obtain an operator identification code assigned to the first terminal, and in response, the first terminal receives a request from the core network device to obtain an operator identification code assigned to the first terminal, where the request includes the EPC of the first terminal.

[0344] The order of steps 506, 507, 508, and 509 is not limited.

[0345] Step 510: The first terminal sends an operator identification code assigned to the first terminal to the core network device.

[0346] In response, the core network device receives an operator identification code assigned to the first terminal.

[0347] Step 511: The core network device may determine, based on the operator identification code and the subscription information of the first terminal, that the operator needs to perform authentication on the operator identification code. The subscription information includes information about whether authentication needs to be performed on the operator identification code.

[0348] Step 511 is an optional step and may not be performed.

[0349] Step 512: The core network device triggers authentication between the first terminal and the operator device based on the operator identification code.

[0350] Authentication based on the operator identification code can be understood as follows: in an authentication procedure between a terminal and an operator device, the parameters used for authentication (random number, check value, ciphertext information) and the operator identification code are in the same message. In this way, it can be determined that authentication is performed for the terminal identified by the operator identification code. Alternatively, the terminal is first determined as a unique terminal based on the operator identification code. In the authentication procedure, it can be determined that authentication is performed for the terminal identified by the operator identification code, even if the message carrying the authentication parameters (random number, check value, and ciphertext information) does not carry the operator identification code.

[0351] 6 is a possible flowchart of communication when an operator manages a terminal according to an embodiment of the present application. In FIG. 6, the capability of the first terminal is to report an EPC by default. After accessing an access network device (e.g., successful random access), the first terminal may actively transmit a first EPC assigned to the first terminal. In the process of searching for the first terminal, the access network device instructs the first terminal to transmit an operator identification code assigned to the first terminal. In this way, after accessing an access network device (e.g., successful random access), the first terminal may transmit an operator identification code assigned to the first terminal.

[0352] Step 601: A requestor sends fourth information to a core network device, where the fourth information indicates one or more terminals (including the first terminal).

[0353] In response, the core network device receives fourth information from the requestor.

[0354] For the process of step 601, please refer to the process of step 501. The details will not be described again.

[0355] Step 602: The core network device sends fifth information to the access network device, where the fifth information instructs the core network device to search for one or more terminals (including the first terminal) and to request to obtain operator identification codes assigned to the one or more terminals (including the first terminal).

[0356] In response, the access network device receives fifth information from the core network device.

[0357] For the process of step 602, please refer to the process of step 502. Based on this, the fifth information may instruct to request to obtain operator identification codes assigned to one or more terminals (including the first terminal) by using a specific information format, or the fifth information includes instruction information for requesting to obtain operator identification codes, thereby instructing the access network device to request to obtain operator identification codes assigned to one or more terminals (including the first terminal).

[0358] The instruction information for requesting acquisition of the operator identification code may occupy one or more bits, and the value of the bit indicates a request to acquire the operator identification code. For example, when the value of one bit at a particular position is expanded or the value of the bit is set to 1, it indicates that the operator identification code should be acquired; when the value of the bit at that position is 0 or set to 0, it indicates that the operator identification code should not be acquired.

[0359] The instruction to request obtaining an operator identification code may be considered a mark of SUPI replication or a mark of SUPI-like replication.

[0360] Optionally, before performing step 602, the core network device may determine that an operator needs to perform authentication for one or more terminals. In this case, the fifth information may indicate a request to obtain an operator identification code assigned to the first terminal. If an operator does not need to perform authentication, the fifth information may not indicate a request to obtain an operator identification code assigned to the first terminal.

[0361] Step 603: The access network device searches for one or more terminals (including the first terminal) based on the fifth information, and instructs the one or more terminals (including the first terminal) to transmit operator identification codes assigned to the terminals.

[0362] Terminal searching can also be understood as terminal selection or terminal filtering.

[0363] For the process in which the access network device searches for one or more terminals (including the first terminal) based on the fifth information, please refer to the description of step 503. The details will not be described again.

[0364] Optionally, the query command sent by the access network device to the one or more terminals must further include instruction information for transmitting an operator identification code assigned to the terminal, to instruct the terminal to transmit the operator identification code assigned to the terminal.

[0365] The instruction information for transmitting the operator identification code may occupy one bit or even more bits, and the value of the bit indicates a request to obtain the operator identification code. For example, when the value of the bit in a position is 1 or is set to 1, it indicates to obtain the operator identification code; when the value is 0 or is set to 0, it indicates not to obtain the operator identification code.

[0366] The instruction to request obtaining an operator identification code may be considered a mark of SUPI replication or a mark of SUPI-like replication.

[0367] Step 604: A first terminal in the one or more discovered terminals accesses the access network device.

[0368] For the process of step 604, please refer to the description of step 504. The details will not be described again.

[0369] Step 605: The first terminal sends an operator identification code and a first EPC assigned to the first terminal to the core network device.

[0370] In response, the core network device receives an operator identification code and a first EPC assigned to the first terminal.

[0371] The capability of the first terminal is to report to the EPC by default. After accessing the access network device (e.g., successful random access), the first terminal may actively transmit the first EPC assigned to the first terminal. In the process of searching for the first terminal, the access network device instructs the first terminal to transmit the operator identification code assigned to the first terminal. In this way, after accessing the access network device (e.g., successful random access), the first terminal may transmit the operator identification code assigned to the first terminal.

[0372] In a possible implementation, the first terminal transmitting the operator identification code and the first EPC assigned to the first terminal to the core network device includes: the first terminal transmitting a request message to the core network device through the access network device, where the request message includes the operator identification code and the first EPC assigned to the first terminal. The access network device transparently transmits the request message. The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0373] Step 606: The core network device may determine, based on the operator identification code and the subscription information of the first terminal, that the operator needs to perform authentication on the operator identification code. The subscription information includes information about whether authentication needs to be performed on the operator identification code.

[0374] Step 606 is an optional step and may not be performed.

[0375] Step 607: The core network device triggers authentication between the first terminal and the operator device based on the operator identification code.

[0376] For the process of step 607, please refer to the process of step 512. The details will not be described again.

[0377] Step 608: Based on the subscription information of the first EPC and the first terminal, the core network device may determine that the operator or requestor needs to perform authentication to the first EPC and then perform step 609.

[0378] If it determines that authentication does not need to be performed for the first EPC, the core network device may not need to perform step 600. The subscription information includes information about whether authentication needs to be performed for an EPC.

[0379] Step 609: The core network device triggers authentication between the first terminal and the operator device or requestor based on the first EPC of the first terminal.

[0380] Step 609 is an optional step and may not be performed.

[0381] The order of steps 606, 607, 608, and 609 is not limited.

