Communication methods and devices
The communication method and apparatus provide operator management and authentication for passive IoT terminals by assigning and managing operator identification codes, addressing the lack of management capabilities in existing systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2023-09-11
- Publication Date
- 2026-07-22
AI Technical Summary
Current systems lack the ability for operators to manage passive Internet of Things terminals, such as tags, after they are purchased by enterprises, as there is no effective method to integrate operator identification or management capabilities.
A communication method and apparatus that allows a core network device to assign and manage operator identification codes to terminal devices, including public land mobile network identifiers and electronic product codes, enabling operators to manage and authenticate these terminals.
Enables operators to effectively manage and authenticate passive IoT terminals, ensuring secure and efficient operation of these devices within communication networks.
Smart Images

Figure 0007893530000001 
Figure 0007893530000002 
Figure 0007893530000003
Abstract
Description
Technical Field
[0001]
[0002] Embodiments of the present application relate to the field of communication technologies, particularly to communication methods and apparatuses.
Background Art
[0003] With the development of technologies, passive Internet of Things has the prospect of large-scale application and deployment. However, passive Internet of Things terminals (such as tags) have simple functions and need to rely on external stimuli to transmit information to the outside. The stimuli are generally from card readers / writers. Referring to the resources of a wireless communication system, the functions of the reader / writer can be integrated into an access network device, and the tag is stimulated by using wireless air interface technology.
[0004] Currently, after an enterprise purchases tags from a tag manufacturer, the enterprise (such as an application function) can manage the purchased tags together. In a possible implementation scenario, the enterprise can approve for the operator to manage the tags purchased by the enterprise together. However, currently, there is no solution for the operator to manage tags.
Summary of the Invention
[0005] Embodiments of the present application provide a communication method and apparatus for an operator to manage terminal devices.
[0006] According to the first embodiment, a communication method is provided. The method may be performed by a core network device or by a component used in the core network device, such as a chip or a processor. The following description uses an example in which the method is performed by a core network device. First, the core network device receives first information from the requester, where the first information indicates a first terminal. Next, the core network device obtains an operator identification code assigned to the first terminal by an operator device. Next, the core network device transmits second information to the first terminal, where the second information instructs the first terminal to save the operator identification code.
[0007] After the operator identification code is stored on the terminal, the operator can manage the terminal based on the operator identification code.
[0008] In possible implementations, the operator identification code includes a public land mobile network (PLMN) identifier.
[0009] In possible implementations, the operator identification code further includes one or more of the following: a first electronic product code (EPC), a company code assigned to the first terminal, and a unique identification code for the first terminal in the operator device, mapped from the first electronic product code (EPC), where the first EPC is assigned by the operator device or the first EPC is from the requester. Since the operator identification code includes this information, it can consequently replace the function of the EPC.
[0010] In possible implementations, the second information further includes first location information for storing the operator identification code. The storage location of the operator identification code can be flexibly indicated using the second information.
[0011] In a possible implementation, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned to the first terminal by an operator device, or the first EPC is from the requester.
[0012] In possible implementations, the second information further includes second location information for storing the first EPC. The storage location of the EPC can be flexibly indicated by using the second information.
[0013] In a possible implementation, after receiving the first information from the requester, the core network device may further obtain a key corresponding to the first terminal, where the second information further instructs the first terminal to save the corresponding first key.
[0014] In a possible implementation, if the first information includes a key assigned to the first terminal, the core network device may, based on the first information, obtain the key corresponding to the first terminal.
[0015] In possible implementations, the core network device assigns a key to the first terminal.
[0016] In possible implementations, the core network device obtains the key corresponding to the first terminal from the operator device.
[0017] In a possible implementation, the core network device includes a first core network device and a second core network device. The first core network device obtains a key corresponding to a first terminal and sends the key to the second core network device. The second core network device is configured to communicate with access network devices and terminals. For example, the second core network device sends second information to the first terminal. For example, the first core network device is a UDM and the second core network device is a TMF. The UDM checks whether a key corresponding to the first terminal is stored locally. If a key corresponding to the first terminal is stored locally, the UDM may send the key corresponding to the first terminal directly to the TMF. If the key is not stored locally, the UDM requests information about the key storage network element (such as address information) from the NRF. The UDM receives the information about the key storage network element sent by the NRF. The network element is, for example, a UDR or AUSF. Based on the information about the network element, the UDM requests the key corresponding to the first terminal from the key storage network element. After obtaining the key corresponding to the first terminal, the UDM sends the key corresponding to the first terminal to the TMF. Furthermore, optionally, before the UDM obtains the key corresponding to the first terminal, the TMF sends instruction information to the UDM for obtaining the key corresponding to the first terminal. After receiving the instruction information for obtaining the key corresponding to the first terminal, the UDM sends the obtained information about the key corresponding to the first terminal to the TMF. If there is no corresponding key information on the UDM, the UDM obtains the key corresponding to the first terminal based on the instruction information and sends the key corresponding to the first terminal to the TMF.
[0018] In a possible implementation, the core network device includes a first core network device and a second core network device. The second core network device obtains a key corresponding to the first terminal. The second core network device is configured to communicate with access network devices and terminals. For example, the second core network device transmits second information to the first terminal. For example, the first core network device is a UDM and the second core network device is a TMF. The UDM recognizes information about key storage network elements through the NRF and transmits this information to the TMF. The TMF then obtains keys corresponding to one or more terminals from the key storage network elements (including the first terminal) based on the information about the key storage network elements. Optionally, before the UDM recognizes information about the key storage network elements through the NRF, the TMF may transmit instruction information to the UDM to obtain the key for the first terminal, or obtain information about the key storage network elements. After the UDM receives instruction information to obtain the key for the first terminal, or after obtaining information about the key storage network element, the UDM recognizes the information about the key storage network element via the NRF and transmits the information about the key storage network element to the TMF.
[0019] In possible implementations, the core network device is a TMF, which, through an NRF, recognizes information about key-storage network elements. Network elements are, for example, UDMs, UDRs, or AUSFs. The TMF then retrieves keys corresponding to one or more terminals from the key-storage network elements (including the first terminal) based on the information about the key-storage network elements.
[0020] In possible implementations, the second piece of information further includes a third piece of location information for storing the first key.
[0021] In a possible implementation, the first information includes one or more of the following: the tag identifier (TID) type of the first terminal, the default electronic product code (EPC) of the first terminal, and information about the requester, where the requester manages the first terminal. The first terminal can be matched using this information, and naturally, other terminals can be matched.
[0022] In a possible implementation, before sending the second piece of information to the first terminal, the core network device may send a third piece of information to the access network device, which instructs it to search for the first terminal; the core network device then receives the default electronic product code (EPC) from the first terminal.
[0023] In possible implementations, the third piece of information includes one or both of the tag identifier (TID) type and the default electronic product code (EPC) of the first terminal. The first terminal can be matched using this information, and naturally, other terminals can be matched.
[0024] According to a second embodiment, a communication method is provided. The method may be performed by a core network device or by a component used in the core network device, such as a chip or processor. The following description uses an example in which the method is performed by a core network device. First, the core network device receives fourth information from the requester, where the fourth information indicates a first terminal; next, it sends fifth information to the access network device, where the fifth information instructs it to look up the first terminal; next, it receives a first EPC assigned to the first terminal; and requests to obtain an operator identification code assigned to the first terminal based on the first EPC. Next, the core network device receives the operator identification code assigned to the first terminal, and based on the operator identification code, the core network device triggers authentication between the first terminal and the operator device.
[0025] The capability of the first terminal is to report an EPC by default. After accessing an access network device (e.g., successful random access), the first terminal may proactively send a first EPC assigned to it. After obtaining the first terminal's first EPC, the core network device may request an operator identification code assigned to the first terminal based on the first terminal's first EPC. Furthermore, authentication is performed on the terminal based on the operator identification code so that the operator can manage the terminal.
[0026] According to a third aspect, a communication method is provided. The method may be performed by a core network device or by a component used in the core network device, such as a chip or processor. The following description uses an example in which the method is performed by a core network device. First, the core network device receives fourth information from the requester, where the fourth information indicates a first terminal; next, the core network device sends fifth information to an access network device, where the fifth information instructs the access network device to search for the first terminal and to request the acquisition of an operator identification code assigned to the first terminal; next, the core network device receives the operator identification code assigned to the first terminal; and further, the core network device triggers the first terminal to perform authentication with the operator device based on the operator identification code.
[0027] The capability of the first terminal is to report the EPC by default. After accessing the access network device (for example, random access is successful), the first terminal can actively send the first EPC assigned to the first terminal. In the process of searching for the first terminal, the access network device instructs the first terminal to send the operator identification code assigned to the first terminal. In this way, after accessing the access network device (for example, random access is successful), the first terminal can send the operator identification code assigned to the first terminal. Further, authentication is performed on the terminal based on the operator identification code so that the operator can manage the terminal.
[0028] According to a fourth aspect, a communication method is provided. The method can be executed by a core network device or can be a component used in a core network device, such as a chip or a processor. Hereinafter, an example in which the method is executed by a core network device will be used for explanation. First, the core network device receives fourth information from a requester, where the fourth information instructs the first terminal; next, the core network device sends fifth information to the access network device, where the fifth information instructs the access network device to search for the first terminal. Next, the core network device receives the operator identification code assigned to the first terminal. Next, the core network device triggers the first terminal to perform authentication with the operator device based on the operator identification code.
[0029] The capability of the first terminal is to report the operator identification code by default. After accessing the access network device (for example, random access is successful), the first terminal can actively send the operator identification code assigned to the first terminal. Further, authentication is performed on the terminal based on the operator identification code so that the operator can manage the terminal.
[0030] The following possible implementations are applicable to the second, third, and fourth embodiments.
[0031] In a possible implementation, the fourth piece of information includes information about the requester, who manages the first terminal; before the core network device sends the fifth piece of information to the access network device, the core network device determines, based on the information about the requester, the public land mobile network identifier (PLMN ID) assigned to the first terminal, where the fifth piece of information includes the assigned PLMN ID. The PLMN ID is used to match the terminal being searched.
[0032] In possible implementations, before sending the fifth piece of information to the access network device, the core network device determines the enterprise identifier assigned to the first terminal based on the information about the requester, where the fifth piece of information further includes the assigned enterprise identifier. The PLMN ID and enterprise identifier are used to match the terminal being searched.
[0033] The company identifier is the company code assigned to the first terminal; or the company identifier is the service identifier in the CompanyPrefix in the electronic product code EPC memory bank of the first terminal.
[0034] In possible implementations, the fourth piece of information includes one or more of the following: the first electronic product code EPC of the first terminal, the TID type of the first terminal, and information about the requester, where the requester manages the first terminal. The fifth piece of information includes one or more of the following: the first electronic product code EPC of the first terminal, the operator identification code associated with the first electronic product code EPC of the first terminal, and the TID type of the first terminal. This information is used to match the terminal being searched.
[0035] In possible implementations, before triggering authentication between the first terminal and the operator device based on the operator identification code, the core network device may further determine, based on the operator identification code and the subscription information of the first terminal, that the operator needs to perform authentication against the operator identification code. The determination that the operator needs to perform authentication against the operator identification code is made first, followed by the performance of the authentication, thereby avoiding signaling exchanges resulting from invalid authentication.
[0036] According to a fifth aspect, a communication method is provided. The method may be performed by a first terminal or by a component used by the first terminal, such as a chip or a processor. The following description uses an example in which the method is performed by a first terminal. First, the first terminal receives second information from a core network device, where the second information instructs the first terminal to store an operator identification code, which is assigned to the first terminal by an operator device. Next, the first terminal stores the operator identification code.
[0037] In a possible implementation, the second information further includes first location information for storing an operator identification code; the first terminal stores the operator identification code in a first storage location corresponding to the first location information.
[0038] In a possible implementation, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by an operator device or is from a requester; the first terminal may further store the first EPC.
[0039] In a possible implementation, the second information further includes second location information for storing the first EPC; the first terminal stores the first EPC in a second memory location corresponding to the second location information.
[0040] In a possible implementation, the second piece of information may further instruct the first terminal to store the first key corresponding to the first terminal, and the first terminal may further store the first key.
[0041] In a possible implementation, the second piece of information further includes a third location for storing the first key, and the first terminal stores the first key in a third memory location corresponding to the third location.
[0042] In possible implementations, the first terminal receives information from the second terminal. to Before receiving from the network device, the first terminal accesses the access network device; and the first terminal's default electronic product code (EPC) is transmitted through the access network device. Te Ko Send to network devices.
[0043] According to a sixth aspect, a communication device is provided. The device has a function that implements any one of the above aspects or a possible implementation thereof. The function may be implemented by using hardware, or by hardware by running corresponding software. The hardware or software includes one or more functional modules corresponding to the above function.
[0044] According to the seventh aspect, a communication device is provided. The device comprises a processor and optionally further comprises memory. The processor is coupled to the memory. The memory is configured to store computer programs or instructions. The processor is configured to execute some or all of the computer programs or instructions in the memory; when executing some or all of the computer programs or instructions, the processor is configured to implement the functions in any one of the above aspects and any possible implementations thereof.
[0045] In possible implementations, the device may further include a transceiver. The transceiver is configured to: transmit a signal to be processed by a processor, or receive a signal input to a processor. The transceiver may perform a transmit operation or a receive operation in any one of the embodiments and possible implementations of the embodiment.
[0046] According to the eighth aspect, the present invention provides a chip system comprising one or more processors (which may also be referred to as processing circuits). The processors are electrically coupled to memory (which may also be referred to as a storage medium). The memory may or may not be located within the chip system. The memory is configured to store computer programs or instructions. The processors are configured to execute some or all of the computer programs or instructions in the memory; when executing some or all of the computer programs or instructions, the processors are configured to implement the functions in any one of the above aspects and any possible implementations thereof.
[0047] In possible implementations, the chip system may further include input / output interfaces (which may also be called communication interfaces). These input / output interfaces are configured to: output signals processed by the processor, or receive signal inputs to the processor. The input / output interfaces may perform either transmit or receive operations in any one of the embodiments and possible implementations of the embodiments. Specifically, the output interface performs transmit operations, and the input interface performs receive operations.
[0048] In possible implementations, the chip system may include a chip, or it may include a chip and other discrete devices.
[0049] According to the ninth aspect, a computer-readable storage medium is provided and configured to store a computer program. The computer program includes instructions for implementing a function in any one of the aspects and possible implementations thereof.
[0050] Alternatively, a computer-readable storage medium is provided and configured to store computer programs. When a computer program is executed by a computer, the computer may be able to perform a method according to any one of the above embodiments or possible implementations thereof.
[0051] According to the tenth aspect, a computer program product is provided. The computer program product includes computer program code. When the computer program code is executed by a computer, the computer may perform a method according to any one of the above aspects or a possible implementation thereof.
[0052] According to the eleventh aspect, a communication system is provided. The system comprises a core network device that performs the method according to either the first aspect or a possible implementation thereof, and a first terminal that performs the method according to either the first aspect or a possible implementation thereof. Optionally, the communication system further comprises a requester that communicates with the core network device.
[0053] According to the twelfth aspect, a communication system is provided. The system comprises a core network device that performs a method according to either the second aspect or a possible implementation thereof, and a first terminal that communicates with the core network device. Optionally, the communication system further comprises a requester that communicates with the core network device.
[0054] According to the thirteenth aspect, a communication system is provided. The system comprises a core network device that performs a method according to either the third aspect or a possible implementation thereof, and a first terminal that communicates with the core network device. Optionally, the communication system further comprises a requester that communicates with the core network device.
[0055] According to the fourteenth aspect, a communication system is provided. The system comprises a core network device that performs a method according to either the fourth aspect or a possible implementation thereof, and a first terminal that communicates with the core network device. Optionally, the communication system further comprises a requester that communicates with the core network device.
[0056] For the technical effects of the 6th to 14th aspects, please refer to the descriptions of the 1st to 5th aspects. Repeated sections will not be described again. [Brief explanation of the drawing]
[0057] [Figure 1] Figure 1a is a diagram showing the structure of a communication system according to an embodiment of the present invention. Figure 1b is a diagram showing the structure of another communication system according to an embodiment of the present invention. [Figure 2] This is a diagram illustrating the format of the tag memory bank in conventional technology. [Figure 3] This is a flowchart of communication according to the embodiment of the present invention. [Figure 4] This is a communication flowchart for storing an operator identification code in the first terminal according to an embodiment of the present invention. [Figure 5] This is a flowchart of communication in which an operator manages a terminal, according to an embodiment of the present invention. [Figure 6] This is a flowchart of communication in which an operator manages a terminal, according to an embodiment of the present invention. [Figure 7] This is a flowchart of communication in which an operator manages a terminal, according to an embodiment of the present invention. [Figure 8] This is a schematic flowchart illustrating how a network performs authentication on a terminal according to an embodiment of the present invention. [Figure 9] This is a schematic flowchart showing how a terminal performs authentication to the network according to an embodiment of the present invention. [Figure 10] This is a communication flowchart in a case of corporate mismatch according to an embodiment of the present invention. [Figure 11] This is a communication flowchart in a case of corporate mismatch according to an embodiment of the present invention. [Figure 12] This is a diagram showing the structure of a communication device according to an embodiment of the present invention. [Figure 13] This is a diagram showing the structure of a communication device according to an embodiment of the present invention. [Modes for carrying out the invention]
[0058] The communication methods provided in this application can be applied to various communication systems, such as the Internet of Things (IoT), Passive IoT (P-IoT; or Ambient IoT, A-IoT), Semi-Passive IoT, Semi-Active IoT, Active IoT, Narrowband Internet of Things (NB-IoT), Long-Term Evolution (LTE) systems, 5th Generation (5G) communication systems, LTE and 5G hybrid architectures, or new communication systems that will emerge in the development of 6G or future communications. Alternatively, the communication system may be a machine-to-machine (M2M) network, a machine-type communication (MTC) network, or another network.
[0059] Figure 1a is a diagram of a possible communication system applicable to embodiments of the present invention. The communication system comprises a terminal device, an access network device, a core network device, and a requester.
[0060] The requester may perform operations on a terminal device (e.g., a tag), including, but not limited to, obtaining information about the terminal device, inventory operations (or inventory lookup operations), read operations, write operations, disable operations, kill operations, and similar operations. The requester transmits operation commands through a core network device. In a possible implementation, the core network device instructs an access network device to initiate random access to the terminal device. After the terminal device successfully performs random access, the access network device sends or transfers information to the terminal device about the operations that need to be performed. In another possible implementation, the core network device instructs a second terminal device to initiate random access to a first terminal device. After the terminal device successfully performs random access, the second terminal device sends or transfers information to the first terminal device about the operations that need to be performed.
[0061] The terminal device retrieves or transmits corresponding information based on the information received about the operation. For example, when the operation is an inventory operation, the terminal device transmits its identification information; when the operation is a read operation, the terminal device transmits data information stored in the terminal device's memory bank; or when the operation is a write operation, the terminal device stores the data information that needs to be written in the terminal device's memory bank.
[0062] Access network devices transmit information from terminal devices to core network devices, and core network devices transmit information to the requester.
[0063] Terminal devices can be terminal devices in Internet of Things technology, and include, but are not limited to, passive terminal devices, semi-passive terminal devices, semi-active terminal devices, active terminal devices, low-power terminal devices, zero-power terminal devices, passive terminal devices, active terminal devices, and similar devices.
[0064] Terminal devices may also be referred to as user equipment (UE), terminals, access terminals, subscriber units, subscriber stations, mobile stations, remote stations, remote terminals, mobile devices, user terminals, wireless communication devices, user agents, or user equipment. Terminal devices can be widely used in various scenarios, such as the Internet of Things (IoT), device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-type communication (MTC), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearable devices, smart transportation, and smart cities. Terminal devices may include cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs®), handheld devices with wireless communication capabilities, computing devices, other processing devices connected to wireless modems, in-vehicle devices, wearable devices, terminal devices in 5G networks, terminal devices in future evolved public land mobile networks (PLMN) or non-terrestrial networks (NTN), or similar.Alternatively, a terminal device may be an end device, logical entity, smart device, or similar, such as a mobile phone or smart terminal; a communication device such as a server, gateway, base station, or controller; or an Internet of Things (IoT) device such as a tag (passive tag, active tag, or semi-active tag, etc.), sensor, electric meter, or water meter. Alternatively, a terminal device may be an unmanned aerial vehicle or uncrewed aerial vehicle (UAV) with communication capabilities. When a terminal device is a passive terminal, semi-passive terminal, semi-active terminal, active terminal, or tag, it may receive or transmit data by acquiring energy. Energy acquisition methods include, but are not limited to, electromagnetic waves, solar energy, light energy, wind energy, hydroelectric energy, thermal energy, kinetic energy, and similar. Energy acquisition methods for passive terminals, semi-passive terminals, semi-active terminals, active terminals, or tags are not limited in this application. In addition, the tags in this application may be in tag form or in any terminal form.
[0065] Access network devices are configured to connect terminal devices to a wireless network. Access network devices may include base stations, pole sites, indoor base stations (e.g., Lampsites), home base stations (e.g., home NBs), micro base stations, integrated access and backhaul (IAB) nodes, mobile base stations, wireless access networks, wireless access network devices, evolved NodeB (eNodeB) in LTE or LTE-Advanced (LTE-A) systems, next-generation NodeB (gNB) in 5G communication systems, transmission reception points (TRPs), baseband units (BBUs), Wi-Fi® access points (APs), base stations in future mobile communication systems, access nodes in Wi-Fi® systems, or similar. Alternatively, an access network device may be a module or unit that implements some of the functions of a base station, for example, a central unit (CU) or a distributed unit (DU). The specific technologies and device configurations used by access network devices are not limited to the embodiments of this application. For example, in a network structure, an access network device may be a CU node, a DU node, or an access network device comprising both CU and DU nodes. Specifically, a CU node is configured to support protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP).The DU node is configured to support radio link control (RLC) layer protocols, medium access control (MAC) layer protocols, and physical layer protocols. Alternatively, the access network device may be a device with reader functionality.
[0066] The requester can be understood as a device that sends an operation command, such as a third-party device, server, P-IoT server, application server (AS), application function (AF), passive Internet of Things application function (P-IoT AF), Internet of Things application function (IoT AF), or another device that sends an operation command. The requester can correspond to a specific type of user. A specific type of user may include, but is not limited to, an enterprise, tenant, third party, or company. The fact that the requester corresponds to a specific type of user can be understood as the requester belonging to and being managed by a specific type of user.
[0067] A core network device may include one or more of the following network elements:
[0068] An access management network element (which may also be referred to as an access management network element, a mobility management network element, or an access and mobility management network element) is a control plane network element provided by the operator network, responsible for access control and mobility management for terminal devices to access the operator network, and includes functions such as mobility status management, temporary user identification number assignment, and user authentication. In a 5G communication system, the access management network element may be an access and mobility management function (AMF) network element. In future communication systems, the access management network element may still be an AMF network element or may have a different name. This is not limited to the present invention.
[0069] Session management network elements are primarily responsible for session management in mobile networks, such as session establishment, modification, and release. Specific functions include, for example, assigning IP addresses to users and selecting user plane network elements that provide packet forwarding capabilities. In 5G communication systems, session management network elements may be session management function (SMF) network elements. In future communication systems, session management network elements may still be SMF network elements or may have different names. This is not limited to the present invention.
[0070] User plane network elements are responsible for transferring and receiving user data at terminal devices. User plane network elements can receive user data from the data network and transmit it to terminal devices via access network devices. User plane network elements can also receive user data from terminal devices via access network devices and transfer it to the data network. Transmission resources and scheduling functions in user plane network elements that provide services to terminal devices are managed and controlled by SMF network elements. In a 5G communication system, user plane network elements may be user plane function (UPF) network elements. In future communication systems, user plane network elements may still be UPF network elements or may have a different name. This is not limited to the present invention.
[0071] The data management network element is configured for generating authentication certificates, user identification processing (e.g., storing and managing persistent user identifiers), access control, subscription data management, and similar functions. In a 5G communication system, the data management network element may be a unified data management (UDM) network element. In future communication systems, unified data management may still be a UDM network element or may have a different name. This is not limited to the present invention.
[0072] The policy control network element is primarily responsible for providing an integrated policy framework for managing network behavior, supporting the provision of policy rules to control layer network functions, and obtaining user subscription information regarding policy decisions. In a 4G communication system, the policy control network element may be a policy and charging rules function (PCRF) network element. In a 5G communication system, the policy control network element may be a policy control function (PCF) network element. In future communication systems, the policy control network element may still be a PCF network element or may have a different name. This is not limited to the present invention.
[0073] A network repository network element may be configured to provide network element discovery functionality and, based on requests from other network elements, provide network element information corresponding to the network element type. The NRF may further provide network element management services, such as network element registration, updating, and de-updating, and network element status subscription and push. In a 5G communication system, a network repository network element may be a network repository function (NRF) network element. In future communication systems, a network repository network element may still be an NRF network element or may have a different name. This is not limited to the present invention.
[0074] Network-open network elements are control plane network elements provided by operators. Network-open network elements can be configured to securely open the external interface of the operator network to third parties and securely open services and capabilities provided by 3rd generation partnership project (3GPP®) network function devices and similar devices. When a session management network element needs to communicate with a third-party network element, a network-open network element can be used as a relay for communication between the session management network element and the third-party network element. When a network-open network element provides services as a relay, it can convert subscriber identification information and third-party network element identification information. For example, when a network-open network element transmits a subscriber's subscription permanent identifier (SUPI) from the operator network to a third party, the SUPI can be converted to a corresponding external identification number (ID). Conversely, when transmitting an external ID (third-party network element ID) to the operator network, the network-open network element can convert the external ID to a SUPI. In a 5G communication system, a network exposure function network element may be a network exposure function (NEF) network element. In future communication systems, a network exposure function network element may still be an NEF network element, or may have a different name. This is not limited to the present invention.
[0075] A network slice selection network element may be configured to select an appropriate network slice for terminal services. In a 5G communication system, a network slice selection network element may be a network slice selection function (NSSF) network element. In future communication systems, a network opening function network element may still be an NSSF network element or may have a different name. This is not limited to the present invention.
[0076] A network data analysis network element can collect data from each network function (NF), such as a policy control network element, a session management network element, a user plane network element, an access management network element, and an application function network element (through a network capability release function network element), and perform analysis and prediction. In a 5G communication system, the network data analysis network element may be a network data analytics function (NWDAF). In future communication systems, the network capability release function network element may still be an NWDAF network element, or may have a different name. This is not limited to the present invention.
[0077] The integrated data repository network element is responsible for storing structured data information, including subscription information, policy information, and network data or service data defined in a standard format. In a 5G communication system, the integrated data repository network element may be a unified data repository (UDR). In future communication systems, the network open function network element may still be a UDR network element or may have a different name. This is not limited to the present invention.
[0078] The Authentication Server Function (AUSF) is a functional entity used by the network to perform authentication on UEs, to verify whether UEs are trustworthy, and can support access service authentication as defined in the 3GPP® framework, as well as authentication for non-3GPP® access networks.
[0079] The network slice-specific and standalone non-public network authentication and authorization function (NSSAAF) is primarily configured to connect to external authentication, authorization, and accounting (AAA) servers, translate between service-based interfaces (SBI) and AAA interfaces, and act as an intermediate network element connecting internal network elements and external AAA servers within a 3GPP® network. For example, a correspondence between AAA server address information and domain information is pre-configured in the NSAAF. After receiving domain information, the NSAAF can determine the AAA server based on the AAA server address information and then send the received message to the AAA server. In another example, the NSSAAF may request the AAA server address information from a domain name server (DNS) based on the domain information, retrieve the AAA server address information from the DNS server, and then send the received message to the AAA server. NSSAAF can also be configured to support accessing standalone non-public networks using certificates from a credentials holder (CH) that uses an AAA server, or from a default credentials server (DCS) that uses an AAA server. If the certificate holder or default certificate server is from a third party, NSSAAF may communicate with the AAA server via an AAA proxy.
[0080] A tag management function (TMF) network element may also be called an Internet of Things management function (IMF) network element or an Internet of Things device management function (IDMF) network element, and may implement one or more of the following functions: (1) identify commands sent by the requester and perform operations on Internet of Things devices in accordance with the commands sent by the requester; (2) instruct access network devices or terminal devices to perform random access procedures on Internet of Things devices; (3) retrieve data from Internet of Things devices, where data sent by Internet of Things devices may be filtered or collected; (4) send data from Internet of Things devices to the requester; (5) connect to one or more requesters and perform data routing; and (6) perform security authentication procedures on Internet of Things devices, where the security procedures may be performed based on context information, policy information, or subscription data corresponding to the requester or Internet of Things device. A TMF network element can be an independent network element and deployed independently; or it can be part of the functionality of an existing network element and deployed together with that existing network element. For example, TMF and AMF or UPF can be deployed together.
[0081] The network elements or functions described above may be understood to be network elements in hardware devices, software functions running on dedicated hardware, or virtualization functions instantiated on a platform (e.g., a cloud platform). Network elements may also be referred to as “devices,” “entities,” or similar entities. One or more services may be obtained through the division into the network elements or functions described above. Furthermore, services may arise that exist independently of network functions. In this application, instances of functions, instances of services included in functions, or instances of services that exist independently of network functions may be referred to as service instances.
[0082] Figure 1a is merely an example of an applicable network architecture, and it should be understood that the network architecture actually applied may include more or fewer network elements than those shown in Figure 1a. In embodiments of the present application, the names of the network elements used above may be changed, although the function of the network elements may remain the same in future communication systems.
[0083] Figure 1b is a diagram illustrating the structure of a communication system applicable to the present invention. The tag management function TMF has a direct connection interface with a UDM, access network device, NEF, or AF for message exchange. The dashed boxes and dashed lines represent optional network elements or optional connections.
[0084] To facilitate understanding of the embodiments of this application, some terms used in the embodiments are described below to help those skilled in the art to have a better understanding.
[0085] (1) Figure 2 is a diagram of the memory bank format for tags in the prior art. The memory bank includes a reserved memory bank, an electronic product code (EPC) memory bank, a tag identifier (TID) memory bank, and a user memory bank. Each memory bank is described below.
[0086] The reserved memory bank is used to store one or more passwords required for the functionality of the kill command and / or access command.
[0087] The EPC memory bank identifies tagged EPCs, including StoredCRC, StoredPC, EPC, and extended XPC. An EPC uniquely identifies an object. From the perspective of higher-layer applications, an EPC is in uniform resource identifier (URI) format and is stored within the tag as binary code. The URI format includes urn:epc:id:scheme:component1.component2.... Different EPC schemes are named using the scheme. The specific form of component1, component2, and the rest of the EPC held within the EPC scheme depends on the EPC scheme used. The EPC also contains control information, which is used by the card reader to control the card reading procedure.
[0088] Multiple EPC schemes are defined in the existing EPC tag data standard (TDS), and the URI formats for different schemes are different. For example:
[0089] When the scheme is SGTIN, the corresponding URI format is as follows: urn:epc:id:sgtin:CompanyPrefix.ItemRefAndIndicator.SerialNumber.
[0090] When the scheme is SGLN, the corresponding URI format is as follows: urn:epc:id:sgln:CompanyPrefix.LocationReference.Extension.
[0091] The TID memory bank stores tag and vendor-specific data, such as tag manufacturer unique identifiers, tag type identifiers, and tag capabilities.
[0092] The user memory bank is an optional extension area that allows for the storage of user-specific data.
[0093] (2) An inventory operation may also be called an inventory lookup operation. This operation may be performed to obtain terminal identification information by using commands such as a query command or an acknowledgment command to obtain terminal identification information. Terminal identification information may be, for example, an electronic product code (EPC) and a tag identifier (TID).
[0094] (3) A read operation may involve reading data from the terminal's memory bank. For example, the data in the memory bank may include identification information (e.g., electronic product code EPC and tag identifier TID), content stored in the reservation bank, or content stored in the user memory bank.
[0095] (4) A kill operation can disable a device. For example, a disabled device cannot function.
[0096] (5) A lock operation can lock information about the terminal to prevent read or write operations on the tag. Alternatively, a lock operation can lock a memory bank to prevent or enable read or write operations on the memory bank.
[0097] (6) Block write operations may enable a reader / writer to perform multibyte write operations on a terminal's memory bank (e.g., reserved bank, EPC memory bank, TID memory bank, or user memory bank) by using a single command.
[0098] (7) Block erase operations may enable the reader / writer to perform multibyte erase operations on the terminal's memory banks (e.g., reserved bank, EPC memory bank, TID memory bank, or user memory bank).
[0099] (8) The access operation allows a terminal with a non-zero access password to change from an open state to a secured state.
[0100] (9) Write operations may be performed on the terminal's memory banks. For example, identification information (e.g., EPC or TID) in a memory bank may be written to or rewritten. Alternatively, write or rewrite operations may be performed on data in a reserved bank or user memory bank.
[0101] In embodiments of this application, “at least one” means one or more, and “multiple” means two or more. The term “and / or” describes a relationship between related subjects and indicates that three relationships may exist. For example, A and / or B may represent the following cases: only A exists, both A and B exist, and only B exists, where A and B may be singular or plural. The letter “ / ” generally indicates an “or” relationship between related subjects. At least one of the following items or similar expressions indicates any combination of these items, including one item or any combination of multiple items. For example, at least one of a, b, or c may represent a, b, c, a and b, a and c, b and c, or a, b and c, where a, b, and c may be singular or plural.
[0102] In addition, unless otherwise stated, ordinal numbers such as “First” and “Second” as referred to in the embodiments of this application are used to distinguish between multiple subjects and are not intended to limit the size, content, order, chronological order, priority, importance, or similar aspects of the multiple subjects. For example, the first piece of information and the second piece of information are used simply to distinguish between different pieces of information and do not indicate different content, priority, importance, or similar aspects of the two pieces of information.
[0103] Currently, the requester (which can be understood as a company or a third party) can co-manage the tags. For example, the requester performs authentication on the tags by using the Electronic Product Code (EPC) on the tags. In implementable scenarios, the operator also co-manages the tags. Currently, there is no solution for the operator to manage the tags. This application provides a solution for the operator to manage the tags.
[0104] The following describes the technical solutions in the embodiments of this application with reference to the accompanying drawings.
[0105] In current technology, a default EPC is already stored in the EPC memory bank before the terminal (e.g., a tag) is delivered. It can be understood that the default EPC is stored by the terminal manufacturer. The default EPCs for multiple terminals manufactured by the manufacturer are usually identical. After purchasing a terminal from the manufacturer, the requester (which can be understood as a company or a third party) may perform a procedure to overwrite the default EPC stored in the EPC memory bank by storing (storing can be understood as printing or writing) an EPC (which is an EPC for terminal management, not the default EPC, and which can be understood as an EPC usually assigned to the terminal by the requester) in the terminal's EPC memory bank. The requester can then manage the terminal together by using the EPC assigned to the terminal by the requester. The requester assigns different EPCs to different terminals. The assigned EPC can uniquely identify the terminal.
[0106] In embodiments of the present application, an operator may purchase a terminal from a manufacturer or terminal company, and the operator assigns an operator identification code to the terminal. The operator identification code may uniquely identify the operator, and the operator may assign different operator identification codes to different terminals. The operator identification code may uniquely identify the terminal. After the terminal has stored the operator identification code assigned by the operator (storage may be understood as printing or writing), the operator may manage the terminal by using the operator identification code. For example, management may include: performing network access identification by using the operator identification code, performing security authentication on the terminal, and so on.
[0107] The EPC stored in the EPC memory bank of a terminal purchased by an operator may be the default EPC stored by the terminal manufacturer (in other words, the requester has not performed the procedure to store the EPC assigned to the terminal by the requester), or it may be the EPC assigned to the terminal by the requester (in other words, the requester has performed the procedure to store the EPC assigned to the terminal by the requester).
[0108] The operator identification code includes a Public Land Mobile Network identifier (PLMN) ID, which may be a combination of a mobile country code (MCC) and a mobile network code (MNC). Based on this, the operator identification code may optionally further include an enterprise-level identification code or an EPC-level identification code. For example, the operator identification code may further include one or more of the following: an EPC for terminal management (which can uniquely identify a terminal), an enterprise code assigned to the terminal (the enterprise code may be replaced by an application code or service code), and a unique identification code for the terminal in the operator device mapped from the EPC for terminal management. The EPC for terminal management is assigned by the operator device or by the requester. A service code assigned by the operator device may be considered an enterprise-level identification code. The EPC for terminal management may be considered an EPC-level identifier. A unique identification code for the terminal in the operator device mapped from the EPC for terminal management may be considered an EPC-level identification code.
[0109] Generally, a company has multiple departments, and different departments manage different terminals. The same company code may be assigned to terminals in the same department, and different company codes may be assigned to terminals in different departments. In this way, by using departments as units, a differentiated inventory can be performed on terminals. Naturally, the same company code may also be assigned to terminals managed by the company, and as a result, a complete inventory of the company can be performed. A company code can uniquely identify a company or a department of a company.
[0110] In a different scenario, for example, different terminals may provide different services, such as gas services, water billing services, transportation services, electric vehicle services, and automobile services. The same identification code (e.g., referred to as an application code or service code) may be assigned to terminals providing the same service, and different identification codes (e.g., referred to as application codes or service codes) may be assigned to terminals providing different services. In this way, by using services as units, a differentiated inventory can be performed on terminals.
[0111] Enterprise codes, application codes, and service codes can be understood as being able to uniquely identify the type of terminal. The definition of "type" can be flexible. For example, an enterprise may be the type, a department or multiple departments of an enterprise may be the type, a service may be the type, and multiple services may be the type. The names of enterprise codes, application codes, and service codes should not limit the scenario.
[0112] The difference between the default EPC and the EPC for terminal management is that the default EPC is stored before the terminal is delivered and is stored by the terminal manufacturer; the EPC for terminal management is assigned to the terminal by the operator device or requester after the terminal has been delivered; and the EPC for terminal management can uniquely identify the terminal. In current technology, only the requester assigns the EPC for terminal management to a terminal. In this application, it is proposed that the operator device or requester may assign the EPC for terminal management to a terminal.
[0113] The operator identification code can be stored in one of the following memory banks on the terminal: reserved memory bank, EPC memory bank, TID memory bank, and user memory bank.
[0114] In certain systems, the operator identification code is stored in the terminal's EPC memory bank. For the format of the operator identification code, please refer to the Subscription Persistent Identifier (SUPI) format or SUPI-like format.