[0382] 7 is a possible flowchart for an operator to manage a terminal according to an embodiment of the present application. In FIG. 6, the capability of the first terminal is to report an operator identification code by default. After accessing an access network device (e.g., successfully random accessing), the first terminal can actively transmit to the operator identification code assigned to the first terminal.

[0383] Step 701: A requestor sends fourth information to a core network device, where the fourth information indicates a first terminal.

[0384] In response, the core network device receives fourth information from the requestor.

[0385] For step 701, please refer to the description of step 501. Details will not be described again.

[0386] Step 702: The core network device sends fifth information to the access network device, where the fifth information instructs to search for one or more terminals (including the first terminal).

[0387] In response, the access network device receives fifth information from the core network device.

[0388] For step 702, please refer to the description of step 502. Details will not be described again.

[0389] Step 703: The access network device searches for one or more terminals (including the first terminal) based on the fifth information.

[0390] For step 703, please refer to the description of step 503. Details will not be described again.

[0391] Step 704: A first terminal in the one or more discovered terminals accesses the access network device.

[0392] For the process of step 704, please refer to the description of step 504. The details will not be described again.

[0393] Step 705: The first terminal sends an operator identification code assigned to the first terminal to the core network device.

[0394] In response, the core network device receives an operator identification code assigned to the first terminal.

[0395] In a possible implementation, the first terminal transmitting the operator identification code assigned to the first terminal to the core network device includes: the first terminal transmitting a request message to the core network device through the access network device, where the request message includes the operator identification code assigned to the first terminal. The access network device transparently transmits the request message. The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0396] Step 706: The core network device may determine, based on the operator identification code and the subscription information of the first terminal, that the operator needs to perform authentication on the operator identification code. The subscription information includes information about whether authentication needs to be performed on the operator identification code.

[0397] Step 706 is an optional step and may not be performed.

[0398] Step 707: The core network device triggers authentication between the first terminal and the operator device based on the operator identification code.

[0399] For the process of step 707, please refer to the process of step 512. The details will not be described again.

[0400] In a possible implementation, if the capabilities of the first terminal further include reporting an EPC by default, a first EPC assigned to the first terminal may further be received in step 705.

[0401] In a possible implementation, if the capability of the first terminal does not include reporting the EPC by default, the manner of obtaining the EPC may include:

[0402] Method 1: After the operator identification code assigned to the first terminal is obtained, the first terminal receives a request from a core network device to request the first terminal to obtain the first EPC assigned to the first terminal based on the operator identification code.

[0403] In a possible implementation, the core network device sends a request to the first terminal to obtain a first EPC assigned to the first terminal, and in response, the first terminal receives a request from the core network device to obtain the first EPC assigned to the first terminal, where the request includes an operator identification code of the first terminal.

[0404] Method 2: In step 702, the fifth information sent by the core network device to the access network device instructs the access network device to search for one or more terminals (including the first terminal), and further instructs the access network device to request obtaining an EPC assigned to the one or more terminals (including the first terminal).

[0405] The fifth information may instruct one or more terminals (including the first terminal) to request to obtain the EPC assigned to them by using a specific information format, or the fifth information includes instruction information for requesting to obtain the EPC, thereby instructing the access network device to request to obtain the EPC assigned to one or more terminals (including the first terminal). The instruction information for requesting to obtain the EPC may be a mark for EPC duplication.

[0406] After the first EPC is obtained, step 708 may be executed: the core network device may determine, based on the first EPC and the subscription information of the first terminal, that the operator or the requestor needs to perform authentication for the first EPC, and then execute step 709. If authentication does not need to be performed, step 709 may not be executed. Step 708 is an optional step and may not be executed.

[0407] Step 709: The core network device may trigger authentication between the first terminal and the operator device or requestor based on the first EPC.

[0408] The order of steps 706, 707, 708, and 709 is not limited.

[0409] In a possible implementation, when the first operation is one or more of a read operation, a write operation, a delete operation, an encryption operation, an access operation, a block write operation, a block erase operation, or a kill operation, after the first terminal is authenticated, the core network device may further perform the first operation on the first terminal.

[0410] In a possible implementation, after the first terminal is authenticated, the core network device may send a response message to the first terminal. In response, the first terminal receives a response message from the core network device. The response message may be a registration acceptance message, indication information indicating that the first terminal has successfully accessed, an access success message, a response message regarding successful network access, or a response message regarding successful network registration. The name of the response message is not limited in this application. For example, the core network device may transparently send the response message to the first terminal through the access network device.

[0411] In a possible implementation, after the first terminal is authenticated, the core network device may further send instruction information for a next terminal inventory to the access network device. Correspondingly, the access network device receives instruction information for a next terminal inventory from the core network device. The inventory may be understood as managing the next terminal or performing a first operation on the next terminal.

[0412] In the example of FIG. 5, if not all terminals indicated in the fifth information are inventoried in step 502, steps 503 to 512 may be repeatedly executed.

[0413] In the example of FIG. 6, if not all terminals indicated in the fifth information are inventoried in step 602, steps 603 to 609 may be repeatedly executed.

[0414] In the example of FIG. 7, if not all terminals indicated in the fifth information are inventoried in step 702, steps 703 to 709 may be repeatedly executed.

[0415] When all terminals indicated in the fifth information have been inventoried, the access network device may send inventory completion indication information to the core network device. The core network device may send the inventory result to the requestor.

[0416] When the first core network device and the second core network device are different core network devices, information is exchanged between the first core network device and the second core network device. Referring to the communication procedures in Figures 5, 6 and 7, the following describes the communication procedures when the first core network device and the second core network device are different core network devices.

[0417] Steps 501, 601, and 701 may be replaced by the requestor sending fourth information to the first core network device, and the first core network device correspondingly receiving the fourth information from the requestor.

[0418] Steps 502, 601, and 701 may be replaced by the second core network device sending fifth information to the access network device and, correspondingly, the second core network device receiving the fifth information from the requestor.

[0419] Before step 502, step 602, and step 702, a new step is added: the first core network device sends second indication information to the second core network device, where the second indication information indicates one or more terminals.

[0420] In response, the second core network device receives second indication information from the first core network device.

[0421] For example, for the content included in the second instruction information, please refer to the fifth information sent by the core network device to the access network device in step 502.

[0422] In other steps, the core network device is the first core network device when communicating with the first terminal or access network device, and is the second core network device when communicating with the requestor. For specific details of the communication procedure, please refer to the descriptions in Figures 5, 6 and 7. The details will not be described again.

[0423] After the key is written to the terminal, the network can perform authentication to the terminal based on the key. Figure 8 is a schematic flowchart of the network performing authentication to the terminal based on the key.

[0424] Step 101: A requestor (eg, an AF) sends an operation request to a core network device (eg, a TMF), where the operation request indicates one or more terminals (including a first terminal).

[0425] In response, the core network device receives an operation request from the requestor.

[0426] In a particular example, the operation request instructs that data 1 be written to one or more terminals.