[0115] For example, the current SUPI format based on the International Mobile Subscriber Identity (IMSI), i.e., the Network Access Identifier (NAI), is as follows: <imsi>@ims.mnc <mnc>.mcc <mcc>.3gppnetwork.org.
[0116] Referring to the SUPI format, the format of the operator identification code is: <epc>.3gppnetwork.org or <epc>.mnc <mnc>.mcc <mcc>It could be .3gppnetwork.org.
[0117] Specifically, the following multiple save formats may be included:
[0118] Format 1: EPC is extended, and a new EPC scheme is added. It is defined as follows: The new EPC scheme includes MNC and MCC, and optionally further includes enterprise-level identification codes or EPC-level identification codes.
[0119] Based on the explanation in Figure 2, in current technology, when the scheme is SGTIN, the corresponding URI format is as follows: urn:epc:id:sgtin:CompanyPrefix.ItemRefAndIndicator.SerialNumber.
[0120] In the example, the format of the URI corresponding to the new EPC scheme added in the embodiment of the present application is as follows: urn:epc:id:PLMN: PLMN ID.CompanyPrefix.ItemRefAndIndicator.SerialNumber.
[0121] Format 2: EPC schemes differ in different application scenarios. Each EPC scheme is extended. It is defined as follows: An extended EPC scheme includes MNC and MCC, and optionally further includes a corporate-level identification code or an EPC-level identification code. The extended EPC scheme is similar to the URI format described above corresponding to any new EPC schemes added to embodiments of this application.
[0122] The operator identification code is stored in the terminal's EPC memory bank, and the EPC cannot be completely occupied. For flexible allocation, the EPC encoding space needs to be reserved for the enterprise. Therefore, the operator identification code can be considered to include the enterprise-level identification code (e.g., the enterprise code assigned to the terminal), which is used for password verification for enterprise network access.
[0123] In other specific schemes, the operator identification code is written to a non-EPC memory bank. For example, a non-EPC memory bank could be a reserved memory bank, a TID memory bank, a user memory bank, or another memory bank extended in the terminal.
[0124] The format of the operator identification code may be an extended SUPI-like format based on a serialized TID (TID), where the extended SUPI-like format based on an STID is as follows: <stid>.mnc <mnc>.mcc <mcc>.3gppnetwork.org. STID can uniquely identify a tag.
[0125] Operator identification codes are written to a non-EPC memory bank and do not occupy an EPC memory bank. Enterprises may customize EPC memory bank assignments for different application scenarios within the enterprise, such as object type classification of different parts. EPC memory banks may be used for verification of network access to EPCs for terminal management, and similar purposes. When authentication is required, operators may perform authentication based on operator identification codes, where authentication may also be understood as STID-based authentication, and enterprises may perform authentication based on EPCs in the EPC memory bank.
[0126] Figure 3 is a flowchart of communication for storing an operator identification code in the first terminal. The requester may be a requester in Figure 1a, for example, a third-party device, server, P-IoT server, application server AS, application function AF, passive Internet of Things application function (P-IoT AF), or Internet of Things application function (IoT AF). The core network device may be a core network device in Figure 1a, for example, an AMF, UDM, TMF, AUSF, NSSAAF, SMF, UPF, PCF, NEF, or UDR. The core network device may communicate with the requester directly or through another core network device. The first terminal may be a terminal device in Figure 1a. The operator device may be a device having one or more of the following functions: namely, assigning an operator identification code to the terminal, performing authentication on the terminal, assigning an EPC for terminal management to the terminal, assigning a key to the terminal, and so on. Operator devices may be devices deployed in the core network, such as AMF, UDM, TMF, AUSF, NSSAAF, PCF, or UDR. Alternatively, operator devices, such as AAA servers, may not be deployed in the core network.
[0127] To facilitate distinction, the core network device communicating with the requester is referred to as the first core network device, and the core network device communicating with the terminal / access network device is referred to as the second core network device. The first and second core network devices may be the same core network device or may be different core network devices. Figure 3 illustrates this using an example where the first and second core network devices are a single unit. The first and second core network devices are collectively referred to as the core network device. Alternatively, in Figure 3, an example where the first and second core network devices are the same is used, and the first and second core network devices are abbreviated as the core network device.
[0128] Step 301: The requester sends the first piece of information to the core network device, where the first piece of information directs to the first terminal.
[0129] In response, the core network device receives the first piece of information from the requester.
[0130] The first terminal is a terminal to which an operator identification code must be assigned (or printed, stored, or written). The operator identification code can uniquely identify the operator or the terminal.
[0131] In addition to indicating a first terminal, the first information may be understood to indicate yet another terminal. In a particular example, the first information indicates that a corresponding operator identification code should be assigned to one or more terminals (including the first terminal). In the example, the values of bits at one or more specific positions in the bits occupied by the first information indicate whether the operator identification code should be assigned to a terminal or not. For example, a value of 0 for a bit at a specific position indicates that the operator identification code should be assigned to a terminal; or a value of 1 for a bit at a specific position indicates that the operator identification code should not be assigned to a terminal. The meanings represented by the bit values are merely examples and should not constitute a limitation on the solution.
[0132] The core network device may determine, based on first information, one or more terminals to which an operator identification code needs to be assigned, including the first terminal. The EPC memory bank of the one or more terminals to which an operator identification code needs to be assigned, as indicated by first information, may store a default EPC, or the EPC memory bank may be empty, in other words, no default EPC is stored.
[0133] The process of assigning operator identification codes to all terminals is similar. In the example in Figure 3, we will explain using only the example where the operator identification code is assigned to the first terminal.
[0134] The first information may indicate the first terminal in one or more of the following ways:
[0135] For example, the first piece of information includes a default EPC range, and the default EPC range includes the default EPC of the first terminal. The first piece of information can be understood as the EPC range to which operator identification code assignments are subscribed to or approved and sent to the core network device by the requester. Based on the default EPC range, the core network device determines that the default EPC should assign operator identification codes to terminals that belong to the default EPC range.
[0136] For example, the first piece of information includes one or more default EPCs, and one or more default EPCs include the default EPCs of the first terminal. The first piece of information can be understood as one or more default EPCs that are subscribed to or approved for operator identification code assignment and that are sent to the core network device by the requester. Based on one or more default EPCs, the core network device determines that the default EPCs should be assigned to terminals to which one or more default EPCs belong.
[0137] For example, the first piece of information includes one or more target TID types, and the TID of the first terminal belongs to one of the target TID types. The first piece of information can be understood as one or more target TID types to which operator identification code assignments are subscribed to or authorized and transmitted to the core network device by the requester. Based on the one or more target TID types, the core network device determines that an operator identification code should be assigned to a terminal whose TID type belongs to one or more target TID types.
[0138] For example, the first piece of information may include information about the requester, which may indicate a default EPC range or one or more default EPCs corresponding to (or managed by) the requester. The default EPC range or one or more default EPCs corresponding to (or managed by) the requester include the default EPC of the first terminal. Based on the information about the requester, the core network device may determine that an operator identification code should be assigned to the terminal whose default EPC belongs to the default EPC range or one or more default EPCs corresponding to (or managed by) the requester.
[0139] Information about the requester may include one or more of the following: AF identifier (AF identifier or AF identity, AF ID), service identifier (service identifier or service identity, service ID), application identifier (application identifier or application identity, APP ID), AF address information, AF port information, application server AS address information, and application server AS port information. The AF or AS address may be, for example, an Internet Protocol address (IP), a Medium Access Control (MAC) address, or an IPv6 prefix. The AF or AS port may be, for example, a transmission control protocol (TCP) port or a user datagram protocol (UDP) port.
[0140] A default EPC range or one or more default EPCs corresponding to (or managed by) a requester may be stored or configured on a core network device, or on another core network device. A core network device may send information about a requester to another core network device, which, based on the information about the requester, retrieves a default EPC range or one or more default EPCs corresponding to (or managed by) the requester and sends the default EPC range or one or more default EPCs to the core network device. For example, another core network device may include core network devices such as UDM, UDR, AUSF, NEF, PCF, SMF, TMF, or NSSAAF.
[0141] In conclusion, the first information may be recognized as including one or more of the following: the tag identifier (TID) type of the first terminal, the default electronic product code (EPC) of the first terminal, and information about the requester. A core network device may determine the first terminal based on the information contained in the first information, and, of course, may determine other terminals.
[0142] Optionally, based on instructions from the first terminal, the first information may further include a service scope. For example, the service scope may include area information A, where area information A indicates an area corresponding to one or more terminals to which an operator identification code needs to be assigned. For example, area information A may be a geographical location, municipal location, or 3GPP® location information (such as a tracking area (TA) list or cell list) corresponding to one or more terminals to which an operator identification code needs to be assigned. The service scope is used to query access network devices.
[0143] Optionally, the requester may further request the core network device to assign (or print, save, or write) an EPC for terminal management to a terminal. For example, the first information instructs the assignment of the corresponding EPC for terminal management to one or more terminals (including the first terminal). In the example, the values of the bits at one or more specific positions in the bits occupied by the first information indicate whether the EPC is assigned to a terminal or not. For example, a value of 0 at a specific position indicates that the EPC is assigned to a terminal; or a value of 1 at a specific position indicates that the EPC is not assigned to a terminal. The meanings represented by the bit values are merely examples and should not constitute a limitation on the solution.
[0144] When an EPC needs to be assigned to a terminal, in the example, the requester instructs the core network device to assign an EPC for terminal management to each of the one or more terminals (including the first terminal) indicated by the first information. For example, the first information may further include a range of EPCs for terminal management, or a range of EPCs corresponding to each type, and as a result, the core network device stores the EPCs for terminal management to the corresponding terminals. A company may define terminal types and EPC ranges for different purposes and send them to the operator for printing. In another example, the requester does not instruct the core network device to assign an EPC for terminal management to each of the one or more terminals (including the first terminal) indicated by the first information, but the operator assigns EPC codes to the one or more terminals indicated by the first information.
[0145] Optionally, the requester may further request the core network device to assign (or print, save, or write) a key to the terminal. The key is used for security authentication between the terminal and the core network device or the requester. In the example, the values of bits at one or more specific positions in a set of bits occupied by the first information indicate whether the key is assigned to the terminal or not. For example, a value of 0 at a specific position indicates that the key is assigned to the terminal; or a value of 1 at a specific position indicates that the key is not assigned to the terminal. The meanings represented by the bit values are merely examples and should not constitute a limitation on the solution.
[0146] When a key needs to be assigned to a terminal, in an optional example, the requester instructs the core network device to assign a key to each of the one or more terminals (including the first terminal) indicated by the first information. For example, the first information further indicates a key to each of the one or more terminals. In possible examples, the one or more terminals indicated by the first information share one or more keys; the one or more terminals indicated by the first information correspond to different keys; or terminals of the same type in the one or more terminals indicated by the first information share one or more keys, while terminals of different types correspond to different keys.
[0147] When a key needs to be assigned to a terminal, in another optional example, the requester does not instruct the core network device to assign a key to each of the one or more terminals (including the first terminal) indicated by the first information, and the core network device assigns the corresponding key to the one or more terminals (including the first terminal) indicated by the first information; or the core network device obtains a key from the operator device to assign a key to each of the one or more terminals (including the first terminal) indicated by the first information.
[0148] In an example where the requester does not instruct the core network device on a key corresponding to each of the one or more terminals (including the first terminal) indicated by the first information, the requester may instruct the core network device on key requirements, and the core network device may assign keys to terminals based on the key requirements. In a possible implementation, the first information further instructs on key requirements. The key requirements instruct that the one or more terminals indicated by the first information share one or more keys, that the one or more terminals indicated by the first information correspond to different keys, or that terminals of the same type in the one or more terminals indicated by the first information share one or more keys, and that terminals of different types correspond to different keys.
[0149] For example, the first piece of information specifies key requirements by using a package service identifier or a security level service identifier. For example, package service identifier A or security level service identifier A corresponds to the case where terminals correspond to different keys, package service identifier B or security level service identifier B corresponds to the case where all terminals share one or more keys, package service identifier C or security level service identifier C corresponds to the case where terminals of the same type share one or more keys, and different types of terminals correspond to different keys.
[0150] In the example, the values of bits at one or more specific positions in the bits occupied by the first information indicate the key requirements. For example, when the values of bits at two specific positions are 00, it indicates that terminals correspond to different keys, or indicates package service identifier A or security level service identifier A; when the values of bits at two specific positions are 11, it indicates that all terminals share one or more keys, or indicates package service identifier B or security level service identifier B; or when the values of bits at two specific positions are 01, it indicates that terminals of the same type share one or more keys, and different types of terminals each correspond to different keys, or indicates package service identifier C or security level service identifier C. The meanings represented by the bit values are merely examples and should not constitute limitations on the solution.
[0151] In another example, key requirements may alternatively be determined by the operator device or core network device, and do not need to be determined by the requester. In addition, the operator may further determine the terminal's security policy, such as whether authentication is required or not, whether the authentication method is one-way or two-way, and whether message encryption and / or integrity protection is supported or not.
[0152] Step 302: The core network device obtains the operator identification code assigned to the first terminal by the operator device.
[0153] When the first piece of information indicates that an operator identification code should be assigned to one or more terminals (including the first terminal), the core network device may, based on the first piece of information, determine which one or more terminals (including the first terminal) need to be assigned the operator identification code and obtain the operator identification code assigned to one or more terminals by the operator device. The operator device may assign different operator identification codes to different terminals, and the operator identification codes may uniquely identify the terminals.
[0154] The operator device and the core network device may be the same device or may be different devices. If the operator device and the core network device are the same device, the process by which the core network device obtains operator identification codes assigned to one or more terminals by the operator device includes: the core network device assigning operator identification codes to one or more terminals, or the core network device selecting corresponding operator identification codes for one or more terminals from a pre-stored set of operator identification codes. If the operator device and the core network device are not the same device, the process by which the core network device obtains operator identification codes assigned to one or more terminals by the operator device includes: the core network device receiving operator identification codes for one or more terminals from the operator device.
[0155] When the first piece of information instructs that an EPC for terminal management be assigned to one or more terminals (including the first terminal), the requester does not instruct the core network device to assign an EPC for terminal management to each of the one or more terminals (including the first terminal) indicated by the first piece of information, and the core network device may further obtain the EPC for terminal management that has been assigned to one or more terminals (including the first terminal) by the operator device.
[0156] The operator device and the core network device may be the same device or may be different devices. If the operator device and the core network device are the same device, the process by which the core network device obtains the EPC for terminal management assigned to one or more terminals by the operator device includes: the core network device assigning the EPC for terminal management to one or more terminals; or the core network device selecting the corresponding EPC for terminal management for one or more terminals from a pre-stored EPC for terminal management. If the operator device and the core network device are not the same device, the process by which the core network device obtains the EPC for terminal management assigned to one or more terminals by the operator device includes: the core network device receiving the EPC for terminal management for one or more terminals from the operator device.
[0157] If the first piece of information instructs that a key be assigned to one or more terminals (including the first terminal), and the requester does not instruct the core network device to assign a key to each of the one or more terminals (including the first terminal) indicated by the first piece of information, the core network device may further obtain the key assigned to one or more terminals (including the first terminal) by the operator device. Optionally, if the first piece of information further instructs the key requirements, the core network device may obtain the key assigned to one or more terminals (including the first terminal) by the operator device based on the key requirements.
[0158] The operator device and the core network device may be the same device or may be different devices. If the operator device and the core network device are the same device, the process by which the core network device obtains keys assigned to one or more terminals by the operator device includes: the core network device assigning keys to one or more terminals, or the core network device selecting corresponding keys from a pre-stored set of keys for one or more terminals. If the operator device and the core network device are not the same device, the process by which the core network device obtains keys assigned to one or more terminals by the operator device includes: the core network device receiving keys for one or more terminals from the operator device.
[0159] Step 303: The core network device sends second information to the first terminal, instructing the first terminal to store the operator identification code.
[0160] In response, the first terminal receives the second piece of information from the core network device.
[0161] The second piece of information instructs the first terminal to save the operator identification code. For example, the second piece of information includes the operator identification code assigned to the first terminal. For example, the second piece of information is a write command.
[0162] In possible implementations, the operator identification code is stored in a default memory location on the terminal, and the core network device does not need to instruct the terminal on the location of the operator identification code, thereby reducing signaling overhead.
[0163] Therefore, in another possible implementation, the core network device may instruct a terminal on the storage location of the operator identification code. For example, based on the second information instructing a first terminal to store the operator identification code, the second information further includes first location information for storing the operator identification code. For example, the first location information indicates a memory bank, e.g., an EPC memory bank, a reserved memory bank, a TID memory bank, or a user memory bank. The storage location for storing the operator identification code, instructed by the core network device to multiple terminals, may be the same; or, the storage location for storing the operator identification code, instructed by the core network device to terminals of the same type, may be the same, while the storage location for storing the operator identification code, instructed by the core network device to terminals of different types, may be different. In a particular implementation, the design may be carried out based on different requirements. This is not limited to the present invention.
[0164] When the procedure for saving the operator identification code to the terminal is performed, the terminal's EPC memory bank either saves a default EPC saved by the terminal manufacturer or does not save a default EPC (in other words, the requester has not performed the procedure for saving an EPC assigned to the terminal by the requester). In this case, the procedure for saving the operator identification code to the terminal may also save an EPC for terminal management to the terminal, eliminating the need to perform a separate procedure for saving an EPC for terminal management to the terminal, and consequently reducing signaling exchange. In possible implementations, based on the second information instructing the first terminal to save the operator identification code, the second information optionally further instructs the first terminal to save a first electronic product code EPC corresponding to the first terminal, where the first EPC may be assigned to the first terminal by an operator device or the first EPC is from the requester. The first EPC is an EPC for terminal management that is assigned to the first terminal by the operator device or requester, and the first EPC uniquely identifies the first terminal.
[0165] In possible implementations, the EPC for terminal management is stored in a default memory location on the terminal, eliminating the need for core network devices to instruct the terminal on the EPC's location, thus reducing signaling overhead.
[0166] Therefore, in another possible implementation, the core network device may instruct a terminal on the storage location of the EPC for terminal management. For example, based on the second information instructing a first terminal to store a first EPC, the second information further includes second location information for storing the first EPC. For example, the second location information points to a memory bank, e.g., an EPC memory bank. The storage locations for storing EPCs instructed by the core network device to multiple terminals may be the same; or, the storage locations for storing EPCs instructed by the core network device to terminals of the same type may be the same, while the storage locations for storing EPCs instructed by the core network device to terminals of different types may be different. In a particular implementation, the design may be carried out based on different requirements. This is not limited to the present application.
[0167] Based on the second piece of information instructing the first terminal to store an operator identification code, optionally, in a possible implementation, the second piece of information may further instruct the first terminal to store a key. For example, the second piece of information may include a key assigned to the first terminal.
[0168] In possible implementations, the key is stored in a default location on the terminal, and the core network device does not need to instruct the terminal on the key's location, thereby reducing signaling overhead.
[0169] In another possible implementation, the core network device may instruct a terminal to store a key. For example, based on the second information instructing a first terminal to store a key, the second information further includes a third location for storing the key. For example, the third location indicates a memory bank, such as an EPC memory bank, a reserved memory bank, a TID memory bank, or a user memory bank. The storage location for storing keys instructed to multiple terminals by the core network device may be the same; or the storage location for storing keys instructed to terminals of the same type by the core network device may be the same, while the storage location for storing keys instructed to terminals of different types by the core network device may be different. In a particular implementation, the design may be carried out based on different requirements. This is not limited herein.
[0170] Step 304: The first terminal stores the operator identification code.
[0171] When the first terminal stores the operator identification code, for example, the first terminal stores the operator identification code in a default storage location; or in another example, the second information includes first location information for storing the operator identification code assigned to the first terminal, and the first terminal stores the operator identification code assigned to the first terminal in a first storage location corresponding to the first location information. In possible examples, the storage location corresponding to the first location information may include the storage location of the EPC in a terminal in the prior art. In this way, the operator identification code may be stored in the EPC storage location, the operator identification code may replace the function of the EPC, and the EPC does not need to be stored in the terminal. If the default EPC is stored in the EPC storage location, the operator identification code may override the default EPC.
[0172] The first terminal may further save the first EPC when the second piece of information instructs the first terminal to save the first EPC corresponding to the first terminal. The first EPC is assigned by the operator device or the requester. The first EPC may override the default EPC.
[0173] When the first terminal saves the first EPC, for example, the first terminal saves the first EPC to a default memory location; or, in another example, the second information includes second location information for saving the first EPC, and the first terminal saves the first EPC to a second memory location corresponding to the second location information. For example, the second location information points to an EPC memory bank. If the default EPC is saved to an EPC memory location, the first EPC may overwrite the default EPC.
[0174] In the process described above, the operator identification code assigned to the terminal by the operator device is stored on the terminal, and the operator can manage the terminal based on the operator identification code. Optionally, the terminal may further store an EPC for terminal management assigned to the terminal by the operator device or requester, and the operator device or requester can manage the terminal based on the EPC for terminal management.
[0175] The first terminal may store additional keys if the second piece of information further instructs the first terminal to store keys corresponding to the first terminal. Keys may be assigned to the first terminal by an operator device or requester. When the first terminal stores a key, for example, the first terminal stores the key in a default storage location; or, in another example, the second piece of information includes a third location for storing keys assigned to the first terminal, and the first terminal stores the keys assigned to the first terminal in a third storage location corresponding to the third location. The terminal stores keys assigned to it by an operator device or requester, and the operator device or requester may perform authentication against the terminal based on the keys.
[0176] When the first core network device and the second core network device are different core network devices, information is exchanged between the first core network device and the second core network device. The first core network device is, for example, an AMF, UDM, TMF, AUSF, NSSAAF, SMF, UPF, PCF, NEF, or UDR, and the second core network device is, for example, an AMF, UDM, TMF, AUSF, NSSAAF, SMF, UPF, PCF, NEF, or UDR. It can be understood that the first core network device can communicate with the second core network device directly, or can communicate with the second core network device through another core network device. The first core network device can communicate with the requester directly, or can communicate with the requester through another core network device. The second core network device can communicate with the terminal / access network device directly, or can communicate with the terminal / access network device through another core network device.
[0177] Referring to the communication procedure in Figure 3, the following describes the communication procedure when the first core network device and the second core network device are different core network devices.
[0178] Step 301 can be replaced with the following: The requester sends the first information to the first core network device, and in response, the first core network device receives the first information from the requester.
[0179] Step 302 may be replaced by: The first core network device obtains the operator identification code assigned to the first terminal by the operator device.
[0180] A new step is added before step 303: The first core network device sends first instruction information to the second core network device, instructing it to write the corresponding operator identification code to one or more terminals (including the first terminal).
[0181] In response, the second core network device receives the first instruction information from the first core network device.
[0182] The first instruction information could be a request to write an operator identification code to a blank tag.
[0183] Based on the first instruction information instructing one or more terminals (including the first terminal) to write a corresponding operator identification code, the first instruction information further optionally includes first location information for storing the operator identification code.
[0184] Based on the first instruction information instructing that a corresponding operator identification code be written to one or more terminals (including the first terminal), the first instruction information may further instruct that a corresponding terminal management EPC (the EPC for managing the first terminal is referred to as the first EPC) be written to one or more terminals (including the first terminal), where the terminal management EPC (including the first EPC) is assigned to the first terminal by the operator device; or the terminal management EPC (including the first EPC) is from the requester. In a particular example, the first instruction information includes a relationship between the operator identification code and the terminal management EPC, and the operator identification code and terminal management EPC assigned to each terminal may be determined based on the relationship. The first instruction information may be a request to write the operator identification code and EPC to a blank tag.
[0185] Based on the first instruction information further instructing that a corresponding first EPC be written to one or more terminals (including the first terminal), the first instruction information further optionally includes second location information for storing an EPC (including the first EPC) for terminal management.
[0186] Based on the first instruction information instructing that a corresponding operator identification code be written to one or more terminals (including the first terminal), the first instruction information may further optionally instruct that a corresponding key be written to one or more terminals (including the first terminal). The key is assigned to the first terminal by the operator device, or the key is from the requester. In a particular example, the first instruction information includes a relationship between the operator identification code and the key, and the operator identification code and key assigned to each terminal may be determined based on this relationship. The first instruction information may be a request to write the operator identification code and key to a blank tag.
[0187] In an optional example, the first instruction information instructs that a corresponding operator identification code, an EPC for terminal management, and a key be written to one or more terminals (including the first terminal). For example, the first instruction information includes the relationships between the operator identification code, the EPC for terminal management, and the key. The operator identification code, the EPC for terminal management, and the key assigned to each terminal may be determined based on these relationships. The first instruction information may be a request to write the operator identification code, the EPC for terminal management, and the key to a blank tag.
[0188] When the first information transmitted by the requester to the first core network device indicates the key requirements, and the first instruction information instructs that the corresponding key be written to one or more terminals (including the first terminal), the first instruction information may optionally further specify the key requirements.
[0189] For example, the first instruction information includes a default EPC range, and the default EPC range includes the default EPC of the first terminal. The second core network device determines, based on the default EPC range, that the default EPC should assign an operator identification code to terminals that belong to the default EPC range.
[0190] For example, the first instruction information includes one or more default EPCs, and one or more default EPCs include the default EPC of the first terminal. The second core network device determines, based on one or more default EPCs, that the default EPCs should be assigned to terminals to which one or more default EPCs belong.
[0191] For example, the first instruction information includes one or more target TID types, and the TID of the first terminal belongs to one of the target TID types. The second core network device determines, based on one or more target TID types, that an operator identification code should be assigned to terminals whose TID type belongs to one or more target TID types.
[0192] In conclusion, the first instruction information may be recognized as including one or both of the following: the tag identifier (TID) type of the first terminal, and the default electronic product code (EPC) of the first terminal. A second core network device may determine the first terminal based on the information contained in the first instruction information, and, of course, may determine other terminals.
[0193] Optionally, the first instruction information may further include a service scope, based on the assumption that the first instruction information instructs one or more terminals (including the first terminal) to write a corresponding operator identification code. The service scope is used to query access network devices.
[0194] Step 303 can be replaced as follows: The second core network device sends the second information to the first terminal.
[0195] In response, the first terminal receives the second piece of information from the second core network device.
[0196] For specific details of the communication procedure, please refer to the explanation in Figure 3. Further details will not be explained again.
[0197] In an optional example, before the core network device (or second core network device) sends second information to the first terminal, the core network device (or second core network device) first sends third information to the access network device, which instructs it to search for one or more terminals (including the first terminal) or to obtain the default EPC of one or more terminals (including the first terminal). Correspondingly, the access network device receives third information from the core network device (or second core network device). Based on the third information, the access network device searches for one or more terminals (including the first terminal) (the search for terminals may also be understood as terminal selection or terminal filtering), and the first terminal among the one or more found terminals accesses the access network device. After the first terminal has accessed the access network device, the first terminal sends its default EPC to the core network device (or second core network device) through the access network device. In response, the core network device (or the second core network device) receives the default EPC from the first terminal. Furthermore, the core network device (or the second core network device) sends the second piece of information to the first terminal.
[0198] The third piece of information may be referred to as an inventory command or inventory request. The third piece of information may indicate one or more terminals in one or more of the following ways:
[0199] For example, the third piece of information includes the default EPC range, and the default EPC range includes the default EPC of the first terminal. Based on the default EPC range, the access network device determines whether the default EPC should be retrieved for terminals belonging to the default EPC range, or whether the default EPC within the default EPC range should be retrieved.
[0200] For example, the third piece of information includes one or more default EPCs, and one or more default EPCs include the default EPC of the first terminal. Based on one or more default EPCs, the access network device determines whether a terminal to which the default EPC belongs needs to be searched, or whether one or more default EPCs need to be retrieved.
[0201] For example, the third piece of information includes one or more target TID types, and the TID of the first terminal belongs to one of the target TID types. Based on one or more target TID types, the access network device determines whether terminals whose TID type belongs to one or more target TID types need to be searched for, or whether the default EPC of terminals whose TID type belongs to one or more target TID types needs to be retrieved.
[0202] In conclusion, the third piece of information may be recognized as including one or both of the following: the tag identifier (TID) type of the first terminal, and the default electronic product code (EPC) of the first terminal. An access network device may determine the first terminal based on the third piece of information, and, of course, further determine other terminals.
[0203] In a possible implementation, the process by which an access network device searches for one or more terminals (including a first terminal) based on third information includes: the access network device sending radio frequency information to terminals in the access network device's coverage area based on third information to provide a stimulus signal to the terminals in the access network device's coverage area, and as a result the terminals sending a signal to the access network device; the access network device performing a selection operation on terminals in the coverage area to select one or more terminals by performing the selection operation; and further, the access network device searching for one or more terminals (including a first terminal) by sending a query command to the selected one or more terminals (including a first terminal).
[0204] In a possible implementation, the process by which a first terminal among one or more discovered terminals accesses an access network device includes: one or more terminals initiating a random access procedure after receiving a query command, where one terminal (i.e., the first terminal) successfully performs the random access, in other words, accesses the access network device.
[0205] In a possible implementation, the random access procedure may be as follows: After receiving a query command, one or more terminals separately send random numbers to an access network device, which can accurately receive the random numbers and accurately feed them back to the terminals. The terminals that send the random numbers determine that the random access was successful.
[0206] Optionally, a query command sent by the access network device to one or more terminals includes the TID type of one or more terminals or the default EPC of one or more terminals. After receiving the query command, one or more terminals may match the TID type in the query command with the terminal's TID type, or match the default EPC in the query command with the terminal's default EPC, and after a successful match, initiate a random access procedure (e.g., sending a random number to the access network device). Naturally, the first terminal may also initiate a random access procedure first, and after a successful random access and before the first terminal's default EPC is sent to the core network device, the first terminal may perform the process of matching the information in the query command with the first terminal's information, and after a successful match, send the first terminal's default EPC to the core network device.
[0207] In a possible implementation, the sending of the first terminal's default EPC to the core network device (or second core network device) includes the sending of a request message to the core network device (or second core network device) via an access network device, the request message including the first terminal's default EPC. The access network device may transparently send the request message. The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited herein. The request message may be a non-access stratum (NAS) message or a non-NAS message.
[0208] Referring to the communication system shown in Figure 1b, Figure 4 is a diagram of a specific communication procedure for storing an operator identification code in a first terminal. The communication procedure will be explained using an example where the requester is an AF, the first core network device is a UDM, and the second core network device is a TMF. The UDM and AF can communicate with each other directly or through another core network device (e.g., a NEF).
[0209] Step 401: The AF transmits first information to the UDM, where the first information indicates one or more terminals, and the one or more terminals include the first terminal.
[0210] In response, the UDM receives the first piece of information from the AF.
[0211] The AF may transmit the first information directly to the UDM, or it may transmit the first information to the UDM through another core network device (e.g., NEF).
[0212] For the process in step 401, please refer to the process in step 301. Further details will not be provided again.
[0213] Step 402: Once the AF (which can be understood as a company) has paid the operator, the subscription may be considered successful, and the UDM will assign a company code to the AF, where the company code uniquely identifies the AF.
[0214] The enterprise code can be replaced by the application code or service code.
[0215] Step 403a: The UDM obtains the operator identification code assigned to one or more terminal devices by the operator device.
[0216] After receiving the first information from the AF, the UDM may obtain the operator identification codes assigned to one or more terminal devices by the operator device. For example, the UDM may assign each corresponding operator identification code to one or more terminals that need to store the operator identification codes, where different operator identification codes are assigned to different terminals. Naturally, the UDM may also obtain the operator identification codes corresponding to one or more terminals from the operator device. For a specific process, see the process described in step 302, in which the core network device obtains the operator identification codes assigned to the first terminal by the operator device.
[0217] If the first information transmitted to the UDM by the AF in step 401 instructs the assignment of an EPC for terminal management to one or more terminals (including the first terminal), and the first information does not include an EPC for terminal management for each of the one or more terminals (including the first terminal), the UDM may further retrieve the EPC for terminal management assigned to one or more terminals (including the first terminal) by the operator device. For a specific process, see step 302, in which the core network device retrieves the EPC for terminal management assigned to one or more terminals (including the first terminal) by the operator device. Different terminals correspond to different EPCs for terminal management.
[0218] If the first information transmitted to the UDM by the AF in step 401 instructs the UDM to assign keys to one or more terminals (including the first terminal), and the first information does not include keys corresponding to each of the one or more terminals (including the first terminal), the UDM may further retrieve the keys assigned to one or more terminals (including the first terminal) by the operator device, and the keys corresponding to different terminals may be different or the same. For a specific process, see step 302, in which the core network device retrieves the keys assigned to one or more terminals (including the first terminal) by the operator device.
[0219] Specific examples are provided by using an example in which the UDM obtains keys corresponding to one or more terminals (including the first terminal).
[0220] The UDM can check whether keys corresponding to one or more terminals are stored locally. If keys are stored, the UDM can use them directly. If keys are not stored locally, the UDM requests information about the key-storing network element (such as address information) from the NRF. The network element storing the key information registers with the NRF. Thus, the NRF recognizes the network element storing the key information.
[0221] The NRF transmits information about key storage network elements to the UDM. In response, the UDM receives the information about key storage network elements transmitted by the NRF. Network elements include, for example, UDRs or AUSFs.
[0222] Based on information about the network element, the UDM requests a key storage network element to assign keys to one or more terminals, as indicated by the first piece of information. For example, the UDM sends a request message to the key storage network element, which is used to request one or more keys. Optionally, the request message may further specify key requirements, and the key storage network element may assign corresponding keys to one or more terminals based on those requirements. Optionally, the request message may further specify a default EPC code range and / or TID type.
[0223] The key storage network element sends a key corresponding to one or more terminals to the UDM. In response, the UDM receives the key corresponding to one or more terminals that was sent by the key storage network element.
[0224] In certain cases, both the operator identification code and the key can be obtained from a key storage network element. For example, the UDM sends a request message to the key storage network element, which is used to request the operator identification code and key corresponding to one or more terminals. The key storage network element sends the operator identification code and key corresponding to each of the one or more terminals to the UDM. Correspondingly, the UDM receives the operator identification code and key corresponding to each of the one or more terminals transmitted by the key storage network element.
[0225] For each terminal indicated by the first information from the AF, the UDM stores the mapping relationship between the operator identification code and key assigned to the terminal. Furthermore, optionally, for each terminal indicated by the first information from the AF, the UDM stores the mapping relationship between the operator identification code, the EPC for terminal management, and the key assigned to the terminal.
[0226] Step 403: The UDM sends the first instruction information to the TMF, which instructs the TMF to write the corresponding operator identification code to one or more terminals (including the first terminal).
[0227] In response, the TMF receives the first instruction information from the UDM.
[0228] Furthermore, optionally, the first instruction information further includes first location information for storing an operator identification code.
[0229] Optionally, the first instruction information further instructs to write the corresponding EPC for terminal management to one or more terminals (including the first terminal). Optionally, the first instruction information further includes second location information for saving the EPC for terminal management (including the first EPC).
[0230] Optionally, the first instruction information further instructs to write the corresponding key to one or more terminals (including the first terminal). Optionally, the first instruction information further includes a third location for storing the key. Optionally, the first instruction information further includes the key requirements.
[0231] For the process in step 403, please refer to the process described above in which the first core network device sends the first instruction information to the second core network device. Further details will not be explained again.
[0232] The operator identification code writing procedure may be performed separately for different types of terminals; or it may be understood that the operator identification code writing procedure may be performed simultaneously for multiple types of terminals. The procedure for writing the EPC for terminal management may be performed separately for different types of terminals; or the procedure for writing the EPC for terminal management may be performed simultaneously for multiple types of terminals. The key writing procedure may be performed separately for different types of terminals, or the key writing procedure may be performed simultaneously for multiple types of terminals.
[0233] Step 404: TMF determines the access network device based on the service scope.
[0234] If the first instruction information instructs that the corresponding operator identification code and EPC for terminal management be written to one or more terminals (including the first terminal), the TMF stores the association between the operator identification code and the EPC for terminal management.
[0235] If the first instruction information instructs that the corresponding operator identification code and key be written to one or more terminals (including the first terminal), the TMF stores the association between the operator identification code and the key.
[0236] If the first instruction information instructs that the corresponding operator identification code, EPC for terminal management, and key be written to one or more terminals (including the first terminal), the TMF stores the association between the operator identification code, the EPC for terminal management, and the key.
[0237] Step 405: The TMF sends third information to the access network device determined in Step 404, instructing it to search for one or more terminals (including the first terminal).
[0238] In response, the access network device receives third information from the TMF.
[0239] For the process in step 405, please refer to the process described above in which the second core network device sends the third information to the access network device. Further details will not be explained again.
[0240] Step 406: The access network device searches for one or more terminals (including the first terminal) based on the third piece of information.
[0241] Device search can also be understood as device selection or device filtering.
[0242] For the process in step 406, please refer to the process described above in which the access network device searches for one or more terminals (including the first terminal) based on the third piece of information.
[0243] For example, based on third information, the access network device transmits radio frequency information to terminals in the access network device's coverage area to provide a stimulus signal to the terminals in the access network device's coverage area, and as a result, the terminals transmit a signal to the access network device. The access network device performs a selection operation on the terminals in the coverage area to select one or more terminals. Furthermore, the access network device sends a query command to the selected one or more terminals (including the first terminal) to search for one or more terminals (including the first terminal).
[0244] Optionally, query commands sent by an access network device to one or more terminals include the TID type of one or more terminals or the default EPC of one or more terminals.
[0245] Step 407: The first terminal in one or more discovered terminals accesses the access network device.
[0246] For the process in step 407, please refer to the process described above in which the first terminal in one or more discovered terminals accesses the access network device.
[0247] For example, after receiving a query command, one or more terminals initiate a random access procedure, and one terminal (i.e., the first terminal) successfully performs the random access, in other words, gains access to the access network device.
[0248] Optionally, query commands sent by an access network device to one or more terminals include the TID type of one or more terminals or the default EPC of one or more terminals. After receiving a query command, one or more terminals may match the TID type in the query command with the terminal's TID type, or match the default EPC in the query command with the terminal's default EPC, and if the matching is successful, initiate a random access procedure.
[0249] After receiving a query command, one or more terminals will use the TID type in the query command as the terminal's TID The first terminal may match the type, or match the default EPC in the query command with the terminal's default EPC, and if the matching is successful, initiate a random access procedure. Of course, the first terminal may alternatively initiate a random access procedure first. After the random access is successful, and before step 408, the first terminal matches the information in the query command with the information of the first terminal. After the matching is successful, step 408 is executed.
[0250] Step 408: The first terminal sends a request message to the access network device.
[0251] In response, the access network device receives the request message from the first terminal.