[0427] For the operation request, please refer to the description of the fourth information in step 501. For the process of step 101, please refer to the description of the process of step 501. The details will not be described again.

[0428] Step 102: If the core network device (e.g., TMF) determines that operator-side authentication needs to be performed for one or more terminals indicated in the operation request, the core network device obtains the random number and operator identification code required for authentication.

[0429] For example, the core network device may obtain and store the corresponding random number and operator identification code by referring to the methods described in the examples or the methods described in possible implementations a, b, c and d in Figure 4.

[0430] Step 103: The core network device (eg, the TMF) sends an inventory command to the access network device, where the inventory command instructs the access network device to search for one or more terminals (including the first terminal).

[0431] In response, the access network device receives an inventory command from the core network device (eg, TMF).

[0432] The inventory command includes an operator identification code corresponding to one or more terminals and a random number. The operator identification code corresponding to one or more terminals can be represented by using an operator identification code range.

[0433] When multiple terminals are inventoried, the keys corresponding to the multiple terminals may be the same or different, and the random numbers corresponding to the multiple terminals may also be the same or different. If the keys and random numbers are different, they may be arranged in order in the inventory command, so that the access network device can identify the keys and random numbers corresponding to the same terminal. For example, in Key 1, Key 2, Key 3, Random Number 1, Random Number 2, and Random Number 3, Key 1 and Random Number 1 correspond to the same terminal, Key 2 and Random Number 2 correspond to the same terminal, and Key 3 and Random Number 3 correspond to the same terminal.

[0434] Step 104: The access network device searches for one or more terminals (including the first terminal) according to the inventory command.

[0435] Terminal search can also be understood as terminal selection or terminal filtering. For the specific process, please refer to the above description. The details will not be described again.

[0436] If the random numbers corresponding to multiple terminals are the same, the access network device may transmit the random numbers to the corresponding terminals in a search process.

[0437] If the random numbers corresponding to multiple terminals are different, the access network device may transmit the random numbers to the corresponding terminals after step 104a and before step 105.

[0438] Step 104a: The random access of a terminal (eg, a first terminal) is successful.

[0439] If the random numbers corresponding to multiple terminals are different, after step 104a, the first terminal may send the first EPC or operator identification code of the first terminal to the access network device, and the access network device identifies the first terminal based on the first EPC or operator identification code and sends the random number corresponding to the first terminal to the first terminal.

[0440] Step 105: The first terminal generates a first authentication parameter based on the pre-printed key and the received random number.

[0441] For example, the first authentication parameter is an identification number authentication result (RES).

[0442] Step 106: The first terminal sends a request message to a core network device (eg, a TMF) through the access network device.

[0443] In response, the core network device (eg, the TMF) receives a request message from the first terminal.

[0444] Optionally, the request message includes the operator identification code of the first terminal and the first authentication parameter generated in step 105 .

[0445] The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0446] Step 107: A core network device (eg, a TMF) sends an authentication request message to another core network device (eg, a UDR or an AUSF).

[0447] Another core network device (eg, a UDR or an AUSF) receives an authentication request message from a core network device (eg, a TMF).

[0448] The authentication request message includes the operator identification code and the first authentication parameter from the first terminal in step 106 .

[0449] Another core network device is a core network device or authentication server that is configured to determine whether the authentication parameters are correct based on the stored operator identification code and key.

[0450] Step 108: The other core network device determines whether the first authentication parameter is accurate based on the operator identification code and key stored for the first terminal.

[0451] Another core network device stores an association relationship between operator identification codes and keys, and the other core network device can discover the key associated with the operator identification code of the first terminal based on the operator identification code of the first terminal in step 107.

[0452] The other core network device decrypts the first authentication parameter based on the discovered key. If the decryption is successful, it is determined that the first authentication parameter is accurate and the network has successfully authenticated the first terminal. If the decryption is unsuccessful, it is determined that the first authentication parameter is inaccurate and the network has failed to authenticate the first terminal.

[0453] Step 109: The other core network device sends indication information to the core network device, indicating that the network has successfully authenticated the first terminal.

[0454] The core network device receives an indication from another core network device indicating that the network has successfully authenticated the first terminal.

[0455] If the network fails to authenticate the first terminal, the other core network device sends indication information to the core network device indicating that the network failed to authenticate the first terminal. The core network device receives indication information from the other core network device indicating that the network failed to authenticate the first terminal.

[0456] In an example, the message flag bit may be set to indicate whether authentication was successful. For example, if the message flag bit is set to 1, it indicates that the network successfully authenticated the first terminal; or, if the message flag bit is set to 0, it indicates that the network failed to authenticate the first terminal.

[0457] Optionally, the indication information indicating that the network has successfully authenticated the first terminal or the indication information indicating that the network has failed to authenticate the first terminal includes an operator identification code of the first terminal, and the first terminal is identified by using the operator identification code of the first terminal.

[0458] Optionally, in step 110, the core network device sends a response message to the first terminal.

[0459] In response, the first terminal receives a response message from the core network device.

[0460] The response message may be a registration acceptance message, an indication information indicating that the first terminal has successfully accessed, an access success message, a response message for successful network access, or a response message for successful network registration, where the name of the response message is not limited in this application.

[0461] For example, the core network device transparently transmits the response message to the first terminal through the access network device.

[0462] After steps 102 to 110, the network completes authentication of the first terminal. If the network successfully authenticates the first terminal, the core network device (e.g., TMF) can write data 1 to the first terminal based on the operation request in step 101. If the network fails to authenticate the first terminal, the subsequent process is not executed.

[0463] Step 111: The core network device (eg, TMF) sends instruction information to the first terminal to write data 1.

[0464] Optionally, the indication information includes an operator identification code of the first terminal.

[0465] For example, the core network device transparently transmits the indication information to the first terminal through the access network device.

[0466] Step 112: The first terminal sends a write success indication information to the core network device (eg, TMF).

[0467] Optionally, the indication information includes an operator identification code of the first terminal.

[0468] Step 113: The core network device (for example, the TMF) sends a write success indication to the requestor (for example, the AF).

[0469] Optionally, the indication information includes an operator identification code of the first terminal.

[0470] Step 114: The core network device sends instruction information for the next terminal inventory to the access network device.

[0471] In response, the access network device receives indication information about the next terminal inventory from the TMF.

[0472] The order of steps 113 and 114 is not limited.

[0473] The above-described steps 104 to 114 are repeatedly executed until data is written to one or more discovered terminals indicated in the inventory command in step 103; in other words, all terminals are inventoried.