[0252] Optionally, the request message includes the default EPC of the first terminal.
[0253] A request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. A request message may be a non-access stratum (NAS) message or a non-NAS message.
[0254] Step 409: The access network device transparently sends the request message to the TMF.
[0255] Step 410: TMF sends a response message to the first terminal.
[0256] In response, the first terminal receives a response message from the TMF.
[0257] The response message may be a registration acceptance message, instruction information indicating that the first terminal's access was successful, an access success message, a response message for successful network access, or a response message for successful network registration. The names of the response messages are not limited in this application.
[0258] For example, TMF transparently sends a response message to the first terminal through the access network device.
[0259] Step 411: The TMF sends the second piece of information to the first terminal, which instructs the first terminal to save the operator identification code.
[0260] In response, the first terminal receives the second piece of information from the core network device.
[0261] Optionally, based on the second information instructing the first terminal to save the operator identification code, the second information further includes first location information for saving the operator identification code.
[0262] Optionally, the second information further instructs the first terminal to save the first EPC. Furthermore, optionally, the second information further includes second location information for saving the first EPC.
[0263] Optionally, the second piece of information further instructs the first terminal to save the key. Furthermore, optionally, the second piece of information further includes a third location information for saving the key.
[0264] For the process in step 411, please refer to the process in step 303. Further details will not be provided again.
[0265] Step 412: The first terminal stores the operator identification code assigned to the first terminal.
[0266] Optionally, the first terminal may further store the first EPC assigned to the first terminal.
[0267] Optionally, the first terminal may further store the key assigned to it.
[0268] For the process in step 412, please refer to the process in step 304. Further details will not be provided again.
[0269] Step 413: The first terminal sends a save success instruction to the TMF.
[0270] In response, TMF receives information indicating successful saving from the first terminal.
[0271] In a particular example, the instruction information may indicate that the storage of one or more of the operator identification code, the first EPC, and the key was successful.
[0272] Successful saving can be replaced by successful writing, successful printing, successful inventorying, or similar.
[0273] Step 414: The TMF sends instruction information for the next terminal inventory to the access network device.
[0274] In response, the access network device receives instructional information from the TMF regarding the next terminal inventory.
[0275] Inventory can be understood as the operator identification code being written to the terminal (stored therein or printed therein), and optionally further understood as the EPC and / or key for terminal management being written to the terminal.
[0276] If not all terminals indicated by the third information are inventoryed in step 405, steps 406 to 414 are repeated; or, if all terminals indicated by the third information are inventoryed in step 405, step 415 is executed.
[0277] In a possible implementation, to determine whether all terminals are inventoryed, the access network device may consider all terminals to be inventoryed if it determines that a predetermined number of terminals are to be inventoryed. For example, if there are 2000 matched terminals in the access network device's coverage area, and the core network device only needs to print 1000 terminals, the access network device may determine that inventory is complete after it has determined that 1000 terminals are to be inventoryed. In another possible implementation, the access network device determines that inventory is complete if it determines that a terminal is unresponsive. For example, if the core network device needs to print 1000 terminals, 1000 terminals are deployed in the access network device's coverage area. When it determines that a terminal is unresponsive, the access network device may determine that 1000 terminals are to be inventoryed.
[0278] Step 415: The access network device sends inventory completion instruction information to the TMF.
[0279] The completion of the inventory can be replaced by the success of saving, writing, printing, or the like.
[0280] In a specific example, the indication information may indicate that one or more of the operator identification code, the EPC for terminal management, and the key have been successfully saved (or successfully written, or successfully printed).
[0281] Step 416: The TMF sends the write completion indication information to the UDM.
[0282] Step 417: The UDM sends the write completion indication information to the AF.
[0283] In a specific example, the indication information may indicate that one or more of the operator identification code, the EPC for terminal management, and the key are written.
[0284] The completion of writing can be replaced by the success of writing, the completion of inventory, the success of subscription, the success of printing, or the like.
[0285] Optionally, step 417 includes one or more of the following items assigned to one or more (including the first terminal): EPC code range (EPC for terminal management and not the default EPC), operator identification code, and key.
[0286] In the scenario where the key is written to the terminal, when the UDM receives the first information from the AF, where the first information instructs to assign the key to one or more terminals (including the first terminal), and when the first information does not include the key corresponding to each of the one or more terminals (including the first terminal), in step 403a of the example in FIG. 4, after recognizing the key storage network element through the NRF, the UDM obtains the key corresponding to the one or more terminals (including the first terminal) from the key storage network element and sends the key corresponding to the one or more terminals to the TMF. In addition, there may be other possible implementations.
[0287] In a possible implementation a, the UDM recognizes information about the key storage network element through the NRF and sends the information about the key storage network element to the TMF. Next, the TMF obtains keys corresponding to one or more terminals from the key storage network element (including the first terminal) based on the information about the key storage network element.
[0288] In a possible implementation b, the UDM instructs the TMF that it is necessary to print keys for one or more terminals. Next, the TMF recognizes information about the key storage network element through the NRF. Next, the TMF obtains keys corresponding to one or more terminals from the key storage network element (including the first terminal) based on the information about the key storage network element.
[0289] Referring to implementations a and b described above, the TMF obtains keys corresponding to one or more terminals (including the first terminal) from the key storage network element. In this example, there are multiple implementations.
[0290] In a possible implementation c, before the TMF receives a request message from the first terminal (e.g., steps 408 and step 409), the TMF obtains keys corresponding to one or more terminals (including the first terminal) from the key storage network element. It can be understood that in this method, before any one of the one or more terminals is discovered, the keys corresponding to the one or more terminals (including the first terminal) are obtained in batch from the key storage network element.
[0291] In a possible implementation d, after the TMF receives a request message from the first terminal (e.g., steps 408 and step 409), the TMF obtains keys corresponding to one or more terminals (including the first terminal) from the key storage network element. It can be understood that in this method, when the first terminal among the one or more terminals (i.e., the first terminal) is discovered, the keys corresponding to the one or more terminals (including the first terminal) are obtained in batch from the key storage network element.
[0292] In possible implementation d, after the TMF receives a request message from the first terminal (e.g., steps 408 and 409), the TMF retrieves the key corresponding to the first terminal from the key storage network element. This can be understood as the key corresponding to any terminal being discovered from the key storage network element whenever any terminal is discovered.
[0293] The examples in Figure 4 and other possible implementations a, b, c, and d described above use an example where the first core network device is a UDM. In another example, the first core network device may alternatively be a NEF. For further details, please refer to the examples in Figure 4 and the descriptions of other possible implementations a, b, c, and d. Further details will not be explained again.
[0294] In addition, in order to write three pieces of information, namely an operator identification code, an EPC for terminal management, and a key, to one or more terminals, in this embodiment of the present application, the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in one step; the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in three steps; or any two of the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in one step, and the remaining one of the operator identification code, the EPC for terminal management, and the key may be written to one or more terminals in another step.
[0295] After an operator identification code is stored on the terminal, the operator can manage the terminal based on the operator identification code. Optionally, after an EPC for terminal management is stored on the terminal, the operator or requester can manage the terminal based on the EPC for terminal management (all EPCs described in the following examples are EPCs used for terminal management and are not the default EPC). Referring to Figures 5, 6, and 7, the following describes the process by which an operator manages a terminal. The first core network device (the core network device that communicates with the requester) and the second core network device (the core network device that communicates with the terminal / access network device) are a single entity, and the first and second core network devices are collectively referred to as the core network device. Alternatively, the first and second core network devices are identical, and the first and second core network devices are abbreviated as the core network device.
[0296] Figure 5 is a flowchart of possible communication in which an operator manages a terminal according to an embodiment of the present invention. In Figure 5, the capability of the first terminal is to report an EPC by default. After accessing an access network device (e.g., successful random access), the first terminal may proactively transmit a first EPC assigned to the first terminal. After obtaining the first EPC of the first terminal, the core network device may request an operator identification code assigned to the first terminal based on the first EPC of the first terminal.
[0297] Step 501: The requester sends fourth information to the core network device, where the fourth information indicates one or more terminals (including the first terminal).
[0298] In response, the core network device receives a fourth piece of information from the requester.
[0299] In addition to indicating a first terminal, the fourth piece of information may be understood to indicate yet another terminal. Based on the fourth piece of information, the core network device may determine one or more terminals that need to be managed, including the first terminal. Management may be understood as performing authentication on the terminals based on an operator identification code, and optionally, further understood as performing operations on the terminals. The process for managing all terminals is similar. The example in Figure 5 illustrates this using an example where only the first terminal is managed.
[0300] The fourth piece of information may indicate the first terminal using one or more of the following methods:
[0301] For example, the fourth piece of information includes an EPC range, which includes the first EPC of the first terminal. The fourth piece of information can be understood as an EPC range that needs to be managed, which is sent by the requester to the core network device. Based on the EPC range, the core network device determines that the terminals belonging to the EPC range need to be managed.
[0302] For example, the fourth piece of information may include one or more EPCs, where one or more EPCs include the first EPC of the first terminal. The fourth piece of information may be understood as one or more EPCs that need to be managed, instructed by the requester to the core network device. Based on the one or more EPCs, the core network device determines that the terminals to which the EPCs belong need to be managed.
[0303] For example, the fourth piece of information includes one or more target TID types, and the TID of the first terminal belongs to one of the target TID types. The fourth piece of information can be understood as one or more target TID types that the requester instructs the core network device to manage. Based on the one or more target TID types, the core network device determines that terminals whose TID type belongs to one or more target TID types need to be managed.
[0304] For example, the fourth piece of information includes information about the requester. Information about the requester may indicate an EPC range or one or more EPCs that correspond to (or are managed by) the requester. The EPC range or one or more EPCs that correspond to (or are managed by) the requester include the first EPC of the first terminal. Based on the information about the requester, the core network device may determine which terminals belong to the EPC range or one or more EPCs that correspond to (or are managed by) the requester that need to be managed.
[0305] For information about the requester, please refer to the explanation in step 301. Further details will not be provided again.
[0306] An EPC range or one or more EPCs corresponding to (or managed by) a requester may be stored or configured on a core network device, or on another core network device. A core network device may transmit information about a requester to another core network device, which, based on the information about the requester, retrieves an EPC range or one or more EPCs corresponding to (or managed by) the requester and transmits the EPC range or one or more EPCs to the core network device. For example, another core network device may include core network devices such as UDM, UDR, AUSF, NEF, PCF, SMF, TMF, or NSSAAF.
[0307] In conclusion, the fourth piece of information may be recognized as including one or more of the following: the tag identifier (TID) type of the first terminal, the first electronic product code (EPC) of the first terminal, and information about the requester. A core network device may determine the first terminal based on the first piece of information, and may, of course, further determine other terminals.
[0308] In a possible implementation, the first information may instruct to perform a first operation on one or more terminals (including the first terminal). The first operation may be an operation to obtain the identifier of the first terminal (an inventory operation, a stocktaking operation, or an inventory which may also be referred to), a read operation, a write operation, a delete operation, an encryption operation, an access operation, a block write operation, a block erase operation, a kill operation, or the like. For example, the first information includes information about the first operation, and the information about the first operation instructs the first operation. Further, optionally, the first information further includes operation parameters corresponding to the first operation. For example, the operation parameters corresponding to the read operation may include the memory bank to be read, the start byte address of the memory bank to be read, the number of bytes of the memory bank to be read, and the like. The operation parameters corresponding to the write operation may include the write memory bank, the start byte of the memory bank to be read, and the write data. In addition, the operation to obtain the identifier of the first terminal (an inventory operation, a stocktaking operation, or an inventory which may also be referred to) may not be held in the first information. For example, when the first information does not include the first operation, it may instruct that the first information is used to obtain the identifier of the first terminal.
[0309] Optionally, based on the instruction of the fourth information, the first terminal may further include a service range. For example, the service range includes target area information A, where the target area information A instructs an area corresponding to one or more terminals to which an operator identification code needs to be assigned. For example, the target area information A may be a geographical location, a municipality location, or 3GPP (registered trademark) location information (such as a tracking area (TA) list or a cell list) corresponding to one or more terminals to which an operator identification code needs to be assigned. The service range is used to query an access network device.
[0310] Step 502: The core network device sends fifth information to the access network device, which instructs it to search for one or more terminals (including the first terminal).
[0311] In response, the access network device receives a fifth piece of information from the core network device.
[0312] It can be understood that, in addition to instructions to search for the first terminal, the fifth piece of information may further instruct to search for another terminal. Based on the fifth piece of information, the access network device may determine one or more terminals that need to be searched, including the first terminal.
[0313] The fifth piece of information may be referred to as an inventory request or inventory request. The fifth piece of information may indicate the first terminal in one or more of the following ways:
[0314] For example, the fifth piece of information includes the EPC range, and the EPC range includes the EPC of the first terminal. Based on the EPC range, the access network device determines that the terminals whose EPCs belong to the EPC range need to be searched.
[0315] For example, the fifth piece of information includes one or more EPCs, and one or more EPCs include the EPC of the first terminal. Based on one or more EPCs, the access network device determines that the terminals to which the EPC belongs need to be searched.
[0316] For example, the fifth piece of information includes one or more target TID types, and the TID of the first terminal belongs to one of the target TID types. Based on the one or more target TID types, the access network device determines that terminals whose TID type belongs to one or more target TID types should be searched for.
[0317] For example, the fifth piece of information includes operator identification codes associated with the EPC for terminal management of one or more terminals (including the operator identification code associated with the first EPC of the first terminal). Based on the operator identification codes, the access network device determines that terminals to which the operator identification code belongs need to be searched.
[0318] For example, when the fourth piece of information includes information about the requester (the requester manages one or more terminals (including the first terminal)), the core network device may determine, based on the information about the requester, the Public Land Mobile Network Identifier (PLMN) ID assigned to one or more terminals (including the first terminal), and the fifth piece of information includes the PLMN ID assigned to one or more terminals (including the first terminal). Furthermore, optionally, the core network device may determine, based on the information about the requester, the corporate identifier assigned to one or more terminals (including the first terminal), where the fifth piece of information further includes the corporate identifier assigned to one or more terminals (including the first terminal). The corporate identifier is a corporate code, an application code, or a service code assigned to the first terminal by the operator device (see step 402); or the corporate identifier is a service identifier in the CompanyPrefix in the EPC memory bank of one or more terminals (including the first terminal). The corporate identifier may also be replaced by a service identifier or an application identifier. Enterprise identifiers, application identifiers, and service identifiers can be understood as being able to uniquely identify the type of device. The definition of "type" can be flexible. For example, an enterprise could be the type, a department or multiple departments of an enterprise could be the type, a service could be the type, and multiple services could be the type. The names of enterprise identifiers, application identifiers, and service identifiers should not be restrictive to specific scenarios.
[0319] In certain cases, when the fifth piece of information includes a PLMN ID and a company identifier, the EPC may be optional. When no EPC is included, the fifth piece of information can be understood as instructing to search for all EPCs managed by the company corresponding to the company identifier. When an EPC is included, the fifth piece of information can be understood as instructing to search for EPCs that match the EPC included in the fifth piece of information and are managed by the company corresponding to the company identifier.
[0320] In conclusion, the fifth piece of information may be recognized as including one or more of the following: the tag identifier TID type of the first terminal, the first EPC of the first terminal, the operator identification code associated with the first EPC of the first terminal, the PLMN ID assigned to the first terminal, and the corporate identifier assigned to the first terminal. An access network device may determine the first terminal based on the fifth piece of information, and may, of course, further determine other terminals.
[0321] Step 503: The access network device searches for one or more terminals (including the first terminal) based on the fifth piece of information.
[0322] Device search can also be understood as device selection or device filtering.
[0323] In a possible implementation, the process by which an access network device searches for one or more terminals (including the first terminal) based on the fifth information includes: the access network device sending radio frequency information to terminals in the access network device's coverage area based on the fifth information to provide a stimulus signal to the terminals in the access network device's coverage area, and as a result the terminals sending a signal to the access network device; the access network device performing a selection operation on terminals in the coverage area to select one or more terminals by performing the selection operation; and further, the access network device sending query commands to the selected one or more terminals (including the first terminal) to search for one or more terminals (including the first terminal).
[0324] Optionally, query commands sent by an access network device to one or more terminals may include one or more of the following: the TID type of one or more terminals, the EPC of one or more terminals, the operator identification code associated with the EPC of one or more terminals, the PLMN ID assigned to one or more terminals, and the corporate identifier assigned to one or more terminals.
[0325] Step 504: The first terminal in one or more discovered terminals accesses the access network device.
[0326] In a possible implementation, the process by which a first terminal among one or more discovered terminals accesses an access network device includes: one or more terminals initiating a random access procedure after receiving a query command, where one terminal (i.e., the first terminal) successfully performs the random access, in other words, accesses the access network device.
[0327] In a possible implementation, the random access procedure may be as follows: After receiving a query command, one or more terminals separately send random numbers to an access network device, which can accurately receive the random numbers and accurately feed them back to the terminals. The terminals that send the random numbers determine that the random access was successful.
[0328] Optionally, a query command sent by the access network device to one or more terminals may include one or more of the following: the TID type of one or more terminals, the EPC of one or more terminals, the operator identification code associated with the EPC of one or more terminals, the PLMN ID assigned to one or more terminals, and the corporate identifier assigned to one or more terminals. After receiving the query command, a terminal may match the information in the query command with its own information. After a successful match, the terminal initiates a random access procedure (e.g., sending a random number to the access network device). Of course, the first terminal may alternatively initiate a random access procedure first. After a successful random access, before step 505, the first terminal matches the information in the query command with its own information. After a successful match, step 505 is performed.
[0329] Step 505: The first terminal sends the first EPC assigned to the first terminal to the core network device.
[0330] In response, the core network device receives the first EPC assigned to the first terminal.
[0331] When the capability of the first terminal is to report EPCs by default, after accessing an access network device (e.g., successfully performing random access), the first terminal may proactively send the first EPC assigned to the first terminal to the core network device via the access network device.
[0332] In a possible implementation, the transmission of a first terminal to a core network device by a first terminal to a first EPC assigned to the first terminal includes the transmission of a request message to the core network device through an access network device, the request message including the first EPC assigned to the first terminal. The access network device transmits the request message transparently. The request message may be a registration request message, an access request message, a request message used by an access network device, or a request message used for network registration. The name of the request message is not limited herein. The request message may be a non-access stratum (NAS) message or a non-NAS message.
[0333] Step 506: Based on the subscription information of the first EPC and the first terminal, the core network device may determine that the operator or requester needs to perform authentication with the first EPC and then perform step 507.
[0334] If it is determined that authentication does not need to be performed for the first EPC, the core network device may not need to perform step 507.
[0335] Subscription information includes information about whether authentication needs to be performed against the EPC.
[0336] Step 506 is an optional step and may not be performed.
[0337] Step 507: The core network device triggers authentication between the first terminal and the operator device or requester based on the first EPC. Step 507 is an optional step and may not be performed.
[0338] Step 508: The core network device determines that the first EPC is associated with an operator identification code, and may then perform step 509.
[0339] If the first EPC is not associated with an operator identification code, step 509 may not be performed. For example, in step 404, the TMF stores the association between the operator identification code and the EPC for terminal management.
[0340] Step 508 is an optional step and may not be performed.
[0341] Step 509: The core network device requests the first terminal to obtain the operator identification code assigned to the first terminal based on the first EPC.
[0342] In response, the first terminal receives a request from the core network device to request the first terminal to obtain the operator identification code assigned to the first terminal based on the first EPC.
[0343] In a possible implementation, the core network device sends a request to the first terminal to obtain the operator identification code assigned to the first terminal. Correspondingly, the first terminal receives a request from the core network device to obtain the operator identification code assigned to the first terminal, the request including the first terminal's EPC.
[0344] The order of steps 506, 507, 508, and 509 is not limited.
[0345] Step 510: The first terminal transmits the operator identification code assigned to the first terminal to the core network device.
[0346] In response, the core network device receives the operator identification code assigned to the first terminal.
[0347] Step 511: The core network device may determine, based on the operator identification code and the subscription information of the first terminal, that the operator needs to perform authentication against the operator identification code. The subscription information includes information about whether authentication needs to be performed against the operator identification code.
[0348] Step 511 is an optional step and may not be performed.
[0349] Step 512: The core network device triggers authentication between the first terminal and the operator device based on the operator identification code.
[0350] Authentication based on operator identification codes can be understood as follows: In an authentication procedure between a terminal and an operator device, the parameters used for authentication (random numbers, check values, ciphertext information) and the operator identification code are in the same message. In this way, it may be determined that authentication is performed for the terminal identified by the operator identification code. Alternatively, a terminal is first determined as a unique terminal based on the operator identification code. In an authentication procedure, even if the message containing the authentication parameters (random numbers, check values, and ciphertext information) does not contain the operator identification code, it may still be determined that authentication is performed for the terminal identified by the operator identification code.
[0351] Figure 6 is a flowchart of possible communications according to an embodiment of the present invention, in which an operator manages a terminal. In Figure 6, the capability of the first terminal is to report an EPC by default. After accessing an access network device (e.g., successful random access), the first terminal may proactively transmit a first EPC assigned to it. In the process of locating the first terminal, the access network device instructs the first terminal to transmit an operator identification code assigned to it. Thus, after accessing an access network device (e.g., successful random access), the first terminal may transmit an operator identification code assigned to it.
[0352] Step 601: The requester sends fourth information to the core network device, where the fourth information indicates one or more terminals (including the first terminal).
[0353] In response, the core network device receives a fourth piece of information from the requester.
[0354] For the process in step 601, please refer to the process in step 501. Further details will not be provided again.
[0355] Step 602: The core network device transmits fifth information to the access network device, which instructs the access network device to search for one or more terminals (including the first terminal) and to request the acquisition of operator identification codes assigned to one or more terminals (including the first terminal).
[0356] In response, the access network device receives a fifth piece of information from the core network device.
[0357] For the process in step 602, see the process in step 502. Based on this, the fifth information may instruct to request the acquisition of operator identification codes assigned to one or more terminals (including the first terminal) by using a specific information format, or the fifth information may include instruction information for requesting the acquisition of operator identification codes, thereby instructing the access network device to request the acquisition of operator identification codes assigned to one or more terminals (including the first terminal).
[0358] Instructional information for requesting the acquisition of an operator identification code may occupy one or more bits, the value of which indicates the request to acquire the operator identification code. For example, if the value of one bit at a particular location is extended or the value of the bit is set to 1, it indicates the request to acquire the operator identification code; if the value of that bit at that location is 0 or set to 0, it indicates not to acquire the operator identification code.
[0359] Instructions requesting the acquisition of an operator identification code may be considered a mark of SUPI replication or a mark of SUPI-like replication.
[0360] Optionally, before performing step 602, the core network device may determine that the operator needs to perform authentication on one or more terminals. In this case, the fifth piece of information may instruct the operator to request the operator identification code assigned to the first terminal. If the operator does not need to perform authentication, the fifth piece of information may not instruct the operator to request the operator identification code assigned to the first terminal.
[0361] Step 603: Based on the fifth piece of information, the access network device searches for one or more terminals (including the first terminal) and instructs one or more terminals (including the first terminal) to transmit the operator identification code assigned to the terminal.
[0362] Device search can also be understood as device selection or device filtering.
[0363] For the process by which the access network device searches for one or more terminals (including the first terminal) based on the fifth piece of information, please refer to the description in step 503. Further details will not be provided again.
[0364] Optionally, query commands sent by an access network device to one or more terminals may further include instruction information for sending the operator identification code assigned to the terminal, instructing the terminal to send the operator identification code assigned to the terminal.
[0365] The instruction information for transmitting the operator identification code may occupy one or more bits, and the value of the bit instructs to request the acquisition of the operator identification code. For example, when the value of the bit at position is 1 or set to 1, it instructs to acquire the operator identification code; when the value is 0 or set to 0, it instructs not to acquire the operator identification code.
[0366] Instructions requesting the acquisition of an operator identification code may be considered a mark of SUPI replication or a mark of SUPI-like replication.
[0367] Step 604: The first terminal in one or more discovered terminals accesses the access network device.
[0368] For the process in step 604, please refer to the explanation in step 504. Further details will not be provided again.
[0369] Step 605: The first terminal transmits the operator identification code assigned to the first terminal and the first EPC to the core network device.
[0370] In response, the core network device receives the operator identification code and the first EPC assigned to the first terminal.
[0371] The capability of the first terminal is, by default, to report to the EPC. After accessing an access network device (e.g., successful random access), the first terminal may proactively transmit the first EPC assigned to it. In the process of finding the first terminal, the access network device instructs the first terminal to transmit the operator identification code assigned to it. In this way, after accessing an access network device (e.g., successful random access), the first terminal may transmit the operator identification code assigned to it.
[0372] In a possible implementation, the transmission of the operator identification code and the first EPC assigned to the first terminal to the core network device includes: the transmission of a request message to the core network device via the access network device, wherein the request message includes the operator identification code and the first EPC assigned to the first terminal. The access network device transmits the request message transparently. The request message may be a registration request message, an access request message, a request message used by an access network device, or a request message used for network registration. The name of the request message is not limited herein. The request message may be a non-access stratum (NAS) message or a non-NAS message.
[0373] Step 606: The core network device may determine, based on the operator identification code and the subscription information of the first terminal, that the operator must perform authentication against the operator identification code. The subscription information includes information about whether authentication must be performed against the operator identification code.
[0374] Step 606 is an optional step and may not be performed.
[0375] Step 607: The core network device triggers authentication between the first terminal and the operator device based on the operator identification code.
[0376] For the process in step 607, please refer to the process in step 512. Further details will not be provided again.
[0377] Step 608: Based on the subscription information of the first EPC and the first terminal, the core network device may determine that the operator or requester needs to perform authentication with the first EPC and then perform step 609.
[0378] If it is determined that authentication does not need to be performed against the first EPC, the core network device may not need to perform step 600. The subscription information includes information about whether authentication needs to be performed against the EPC.
[0379] Step 609: The core network device triggers authentication between the first terminal and the operator device or requester based on the first EPC of the first terminal.
[0380] Step 609 is an optional step and may not be performed.
[0381] The order of steps 606, 607, 608, and 609 is not limited.
[0382] Figure 7 is a flowchart showing how an operator can manage a terminal according to an embodiment of the present invention. In Figure 6, the capability of the first terminal is to report an operator identification code by default. After accessing an access network device (e.g., successful random access), the first terminal may proactively transmit to the operator identification code assigned to the first terminal.
[0383] Step 701: The requester sends the fourth piece of information to the core network device, where the fourth piece of information directs the first terminal.
[0384] In response, the core network device receives a fourth piece of information from the requester.
[0385] For Step 701, please refer to the explanation for Step 501. Further details will not be provided again.
[0386] Step 702: The core network device sends fifth information to the access network device, which instructs it to search for one or more terminals (including the first terminal).
[0387] In response, the access network device receives a fifth piece of information from the core network device.
[0388] For Step 702, please refer to the explanation for Step 502. Further details will not be provided again.
[0389] Step 703: The access network device searches for one or more terminals (including the first terminal) based on the information in step 5.
[0390] For Step 703, please refer to the explanation for Step 503. Further details will not be provided again.
[0391] Step 704: The first terminal in one or more discovered terminals accesses the access network device.
[0392] For the process in step 704, please refer to the explanation in step 504. Further details will not be provided again.
[0393] Step 705: The first terminal transmits the operator identification code assigned to the first terminal to the core network device.
[0394] In response, the core network device receives the operator identification code assigned to the first terminal.
[0395] In a possible implementation, the transmission of the operator identification code assigned to the first terminal to the core network device includes: the transmission of a request message to the core network device via an access network device, the request message including the operator identification code assigned to the first terminal. The access network device transmits the request message transparently. The request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited herein. The request message may be a non-access stratum (NAS) message or a non-NAS message.
[0396] Step 706: The core network device may determine, based on the operator identification code and the subscription information of the first terminal, that the operator must perform authentication against the operator identification code. The subscription information includes information on whether authentication must be performed against the operator identification code.
[0397] Step 706 is an optional step and may not be performed.
[0398] Step 707: The core network device triggers authentication between the first terminal and the operator device based on the operator identification code.
[0399] For the process in step 707, please refer to the process in step 512. Further details will not be provided again.
[0400] In possible implementations, if the capability of the first terminal further includes reporting EPCs by default, the first EPC assigned to the first terminal may be further received in step 705.
[0401] In possible implementations, if the ability of the first terminal does not include reporting the EPC by default, the methods for obtaining the EPC may include the following:
[0402] Method 1: After the operator identification code assigned to the first terminal is obtained, the first terminal receives a request from the core network device to request the first terminal to obtain the first EPC assigned to the first terminal, based on the operator identification code.
[0403] In a possible implementation, the core network device sends a request to the first terminal to obtain the first EPC assigned to the first terminal. Correspondingly, the first terminal receives a request from the core network device to obtain the first EPC assigned to the first terminal, the request including the operator identification code of the first terminal.
[0404] Method 2: In step 702, the fifth piece of information transmitted by the core network device to the access network device instructs it to search for one or more terminals (including the first terminal), and further instructs it to request that it retrieve the EPCs assigned to one or more terminals (including the first terminal).
[0405] The fifth piece of information may, by using a specific information format, instruct one or more terminals (including the first terminal) to request the acquisition of an EPC, or the fifth piece of information may include instruction information for requesting the acquisition of an EPC, thereby instructing an access network device to request the acquisition of an EPC assigned to one or more terminals (including the first terminal). The instruction information for requesting the acquisition of an EPC may be a mark for EPC duplication.
[0406] After the first EPC is obtained, step 708 may be performed: the core network device may determine, based on the first EPC and the subscription information of the first terminal, that the operator or requester needs to perform authentication to the first EPC, and then perform step 709. If authentication does not need to be performed, step 709 may not be performed. Step 708 is an optional step and may not be performed.
[0407] Step 709: The core network device may trigger authentication between the first terminal and the operator device or requester based on the first EPC.
[0408] The order of steps 706, 707, 708, and 709 is not limited.
[0409] In a possible implementation, if the first operation is one or more of a read operation, write operation, delete operation, encryption operation, access operation, block write operation, block erase operation, or kill operation, the core network device may perform further first operations on the first terminal after the first terminal has been authenticated.
[0410] In possible implementations, after the first terminal has been authenticated, the core network device may send a response message to the first terminal. Correspondingly, the first terminal receives the response message from the core network device. The response message may be a registration acceptance message, instructional information indicating that the first terminal's access was successful, an access success message, a response message for successful network access, or a response message for successful network registration. The names of the response messages are not limited in this application. For example, the core network device transparently sends the response message to the first terminal through the access network device.
[0411] In possible implementations, after the first terminal is authenticated, the core network device may further send instructional information for the next terminal inventory to the access network device. Correspondingly, the access network device receives instructional information for the next terminal inventory from the core network device. Inventory can be understood as managing the next terminal or performing the first operation on the next terminal.
[0412] In the example shown in Figure 5, if not all terminals indicated in the fifth piece of information are inventoryed in step 502, steps 503 to 512 may be repeated.
[0413] In the example in Figure 6, if not all terminals indicated in the fifth piece of information are inventoryed in step 602, steps 603 to 609 may be repeated.
[0414] In the example shown in Figure 7, if not all terminals indicated in the fifth piece of information are inventoryed in step 702, steps 703 to 709 may be repeated.
[0415] If all terminals indicated in the fifth piece of information are inventoryed, the access network device may send inventory completion information to the core network device. The core network device may send the inventory results to the requester.
[0416] When the first core network device and the second core network device are different core network devices, information is exchanged between the first core network device and the second core network device. Referring to the communication procedures in Figures 5, 6, and 7, the following describes the communication procedure when the first core network device and the second core network device are different core network devices.
[0417] Steps 501, 601, and 701 may be replaced by the requester sending the fourth information to the first core network device, and the first core network device correspondingly receiving the fourth information from the requester.
[0418] Steps 502, 601, and 701 may be replaced by the second core network device sending the fifth information to the access network device, and the second core network device correspondingly receiving the fifth information from the requester.
[0419] A new step is added before steps 502, 602, and 702: the first core network device sends second instruction information to the second core network device, where the second instruction information directs one or more terminals.
[0420] In response, the second core network device receives second instruction information from the first core network device.
[0421] For example, regarding the contents of the second instruction information, please refer to the fifth piece of information sent by the core network device to the access network device in step 502.
[0422] In other steps, the core network device is the first core network device when communicating with the first terminal or access network device, and the core network device is the second core network device when communicating with the requester. For specific details of the communication procedure, please refer to the explanations in Figures 5, 6, and 7. Further details will not be explained again.
[0423] After the key is written to the terminal, the network can perform authentication on the terminal based on the key. Figure 8 is a schematic flowchart of how the network performs authentication on a terminal based on the key.
[0424] Step 101: The requesting party (e.g., AF) sends an operation request to a core network device (e.g., TMF), where the operation request specifies one or more terminals (including the first terminal).
[0425] In response, the core network device receives the operation request from the requesting party.
[0426] In a specific example, the operation request instructs to write data 1 to one or more terminals.
[0427] For details regarding the operation request, please refer to the explanation of the fourth piece of information in step 501. For details regarding the process in step 101, please refer to the explanation of the process in step 501. Further details will not be explained again.
[0428] Step 102: If the core network device (e.g., TMF) determines that operator authentication needs to be performed for one or more terminals specified in the operation request, the core network device obtains the random number and operator identification code required for authentication.
[0429] For example, a core network device may obtain and store a corresponding random number and operator identification code by referring to the method described in the example, or the methods described in possible implementations a, b, c, and d in Figure 4.
[0430] Step 103: The core network device (e.g., TMF) sends an inventory command to the access network device, which instructs it to search for one or more terminals (including the first terminal).
[0431] In response, the access network device receives inventory commands from the core network device (e.g., TMF).
[0432] An inventory command includes an operator identification code and a random number corresponding to one or more terminals. The operator identification code corresponding to one or more terminals may be represented by using an operator identification code range.
[0433] When multiple terminals are inventoryed, the keys corresponding to the multiple terminals may be the same or different, and the random numbers corresponding to the multiple terminals may also be the same or different. If the keys and random numbers are different, they may be arranged sequentially in the inventory command, and as a result, the access network device will identify the keys and random numbers corresponding to the same terminal. For example, in key 1, key 2, key 3, random number 1, random number 2, and random number 3, key 1 and random number 1 correspond to the same terminal, key 2 and random number 2 correspond to the same terminal, and key 3 and random number 3 correspond to the same terminal.
[0434] Step 104: The access network device searches for one or more terminals (including the first terminal) according to the inventory command.
[0435] Terminal search can also be understood as terminal selection or terminal filtering. Please refer to the above description for the specific process. Further details will not be explained again.
[0436] If the random numbers corresponding to multiple terminals are the same, the access network device may send the random numbers to the corresponding terminals during the search process.
[0437] If the random numbers corresponding to multiple terminals are different, the access network device may send the random numbers to the corresponding terminals after step 104a and before step 105.
[0438] Step 104a: Random access to a terminal (e.g., terminal 1) is successful.
[0439] If the random numbers corresponding to multiple terminals are different, after step 104a, the first terminal may transmit its first EPC or operator identification code to the access network device, the access network device identifies the first terminal based on the first EPC or operator identification code and transmits the random number corresponding to the first terminal to the first terminal.
[0440] Step 105: The first terminal generates the first authentication parameters based on the pre-printed key and the received random number.
[0441] For example, the first authentication parameter is the authentication result (RES).
[0442] Step 106: The first terminal sends a request message to the core network device (e.g., TMF) through the access network device.
[0443] In response, the core network device (e.g., TMF) receives the request message from the first terminal.
[0444] Optionally, the request message includes the operator identification code of the first terminal and the first authentication parameters generated in step 105.
[0445] A request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. A request message may be a non-access stratum (NAS) message or a non-NAS message.
[0446] Step 107: The core network device (e.g., TMF) sends an authentication request message to another core network device (e.g., UDR or AUSF).
[0447] Another core network device (e.g., UDR or AUSF) receives an authentication request message from the core network device (e.g., TMF).
[0448] The authentication request message includes the operator identification code from the first terminal in step 106 and the first authentication parameters.
[0449] Another core network device is a core network device or authentication server configured to determine whether the authentication parameters are correct based on the stored operator identification code and key.
[0450] Step 108: Another core network device determines whether the first authentication parameters are correct based on the operator identification code and key stored for the first terminal.
[0451] Another core network device stores the association between the operator identification code and the key, and another core network device can find the key associated with the operator identification code of the first terminal based on the operator identification code of the first terminal in step 107.
[0452] Another core network device decrypts the first authentication parameter based on the discovered key. If decryption is successful, it is determined that the first authentication parameter is correct and the network has successfully authenticated the first terminal. If decryption fails, it is determined that the first authentication parameter is incorrect and the network has failed to authenticate the first terminal.
[0453] Step 109: Another core network device sends instruction information to the core network device indicating that the network has successfully authenticated the first terminal.
[0454] A core network device receives instruction information from another core network device indicating that the network has successfully authenticated the first terminal.
[0455] If the network fails to authenticate the first terminal, another core network device sends an instruction to the core network device indicating that the network failed to authenticate the first terminal. The core network device receives an instruction from the other core network device indicating that the network failed to authenticate the first terminal.
[0456] In the example, the message flag bit may be set to indicate whether authentication was successful. For example, if the message flag bit is set to 1, it indicates that the network successfully authenticated the first terminal; or if the message flag bit is set to 0, it indicates that the network failed to authenticate the first terminal.
[0457] Optionally, instructional information indicating that the network has successfully authenticated the first terminal, or instructional information indicating that the network has failed to authenticate the first terminal, includes the operator identification code of the first terminal, and the first terminal is identified by using the operator identification code of the first terminal.
[0458] Optionally, in step 110, the core network device sends a response message to the first terminal.
[0459] In response, the first terminal receives a response message from the core network device.
[0460] The response message may be a registration acceptance message, instruction information indicating that the first terminal's access was successful, an access success message, a response message for successful network access, or a response message for successful network registration. The names of the response messages are not limited in this application.
[0461] For example, a core network device transparently sends a response message to a first terminal through an access network device.
[0462] After steps 102 to 110, the network completes authentication for the first terminal. If the network successfully authenticates the first terminal, the core network device (e.g., TMF) may write data 1 to the first terminal based on the operation request in step 101. If the network fails to authenticate the first terminal, the subsequent processes are not executed.
[0463] Step 111: The core network device (e.g., TMF) sends instruction information to the first terminal to write data 1.