[0474] In another scenario, if the operation request in step 101 instructs to read data 1 from one or more terminals, in step 111, the core network device (e.g., TMF) sends instruction information to the first terminal to read data 1; in step 112, the first terminal sends read success instruction information to the core network device (e.g., TMF), where the instruction information includes read data 1; in step 113, the core network device (e.g., TMF) sends read and write success instruction information to the requestor (e.g., AF), where the instruction information includes read data 1. Steps 104 to 114 described above are repeatedly executed until the data of one or more discovered terminals instructed in the inventory command in step 103 is read, in other words, all terminals are inventoried.

[0475] After the key is written to the terminal, the terminal can perform authentication to the network based on the key. Figure 9 is a schematic flowchart of the terminal performing authentication to the network based on the key.

[0476] Step 201: A requestor (eg, an AF) sends an operation request to a core network device (eg, a TMF), where the operation request indicates one or more terminals (including a first terminal).

[0477] In response, the core network device receives an operation request from the requestor.

[0478] In a particular example, the operation request instructs that data 1 be read from one or more terminals.

[0479] For the operation request, please refer to the description of the fourth information in step 501. For the process of step 201, please refer to the description of the process of step 501. The details will not be described again.

[0480] Step 202: The core network device obtains operator identification codes corresponding to one or more terminals.

[0481] Step 203: The core network device (eg, the TMF) sends an inventory command to the access network device, where the inventory command instructs the access network device to search for one or more terminals (including the first terminal).

[0482] In response, the access network device receives an inventory command from the core network device (eg, TMF).

[0483] The inventory command includes an operator identification code corresponding to one or more terminals, which may be represented by using an operator identification code range.

[0484] Step 204: The access network device searches for one or more terminals (including the first terminal) according to the inventory command.

[0485] Terminal search can also be understood as terminal selection or terminal filtering. For the specific process, please refer to the above description. The details will not be described again.

[0486] Step 204a: The random access of a terminal (eg, a first terminal) is successful.

[0487] Step 205: The first terminal may determine by itself whether the random number needs to be retained during the duplication of the operator identification code. If the first terminal determines that the random number needs to be retained during the duplication of the operator identification code, the random number is retained in step 206.

[0488] Step 206: The first terminal sends a request message to a core network device (eg, a TMF) through the access network device.

[0489] In response, the core network device (eg, the TMF) receives a request message from the first terminal.

[0490] Optionally, the request message includes an operator identification code of the first terminal and a random number, which may be pre-stored in the first terminal or generated by the first terminal.

[0491] The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. The request message may be a non-access stratum (NAS) message or a non-NAS message.

[0492] Step 207: A core network device (eg, a TMF) sends an authentication request message to another core network device (eg, a UDR or an AUSF).

[0493] Another core network device (eg, a UDR or an AUSF) receives an authentication request message from a core network device (eg, a TMF).

[0494] The authentication request message includes the operator identification code and the random number from the first terminal in step 206 .

[0495] Another core network device is a core network device or authentication server configured to calculate an authentication parameter (eg, a MAC) based on a stored operator identification code and a random number.

[0496] Step 208: The other core network device generates a first authentication parameter (eg, a MAC) based on the stored key, and the operator identification code and the random number in step 207.

[0497] Step 209: The other core network device sends authentication response information to the core network device.

[0498] The core network device receives authentication response information from another core network device.

[0499] The authentication response information includes the first authentication parameter. Optionally, the authentication response information includes an operator identification code of the first terminal.

[0500] Step 210: The core network device sends a response message to the first terminal.

[0501] In response, the first terminal receives a response message from the core network device.

[0502] The response message includes the first authentication parameter. Optionally, the response message includes an operator identification code of the first terminal.

[0503] The response message may be a registration acceptance message, an indication information indicating that the first terminal has successfully accessed, an access success message, a response message for successful network access, or a response message for successful network registration, where the name of the response message is not limited in this application.

[0504] For example, the core network device transparently transmits the response message to the first terminal through the access network device.

[0505] Step 211: The first terminal generates a second authentication parameter based on the operator identification code and key stored in the first terminal and the random number sent in step 206, and verifies the received first authentication parameter by using the second authentication parameter generated by the first terminal.

[0506] In other words, the first terminal determines whether the second authentication parameters generated by the first terminal are identical to the received first authentication parameters, and if the second authentication parameters generated by the first terminal are identical to the received first authentication parameters, determines that the first terminal has successfully authenticated the network; or if the second authentication parameters generated by the first terminal are different from the received first authentication parameters, determines that the first terminal has failed to authenticate the network.

[0507] Step 212: When the first terminal determines that it has successfully authenticated the network, the first terminal sends authentication success indication information to the core network device.

[0508] When the first terminal determines that it has failed to authenticate with the network, the first terminal may send authentication failure indication information to the core network device.

[0509] In an example, the message flag bit may be set to indicate whether authentication was successful. For example, if the message flag bit is set to 1, it indicates that the first terminal successfully authenticated the network; or, if the message flag bit is set to 0, it indicates that the first terminal failed to authenticate the network.

[0510] After steps 202 to 212, the first terminal completes authentication with the network. When the first terminal successfully authenticates with the network, the core network device (e.g., TMF) can write data 1 to the first terminal based on the operation request in step 201. If the first terminal fails to authenticate with the network, the subsequent process is not executed.

[0511] Step 213: The core network device (eg, TMF) sends instruction information to the first terminal to write data 1.

[0512] Optionally, the indication information includes an operator identification code of the first terminal.

[0513] For example, the core network device transparently transmits the indication information to the first terminal through the access network device.

[0514] Step 214: The first terminal sends the write success indication information to the core network device (eg, TMF).

[0515] Optionally, the indication information includes an operator identification code of the first terminal.

[0516] Step 215: The core network device (for example, the TMF) sends a write success indication to the requestor (for example, the AF).

[0517] Optionally, the indication information includes an operator identification code of the first terminal.

[0518] Step 216: The core network device sends instruction information for the next terminal inventory to the access network device.

[0519] In response, the access network device receives indication information about the next terminal inventory from the TMF.

[0520] The above described steps 204 to 216 are repeatedly executed until data is written to one or more discovered terminals indicated in the inventory command in step 203; in other words, all terminals are inventoried.

[0521] In another scenario, if the operation request in step 201 instructs to read data 1 from one or more terminals, in step 213, the core network device (e.g., TMF) sends instruction information to the first terminal to read data 1; in step 214, the first terminal sends read success instruction information to the core network device (e.g., TMF), where the instruction information includes read data 1; in step 215, the core network device (e.g., TMF) sends read and write success instruction information to the requestor (e.g., AF), where the instruction information includes read data 1. Steps 204 to 216 described above are repeatedly executed until the data of one or more discovered terminals instructed in the inventory command in step 203 is read, in other words, all terminals are inventoried.

[0522] When a subscribed enterprise has inventory requirements or more other operations, the requestor sends an inventory request to the core network device, which determines whether the EPC in the inventory request belongs to the enterprise based on the EPC ranges to which the enterprise has registered (or is subscribed to or managed by).