[0464] Optionally, the instruction information includes the operator identification code of the first terminal.
[0465] For example, a core network device transparently transmits instruction information to a first terminal through an access network device.
[0466] Step 112: The first terminal sends write success instruction information to the core network device (e.g., TMF).
[0467] Optionally, the instruction information includes the operator identification code of the first terminal.
[0468] Step 113: The core network device (e.g., TMF) sends write success information to the requester (e.g., AF).
[0469] Optionally, the instruction information includes the operator identification code of the first terminal.
[0470] Step 114: The core network device sends instruction information for the next terminal inventory to the access network device.
[0471] In response, the access network device receives instructional information from the TMF regarding the next terminal inventory.
[0472] The order of steps 113 and 114 is not limited.
[0473] Steps 104 to 114 described above are repeated until data is written to one or more discovered terminals as indicated in the inventory command in step 103; in other words, all terminals are inventoryed.
[0474] In another scenario, if the operation request in step 101 instructs to read data 1 from one or more terminals, in step 111, the core network device (e.g., TMF) sends instruction information to the first terminal to read data 1; in step 112, the first terminal sends read success instruction information to the core network device (e.g., TMF), where the instruction information includes read data 1; and in step 113, the core network device (e.g., TMF) sends read and write success instruction information to the requester (e.g., AF), where the instruction information includes read data 1. Steps 104 to 114 described above are repeated until data from one or more discovered terminals instructed in the inventory command in step 103 is read; in other words, all terminals are inventoryed.
[0475] After the key is written to the terminal, the terminal can perform authentication to the network based on the key. Figure 9 is a schematic flowchart of how the terminal performs authentication to the network based on the key.
[0476] Step 201: The requesting party (e.g., AF) sends an operation request to a core network device (e.g., TMF), where the operation request specifies one or more terminals (including the first terminal).
[0477] In response, the core network device receives the operation request from the requesting party.
[0478] In a specific example, the operation request instructs to read data 1 from one or more terminals.
[0479] For details regarding the operation request, please refer to the explanation of the fourth piece of information in step 501. For details regarding the process in step 201, please refer to the explanation of the process in step 501. Further details will not be explained again.
[0480] Step 202: The core network device obtains an operator identification code corresponding to one or more terminals.
[0481] Step 203: The core network device (e.g., TMF) sends an inventory command to the access network device, which instructs it to search for one or more terminals (including the first terminal).
[0482] In response, the access network device receives inventory commands from the core network device (e.g., TMF).
[0483] An inventory command includes an operator identification code corresponding to one or more terminals. The operator identification code corresponding to one or more terminals may be represented by using an operator identification code range.
[0484] Step 204: The access network device searches for one or more terminals (including the first terminal) according to the inventory command.
[0485] Terminal search can also be understood as terminal selection or terminal filtering. Please refer to the above description for the specific process. Further details will not be explained again.
[0486] Step 204a: Random access to a terminal (e.g., terminal 1) is successful.
[0487] Step 205: The first terminal may determine on its own whether a random number needs to be retained during the replication of the operator identification code. If the first terminal determines that a random number needs to be retained during the replication of the operator identification code, the random number is retained in step 206.
[0488] Step 206: The first terminal sends a request message to the core network device (e.g., TMF) through the access network device.
[0489] In response, the core network device (e.g., TMF) receives the request message from the first terminal.
[0490] Optionally, the request message includes the operator identification code of the first terminal and a random number. The random number may be pre-stored in the first terminal or generated by the first terminal.
[0491] A request message may be a registration request message, an access request message, a request message used for an access network device, or a request message used for network registration. The name of the request message is not limited in this application. A request message may be a non-access stratum (NAS) message or a non-NAS message.
[0492] Step 207: The core network device (e.g., TMF) sends an authentication request message to another core network device (e.g., UDR or AUSF).
[0493] Another core network device (e.g., UDR or AUSF) receives an authentication request message from the core network device (e.g., TMF).
[0494] The authentication request message includes an operator identification code and a random number from the first terminal in step 206.
[0495] Another core network device is a core network device or authentication server configured to calculate authentication parameters (e.g., MAC) based on a stored operator identification code and a random number.
[0496] Step 208: Another core network device generates a first authentication parameter (e.g., MAC) based on the stored key and the operator identification code and random number from Step 207.
[0497] Step 209: Another core network device sends authentication response information to the core network device.
[0498] One core network device receives authentication response information from another core network device.
[0499] The authentication response information includes the first authentication parameter. Optionally, the authentication response information includes the operator identification code of the first terminal.
[0500] Step 210: The core network device sends a response message to the first terminal.
[0501] In response, the first terminal receives a response message from the core network device.
[0502] The response message includes the first authentication parameter. Optionally, the response message includes the operator identification code of the first terminal.
[0503] The response message may be a registration acceptance message, instruction information indicating that the first terminal's access was successful, an access success message, a response message for successful network access, or a response message for successful network registration. The names of the response messages are not limited in this application.
[0504] For example, a core network device transparently sends a response message to a first terminal through an access network device.
[0505] Step 211: The first terminal generates a second authentication parameter based on the operator identification code and key stored in the first terminal and the random number transmitted in step 206, and verifies the received first authentication parameter by using the second authentication parameter generated by the first terminal.
[0506] In other words, the first terminal determines whether the second authentication parameter generated by the first terminal is identical to the first authentication parameter received. If the second authentication parameter generated by the first terminal is identical to the first authentication parameter received, the first terminal determines that it has successfully authenticated the network; or, if the second authentication parameter generated by the first terminal is different from the first authentication parameter received, the first terminal determines that it has failed to authenticate the network.
[0507] Step 212: When the first terminal determines that it has successfully authenticated the network, the first terminal sends authentication success information to the core network device.
[0508] When the first terminal determines that it has failed to authenticate the network, the first terminal may send authentication failure information to the core network device.
[0509] In the example, the message flag bit may be set to indicate whether authentication was successful. For example, if the message flag bit is set to 1, it indicates that the first terminal successfully authenticated to the network; or if the message flag bit is set to 0, it indicates that the first terminal failed to authenticate to the network.
[0510] After steps 202 to 212, the first terminal completes authentication with the network. If the first terminal successfully authenticates with the network, the core network device (e.g., TMF) may write data 1 to the first terminal based on the operation request in step 201. If the first terminal fails to authenticate with the network, the subsequent processes are not executed.
[0511] Step 213: The core network device (e.g., TMF) sends instruction information to the first terminal to write data 1.
[0512] Optionally, the instruction information includes the operator identification code of the first terminal.
[0513] For example, a core network device transparently transmits instruction information to a first terminal through an access network device.
[0514] Step 214: The first terminal sends write success instruction information to the core network device (e.g., TMF).
[0515] Optionally, the instruction information includes the operator identification code of the first terminal.
[0516] Step 215: The core network device (e.g., TMF) sends write success information to the requester (e.g., AF).
[0517] Optionally, the instruction information includes the operator identification code of the first terminal.
[0518] Step 216: The core network device sends instruction information for the next terminal inventory to the access network device.
[0519] In response, the access network device receives instructional information from the TMF regarding the next terminal inventory.
[0520] Steps 204 to 216 described above are repeated until data is written to one or more discovered terminals as indicated in the inventory command in step 203; in other words, all terminals are inventoryed.
[0521] In another scenario, if the operation request in step 201 instructs to read data 1 from one or more terminals, in step 213, the core network device (e.g., TMF) sends instruction information to the first terminal to read data 1; in step 214, the first terminal sends read success instruction information to the core network device (e.g., TMF), where the instruction information includes read data 1; and in step 215, the core network device (e.g., TMF) sends read and write success instruction information to the requester (e.g., AF), where the instruction information includes read data 1. Steps 204 to 216 described above are repeated until the data from one or more discovered terminals instructed in the inventory command in step 203 is read; in other words, all terminals are inventoryed.
[0522] When a subscribed company has inventory requirements or more other operations, the requester sends an inventory request to the core network device. The core network device determines whether the EPC in the inventory request belongs to the company based on the EPC scopes to which the company is registered (or subscribed to or managed by) the company.
[0523] Figure 10 is a flowchart of communication in a case of corporate mismatch.
[0524] Step 801: The first requester (which may be understood as the first company) sends an inventory request to the core network device, where the inventory request includes an EPC range or one or more EPCs.
[0525] Accordingly, the core network device receives an inventory request from the first requester.
[0526] Step 802: The core network device determines that the EPC in the inventory request does not belong to an EPC scope registered (or subscribed to or managed by) the first requester.
[0527] In a possible implementation, a core network device may verify whether an EPC in an inventory request belongs to an EPC scope registered by a first requester by using enterprise subscription information stored on the core network device or another core network device.
[0528] For example, a core network device determines that an EPC in an inventory request belongs to an EPC scope registered (or subscribed to or managed by) a second requester (which may also be understood as a second company).
[0529] Step 803: The core network device sends inventory denial instruction information to the first requester.
[0530] In response, the first requester receives inventory rejection instruction information sent by the core network device.
[0531] Inventory rejection instructions can be interpreted as alarm information or information indicating no queries.
[0532] Optionally, inventory rejection instruction information retains the cause. For example, the cause might be that the EPC in the inventory request does not belong to the EPC range registered by the first requester.
[0533] For step 801 in Figure 10, please refer to step 501 in Figure 5, step 601 in Figure 6, and step 701 in Figure 7. The inventory request can be understood as the fourth piece of information in steps 501, 601, and 701, where the fourth piece of information includes the EPC range or one or more EPCs. Further details will not be discussed again.
[0534] Figure 10 is combined with Figures 5, 6, and 7. This can be understood as step 802 and may be performed before steps 502, 602, and 702. Step 803 may be performed after it is determined that the EPC in the inventory request does not belong to the EPC range registered by the first requester. Steps 503, 603, 703, and subsequent steps may be performed after it is determined that the EPC in the inventory request belongs to the EPC range registered by the first requester.
[0535] In an example where a terminal is found using a company identifier, the company submitting the inventory request may be different from the company to which the EPC in the inventory request belongs. The company identifier is a company code, application code, or service code assigned to the first terminal by the operator device (see step 402); or the service identifier is the service identifier in CompanyPrefix in the EPC memory bank for one or more terminals (including the first terminal).
[0536] Figure 11 is a flowchart of communication in a case of corporate mismatch.
[0537] Step 901: The first requester (which may be understood as the first company) sends an inventory request to the core network device, which indicates one or more terminals that are registered (or subscribed to or managed by) the second requester (which may be understood as the second company).
[0538] Accordingly, the core network device receives an inventory request from the first requester.
[0539] An inventory request may include an EPC scope managed by a second company, or the EPC of one or more terminals, in order to point to one or more terminals managed by a second requester.
[0540] Optionally, an inventory request may further include a service scope, which is used to query access network devices.
[0541] Step 902: Based on information about the first requester, the core network device may determine the public land mobile network identifier (PLMN ID) and enterprise identifier assigned to the terminal.
[0542] A company identifier determined based on information about the first requester can be understood as the identifier of the first company.
[0543] Step 903: The core network device sends an inventory command to the access network device, which includes the PLMN ID and the identifier of the first company determined in step 902, and the EPC registered by the second company in step 901.
[0544] In response, the access network device receives inventory commands from the core network device.
[0545] Step 904: The access network device searches for terminals according to the inventory command.
[0546] Terminal search can also be understood as terminal selection or terminal filtering. Please refer to the above description for the specific process. Further details will not be explained again.
[0547] For example, a query command sent by an access network device to one or more terminals includes the PLMN ID, the identifier of the first company, and the EPC registered by the second company.
[0548] Step 905: The first terminal in one or more discovered terminals accesses the access network device.
[0549] Steps 904 and 905 are repeated, and the access network device does not always receive a response from the terminal. The access network device sends inventory completion information to the core network device. The core network device sends the inventory results to the first requester, where the inventory results may be empty.
[0550] In another possible example, when steps 904 and 905 are performed (or repeatedly performed), the terminal of the first company may respond. This case may apply when the EPC registered by the second company is identical to the EPC registered by the first company. The inventory results may include terminal information of the first company.
[0551] The above describes the method in the embodiments of this application, and the following describes the apparatus in the embodiments of this application. The method and apparatus are based on the same technical concept. The method and apparatus have similar principles for solving the problem. Therefore, the implementation of the apparatus and method should be referenced from each other. Details are not repeated here.
[0552] In embodiments of the present application, the device may be divided into functional modules based on the examples of the methods described above. For example, the device may be divided into functional modules corresponding to functions, or two or more functions may be integrated into a single module. These modules may be implemented in hardware form or in the form of software functional modules. Note that in embodiments of the present application, the modularization is illustrative and merely a logical functional division. In specific implementations, other division methods may be used.
[0553] Based on the same technical concept as described above, Figure 12 provides a diagram of the structure of the communication device 1000. The communication device 1000 may include one or more of the following: a processing module 1010, a receiving module 1020a, a transmitting module 1020b, and a storage module 1030. The processing module 1010 may be connected separately to the storage module 1030, the receiving module 1020a, and the transmitting module 1020b. The storage module 1030 may also be connected to the receiving module 1020a and the transmitting module 1020b.
[0554] In the example, the receiving module 1020a and the transmitting module 1020b may, alternatively, be integrated together and defined as a transceiver module.
[0555] In the example, the communication device 1000 may be a core network device, or a chip or functional unit used in a core network device. The communication device 1000 may have any of the functions of the core network device in the method described above. For example, the communication device 1000 may perform steps performed by the core network device in the method shown in Figures 2 to 11.
[0556] The receiving module 1020a may perform the receiving operation performed by the core network device in the embodiment of the method described above.
[0557] The transmitting module 1020b may perform the transmission operation performed by the core network device in the embodiment of the method described above.
[0558] The processing module 1010 can perform operations other than the transmission and reception operations in the operations performed by the core network device in the embodiment of the above method.
[0559] In this example, the receiving module 1020a is configured to receive first information from the requester, which instructs a first terminal; the processing module 1010 is configured to obtain an operator identification code assigned to the first terminal by an operator device; and the transmitting module 1020b is configured to transmit second information to the first terminal, which instructs the first terminal to save the operator identification code.
[0560] In the example, the operator identification code includes the public land mobile network identifier (PLMN ID).
[0561] In the example, the operator identification code further includes: a first electronic product code (EPC), a company code assigned to the first terminal, and one or more unique identification codes for the first terminal in the operator device mapped from the first electronic product code (EPC), where the first EPC is assigned by the operator device or the first EPC is from the requester.
[0562] In the example, the second piece of information further includes the first location information for storing the operator identification code.
[0563] In the example, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned to the first terminal by an operator device, or the first EPC is from the requester.
[0564] In the example, the second piece of information further includes second location information for saving the first EPC.
[0565] In the example, the first information includes one or more of the following: the tag identifier (TID) type of the first terminal, the default electronic product code (EPC) of the first terminal, and information about the requester, where the requester manages the first terminal.
[0566] In the example, the transmitting module 1020b is further configured to transmit a third piece of information to an access network device, which instructs the device to search for a first terminal and to receive a default electronic product code (EPC) from the first terminal.
[0567] In the example, the third piece of information includes one or both of the following: the tag identifier (TID) type of the first terminal, and the default electronic product code (EPC) of the first terminal.
[0568] In the example, the receiving module 1020a is further configured to receive a fourth piece of information from the requester, which indicates a first terminal; the transmitting module 1020b is further configured to transmit a fifth piece of information to an access network device, which instructs the device to search for the first terminal; the receiving module 1020a is further configured to receive a first EPC assigned to the first terminal; the transmitting module 1020b is further configured to request the first terminal to obtain an operator identification code assigned to the first terminal based on the first EPC; the receiving module 1020a is further configured to receive an operator identification code assigned to the first terminal; and the processing module 1010 is further configured to trigger authentication between the first terminal and the operator device based on the operator identification code.
[0569] In the example, the receiving module 1020a is further configured to receive a fourth piece of information from the requester, which indicates a first terminal; the transmitting module 1020b is further configured to transmit a fifth piece of information to an access network device, which indicates a request to search for the first terminal and to obtain an operator identification code assigned to the first terminal; the receiving module 1020a is further configured to receive the operator identification code assigned to the first terminal; and the processing module 1010 is further configured to trigger authentication between the first terminal and the operator device based on the operator identification code.
[0570] In this example, the receiving module 1020a is further configured to receive a fourth piece of information from the requester, which indicates a first terminal; the transmitting module 1020b is further configured to send a fifth piece of information to an access network device, which instructs the device to search for the first terminal; the receiving module 1020a is further configured to receive an operator identification code assigned to the first terminal; and the processing module 1010 is further configured to trigger authentication between the first terminal and the operator device based on the operator identification code.
[0571] In the example, the fourth piece of information includes information about the requester, who manages the first terminal; the processing module 1010 is further configured to determine a public land mobile network identifier (PLMN ID) assigned to the first terminal based on the information about the requester, and the fifth piece of information includes the assigned PLMN ID.
[0572] In the example, the enterprise identifier assigned to the first terminal is determined based on information about the requester, and the fifth piece of information further includes the assigned enterprise identifier.
[0573] In the example, the fourth piece of information includes one or more of the following: the first electronic product code EPC of the first terminal, the TID type of the first terminal, and information about the requester, where the requester manages the first terminal; the fifth piece of information includes one or more of the following: the first electronic product code EPC of the first terminal, the operator identification code associated with the first electronic product code EPC of the first terminal, and the TID type of the first terminal.
[0574] In the example, the processing module 1010 is further configured to determine, based on the operator identification code and subscription information of the first terminal, that the operator needs to perform authentication against the operator identification code.
[0575] In the example, the storage module 1030 may store computer executable instructions in the manner performed by the core network device, and as a result, the processing module 1010, the receiving module 1020a, and the transmitting module 1020b perform the same actions as performed by the core network device in the example.
[0576] For example, a memory module may comprise one or more memories. Memory can be a component in one or more devices or circuits configured to store programs or data. A memory module can be a register, cache, RAM, or similar. A memory module can be integrated into a processing module. A memory module can be ROM or another type of static storage device capable of storing static information and instructions. A memory module can be independent of a processing module.
[0577] The transmit / receive module may consist of input / output interfaces, pins, circuits, or similar components.
[0578] In the example, the communication device 1000 may be the first terminal, or it may be a chip or functional unit used in the first terminal. The communication device 1000 may have any of the functions of the first terminal in the method described above. For example, the communication device 1000 may perform the steps performed by the first terminal in the method shown in Figures 2 to 9.
[0579] The receiving module 1020a may perform the receiving operation performed by the first terminal in the embodiment of the above method.
[0580] The transmitting module 1020b may perform the transmission operation performed by the first terminal in the embodiment of the method described above.
[0581] The processing module 1010 can perform operations other than the transmission and reception operations in the operations performed by the first terminal in the embodiment of the above method.
[0582] In this example, the receiving module 1020a is configured to receive second information from a core network device, instructing a first terminal to store an operator identification code, which is assigned to the first terminal by the operator device; and the processing module 1010 is configured to store the operator identification code.
[0583] In the example, the second information further includes first location information for storing the operator identification code; the processing module 1010 is specifically configured to store the operator identification code in a first storage location corresponding to the first location information.
[0584] In the example, the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by an operator device or is from a requester; the processing module 1010 is specifically configured to store the first EPC.
[0585] In the example, the second information further includes second location information for storing the first EPC; the processing module 1010 is specifically configured to store the first EPC in a second storage location corresponding to the second location information.