[0523] Figure 10 is a flowchart of communication in the case of a corporate mismatch.

[0524] Step 801: A first requestor (which can be understood as a first enterprise) sends an inventory request to a core network device, where the inventory request includes an EPC range or one or more EPCs.

[0525] In response, the core network device receives an inventory request from the first requestor.

[0526] Step 802: The core network device determines that the EPC in the inventory request does not belong to an EPC range registered (or subscribed to or managed by) the first requestor.

[0527] In a possible implementation, the core network device may verify whether the EPC in the inventory request belongs to the EPC range registered by the first requestor by using enterprise subscription information stored in the core network device or another core network device.

[0528] For example, the core network device determines that the EPC in the inventory request belongs to an EPC range registered (or subscribed to or managed by) a second requestor (which may also be understood as a second enterprise).

[0529] Step 803: The core network device sends inventory rejection indication information to the first requestor.

[0530] In response, the first requestor receives the inventory rejection indication information sent by the core network device.

[0531] The inventory rejection instruction information may be understood as alarm information or information indicating no query.

[0532] Optionally, the inventory rejection indication information carries a cause, for example, the cause is that the EPC in the inventory request does not belong to the EPC range registered by the first requestor.

[0533] For step 801 in Fig. 10, please refer to step 501 in Fig. 5, step 601 in Fig. 6, and step 701 in Fig. 7. The inventory request can be understood as the fourth information in step 501, step 601, or step 701, where the fourth information includes an EPC range or one or more EPCs. Other details will not be described again.

[0534] Figure 10 is combined with Figures 5, 6, and 7. This may be understood as step 802, which may be executed before steps 502, 602, and 702. After it is determined that the EPC in the inventory request does not belong to the EPC range registered by the first requestor, step 803 may be executed. After it is determined that the EPC in the inventory request belongs to the EPC range registered by the first requestor, step 503, step 603, step 703, and subsequent steps may subsequently be executed.

[0535] In the example where the terminal is located by using a company identifier, the company sending the inventory request may be different from the company to which the EPC in the inventory request belongs: the company identifier is a company code, an application code, or a service code assigned to the first terminal by the operator device (see step 402); or the service identifier is a service identifier in the CompanyPrefix in the EPC memory bank of one or more terminals (including the first terminal).

[0536] Figure 11 is a flowchart of communication in the case of a corporate mismatch.

[0537] Step 901: A first requestor (which may be understood as a first company) sends an inventory request to a core network device, where the inventory request indicates one or more terminals that are registered (or subscribed to, or managed by) a second requestor (which may be understood as a second company).

[0538] In response, the core network device receives an inventory request from the first requestor.

[0539] The inventory request may include an EPC range managed by the second enterprise or an EPC of one or more terminals to indicate one or more terminals managed by the second requestor.

[0540] Optionally, the inventory request may further include a service range, which is used to query the access network device.

[0541] Step 902: The core network device may determine, based on the information about the first requestor, a public land mobile network identifier (PLMN ID) and an enterprise identifier assigned to the terminal.

[0542] The business identifier determined based on information about the first requestor may be understood to be an identifier of the first business.

[0543] Step 903: The core network device sends an inventory command to the access network device, where the inventory command includes the PLMN ID and identifier of the first enterprise determined in step 902, and the EPC registered by the second enterprise in step 901.

[0544] In response, the access network device receives an inventory command from the core network device.

[0545] Step 904: The access network device searches for the terminal according to the inventory command.

[0546] Terminal search can also be understood as terminal selection or terminal filtering. For the specific process, please refer to the above description. The details will not be described again.

[0547] For example, a query command sent by the access network device to one or more terminals includes a PLMN ID, an identifier of the first enterprise, and an EPC registered by the second enterprise.

[0548] Step 905: A first terminal in the one or more discovered terminals accesses the access network device.

[0549] Steps 904 and 905 are repeatedly performed, and the access network device always fails to receive a response from the terminal. The access network device sends inventory completion indication information to the core network device. The core network device sends the inventory result to the first requester, where the inventory result may be empty.

[0550] In another possible example, when step 904 and step 905 are executed (or repeatedly executed), a terminal of the first company may respond. This case may be applicable to a case where the EPC registered by the second company is the same as the EPC registered by the first company. The inventory result may include the terminal information of the first company.

[0551] The above describes a method in an embodiment of the present application, and the following describes an apparatus in an embodiment of the present application. The method and the apparatus are based on the same technical concept. The method and the apparatus have similar principles for solving problems. Therefore, the implementation of the apparatus and the method should refer to each other. The details will not be repeated here.

[0552] In the embodiments of the present application, the device may be divided into functional modules based on the above-described method examples. For example, the device may be divided into functional modules corresponding to functions, or two or more functions may be integrated into one module. These modules may be implemented in the form of hardware or software functional modules. It should be noted that the module division in the embodiments of the present application is an example and is merely a logical division of functions. In a specific implementation, another division scheme may be used.

[0553] Based on the same technical concept as the above method, Figure 12 provides a diagram of the structure of a communication device 1000. The communication device 1000 may include one or more of the following: a processing module 1010, a receiving module 1020a, a transmitting module 1020b, and a storage module 1030. The processing module 1010 may be separately connected to the storage module 1030, the receiving module 1020a, and the transmitting module 1020b. The storage module 1030 may also be connected to the receiving module 1020a and the transmitting module 1020b.

[0554] In an example, the receiving module 1020a and the transmitting module 1020b may alternatively be integrated together and defined as a transceiving module.

[0555] In an example, the communication device 1000 may be a core network device, or may be a chip or functional unit used in a core network device. The communication device 1000 has any of the functions of the core network device in the above methods. For example, the communication device 1000 can perform the steps performed by the core network device in the methods in FIGS. 2 to 11.

[0556] The receiving module 1020a may perform the receiving operations performed by the core network device in the above method embodiments.

[0557] The transmitting module 1020b may perform the transmitting operations performed by the core network device in the above method embodiments.

[0558] The processing module 1010 may perform operations other than the transmitting and receiving operations performed by the core network device in the above method embodiments.

[0559] In an example, the receiving module 1020a is configured to receive first information from a requestor, where the first information indicates a first terminal; the processing module 1010 is configured to obtain an operator identification code assigned to the first terminal by an operator device; and the sending module 1020b is configured to send second information to the first terminal, where the second information instructs the first terminal to store the operator identification code.

[0560] In an example, the operator identification code comprises a public land mobile network identifier PLMN ID.

[0561] In an example, the operator identification code further includes one or more of: a first electronic product code EPC, an enterprise code assigned to the first terminal, and a unique identification code of the first terminal at the operator device mapped from the first electronic product code EPC, where the first EPC is assigned by the operator device or the first EPC is from the requestor.

[0562] In an example, the second information further includes first location information for storing an operator identification code.

[0563] In an example, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned to the first terminal by an operator device or the first EPC is from the requestor.

[0564] In an example, the second information further includes second location information for storing the first EPC.

[0565] In an example, the first information includes one or more of the following: a tag identifier TID type of the first terminal, a default electronic product code EPC of the first terminal, and information about a requestor, where the requestor manages the first terminal.

[0566] In an example, the sending module 1020b is further configured to: send third information to the access network device, where the third information instructs the access network device to search for the first terminal and to receive a default electronic product code EPC from the first terminal.

[0567] In an example, the third information includes one or both of the following: a tag identifier TID type of the first terminal, and a default electronic product code EPC of the first terminal.

[0568] In an example, the receiving module 1020a is further configured to receive fourth information from a requestor, where the fourth information indicates a first terminal; the sending module 1020b is further configured to send fifth information to the access network device, where the fifth information indicates to search for the first terminal; the receiving module 1020a is further configured to receive a first EPC assigned to the first terminal; the sending module 1020b is further configured to request the first terminal to obtain an operator identification code assigned to the first terminal based on the first EPC; the receiving module 1020a is further configured to receive the operator identification code assigned to the first terminal; and the processing module 1010 is further configured to trigger authentication between the first terminal and the operator device based on the operator identification code.

[0569] In an example, the receiving module 1020a is further configured to receive fourth information from a requestor, where the fourth information indicates a first terminal; the sending module 1020b is further configured to send fifth information to the access network device, where the fifth information indicates a request to search for the first terminal and to obtain an operator identification code assigned to the first terminal; the receiving module 1020a is further configured to receive an operator identification code assigned to the first terminal; and the processing module 1010 is further configured to trigger authentication between the first terminal and the operator device based on the operator identification code.

[0570] In an example, the receiving module 1020a is further configured to receive fourth information from a requestor, where the fourth information indicates the first terminal; the sending module 1020b is further configured to send fifth information to the access network device, where the fifth information indicates to search for the first terminal; the receiving module 1020a is further configured to receive an operator identification code assigned to the first terminal; and the processing module 1010 is further configured to trigger authentication between the first terminal and the operator device based on the operator identification code.

[0571] In an example, the fourth information includes information about a requestor, where the requestor manages the first terminal; the processing module 1010 is further configured to determine a public land mobile network identifier (PLMN ID) assigned to the first terminal based on the information about the requestor, and the fifth information includes the assigned PLMN ID.

[0572] In an example, an enterprise identifier assigned to the first terminal is determined based on the information about the requestor, and the fifth information further includes the assigned enterprise identifier.

[0573] In an example, the fourth information includes one or more of the following: a first electronic product code EPC of the first terminal, a TID type of the first terminal, and information about a requestor, where the requestor manages the first terminal; the fifth information includes one or more of the following: a first electronic product code EPC of the first terminal, an operator identification code associated with the first electronic product code EPC of the first terminal, and a TID type of the first terminal.

[0574] In an example, the processing module 1010 is further configured to determine, based on the operator identification code and subscription information of the first terminal, that the operator needs to perform authentication on the operator identification code.

[0575] In an example, the storage module 1030 may store computer-executable instructions of a method performed by a core network device, such that the processing module 1010, the receiving module 1020a, and the transmitting module 1020b perform the method performed by the core network device in the above example.

[0576] For example, a storage module may comprise one or more memories. A memory may be a component in one or more devices or circuits configured to store programs or data. A storage module may be a register, cache, RAM, or the like. A storage module may be integrated into a processing module. A storage module may be a ROM or another type of static storage device capable of storing static information and instructions. A storage module may be separate from a processing module.

[0577] The transceiver module may be an input / output interface, a pin, a circuit or the like.

[0578] In an example, the communication device 1000 may be a first terminal, or may be a chip or functional unit used in a first terminal. The communication device 1000 has any function of the first terminal in the above-described methods. For example, the communication device 1000 may perform the steps performed by the first terminal in the methods in FIGS. 2 to 9.

[0579] The receiving module 1020a may perform the receiving operations performed by the first terminal in the above method embodiments.

[0580] The transmitting module 1020b may perform the transmitting operations performed by the first terminal in the above method embodiments.

[0581] The processing module 1010 may perform operations other than the transmitting and receiving operations performed by the first terminal in the above method embodiments.

[0582] In an example, the receiving module 1020a is configured to receive second information from a core network device, where the second information instructs the first terminal to store an operator identification code, the operator identification code being assigned to the first terminal by the operator device; and the processing module 1010 is configured to store the operator identification code.

[0583] In an example, the second information further includes first location information for storing the operator identification code; and the processing module 1010 is specifically configured to store the operator identification code in a first memory location corresponding to the first location information.

[0584] In an example, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by an operator device or the first EPC is from a requestor; the processing module 1010 is specifically configured to store the first EPC.

[0585] In an example, the second information further includes second location information for storing the first EPC; and the processing module 1010 is specifically configured to store the first EPC in a second memory location corresponding to the second location information.

[0586] In an example, the sending module 1020b is configured to send a default electronic product code EPC of the first terminal to a second core network device through an access network device.

[0587] In an example, the storage module 1030 may store computer-executable instructions of a method to be performed by the first terminal, such that the processing module 1010, the receiving module 1020a, and the transmitting module 1020b perform the method to be performed by the first terminal in the above example.

[0588] For example, a storage module may comprise one or more memories. A memory may be a component in one or more devices or circuits configured to store programs or data. A storage module may be a register, cache, RAM, or the like. A storage module may be integrated into a processing module. A storage module may be a ROM or another type of static storage device capable of storing static information and instructions. A storage module may be separate from a processing module.

[0589] The transceiver module may be an input / output interface, a pin, a circuit or the like.

[0590] As a possible product form, the device may be implemented by using a general-purpose bus architecture.

[0591] FIG. 13 is a schematic block diagram of a communication device 1100.

[0592] Communications device 1100 may include one or more of the following: a processor 1110, a transceiver 1120, and a memory 1130. The transceiver 1120 may be configured to receive programs or instructions and transmit programs or instructions to the processor 1110. Alternatively, the transceiver 1120 may be configured to perform communication interactions between communications device 1100 and another communications device, for example, to exchange control signaling and / or service data. The transceiver 1120 may be a code and / or data read / write transceiver, or the transceiver 1120 may be a signal transmission transceiver between the processor and the transceiver. The processor 1110 and the memory 1130 are electrically coupled.

[0593] In an example, the communication device 1100 may be a core network device or a chip used in a core network device. It should be understood that the device has any functionality of the core network device in the above methods. For example, the communication device 1100 can perform the steps performed by the core network device in the methods of FIGS. 2 to 11. For example, the memory 1130 is configured to store computer programs or instructions. The processor 1110 may be configured to call the computer programs or instructions stored in the memory 1130 to perform the methods performed by the core network device in the above examples, or to execute the methods performed by the core network device in the above examples via the transceiver 1120.