[0586] In this example, the transmission module 1020b is configured to transmit the default electronic product code (EPC) of the first terminal to the second core network device via an access network device.
[0587] In the example, the storage module 1030 may store computer executable instructions in a manner that is executed by the first terminal, and as a result, the processing module 1010, the receiving module 1020a, and the transmitting module 1020b execute the manner that is executed by the first terminal in the example above.
[0588] For example, a memory module may comprise one or more memories. Memory can be a component in one or more devices or circuits configured to store programs or data. A memory module can be a register, cache, RAM, or similar. A memory module can be integrated into a processing module. A memory module can be ROM or another type of static storage device capable of storing static information and instructions. A memory module can be independent of a processing module.
[0589] The transmit / receive module may consist of input / output interfaces, pins, circuits, or similar components.
[0590] As a possible product form, the device can be implemented by using a general-purpose bus architecture.
[0591] Figure 13 is a schematic block diagram of the communication device 1100.
[0592] The communication device 1100 may include one or more of the following: a processor 1110, a transceiver 1120, and a memory 1130. The transceiver 1120 may be configured to receive programs or instructions and transmit programs or instructions to the processor 1110. Alternatively, the transceiver 1120 may be configured to perform communication interactions between the communication device 1100 and another communication device, for example, by exchanging control signaling and / or service data. The transceiver 1120 may be a code and / or data read / write transceiver, or the transceiver 1120 may be a signal transmission transceiver between the processor and the transceiver. The processor 1110 and the memory 1130 are electrically coupled.
[0593] In the example, the communication device 1100 may be a core network device or a chip used in a core network device. The device should be understood to have any of the functions of the core network device in the manner described above. For example, the communication device 1100 can perform steps performed by the core network device in the manner shown in Figures 2 to 11. For example, memory 1130 is configured to store computer programs or instructions. The processor 1110 may be configured to call the computer programs or instructions stored in memory 1130 to perform the method performed by the core network device in the example above, or to perform the method performed by the core network device in the example above through the transceiver 1120.
[0594] The processing module 1010 in Figure 12 can be implemented by using the processor 1110.
[0595] The receiving module 1020a and transmitting module 1020b in Figure 12 can be implemented using a transceiver 1120. Alternatively, the transceiver 1120 includes a receiver and a transmitter. The receiver performs the functions of the receiving module, and the transmitter performs the functions of the transmitting module.
[0596] The storage module 1030 in Figure 12 can be implemented by using memory 1130.
[0597] In the example, the communication device 1100 may be the first terminal or a chip used in the first terminal. The device should be understood to have any of the functions of the first terminal in the above method. For example, the communication device 1100 may perform the steps performed by the first terminal in the method shown in Figures 2 to 9. For example, the memory 1130 is configured to store a computer program. The processor 1110 may be configured to call the computer program or instructions stored in the memory 1130 to perform the method performed by the first terminal in the above example, or to perform the method performed by the first terminal in the above example through the transceiver 1120.
[0598] The processing module 1010 in Figure 12 can be implemented by using the processor 1110.
[0599] The receiving module 1020a and transmitting module 1020b in Figure 12 can be implemented using a transceiver 1120. Alternatively, the transceiver 1120 includes a receiver and a transmitter. The receiver performs the functions of the receiving module, and the transmitter performs the functions of the transmitting module.
[0600] The storage module 1030 in Figure 12 can be implemented by using memory 1130.
[0601] As a possible product form, the device can be implemented using a general-purpose processor (a general-purpose processor may also be referred to as a chip or chip system).
[0602] In possible implementations, a general-purpose processor implementing a device used in a core network device or a first terminal includes a processing circuit (which may also be referred to as a processor); optionally further including an input / output interface and a storage medium (which may also be referred to as memory) that are internally connected to and communicate with the processing circuit. The storage medium is configured to store instructions that are executed by the processing circuit to perform the method performed by the core network device in the above example.
[0603] The processing module 1010 in Figure 12 can be implemented by using a processing circuit.
[0604] The receiving module 1020a and transmitting module 1020b in Figure 12 can be implemented using an input / output interface. Alternatively, the input / output interface includes an input interface and an output interface. The input interface performs the functions of the receiving module, and the output interface performs the functions of the transmitting module.
[0605] The storage module 1030 in Figure 12 can be implemented by using a storage medium.
[0606] As possible product forms, the apparatus in the embodiments of this application may be implemented by using: one or more FPGAs (Field Programmable Gate Arrays), PLDs (Programmable Logic Devices), controllers, state machines, gate logic, discrete hardware components, and any other suitable circuitry, or any combination of circuitry capable of performing the various functions described herein.
[0607] Embodiments of the present invention further provide a computer-readable storage medium for storing computer programs. When a computer program is executed by a computer, the computer may be able to perform the above-described communication method. In other words, the computer program includes instructions for implementing the above-described communication method.
[0608] Embodiments of the present invention further provide a computer program product, which includes computer program code. When the computer program code is executed on a computer, the computer is capable of performing the communication method described above.
[0609] Embodiments of the present invention further provide a communication system, the communication system comprising at least two of the following: a core network device performing the above communication method, a first terminal of another core network device, and a requester.
[0610] In addition, the processor referred to in the embodiments of this application may be a central processing unit (CPU) or a baseband processor. The baseband processor and CPU may be integrated or separate, or may be a network processor (NP) or a combination of CPU and NP. The processor may further include a hardware chip or another general-purpose processor. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), and another programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or the same, or any combination thereof. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor or the same.
[0611] The memory referred to in the embodiments of this application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. Through this example-only and non-exclusive description, many forms of RAM may be used, such as static random access memory (Static RAM, SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (Synchlink DRAM, SLDRAM), and direct rambus random access memory (Direct Rambus RAM, DR RAM). It should be noted that the memories described herein include, but are not limited to, these memories and any other suitable type of memory.
[0612] The transceiver referred to in the embodiments of the present application may include a separate transmitter and / or a separate receiver, or the transmitter and receiver may be integrated. The transceiver may operate as directed by the corresponding processor. Optionally, the transmitter may correspond to a transmitter in a physical device, and the receiver may correspond to a receiver in a physical device.
[0613] Those skilled in the art will recognize, in combination with the examples described in the embodiments disclosed herein, that the methods, steps, and units may be implemented using electronic hardware, computer software, or a combination thereof. To clearly indicate that hardware and software are interchangeable, the steps and compositions of each embodiment are generally described above based on function. Whether the function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described function for each specific application, but such implementations should not be considered beyond the scope of this application.
[0614] In the various embodiments provided herein, the systems, apparatus, and methods disclosed may be implemented in other ways. For example, the embodiments of the apparatus described are merely examples. For example, the division into units is merely a logical functional division, and other divisions may occur during actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not performed. In addition, the mutual coupling, direct coupling, or communication connection shown or described may be implemented through some interface, indirect coupling, or communication connection between the apparatus or units, or through electrical, mechanical, or other forms of connection.
[0615] Units described as separate parts may or may not be physically separate, and parts shown as units may or may not be physical units, and may be located in one place or distributed across multiple network units. Some or all of the units may be selected on a practical basis to achieve the objectives of the solutions of the embodiments of the present application.
[0616] In addition, the functional units in the embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically independently, or two or more units may be integrated into a single unit. The integrated unit may be implemented in hardware form or in the form of a software functional unit.
[0617] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, the integrated unit may be stored on a computer-readable storage medium. Based on such understanding, the technical solution in this application, either essentially, or a portion contributing to the prior art, or all or part of the technical solution, may be represented in the form of a software product. The computer software product is stored on a storage medium and includes a number of instructions for instructing a computer device (which may be a personal computer, server, network device, or similar) to perform all or part of the steps of the method described in the embodiments of this application. The storage medium includes any medium capable of storing program code, such as a USB flash drive, a removable hard disk drive, read-only memory (ROM), random access memory (RAM), a magnetic disk, or an optical disk.
[0618] While preferred embodiments of the present application are described, those skilled in the art may modify and alter these embodiments after understanding the basic concept of the invention. Therefore, the following claims are intended to be construed as encompassing the preferred embodiments and all modifications and alterations that fall within the scope of the present application.
[0619] Naturally, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of the embodiments. In this way, this application is intended to encompass such modifications and variations to the embodiments of this application, insofar as they fall within the scope of protection defined by the following claims and the equivalent art of this application. (Other possible items) (Item 1) A communication method applicable to core network devices: In the stage of receiving first information from the requester, the first information indicates a first terminal; The steps include: obtaining an operator identification code assigned to the first terminal by the operator device; and In the step of transmitting the second information to the first terminal, the second information instructs the first terminal to save the operator identification code. A method for providing this. (Item 2) The operator identification code includes a public land mobile network identifier (PLMN) ID, as described in item 1. (Item 3) The operator identification code further includes: a first electronic product code (EPC), a company code assigned to the first terminal, and one or more unique identification codes for the first terminal in the operator device, mapped from the first electronic product code (EPC), where The first EPC is assigned by the operator device, or the first EPC is from the requester. The method described in item 2. (Item 4) The method according to any one of items 1 to 3, wherein the second information further includes first location information for storing the operator identification code. (Item 5) The method according to any one of items 1 to 4, wherein the second information further instructs the first terminal to store the first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned to the first terminal by the operator device, or the first EPC is from the requester. (Item 6) The method according to item 5, wherein the second information further includes second location information for saving the first EPC. (Item 7) After the step of receiving the first information from the requester, the method further: In the step of obtaining the key corresponding to the first terminal, here The second information further instructs the first terminal to store the corresponding first key. The method according to any one of items 1 to 6, comprising: (Item 8) The method according to item 7, wherein the second information further includes a third location information for storing the first key. (Item 9) The first piece of information mentioned above is: The method according to any one of items 1 to 8, comprising one or more of the following: the tag identifier TID type of the first terminal, the default electronic product code EPC of the first terminal, and information about the requester, wherein the requester manages the first terminal. (Item 10) Prior to the step of transmitting the second information to the first terminal, the method further: The third information is transmitted to the access network device, where the third information instructs it to search for the first terminal; and The stage of receiving the default electronic product code EPC from the first terminal. The method according to any one of items 1 to 9, comprising: (Item 11) The third piece of information mentioned above is: The tag identifier TID type of the first terminal, and the default electronic product code EPC of the first terminal The method described in item 10, which includes one or both of the above. (Item 12) The aforementioned method further: In the step of receiving a fourth piece of information from the requester, the fourth piece of information indicates the first terminal; In the step of transmitting the fifth piece of information to the access network device, the fifth piece of information instructs the device to search for the first terminal; The step of receiving the first EPC assigned to the first terminal; A step of requesting the first terminal to obtain the operator identification code assigned to the first terminal, based on the first EPC; The step of receiving the operator identification code assigned to the first terminal; and A step in which authentication between the first terminal and the operator device is triggered based on the operator identification code. The method according to any one of items 1 to 11, comprising: (Item 13) The aforementioned method further: In the step of receiving a fourth piece of information from the requester, the fourth piece of information indicates the first terminal; In the step of transmitting the fifth piece of information to the access network device, the fifth piece of information instructs the device to search for the first terminal and to obtain the operator identification code assigned to the first terminal; The step of receiving the operator identification code assigned to the first terminal; and A step in which authentication between the first terminal and the operator device is triggered based on the operator identification code. The method according to any one of items 1 to 11, comprising: (Item 14) The aforementioned method further: In the step of receiving a fourth piece of information from the requester, the fourth piece of information indicates the first terminal; In the step of transmitting the fifth piece of information to the access network device, the fifth piece of information instructs the device to search for the first terminal; The step of receiving the operator identification code assigned to the first terminal; and A step in which authentication between the first terminal and the operator device is triggered based on the operator identification code. The method according to any one of items 1 to 11, comprising: (Item 15) The fourth information includes the information about the requester, the requester manages the first terminal; and prior to the step of transmitting the fifth information to the access network device, the method further: A step in which, based on the information about the requester, the public land mobile network identifier PLMN ID assigned to the first terminal is determined, The fifth piece of information includes the assigned PLMN ID, The method according to any one of items 12 to 14, comprising: (Item 16) Prior to the step of transmitting the fifth piece of information to the access network device, the method further: Based on the information about the requester, the step of determining the corporate identifier assigned to the first terminal, where The fifth information further includes the assigned company identifier, The method described in item 15, comprising: (Item 17) The aforementioned company identifier is the company code assigned to the first terminal; or The aforementioned company identifier is the service identifier in the CompanyPrefix in the electronic product code EPC memory bank of the first terminal. The method described in item 16. (Item 18) The fourth information includes: the first electronic product code EPC of the first terminal, the TID type of the first terminal, and one or more of the information about the requester, where the requester manages the first terminal; and The fifth piece of information mentioned above is: The first electronic product code EPC of the first terminal, the operator identification code associated with the first electronic product code EPC of the first terminal, and the TID type of the first terminal. The method described in any one of items 12 to 17, including one or more of the following. (Item 19) Prior to the step of triggering authentication between the first terminal and the operator device based on the operator identification code, the method further: A step in which the operator determines, based on the operator identification code and the subscription information of the first terminal, that authentication must be performed against the operator identification code. The method according to any one of items 12 to 18, comprising: (Item 20) A communication method applicable to the first terminal: The second information is received from the core network device, where the second information instructs the first terminal to store an operator identification code, and the operator identification code is assigned to the first terminal by the operator device; and Step of saving the aforementioned operator identification code A method for providing this. (Item 21) The second information further includes: first location information for storing the operator identification code; The step of saving the aforementioned operator identification code is: Steps to store the operator identification code in a first storage location corresponding to the first location information. The method described in item 20, including the method described in item 20. (Item 22) The second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by the operator device or the first EPC is from the requester; The aforementioned method further: The stage of saving the above-mentioned EPC 1 The method according to item 20 or 21, comprising: (Item 23) The second information further includes second location information for saving the first EPC; The step of saving the first EPC is: Steps to save the first EPC to a second storage location corresponding to the second location information. The method described in item 22, including the method described in item 22. (Item 24) The second information further instructs the first terminal to store the first key corresponding to the first terminal; The aforementioned method further: The step of saving the first key. The method according to any one of items 20 to 23, comprising: (Item 25) The second information further includes a third location information for storing the first key; The first step of saving the key is: Steps to store the first key in a third memory location corresponding to the third location information. The method described in item 24, including the method described in item 24. (Item 26) Prior to the step of receiving the second information from the second core network device, the method further: The stage of accessing an access network device; and Steps to transmit the default electronic product code (EPC) of the first terminal to the second core network device via the access network device. The method according to any one of items 20 to 25, comprising: (Item 27) A communication device comprising a functional module for implementing the method described in any one of items 1 through 26. (Item 28) A communication device comprising a processor, wherein the processor is coupled to memory; The memory is configured to store computer programs or instructions; The processor is configured to execute all or part of the computer program or instructions in the memory; when executing all or part of the computer program or instructions, the processor is configured to implement the method described in any one of items 1 to 26. Communication device. (Item 29) A communication device comprising a processor and memory, The memory is configured to store computer programs or instructions; The processor is configured to execute all or part of the computer program or instructions in the memory; when executing all or part of the computer program or instructions, the processor is configured to implement the method described in any one of items 1 to 26. Communication device. (Item 30) A chip system comprising a processing circuit, wherein the processing circuit is coupled to a storage medium; The processing circuit is configured to execute all or part of a computer program or instructions in the storage medium; when executing all or part of the computer program or instructions, the processing circuit is configured to implement the method described in any one of items 1 to 26. Chip system. (Item 31) A computer-readable storage medium configured to store a computer program, wherein the computer program includes instructions for implementing the method described in any one of items 1 to 26. (Item 32) A computer program product comprising computer program code; wherein, when the computer program code is executed on a computer, the computer is capable of performing the method described in any one of items 1 to 26. < / mcc> < / mnc> < / stid> < / mcc> < / mnc> < / epc> < / epc> < / mcc> < / mnc> < / imsi>
Claims
1. A communication method applicable to core network devices: The first step involves receiving first information from a requester corresponding to a first terminal, where the first information indicates the first terminal corresponding to the requester; A step of obtaining an operator identification code assigned to one or more terminals by an operator device, wherein the acquisition step includes a step of identifying the operator identification code assigned to the first terminal based on the first information; and In the step of transmitting the second information to the first terminal, the second information instructs the first terminal to save the operator identification code assigned to the first terminal. A method for providing this.
2. The method according to claim 1, wherein the operator identification code includes a public land mobile network identifier (PLMN ID).
3. The operator identification code further includes: a first electronic product code (EPC), a company code assigned to the first terminal, and one or more unique identification codes for the first terminal in the operator device, mapped from the first electronic product code (EPC), where The first EPC is assigned by the operator device, or the first EPC is from the requester. The method according to claim 2.
4. The method according to claim 1, wherein the second information further includes first location information for storing the operator identification code.
5. The method according to claim 1, wherein the second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, wherein the first EPC is assigned to the first terminal by the operator device, or the first EPC is from the requester.
6. The method according to claim 5, wherein the second information further includes second location information for storing the first EPC.
7. A communication device comprising a functional module for implementing the method described in any one of claims 1 to 6.
8. A chip system comprising a processing circuit, wherein the processing circuit is coupled to a storage medium; The processing circuit is configured to execute part or all of the computer program or instructions in the storage medium; when executing part or all of the computer program or instructions, the processing circuit is configured to implement the method according to any one of claims 1 to 6. Chip system.
9. A computer program comprising computer program code, wherein when the computer program code is executed on a computer, the computer is capable of performing the method according to any one of claims 1 to 6.
10. A communication method applicable to the first terminal: The second information is received from the core network device, where the second information instructs the first terminal to store an operator identification code, and the operator identification code is assigned to the first terminal by the operator device; and Steps to save the operator identification code assigned to the first terminal. A method for providing this.
11. The second information further includes: first location information for storing the operator identification code; The step of saving the aforementioned operator identification code is: Steps to store the operator identification code in a first storage location corresponding to the first location information. The method according to claim 10, including the method described in claim 10.
12. The second information further instructs the first terminal to store a first electronic product code EPC corresponding to the first terminal, where the first EPC is assigned by the operator device, or the first EPC is from a requester corresponding to the first terminal; The aforementioned method further: Step of saving the first EPC The method according to claim 10, comprising:
13. The second information further includes second location information for saving the first EPC; The step of saving the first EPC is: Steps to store the first EPC in a second memory location corresponding to the second location information. The method according to claim 12, including the method described in claim 12.
14. The second information further instructs the first terminal to store the first key corresponding to the first terminal; The aforementioned method further: Step of saving the first key The method according to claim 10, comprising:
15. The second information further includes a third location information for storing the first key; The first step of saving the key is: Steps to store the first key in a third memory location corresponding to the third location information. The method according to claim 14, including the method described in claim 14.
16. The method according to claim 10, wherein the operator identification code includes a public land mobile network identifier (PLMN) ID.
17. A communication device comprising a functional module for implementing the method described in any one of claims 10 to 16.
18. A chip system comprising a processing circuit, wherein the processing circuit is coupled to a storage medium; The processing circuit is configured to execute part or all of the computer program or instructions in the storage medium; when executing part or all of the computer program or instructions, the processing circuit is configured to implement the method according to any one of claims 10 to 16. Chip system.
19. A computer program comprising computer program code, wherein when the computer program code is executed on a computer, the computer is capable of performing the method according to any one of claims 10 to 16.