[0594] The processing module 1010 in FIG.

[0595] 12 may be implemented by using the transceiver 1120. Alternatively, the transceiver 1120 includes a receiver and a transmitter, where the receiver performs the function of the receiving module and the transmitter performs the function of the transmitting module.

[0596] The storage module 1030 in FIG.

[0597] In an example, the communication device 1100 may be a first terminal or a chip used in a first terminal. It should be understood that the device has any functionality of the first terminal in the above-described methods. For example, the communication device 1100 can perform the steps performed by the first terminal in the methods in FIGS. 2 to 9. For example, the memory 1130 is configured to store a computer program. The processor 1110 may be configured to call a computer program or instructions stored in the memory 1130 to perform the method performed by the first terminal in the above-described examples, or to execute the method performed by the first terminal in the above-described examples via the transceiver 1120.

[0598] The processing module 1010 in FIG.

[0599] 12 may be implemented by using the transceiver 1120. Alternatively, the transceiver 1120 includes a receiver and a transmitter, where the receiver performs the function of the receiving module and the transmitter performs the function of the transmitting module.

[0600] The storage module 1030 in FIG.

[0601] As a possible product form, the apparatus may be implemented by using a general purpose processor (which may also be referred to as a chip or a chip system).

[0602] In a possible implementation, a general-purpose processor implementing an apparatus used in a core network device or a first terminal includes a processing circuit (here, the processing circuit may also be referred to as a processor); and may optionally further include an input / output interface and a storage medium (here, the storage medium may also be referred to as a memory) internally connected to and communicating with the processing circuit. The storage medium is configured to store instructions executed by the processing circuit to perform the method performed by the core network device in the above example.

[0603] The processing module 1010 in FIG. 12 may be implemented using a processing circuit.

[0604] The receiving module 1020a and the transmitting module 1020b in Figure 12 can be implemented by using an input / output interface. Alternatively, the input / output interface includes an input interface and an output interface. The input interface performs the function of the receiving module, and the output interface performs the function of the transmitting module.

[0605] The storage module 1030 in FIG. 12 may be implemented by using a storage medium.

[0606] As a possible product form, the apparatus of the embodiments of the present application may alternatively be implemented using one or more FPGAs (Field Programmable Gate Arrays), PLDs (Programmable Logic Devices), controllers, state machines, gate logic, discrete hardware components, and any other suitable circuitry or combination of circuitry capable of performing the various functions described herein.

[0607] An embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a computer, the computer may be capable of performing the above-mentioned communication method. In other words, the computer program includes instructions for implementing the above-mentioned communication method.

[0608] An embodiment of the present application further provides a computer program product, which includes computer program code, which, when executed on a computer, enables the computer to perform the above-described communication method.

[0609] An embodiment of the present application further provides a communication system, which includes at least two of the following: a core network device that performs the above communication method, a first terminal of another core network device, and a requestor.

[0610] Additionally, the processor referred to in the embodiments of this application may be a central processing unit (CPU) or a baseband processor. The baseband processor and the CPU may be integrated or separate, or may be a network processor (NP) or a combination of a CPU and an NP. The processor may also include a hardware chip or another general-purpose processor. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), another programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or the like, or any combination thereof. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor or the like.

[0611] The memory referred to in the embodiments of this application may be volatile memory or nonvolatile memory, or may include volatile memory and nonvolatile memory. Nonvolatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of RAM may be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct Rambus random access memory (DR RAM). It should be noted that memory as described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0612] The transceiver referred to in the embodiments of the present application may include a separate transmitter and / or a separate receiver, or the transmitter and receiver may be integrated. The transceiver may operate as instructed by a corresponding processor. Optionally, the transmitter may correspond to a transmitter in a physical device, and the receiver may correspond to a receiver in a physical device.

[0613] Those skilled in the art may recognize that the methods, steps, and units in combination with the examples described in the embodiments disclosed herein may be implemented by using electronic hardware, computer software, or a combination thereof. In order to clearly describe the interchangeability between hardware and software, the above generally describes the steps and compositions of each embodiment based on functionality. Whether a function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but the implementation should not be considered to go beyond the scope of this application.

[0614] In the embodiments provided herein, it should be understood that the disclosed systems, devices, and methods may be implemented in other manners. For example, the described device embodiments are merely examples. For example, the division into units is merely a logical division of function, and other divisions may occur in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not implemented. In addition, the shown or described mutual couplings or direct couplings or communication connections may be implemented through some interfaces, indirect couplings, communication connections, or electrical, mechanical, or other forms of connection between devices or units.

[0615] The units described as separate parts may or may not be physically separate, and the parts shown as units may or may not be physical units, located in one place or distributed over multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments of the present application.

[0616] In addition, the functional units in the embodiments of the present application may be integrated into one processing unit, and each of the units may exist physically alone, or two or more units may be integrated into one unit. The integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0617] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, the integrated unit may be stored in a computer-readable storage medium. Based on this understanding, the technical solution in the present application may be essentially, or a portion that contributes to the prior art, or all or a portion of the technical solution may be expressed in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for instructing a computer device (which may be a personal computer, a server, a network device, or the like) to execute all or a portion of the steps of the method described in the embodiments of the present application. The storage medium includes any medium that can store program code, such as a USB flash drive, a removable hard disk drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0618] Although preferred embodiments of the present application are described, those skilled in the art can make changes and modifications to these embodiments after recognizing the basic inventive concepts. Accordingly, it is intended that the following claims be interpreted to encompass all changes and modifications that fall within the scope of the preferred embodiments and the present application.

[0619] Of course, those skilled in the art can make various modifications and variations to the embodiments of the present application without departing from the spirit and scope of the embodiments of the present application, and thus the present application is intended to cover these modifications and variations to the embodiments of the present application as long as they fall within the scope of protection defined by the following claims and the equivalent technologies of the present application.< / mcc> < / mnc> < / stid> < / mcc> < / mnc> < / epc> < / epc> < / mcc> < / mnc> < / imsi>

Claims

1. 1. A communication method applied to a core network device, comprising: receiving first information from a requestor, wherein said first information indicates a first terminal; obtaining an operator identification code assigned to the first terminal by an operator device; and transmitting second information to the first terminal, wherein the second information instructs the first terminal to store the operator identification code; A method for providing the above.

2. The method of claim 1 , wherein the operator identification code comprises a public land mobile network identifier (PLMN ID).

3. The operator identification code further includes one or more of: a first electronic product code EPC, an enterprise code assigned to the first terminal, and a unique identification code of the first terminal in the operator device mapped from the first electronic product code EPC, wherein The first EPC is assigned by the operator device, or the first EPC is from the requestor; The method of claim 2.

4. The method of claim 1 , wherein the second information further comprises first location information for storing the operator identification code.

5. 5. The method according to claim 1, wherein the second information further instructs the first terminal to store the first electronic product code EPC corresponding to the first terminal, wherein the first EPC is assigned to the first terminal by the operator device or the first EPC is from the requestor.

6. The method of claim 5 , wherein the second information further comprises second location information for storing the first EPC.

7. After the step of receiving first information from a requestor, the method further comprises: obtaining a key corresponding to said first terminal, the second information further instructs the first terminal to store the corresponding first key; The method of any one of claims 1 to 6, comprising:

8. The method of claim 7 , wherein the second information further comprises third location information for storing the first key.

9. The first information is:

9. The method of claim 1, further comprising: a tag identifier TID type of the first terminal; a default electronic product code EPC of the first terminal; and information about the requestor, wherein the requestor manages the first terminal.

10. Prior to the step of transmitting second information to the first terminal, the method may further include: sending third information to an access network device, wherein the third information instructs the access network device to search for the first terminal; and receiving the default electronic product code EPC from the first terminal; The method of any one of claims 1 to 9, comprising:

11. The third information is: the tag identifier TID type of the first terminal and the default electronic product code EPC of the first terminal 11. The method of claim 10, comprising one or both of:

12. The method further comprises: receiving fourth information from the requestor, wherein the fourth information indicates the first terminal; sending fifth information to the access network device, wherein the fifth information instructs the access network device to search for the first terminal; receiving the first EPC assigned to the first terminal; requesting the first terminal to obtain the operator identification code assigned to the first terminal based on the first EPC; receiving the operator identification code assigned to the first terminal; and triggering authentication between the first terminal and the operator device based on the operator identification code; The method of any one of claims 1 to 11, comprising:

13. The method further comprises: receiving fourth information from the requestor, wherein the fourth information indicates the first terminal; sending fifth information to the access network device, wherein the fifth information instructs the access network device to search for the first terminal and to request obtaining the operator identification code assigned to the first terminal; receiving the operator identification code assigned to the first terminal; and triggering authentication between the first terminal and the operator device based on the operator identification code; The method of any one of claims 1 to 11, comprising:

14. The method further comprises: receiving fourth information from the requestor, wherein the fourth information indicates the first terminal; sending fifth information to the access network device, wherein the fifth information instructs the access network device to search for the first terminal; receiving the operator identification code assigned to the first terminal; and triggering authentication between the first terminal and the operator device based on the operator identification code; The method of any one of claims 1 to 11, comprising:

15. the fourth information includes the information about the requestor, the requestor managing the first terminal; and prior to the step of transmitting fifth information to the access network device, the method further comprises: determining the public land mobile network identifier PLMN ID assigned to the first terminal based on the information about the requestor, the fifth information includes the assigned PLMN ID; 15. The method of any one of claims 12 to 14, comprising:

16. Prior to the step of transmitting fifth information to the access network device, the method further comprises: determining an enterprise identifier assigned to the first terminal based on the information about the requestor, the fifth information further includes the assigned company identifier; The method of claim 15, comprising:

17. the company identifier is a company code assigned to the first terminal; or The company identifier is a service identifier in a Company Prefix in an Electronic Product Code (EPC) memory bank of the first terminal; 17. The method of claim 16.

18. The fourth information includes one or more of: the first electronic product code EPC of the first terminal, the TID type of the first terminal, and the information about the requestor, where the requestor manages the first terminal; and The fifth information is: the first electronic product code EPC of the first terminal, the operator identification code associated with the first electronic product code EPC of the first terminal, and the TID type of the first terminal.

18. The method of any one of claims 12 to 17, comprising one or more of:

19. Prior to the step of triggering authentication between the first terminal and the operator device based on the operator identification code, the method further comprises: determining, based on said operator identification code and subscription information of said first terminal, that an operator needs to perform authentication on said operator identification code; 19. The method of any one of claims 12 to 18, comprising:

20. A communication method applied to a first terminal, comprising: receiving second information from a core network device, wherein the second information instructs the first terminal to store an operator identification code, the operator identification code being assigned to the first terminal by an operator device; and storing the operator identification code A method for providing the above.

21. The second information further includes: first location information for storing the operator identification code; The step of storing the operator identification code comprises: storing the operator identification code in a first memory location corresponding to the first location information.

21. The method of claim 20, comprising:

22. The second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by the operator device or the first EPC is from a requestor; The method further comprises: storing the first EPC 22. The method of claim 20 or 21, comprising:

23. the second information further includes second location information for storing the first EPC; The step of storing the first EPC comprises: storing the first EPC in a second storage location corresponding to the second location information; 23. The method of claim 22, comprising:

24. The second information further instructs the first terminal to store a first key corresponding to the first terminal; The method further comprises: storing said first key 24. The method of any one of claims 20 to 23, comprising:

25. the second information further includes third location information for storing the first key; Storing the first key includes: storing the first key in a third storage location corresponding to the third location information; 25. The method of claim 24, comprising:

26. Prior to the step of receiving second information from a second core network device, the method may further comprise: accessing an access network device; and transmitting a default electronic product code EPC of the first terminal to the second core network device through the access network device; 26. The method of any one of claims 20 to 25, comprising:

27. A communication device comprising a functional module for implementing the method of any one of claims 1 to 26.

28. A communications device comprising a processor, the processor coupled to a memory; the memory is configured to store computer programs or instructions; The processor is configured to execute some or all of the computer programs or instructions in the memory; and when executing the some or all of the computer programs or instructions, the processor is configured to implement a method according to any one of claims 1 to 26. Communication equipment.

29. A communication device comprising a processor and a memory, the memory is configured to store computer programs or instructions; The processor is configured to execute some or all of the computer programs or instructions in the memory; and when executing the some or all of the computer programs or instructions, the processor is configured to implement a method according to any one of claims 1 to 26. Communication equipment.

30. a chip system comprising a processing circuit, the processing circuit coupled to a storage medium; The processing circuitry is configured to execute some or all of a computer program or instructions on the storage medium; and when executing the some or all of the computer program or instructions, the processing circuitry is configured to implement a method according to any one of claims 1 to 26. Chip system.

31. 27. A computer readable storage medium configured to store a computer program, said computer program comprising instructions for implementing the method of any one of claims 1 to 26.

32. 27. A computer program product comprising computer program code; said computer program code, when executed on a computer, enabling said computer to carry out the method of any one of claims 1 to 26.

Citation Information

Patent Citations

  • Communication device, management device, and control method thereof

    JP2021114660A

  • Charging method, apparatus, and system

    US20230345212A1

  • Charging method, apparatus and system

    WO2022141498A1

  • System and method for group-based cellular ambient IoT device and service management

    WO2024227205A2